> Is this mostly key rotation plus address format churn
No, the hard part is the long tail of already-published pubkeys and dormant outputs, not the address encoding. Once a key is exposed on-chain you cant just rotate it away, you need some migration path that can move value without trusting every old signer to come back online, and that gets ugly fast for pre-signed scripts and lost keys.