Bitcoin's quantum exposure, sourced and honest.
The threat is to Bitcoin's signatures, not its mining. Here is the picture we can actually defend — which coins are exposed, when “Q-Day” might arrive, and where the migration proposals stand. Figures are shown as a contested range, with sources — never one cherry-picked number.
The honest answer is a range.
“Vulnerable” depends on how you scope it — from coins at appreciable risk to every coin that has ever revealed a public key. We publish both poles.
at appreciable / “disruptive” risk — a conservative read (of ~1.6M BTC, ~8%, sitting in exposed P2PK).
20–50% of supply (4–10M BTC) reachable by a capable quantum attacker.
held in address types that have already revealed a public key.
exposed through address reuse, including Satoshi-era coins.
Methodology & honesty:these are published third-party estimates (mid-2026), not a live on-chain measurement, and the dollar figures use today's BTC price. A live, verifiable on-chain exposed-UTXO tracker is what we're building next — see the roadmap below.
What actually breaks — and what doesn't.
Shor's algorithm breaks ECDSA/Schnorr once a public key is visible. Grover only halves SHA-256 to ~128-bit (still impractical) — so mining, and any address that has never revealed its key, stay safe.
P2PK, P2MS, and Taproot (bc1p) reveal a public key the moment they receive. P2PKH / P2SH / SegWit only expose theirs once the address is spent from or reused.
A pending transaction reveals its public key. A fast enough attacker could, in principle, race it before it confirms.
Exposed public keys can be recorded today and broken whenever a capable machine arrives — so the exposure clock is already running.
Real, accelerating — and still uncertain.
No cryptographically-relevant quantum computer exists today — but the bar keeps dropping. In March 2026 Google cut the resources to break Bitcoin's signatures by ~20×. We track the acceleration honestly: the gap is closing faster than 2025 estimates assumed, even though exactly when it closes is still genuinely contested.
Google Quantum AI showed breaking Bitcoin's ECC needs fewer than 500,000 physical qubits and ~9 minutes once a key is exposed — a ~20× cut from the prior ~9–20M-qubit estimates.
Google set 2029 to migrate its own infrastructure to post-quantum crypto; some now put a possible Q-Day as early as 2029.
Researchers (e.g. Justin Drake) put ~10% odds by 2032; a Google co-author publicly raised the odds in June 2026. NIST plans to deprecate ECC by 2030, disallow by 2035.
The largest machines are ~1,500 physical qubits — still far below the <500,000 needed. The gap is real, but the target keeps dropping and that gap is what's closing.
The break record — and the shrinking target.
Estimates are one thing — here is what has actually been broken on real quantum hardware, and how fast the theoretical bar is falling toward secp256k1, the 256-bit curve protecting real Bitcoin keys. We update this as new results land.
The gap from 15-bit to 256-bit is still astronomical — no machine can cross it today. We track the slope, not the hype: the record key size, the falling qubit estimate, and — soon — our own reproducible runs on each new chip. Sources: Project Eleven Q-Day Prize; Google Quantum AI (Apr 2026); Caltech/Oratomic.
The cryptography is the easy part.
A new output type for post-quantum keys. Authors: Hunter Beast, Ethan Heilman, Isabel Foxen Duke. Merged as a Draft (PR #1670, Feb 2026) — not activated.
Lopp + co-authors: first block legacy sends, then a flag-day that invalidates ECDSA/Schnorr spends. Forces migration; freezes coins that don't.
Matt Corallo's OP_SPHINCS Taproot leaf; Ethan-Levy-style QSB (StarkWare) that needs no soft fork.
ML-DSA, SLH-DSA, ML-KEM finalized Aug 2024. The catch is size: PQ signatures run 2–17KB vs Schnorr's 64 bytes — real block-space and fee pressure.
The fight is governance, not math.
Pubkey-exposed wallets whose owners are gone — including Satoshi-era coins — can't migrate themselves. The community is split four ways: freeze them, let them be stolen, burn them, or allow ZK recovery. Bitcoin has no formal process for a decision this large — which is exactly the gap worth solving.
- Miner signaling (the hashpower that activates a soft fork)
- Node adoption (the economic full nodes that enforce the rules)
- Economic-majority alignment (exchanges, custodians, holders)
- A credible deadline — and no neutral instrument to coordinate it
Neutral instruments, not a side.
We don't build the cryptography or pick a winner in the lost-coins debate. We build the neutral instruments the migration needs to be navigated — the same way the IonGrid Index is a neutral price benchmark.
A sourced, contested-range view of exposure, timelines, and proposals — updated as the field moves.
An on-chain count of pubkey-exposed UTXOs over time — verifiable, not estimated. Plus a simulator for the fee impact of 2–17KB signatures.
A neutral read on where consensus actually stands — miner, node, and economic-majority signaling toward a chosen proposal.
We publish neutral measurement for Bitcoin — hashprice and, now, quantum readiness. Check the live Index, or reach out if you build or research in this space.
Sources: Chaincode Labs (Bitcoin Post-Quantum), CoinShares, Deloitte, NIST FIPS 203/204/205, BIP-360 (PR #1670), BIP-361, Bitcoin Optech. Figures are point-in-time and contested; verify against primary sources before relying on them.