{"id":1541,"date":"2026-09-20T13:15:25","date_gmt":"2026-09-20T05:15:25","guid":{"rendered":"https:\/\/btbitcoin.net\/index.php\/2026\/09\/20\/bitcoin-quantum-risk-7m-btc-exposed-bip-360-2026\/"},"modified":"2026-09-20T13:15:25","modified_gmt":"2026-09-20T05:15:25","slug":"bitcoin-quantum-risk-7m-btc-exposed-bip-360-2026","status":"publish","type":"post","link":"https:\/\/btbitcoin.net\/index.php\/2026\/09\/20\/bitcoin-quantum-risk-7m-btc-exposed-bip-360-2026\/","title":{"rendered":"Bitcoin Quantum Risk: 7M BTC Exposed, BIP-360 [2026]"},"content":{"rendered":"<p class=\"wp-block-paragraph\">A little over one-third of all bitcoin in circulation now sits in addresses that a sufficiently powerful quantum computer could theoretically drain, according to wallet-scanning research that has moved from academic sidebar to boardroom agenda item in 2026. Project Eleven, a startup dedicated to tracking Bitcoin\u2019s quantum exposure, put a number on the problem: roughly 6.99 million BTC live in addresses with exposed public keys, out of about 14 million addresses it scanned with non-zero balances. Coinbase\u2019s internal quantum advisory work reached a similar figure, near 7 million BTC, and flagged that much of that exposure sits in active wallets and exchange cold storage, not just coins abandoned since the Satoshi era.<\/p>\n<nav class=\"ti-toc collapsed\" aria-label=\"Table of Contents\">\n<div class=\"ti-toc-header\">\n<h3 class=\"ti-toc-title\">Table of Contents<\/h3>\n<p><button class=\"ti-toc-toggle\" onclick=\"this.closest('.ti-toc').classList.toggle('collapsed')\" aria-label=\"Toggle table of contents\"><svg width=\"12\" height=\"12\" viewbox=\"0 0 12 12\" fill=\"currentColor\"><path d=\"M2 4l4 4 4-4z\"\/><\/svg><\/button><\/div>\n<ol class=\"ti-toc-list\">\n<li>The Numbers Behind Bitcoin\u2019s Quantum Exposure Problem<\/li>\n<li>BIP-360 and the P2QRH Proposal: What\u2019s Actually on the Table<\/li>\n<li>NIST\u2019s Post-Quantum Standards: Where the Reference Framework Stands<\/li>\n<li>Q-Day Timelines: Optimists, Pessimists, and the Middle Ground<\/li>\n<li>Why Exchanges and Wallet Vendors Are Moving Now, Not Later<\/li>\n<li>Historical Context: This Isn\u2019t Bitcoin\u2019s First Cryptographic Scare<\/li>\n<li>Market Impact: How Traders and Institutions Are Pricing the Risk<\/li>\n<li>Competitive Comparison: How Other Chains Are Handling Post-Quantum Risk<\/li>\n<li>The Address-Reuse Problem Is Bigger Than Quantum Computing<\/li>\n<li>What Happens to Coins Whose Owners Never Move Them<\/li>\n<li>Predictions: Where This Goes From Here<\/li>\n<li>How Individual Holders Can Reduce Exposure Today<\/li>\n<li>Frequently Asked Questions<\/li>\n<ol class=\"ti-toc-sub\">\n<li>Related Coverage<\/li>\n<\/ol>\n<\/ol>\n<\/nav>\n<p class=\"wp-block-paragraph\">That\u2019s the backdrop for a debate that has split the Bitcoin developer community this year: whether to force through a consensus change, BIP-360, that would give the network a quantum-resistant address format before a \u201cQ-Day\u201d ever arrives. The fight isn\u2019t really about cryptography anymore. It\u2019s about timing, coordination costs, and who moves first when 7 million BTC, worth hundreds of billions of dollars at current prices, is the collateral at stake.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-numbers-behind-bitcoins-quantum-exposure-problem\">The Numbers Behind Bitcoin\u2019s Quantum Exposure Problem<\/h2>\n<p class=\"wp-block-paragraph\">Bitcoin\u2019s public-key cryptography relies on the elliptic curve digital signature algorithm, or ECDSA, over the secp256k1 curve. That scheme is considered safe against classical computers for the foreseeable future. It is not considered safe against a large-scale, fault-tolerant quantum computer running Shor\u2019s algorithm, which can derive a private key from a known public key in a fraction of the time classical hardware would need. The catch is narrower than headlines suggest: an attacker needs the actual public key, not just the wallet address, which is a hashed version of it.<\/p>\n<p class=\"wp-block-paragraph\">That distinction is why the exposure breakdown matters so much. Project Eleven\u2019s data shows address reuse is the single biggest culprit, accounting for close to 4.99 million BTC, or about 72% of the exposed total. Every time a bitcoin address is used more than once, the public key that gets revealed on the first outgoing transaction stays visible on the blockchain forever after. Legacy P2PK (pay-to-public-key) outputs, a format barely used today but common in Bitcoin\u2019s earliest years, add another 1.72 million BTC, about 25% of the exposed figure, because those outputs show the raw public key from the moment they\u2019re created. Even newer Taproot (P2TR) addresses aren\u2019t fully immune: researchers flagged around 198,000 BTC, close to 3% of the exposed total, because Taproot\u2019s x-only public key format still becomes visible on-chain under certain spending conditions.<\/p>\n<p class=\"wp-block-paragraph\">Coinbase\u2019s quantum work reached a comparable split, estimating close to 1.7 million BTC sit across roughly 20,000 legacy P2PK addresses where the key has been exposed since inception, and about 5 million BTC more where the key was revealed at some point through a spend. The overlap between these datasets, produced independently by a startup and an exchange, is part of why the estimate has held up as the reference figure cited across the industry this year.<\/p>\n<table>\n<thead>\n<tr>\n<th>Exposure category<\/th>\n<th>Estimated BTC at risk<\/th>\n<th>Share of exposed total<\/th>\n<th>Why it\u2019s exposed<\/th>\n<\/tr>\n<\/thead>\n<tbody readability=\"5\">\n<tr readability=\"3\">\n<td>Address reuse (any type)<\/td>\n<td>~4.99 million BTC<\/td>\n<td>~72.3%<\/td>\n<td>Public key revealed on first spend, stays visible forever<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Legacy P2PK outputs<\/td>\n<td>~1.72 million BTC<\/td>\n<td>~24.8%<\/td>\n<td>Raw public key visible from address creation<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Taproot (P2TR) outputs<\/td>\n<td>~198,000 BTC<\/td>\n<td>~2.9%<\/td>\n<td>X-only public key exposed under certain spend paths<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>Total flagged exposure<\/td>\n<td>~6.99 million BTC<\/td>\n<td>~100%<\/td>\n<td>Combined dataset, Project Eleven scan of 14M+ addresses<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"wp-block-paragraph\">Put in dollar terms at current bitcoin prices, that exposed pool represents a meaningful fraction of the network\u2019s total value, and it includes coins that are actively traded, not just relics. That\u2019s the detail that turned this from an academic curiosity into an item on exchange risk committees\u2019 agendas this year.<\/p>\n<h2 class=\"wp-block-heading\" id=\"bip-360-and-the-p2qrh-proposal-whats-actually-on-the-table\">BIP-360 and the P2QRH Proposal: What\u2019s Actually on the Table<\/h2>\n<p class=\"wp-block-paragraph\">The main technical response under discussion is BIP-360, authored by developer Hunter Beast, which proposes a new address type called P2QRH, short for pay-to-quantum-resistant-hash. The design borrows a page from Taproot\u2019s playbook: instead of putting a raw public key on-chain, it commits to a hash of quantum-resistant signature data, keeping the actual key material hidden until the owner is ready to spend, and only briefly exposed at that point. Galaxy\u2019s research team, which has published some of the more detailed technical breakdowns this year, describes the approach as a soft fork, meaning it could theoretically be adopted without splitting the network the way a hard fork would.<\/p>\n<p class=\"wp-block-paragraph\">The mechanics matter because Bitcoin has no central authority to flip a switch. A quantum-resistant address format only protects funds once users actually move their coins into it. Coins sitting in old-format addresses stay exposed no matter what gets merged into Bitcoin Core, unless the network also implements some kind of forced migration, freeze, or clawback mechanism for unmoved legacy funds, an idea that is far more contentious than the signature scheme itself, since it touches Bitcoin\u2019s core promise that nobody can be forced to move funds they control.<\/p>\n<p class=\"wp-block-paragraph\">BIP-360 isn\u2019t the only proposal that has circulated, but it has become the reference point in 2026 discussions precisely because it tries to solve the exposure problem without touching custody assumptions. Other approaches floated in developer forums include lattice-based signature schemes similar to the NIST-standardized ML-DSA (formerly CRYSTALS-Dilithium) and hash-based schemes like SLH-DSA, both of which trade smaller, faster ECDSA signatures for larger, slower quantum-resistant ones. That tradeoff is a real cost: quantum-resistant signatures generally run several times larger than ECDSA\u2019s roughly 64-72 bytes, which has direct implications for block space and transaction fees if Bitcoin ever migrates its default signature scheme network-wide.<\/p>\n<h2 class=\"wp-block-heading\" id=\"nists-post-quantum-standards-where-the-reference-framework-stands\">NIST\u2019s Post-Quantum Standards: Where the Reference Framework Stands<\/h2>\n<p class=\"wp-block-paragraph\">Bitcoin\u2019s debate doesn\u2019t happen in isolation. The National Institute of Standards and Technology finalized its first set of post-quantum cryptography standards in 2024, covering key encapsulation (ML-KEM, formerly Kyber) and digital signatures (ML-DSA and SLH-DSA). Those standards are already being adopted across the broader internet: Cloudflare has rolled post-quantum key exchange into a large share of its TLS traffic, and browser vendors have shipped hybrid post-quantum key agreement by default in recent releases.<\/p>\n<p class=\"wp-block-paragraph\">Bitcoin\u2019s challenge is different from a TLS handshake, though. A web session\u2019s cryptography can be swapped out server-side overnight. Bitcoin\u2019s consensus rules require broad agreement among miners, node operators, exchanges, and wallet vendors before any change takes effect, and even after a soft fork activates, individual users still have to take action to protect coins sitting in old-format wallets. That coordination gap, more than the math itself, is what security researchers flag as the real risk multiplier: a cryptographic transition that might take a browser vendor a single release cycle could take Bitcoin years.<\/p>\n<h2 class=\"wp-block-heading\" id=\"q-day-timelines-optimists-pessimists-and-the-middle-ground\">Q-Day Timelines: Optimists, Pessimists, and the Middle Ground<\/h2>\n<p class=\"wp-block-paragraph\">\u201cQ-Day,\u201d the informal shorthand for the moment a quantum computer becomes capable of breaking widely deployed public-key cryptography, doesn\u2019t have an agreed date, and that uncertainty is itself part of the story. Estimates tied to Project Eleven\u2019s 2026 research frame a baseline scenario around 2033, with an optimistic (meaning quantum computing advances faster) case of 2030 and a pessimistic case stretching to 2042. That\u2019s an eleven-year spread between the most and least aggressive published estimates, which tells you how immature the forecasting still is.<\/p>\n<p class=\"wp-block-paragraph\">Progress from quantum hardware makers keeps the debate alive. Google\u2019s Willow chip, along with continued milestones from IBM\u2019s superconducting roadmap, has been cited repeatedly in 2026 coverage as evidence that error-corrected, fault-tolerant quantum computing is advancing, even though none of the current generation of quantum processors comes close to the qubit count and error rates needed to actually run Shor\u2019s algorithm against a 256-bit elliptic curve key. Skeptics inside the Bitcoin community make exactly that point: the threat is real in principle but not remotely imminent in practice, and treating it as an emergency risks pushing through consensus changes, and possibly divisive ones around forced migration, before there\u2019s any hardware urgency to justify the risk.<\/p>\n<table>\n<thead>\n<tr>\n<th>Scenario<\/th>\n<th>Estimated Q-Day<\/th>\n<th>Basis<\/th>\n<\/tr>\n<\/thead>\n<tbody readability=\"6\">\n<tr readability=\"4\">\n<td>Optimistic (fast quantum progress)<\/td>\n<td>~2030<\/td>\n<td>Aggressive hardware scaling assumptions<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Baseline<\/td>\n<td>~2033<\/td>\n<td>Current published research consensus<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Pessimistic (slow quantum progress)<\/td>\n<td>~2042<\/td>\n<td>Conservative error-correction and scaling assumptions<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Skeptic position<\/td>\n<td>No fixed date<\/td>\n<td>Argues current hardware isn\u2019t close enough to justify urgency<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"wp-block-heading\" id=\"why-exchanges-and-wallet-vendors-are-moving-now-not-later\">Why Exchanges and Wallet Vendors Are Moving Now, Not Later<\/h2>\n<p class=\"wp-block-paragraph\">Even with a wide range on Q-Day, exchanges have practical reasons to move early. Coinbase\u2019s advisory work on this topic wasn\u2019t published as an alarmist warning, it was framed as inventory and planning, the kind of exercise a large custodian runs on any long-tail risk with a multi-year fuse. Cold storage operators face a specific structural problem: institutional custody wallets often reuse deposit addresses for operational convenience, and consolidating UTXOs (unspent transaction outputs) into fewer addresses, a common treasury practice, can inadvertently expose more public keys rather than fewer.<\/p>\n<p class=\"wp-block-paragraph\">Hardware wallet makers face a parallel migration question. A quantum-resistant signature scheme with a larger key and signature footprint changes firmware requirements, secure element capacity, and potentially the physical design of devices built around today\u2019s ECDSA-sized operations. None of the major hardware wallet vendors has announced a shipped quantum-resistant signing mode as of this year; the work so far is concentrated on research, standards tracking, and roadmap statements rather than production firmware.<\/p>\n<h2 class=\"wp-block-heading\" id=\"historical-context-this-isnt-bitcoins-first-cryptographic-scare\">Historical Context: This Isn\u2019t Bitcoin\u2019s First Cryptographic Scare<\/h2>\n<p class=\"wp-block-paragraph\">Bitcoin has weathered cryptographic anxiety before. The 2017 SegWit and 2021 Taproot activation debates both included side discussions about future-proofing signature schemes, and the broader cryptocurrency industry has already lived through smaller-scale quantum scares, including periodic claims, later walked back or left unsubstantiated, that a breakthrough was imminent. What\u2019s different in 2026 is the quality of the exposure data. Earlier discussions were largely theoretical, arguing about what could happen to an idealized wallet. Project Eleven and Coinbase\u2019s work instead scanned the actual, current state of the blockchain and produced concrete address-level numbers, which is what pushed the conversation from cypherpunk mailing lists into exchange risk assessments and, this year, into mainstream financial press coverage.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s also worth remembering that Bitcoin has successfully executed soft forks before, including Segregated Witness in 2017 and Taproot in 2021, both of which required broad miner and node signaling before locking in. Those precedents give BIP-360 supporters a template to point to. They also show how slow the process can be: Taproot took roughly four years from proposal to activation, and quantum-resistant address adoption, once live, would still need years more for users to actually move funds.<\/p>\n<h2 class=\"wp-block-heading\" id=\"market-impact-how-traders-and-institutions-are-pricing-the-risk\">Market Impact: How Traders and Institutions Are Pricing the Risk<\/h2>\n<p class=\"wp-block-paragraph\">So far, the quantum exposure story hasn\u2019t shown up as a measurable discount in bitcoin\u2019s price, and that\u2019s arguably rational given the Q-Day uncertainty range discussed above. What it has done is shape institutional due diligence. Custody providers evaluating new institutional clients increasingly ask about address reuse policy and UTXO management practices, treating quantum exposure as one input in a broader operational risk score alongside more immediate concerns like key management and multisig configuration.<\/p>\n<p class=\"wp-block-paragraph\">Insurance underwriters covering digital asset custody have also started factoring long-tail cryptographic risk into policy language, generally as an exclusion or a rider rather than a primary rated risk, according to industry discussion of custody insurance terms this year. That\u2019s a meaningfully different posture than five years ago, when quantum risk barely appeared in custody risk questionnaires at all.<\/p>\n<p class=\"wp-block-paragraph\">The more immediate market effect has been on developer mindshare and grant funding. Bitcoin-adjacent research organizations have increased funding for post-quantum cryptography work aimed specifically at Bitcoin\u2019s constraints, namely signature size and verification speed, both of which affect block capacity and fee markets if a new scheme becomes the default rather than an optional address type.<\/p>\n<h2 class=\"wp-block-heading\" id=\"competitive-comparison-how-other-chains-are-handling-post-quantum-risk\">Competitive Comparison: How Other Chains Are Handling Post-Quantum Risk<\/h2>\n<p class=\"wp-block-paragraph\">Bitcoin isn\u2019t the only network with this problem, and comparing approaches is useful context. Ethereum\u2019s roadmap includes post-quantum signature research as part of its longer-term \u201cThe Verge\u201d and account abstraction work, with some proposals aiming to let users opt into quantum-resistant signature schemes at the account level rather than forcing a single network-wide switch. That account-abstraction path is arguably more flexible than Bitcoin\u2019s address-type model, since Ethereum\u2019s smart contract accounts can already support pluggable signature verification logic without a base-layer consensus change.<\/p>\n<p class=\"wp-block-paragraph\">Outside of crypto entirely, the broader internet infrastructure world has moved faster mechanically, if not more completely. TLS 1.3 implementations at companies like Cloudflare and Google have already deployed hybrid post-quantum key exchange in production traffic, something feasible because a web server upgrade doesn\u2019t require the kind of dispersed, adversarial-proof consensus that a public blockchain does. That contrast is the clearest illustration of why \u201cpost-quantum migration\u201d means something very different depending on whether the system in question has a single operator or thousands of independent, mutually distrustful participants.<\/p>\n<table>\n<thead>\n<tr>\n<th>System<\/th>\n<th>Post-quantum approach<\/th>\n<th>Migration mechanism<\/th>\n<th>Status as of 2026<\/th>\n<\/tr>\n<\/thead>\n<tbody readability=\"11.5\">\n<tr readability=\"7\">\n<td>Bitcoin<\/td>\n<td>BIP-360 \/ P2QRH proposed address type<\/td>\n<td>Soft fork + voluntary user migration<\/td>\n<td>Proposal stage, not activated<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Ethereum<\/td>\n<td>Account abstraction + pluggable signatures<\/td>\n<td>Opt-in at smart-contract account level<\/td>\n<td>Research \/ roadmap stage<\/td>\n<\/tr>\n<tr readability=\"7\">\n<td>TLS \/ web infrastructure<\/td>\n<td>Hybrid ML-KEM key exchange (NIST standard)<\/td>\n<td>Server-side rollout, no user action needed<\/td>\n<td>Live in production at major providers<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>DNSSEC (Cloudflare)<\/td>\n<td>Post-quantum signature algorithms<\/td>\n<td>Provider-side rollout<\/td>\n<td>Live, signature volume scaled up significantly in 2026<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"wp-block-heading\" id=\"the-address-reuse-problem-is-bigger-than-quantum-computing\">The Address-Reuse Problem Is Bigger Than Quantum Computing<\/h2>\n<p class=\"wp-block-paragraph\">One point that tends to get lost in quantum coverage: address reuse is bad wallet hygiene regardless of quantum computers. It has always leaked information, linking transactions together for chain analysis firms like Chainalysis and reducing the privacy Bitcoin\u2019s pseudonymous design is supposed to provide. The quantum threat adds a new, more severe consequence to an old best-practice violation, which is part of why some security researchers frame quantum-resistant address adoption less as a novel emergency and more as an opportunity to fix a wallet hygiene problem the ecosystem should have solved already.<\/p>\n<p class=\"wp-block-paragraph\">Practically, that means the near-term advice for individual holders doesn\u2019t require waiting on BIP-360 at all: stop reusing addresses, avoid unnecessary UTXO consolidation that exposes dormant public keys, and treat any address that has ever sent a transaction as public-key-exposed going forward, because it is.<\/p>\n<h2 class=\"wp-block-heading\" id=\"what-happens-to-coins-whose-owners-never-move-them\">What Happens to Coins Whose Owners Never Move Them<\/h2>\n<p class=\"wp-block-paragraph\">The hardest open question in this entire debate has nothing to do with cryptography. It\u2019s about the estimated 1 million-plus BTC widely attributed to Bitcoin\u2019s pseudonymous creator, Satoshi Nakamoto, sitting untouched since the network\u2019s earliest days, entirely in exposed, unmoved, legacy-format addresses. Those coins can\u2019t opt into a new address format because nobody controls them anymore in any active sense. If a fault-tolerant quantum computer ever arrives, that Satoshi-era supply becomes the single largest and most symbolically loaded pool of at-risk bitcoin on the network, and there\u2019s no proposal on the table today that resolves what should happen to it: freeze it permanently, let it be considered fair game, or something in between. That question alone is likely to generate more community conflict than the underlying signature math.<\/p>\n<h2 class=\"wp-block-heading\" id=\"predictions-where-this-goes-from-here\">Predictions: Where This Goes From Here<\/h2>\n<ul class=\"wp-block-list\">\n<li>BIP-360 or a close variant is likely to see continued technical review and testnet experimentation over the next 12 to 18 months, but full mainnet activation before 2028 looks unlikely given Bitcoin\u2019s historical soft-fork timelines.<\/li>\n<li>Expect large custodians and exchanges to publish or update address-reuse policies well ahead of any consensus change, treating it as low-cost risk hygiene rather than waiting for a protocol mandate.<\/li>\n<li>The debate over what happens to unmoved, quantum-exposed legacy coins, including suspected Satoshi-era wallets, will become more politically charged than the cryptographic design itself, and may end up as the primary blocker to consensus.<\/li>\n<li>Hardware wallet vendors will likely announce research roadmaps or firmware previews for larger post-quantum signature support before any of them ship a production quantum-resistant signing mode.<\/li>\n<li>Watch for Ethereum\u2019s account-abstraction-based approach to post-quantum signatures to move faster in practice than Bitcoin\u2019s base-layer address migration, simply because it doesn\u2019t require the same network-wide coordination.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"how-individual-holders-can-reduce-exposure-today\">How Individual Holders Can Reduce Exposure Today<\/h2>\n<p class=\"wp-block-paragraph\">None of this requires waiting for a BIP to activate. Holders who want to cut their personal exposure now can start by generating a fresh receiving address for every transaction instead of reusing one, a setting most modern wallets, including hardware wallets, already support by default with hierarchical deterministic (HD) key derivation. Anyone holding funds in an old wallet created before HD derivation was standard should consider migrating balances to a modern wallet and a fresh seed, moving funds only once and consolidating carefully to avoid triggering unnecessary public-key exposure in the process.<\/p>\n<p class=\"wp-block-paragraph\">For larger holdings, splitting funds across a multisig setup adds a practical layer of defense, since an attacker would need to compromise multiple keys, not just derive one private key from one exposed public key. None of these steps make a Bitcoin wallet quantum-proof. They do meaningfully shrink the pool of exposed, spendable value that any future attack, quantum or otherwise, could target.<\/p>\n<h2 class=\"wp-block-heading\" id=\"frequently-asked-questions\">Frequently Asked Questions<\/h2>\n<p class=\"wp-block-paragraph\"><strong>Is Bitcoin currently vulnerable to a quantum computer attack?<\/strong><br \/>No. No existing quantum computer has the qubit count, error correction, or stability needed to run Shor\u2019s algorithm against a 256-bit elliptic curve key in any practical timeframe. The risk being discussed is a future one, tied to hardware that doesn\u2019t exist yet.<\/p>\n<p class=\"wp-block-paragraph\"><strong>How much bitcoin is actually at risk from quantum computing?<\/strong><br \/>Research from Project Eleven puts the figure at roughly 6.99 million BTC in addresses with exposed public keys, while separate analysis linked to Coinbase\u2019s quantum advisory work estimated a similar figure near 7 million BTC. Both estimates represent close to one-third of circulating supply.<\/p>\n<p class=\"wp-block-paragraph\"><strong>What is BIP-360 and how would it help?<\/strong><br \/>BIP-360 is a Bitcoin Improvement Proposal authored by developer Hunter Beast that introduces a new address format, P2QRH (pay-to-quantum-resistant-hash), which keeps quantum-resistant public key material hidden behind a hash until spend time, reducing long-term on-chain exposure.<\/p>\n<p class=\"wp-block-paragraph\"><strong>When will Bitcoin actually be at risk, according to experts?<\/strong><br \/>Estimates vary widely. Published 2026 research frames a baseline \u201cQ-Day\u201d scenario around 2033, with an optimistic case of 2030 and a pessimistic case as far out as 2042. Some researchers argue no reliable date can be set given how early quantum hardware still is.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Can I protect my bitcoin from this risk right now?<\/strong><br \/>Yes, mostly by avoiding address reuse, which is responsible for roughly 72% of currently exposed BTC. Using a fresh address for every transaction, migrating old pre-HD wallets, and using multisig for large holdings all reduce exposure well ahead of any protocol-level fix.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Does Taproot protect against quantum attacks?<\/strong><br \/>Not fully. Taproot addresses are more resistant than legacy formats in some scenarios, but research has flagged around 198,000 BTC in Taproot outputs as exposed, because Taproot\u2019s key-spend path reveals an x-only public key under certain conditions.<\/p>\n<p class=\"wp-block-paragraph\"><strong>What happens to Satoshi Nakamoto\u2019s bitcoin if quantum computers become viable?<\/strong><br \/>That\u2019s the ecosystem\u2019s most unresolved question. Satoshi-era coins sit in old, exposed address formats with no active owner to migrate them, meaning they would become the largest single pool of at-risk, unmoved bitcoin, and there\u2019s currently no consensus proposal for what should happen to that supply.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Are other cryptocurrencies handling this differently than Bitcoin?<\/strong><br \/>Yes. Ethereum\u2019s long-term roadmap leans on account abstraction to let individual accounts opt into post-quantum signature schemes without a network-wide base-layer change, a more flexible model than Bitcoin\u2019s address-type approach, though it\u2019s still at the research stage rather than shipped.<\/p>\n<h3 class=\"wp-block-heading\" id=\"related-coverage\">Related Coverage<\/h3>\n","protected":false},"excerpt":{"rendered":"<p>A little over one-third of all bitcoin in circulation now sits in addresses that a sufficiently powerful quantum computer could theoretically drain, according to wallet-scanning research that has moved from academic sidebar to boardroom agenda item in 2026. Project Eleven, a startup dedicated to tracking Bitcoin\u2019s quantum exposure, put a number on the problem: roughly [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-1541","post","type-post","status-publish","format-standard","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/posts\/1541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/comments?post=1541"}],"version-history":[{"count":0,"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/posts\/1541\/revisions"}],"wp:attachment":[{"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/media?parent=1541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/categories?post=1541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/btbitcoin.net\/index.php\/wp-json\/wp\/v2\/tags?post=1541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}