IonGrid
IonGrid Research · neutral readiness data

Bitcoin's quantum exposure, sourced and honest.

The threat is to Bitcoin's signatures, not its mining. Here is the picture we can actually defend — which coins are exposed, when “Q-Day” might arrive, and where the migration proposals stand. Figures are shown as a contested range, with sources — never one cherry-picked number.

Mining is safe; signatures are the target Published estimates, dated & citedas of block #961,189
How much is at risk

The honest answer is a range.

“Vulnerable” depends on how you scope it — from coins at appreciable risk to every coin that has ever revealed a public key. We publish both poles.

CoinShares
lower bound
~10,200 BTC
$658.3M at today's price

at appreciable / “disruptive” risk — a conservative read (of ~1.6M BTC, ~8%, sitting in exposed P2PK).

Chaincode Labs
upper bound
up to ~6.26M BTC
$404B at today's price

20–50% of supply (4–10M BTC) reachable by a capable quantum attacker.

Deloitte
~25% of supply

held in address types that have already revealed a public key.

CoinDesk (Apr 2026)
~6.9M BTC
$445B at today's price

exposed through address reuse, including Satoshi-era coins.

Methodology & honesty:these are published third-party estimates (mid-2026), not a live on-chain measurement, and the dollar figures use today's BTC price. A live, verifiable on-chain exposed-UTXO tracker is what we're building next — see the roadmap below.

The threat model

What actually breaks — and what doesn't.

Signatures, not mining

Shor's algorithm breaks ECDSA/Schnorr once a public key is visible. Grover only halves SHA-256 to ~128-bit (still impractical) — so mining, and any address that has never revealed its key, stay safe.

What's exposed

P2PK, P2MS, and Taproot (bc1p) reveal a public key the moment they receive. P2PKH / P2SH / SegWit only expose theirs once the address is spent from or reused.

In-flight risk

A pending transaction reveals its public key. A fast enough attacker could, in principle, race it before it confirms.

Harvest now, decrypt later

Exposed public keys can be recorded today and broken whenever a capable machine arrives — so the exposure clock is already running.

When — “Q-Day”

Real, accelerating — and still uncertain.

No cryptographically-relevant quantum computer exists today — but the bar keeps dropping. In March 2026 Google cut the resources to break Bitcoin's signatures by ~20×. We track the acceleration honestly: the gap is closing faster than 2025 estimates assumed, even though exactly when it closes is still genuinely contested.

Mar 2026
The goalpost moved 20×

Google Quantum AI showed breaking Bitcoin's ECC needs fewer than 500,000 physical qubits and ~9 minutes once a key is exposed — a ~20× cut from the prior ~9–20M-qubit estimates.

2029
Google's own deadline

Google set 2029 to migrate its own infrastructure to post-quantum crypto; some now put a possible Q-Day as early as 2029.

~2032
~10% odds

Researchers (e.g. Justin Drake) put ~10% odds by 2032; a Google co-author publicly raised the odds in June 2026. NIST plans to deprecate ECC by 2030, disallow by 2035.

Today
No CRQC yet

The largest machines are ~1,500 physical qubits — still far below the <500,000 needed. The gap is real, but the target keeps dropping and that gap is what's closing.

Measured frontier · tracked

The break record — and the shrinking target.

Estimates are one thing — here is what has actually been broken on real quantum hardware, and how fast the theoretical bar is falling toward secp256k1, the 256-bit curve protecting real Bitcoin keys. We update this as new results land.

Largest ECC key broken on real hardware
15-bit
Giancarlo Lelli · Apr 2026
512× larger than the prior record — won Project Eleven's Q-Day Prize (1 BTC).
6-bit
Steve Tippeconnic · Sep 2025
First public break of an ECC key on real quantum hardware.
256-bit
secp256k1 · Target
The curve protecting real Bitcoin keys — still an astronomical gap from the record.
Qubits estimated to break 256-bit ECC
~10k
2026 · Caltech + Oratomic
Neutral-atom architecture — the lowest estimate yet for 256-bit ECC.
<500k
Apr 2026 · Google Quantum AI
~20× cut from prior estimates; a ~9-minute break once a key is exposed.
~9–20M
Prior estimates
Where the resource estimates sat before the 2026 papers.

The gap from 15-bit to 256-bit is still astronomical — no machine can cross it today. We track the slope, not the hype: the record key size, the falling qubit estimate, and — soon — our own reproducible runs on each new chip. Sources: Project Eleven Q-Day Prize; Google Quantum AI (Apr 2026); Caltech/Oratomic.

The fix — where the proposals stand

The cryptography is the easy part.

BIP-360 — Pay-to-Merkle-Root
Draft soft fork

A new output type for post-quantum keys. Authors: Hunter Beast, Ethan Heilman, Isabel Foxen Duke. Merged as a Draft (PR #1670, Feb 2026) — not activated.

BIP-361 — phased signature sunset
Proposal

Lopp + co-authors: first block legacy sends, then a flag-day that invalidates ECDSA/Schnorr spends. Forces migration; freezes coins that don't.

No-fork approaches
Research

Matt Corallo's OP_SPHINCS Taproot leaf; Ethan-Levy-style QSB (StarkWare) that needs no soft fork.

NIST PQC standards
Finalized 2024

ML-DSA, SLH-DSA, ML-KEM finalized Aug 2024. The catch is size: PQ signatures run 2–17KB vs Schnorr's 64 bytes — real block-space and fee pressure.

The hard part

The fight is governance, not math.

Pubkey-exposed wallets whose owners are gone — including Satoshi-era coins — can't migrate themselves. The community is split four ways: freeze them, let them be stolen, burn them, or allow ZK recovery. Bitcoin has no formal process for a decision this large — which is exactly the gap worth solving.

A change this big needs
  • Miner signaling (the hashpower that activates a soft fork)
  • Node adoption (the economic full nodes that enforce the rules)
  • Economic-majority alignment (exchanges, custodians, holders)
  • A credible deadline — and no neutral instrument to coordinate it
What IonGrid is building

Neutral instruments, not a side.

We don't build the cryptography or pick a winner in the lost-coins debate. We build the neutral instruments the migration needs to be navigated — the same way the IonGrid Index is a neutral price benchmark.

Now
This readiness page

A sourced, contested-range view of exposure, timelines, and proposals — updated as the field moves.

Next
Live exposure tracker

An on-chain count of pubkey-exposed UTXOs over time — verifiable, not estimated. Plus a simulator for the fee impact of 2–17KB signatures.

Later
Signaling dashboard

A neutral read on where consensus actually stands — miner, node, and economic-majority signaling toward a chosen proposal.

Follow the work.

We publish neutral measurement for Bitcoin — hashprice and, now, quantum readiness. Check the live Index, or reach out if you build or research in this space.

Sources: Chaincode Labs (Bitcoin Post-Quantum), CoinShares, Deloitte, NIST FIPS 203/204/205, BIP-360 (PR #1670), BIP-361, Bitcoin Optech. Figures are point-in-time and contested; verify against primary sources before relying on them.