Block height
Cutoff
H0 is published in advance. Before it, ECDSA still spends. At H0 and after, only a hash-based signature does.
Before H0
One ECDSA transaction moves the full balance onto a new bc1q address. The address that revealed its key ends at zero.
H0 and after
Auth is SPHINCS over SHA-256 or BLAKE. An ECDSA signature is dropped, including one made from a recovered private key.
NS(out) = 1 iff
version = 0
program = HASH160(pk)
length(program) = 20
pk is not in the output
VALID(tx, h) = 1 iff
h < H0 and auth = ECDSA and outputs are NS
or h >= H0 and auth = SPHINCS(SHA-256 | BLAKE)
ECDSA at h >= H0 → rejected
What a node checks
Before H0, a transaction is valid if its authorization is an ECDSA signature and every output that holds the value is native segwit. That is the migration. One signature, full balance, new bc1q.
At H0 and after, the same ECDSA signature is not an authorization. The node does not need to decide whether the signature is mathematically correct. The rule is that ECDSA is no longer sufficient. The spend has to carry SPHINCS over SHA-256 or BLAKE. Curves, lattices, and isogenies are not added as substitutes.
A recovered key
If someone can compute the private key from a public key, they can produce a normal 64-byte signature. After H0 that signature still does not enter a block under this rule. Coins that were never moved are frozen against ECDSA too. The chain cannot tell the owner from the attacker once the key is public, so it stops accepting ECDSA for both. Moving before H0 is how the owner keeps a hash-based way to spend.