But since it'll take years to have a good solution implemented, we better start now.
I don't want any quantum solution to be replacing our current elliptic curve, just added to it. That way, any btc sent to a quantum-resistant address would require both signatures to be spent. The btc in old addresses, should never be consfiscated and always usable with the same old signatures.
We would get a choice : pay more fees to use an additional (big) signature or go cheap and cross your fingers.