Approximately 6.5 million to 6.9 million BTC — worth an estimated $483 billion at current prices — sits in addresses with exposed public keys vulnerable to quantum attack, according to Google Quantum AI research published in early 2026. The Bitcoin developer community has fractured into three dis...
"Bitcoin is the most important decentralized system ever created, but its future is not guaranteed." — Fred Thiel, CEO, MARA Holdings
Approximately 6.5 million to 6.9 million BTC — worth an estimated $483 billion at current prices — sits in addresses with exposed public keys vulnerable to quantum attack, according to Google Quantum AI research published in early 2026. The Bitcoin developer community has fractured into three distinct camps over how to defend this value: a mandatory freeze-and-migrate path (BIP-361), an event-triggered canary system (BitMEX Research), and a voluntary timestamping scheme (Paradigm's PACTs). Each approach carries different tradeoffs between security, sovereignty, and coordination cost.
The urgency accelerated in April 2026 when researcher Giancarlo Lelli broke a 15-bit elliptic curve key on quantum hardware — a 512x improvement over the prior record — winning Project Eleven's 1 BTC Q-Day Prize. Google's refined Shor's algorithm now requires 20x fewer resources than previously estimated to crack ECDSA-256, placing the theoretical break threshold below 500,000 physical qubits. Google's current Willow chip operates at 105 qubits.
No consensus exists on which path forward Bitcoin will adopt. The governance challenge is structural: unlike Ethereum, which formed a dedicated Post-Quantum Security team in January 2026 with a funded multi-fork roadmap targeting 2029 completion, Bitcoin lacks a unified coordination mechanism for emergency security upgrades.
The quantum vulnerability affecting Bitcoin stems from two cryptographic dependencies: ECDSA (Elliptic Curve Digital Signature Algorithm) for transaction signing and the exposure of public keys on-chain.
Scale of at-risk assets:
| Metric | Value | Source | |--------|-------|--------| | BTC with exposed public keys | 6.26M–6.89M BTC | Google Quantum AI (2026) | | Estimated USD value at risk | ~$483B | At ~$70K/BTC | | Percentage of circulating supply | ~30% | CoinDesk (Apr 2026) | | BTC in legacy P2PK scripts | >1.7M BTC | Paradigm (May 2026) | | Satoshi-era wallets exposed | ~1.1M BTC (~$75B) | Paradigm (May 2026) |
Hardware progress timeline:
Google stated publicly it remains "at least 10 years out from breaking RSA." However, the resource reduction trajectory — 20x fewer qubits than previously estimated — has compressed timeline assumptions among cryptographers.
Proposal: "Post Quantum Migration and Legacy Signature Sunset"
Authors: Six co-authors including Jameson Lopp (Casa CTO)
Formally assigned: February 11, 2026
Status: Draft, merged into BIP repository April 15, 2026
BIP-361 outlines a three-phase soft fork:
Phase A (Year 3 post-activation): Network blocks all sends to legacy quantum-vulnerable address types. Users must migrate to quantum-safe formats (BIP-360 P2MR addresses).
Phase B (Year 5 post-activation): All legacy signatures (ECDSA and Schnorr) become invalid at consensus layer. Unmigrated coins are permanently frozen — unable to move.
Phase C (Research stage): Limited recovery mechanism using zero-knowledge proofs tied to seed phrases, allowing frozen-fund owners to demonstrate ownership without exposing private keys.
Economic implications: Phase B would freeze any BTC whose holders fail to migrate within the five-year window. This includes Satoshi Nakamoto's estimated 1.1 million BTC, lost coins, and funds held by deceased owners without estate planning for key migration.
Community response: Yahoo Finance reported the proposal "sparked backlash" from community members who argue freezing coins violates Bitcoin's core sovereignty promise. Adam Back, Blockstream CEO, publicly opposed the mandatory approach at Paris Blockchain Week in April 2026, advocating instead for optional quantum-resistant upgrades that preserve user choice.
Proposal: Quantum Tripwire / Canary Fund
Author: BitMEX Research
Published: April 16, 2026
Status: Informal proposal, community discussion
The canary approach rejects pre-scheduled freezes in favor of a reactive mechanism:
Mechanism: A special Bitcoin address is created where the private key is unknown but the address is valid. A small BTC bounty is placed there. The only way to spend from this address is via quantum computation. If the canary address is ever spent, it serves as cryptographic proof that a quantum-capable attacker exists, triggering an automatic network-wide freeze of vulnerable wallets.
Safety window: Vulnerable coins can still move, but recipients cannot spend them for an extended period (proposed: ~1 year). If the canary triggers during this window, those coins are frozen retroactively.
Advantages: No premature disruption to holders. No philosophical violation of "your keys, your coins." Defense activates only when threat is proven real.
Risks: The model assumes the first quantum-capable entity will claim a small bounty rather than quietly steal billions. Critics note a state-level attacker or criminal organization would rationally bypass the canary to extract maximum value before detection.
Proposal: Provable Address-Control Timestamps (PACTs)
Author: Dan Robinson, Paradigm
Published: May 1, 2026
Status: Published specification, no fork required today
PACTs offer a non-disruptive, opt-in mechanism for vulnerable wallet holders:
Three-step process:
Cost: Zero. The process uses existing Bitcoin infrastructure.
Privacy: Reveals nothing publicly. Proof stored offline by holder.
Future use: If Bitcoin later implements a "sunset" soft fork freezing vulnerable addresses, a PACT holder can submit a STARK zero-knowledge proof showing they controlled the address before a cutoff date established prior to quantum capability arrival.
Limitations:
Target audience: Estimated 1.1 million BTC in Satoshi-era wallets and other long-dormant addresses whose owners may still hold keys but cannot publicly move coins without triggering market disruption.
Independently of the governance debate, technical infrastructure is advancing:
BIP-360 (Pay-to-Merkle-Root) introduces a new quantum-resistant address type that never exposes public keys, even during spending. In March 2026, BTQ Technologies deployed the first working BIP-360 implementation on Bitcoin Quantum testnet v0.3.0.
Testnet specifications:
BIP-360 is the foundational building block that BIP-361's phased timeline depends on. Without a working quantum-safe address type, no migration — voluntary or mandatory — can begin.
MARA Holdings (NASDAQ: MARA): Launched the MARA Foundation on April 27, 2026, with quantum resistance research as a stated priority. Initial $100,000 community grant distributed to three nonprofits via conference vote.
NIST Standards: The U.S. National Institute of Standards and Technology finalized three post-quantum cryptography standards in August 2024: ML-KEM, ML-DSA, and SLH-DSA. Bitcoin developers are evaluating FN-DSA (formerly FALCON) for its shorter signature size, which is critical given Bitcoin's block space constraints.
Canada: Imposed a post-quantum cryptography migration mandate effective April 2026, creating regulatory pressure on Canadian-domiciled custodians and exchanges holding Bitcoin.
Ethereum comparison: The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026. Vitalik Buterin published a structured roadmap identifying four vulnerable layers (BLS signatures, KZG data availability, ECDSA accounts, ZK proofs) with fork milestones targeting 2029 completion. The approach uses hash-based signatures (leanXMSS) paired with a minimal zkVM for 250x data compression.
| Dimension | BIP-361 (Freeze) | Canary (Tripwire) | PACTs (Timestamp) | |-----------|-------------------|--------------------|--------------------| | Fork required today | No (draft) | No | No | | Fork required later | Yes (soft fork) | Yes (soft fork) | Yes (for STARK verification) | | User action required | Migrate within 5yr | None until trigger | One-time timestamp | | Sovereignty preserved | No (frozen if inactive) | Yes (until trigger) | Partially (two-tier) | | Protects lost coins | No | Yes (until attack) | No | | Assumes rational attacker | N/A | Yes (critical assumption) | N/A | | Protects Satoshi's coins | No (frozen at Phase B) | Yes (until trigger) | Yes (if Satoshi timestamps) | | Technical readiness | BIP-360 testnet live | Conceptual | Spec published, no fork needed |
The Bitcoin quantum security debate reveals a fundamental governance tension: the network's decentralization — its core value proposition — becomes a liability when coordinated action is required against an existential but temporally uncertain threat.
The economic value at stake ($483 billion in exposed addresses) ensures this will not remain an academic exercise. The three proposals represent different bets on timing and adversary behavior. BIP-361 bets that five years of warning is sufficient and that lost coins are acceptable collateral damage. The canary bets that attackers are rational and bounty-seeking. PACTs bet that holders are proactive and that future governance will honor timestamped claims.
None of these bets can be evaluated against actual quantum hardware today. The 15-bit ECC break is 2^241 orders of magnitude from threatening production Bitcoin keys. But the trajectory — from 6-bit (September 2025) to 15-bit (April 2026) — demonstrates that the field is not static.
The economic framework matters: whoever controls the governance outcome of this debate will determine the fate of 30% of Bitcoin's circulating supply, including the largest single holder position in cryptocurrency history.