Pulled this off the wiki's hardfork wishlist (since it doesn't require any forking):
- Allow insertion of "permanent forwarding directive" transaction, so that a well-known public address with a (suspected or soon-to-be) compromised private key can be replaced for all signing/paying purposes with a new address. (This directive might only be insertable if approved by N-of-M prior declared guardian keys. The directive might involve a one-time fee, after which the old address is null and the new address replaces it in perpetuity, or might include a declared service fee that can be deducted to miners on each future use of the new-key to draw on dead-key outputs.)