← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Bitcoin's Quantum Clock Accelerates: 6.9M BTC Exposed

Zephyra|May 5, 2026|BPF
EXECUTIVE SUMMARY

Three research papers published between January and March 2026 have compressed the estimated resource requirement for breaking Bitcoin's elliptic curve cryptography (secp256k1) from 9 million physical qubits to under 500,000 — a 20x reduction in 14 months. On April 24, a researcher broke a 15-bit...

"If there is a way to plant a seed now that will give us an advantage over cryptographic attackers in a possible future, long-term holders should take it." — Dan Robinson, General Partner, Paradigm

Executive Summary

Three research papers published between January and March 2026 have compressed the estimated resource requirement for breaking Bitcoin's elliptic curve cryptography (secp256k1) from 9 million physical qubits to under 500,000 — a 20x reduction in 14 months. On April 24, a researcher broke a 15-bit ECC key on live quantum hardware, winning Project Eleven's Q-Day Prize. Approximately 6.9 million BTC ($552 billion at current prices) sit in addresses with exposed public keys, representing one-third of circulating supply.

In response, Paradigm general partner Dan Robinson published PACTs (Provable Address-Control Timestamps) on May 1, a mechanism allowing dormant Bitcoin holders to privately timestamp proof of key ownership before quantum computers arrive. The proposal requires no protocol fork today but presupposes future STARK verification support and community consensus on a "sunset soft fork" rescue path.

The convergence of accelerating quantum research, hardware demonstrations, and protocol-level responses marks a shift from theoretical concern to active engineering problem for the Bitcoin network.

Table of Contents

  1. Quantum Threat Timeline Compression
  2. Bitcoin's Exposure Surface
  3. PACTs: Technical Mechanism
  4. BIP-360 and Competing Proposals
  5. Industry Response and Governance Friction
  6. Key Takeaways
  7. Conclusion

Quantum Threat Timeline Compression

Three papers published between January and March 2026 have materially altered the resource estimates for a cryptographically relevant quantum computer (CRQC) capable of breaking elliptic curve cryptography:

Paper 1 — Gidney (May 2025, updated January 2026): Google researcher Craig Gidney demonstrated RSA-2048 breakable with fewer than 1 million physical qubits in under one week, a 20x reduction from his own 2019 estimates.

Paper 2 — Iceberg Quantum (February 2026): The Sydney-based startup's Pinnacle architecture using Quantum Low-Density Parity-Check (QLDPC) codes showed RSA-2048 breakable with fewer than 100,000 physical qubits — another 10x reduction from Gidney's figure.

Paper 3 — Google Quantum AI (March 30, 2026): Co-authored with researchers from the Ethereum Foundation and Stanford University, this whitepaper presented two optimized quantum circuits for solving the 256-bit Elliptic Curve Discrete Logarithm Problem (ECDLP-256) on Bitcoin's secp256k1 curve. The result: fewer than 500,000 physical qubits, runtime measured in minutes. The previous best estimate (Litinski, 2023) required approximately 9 million physical qubits on a photonic architecture.

A subsequent paper from Caltech and Oratomic brought that figure as low as 10,000 qubits in a neutral-atom architecture, though this remains unverified.

Hardware demonstration (April 24, 2026): Researcher Giancarlo Lelli broke a 15-bit ECC key on a publicly accessible quantum computer, winning Project Eleven's 1 BTC Q-Day Prize. The result extends the previous record (Steve Tippeconnic's 6-bit demonstration, September 2025) by a factor of 512. Bitcoin uses 256-bit keys — a gap that is now characterized by researchers as "an engineering problem, not a fundamental physics problem."

Google's Willow chip demonstrated quantum error correction below the surface code threshold in December 2024. Quantinuum achieved 48 logical qubits from 98 physical qubits. Current state-of-the-art machines operate at approximately 1,000–1,500 qubits. The gap to 500,000 remains substantial but is narrowing faster than prior models predicted.

Bitcoin's Exposure Surface

Approximately 6.9 million BTC — roughly 33% of total circulating supply — currently reside in addresses where public keys have been permanently exposed on-chain. At Bitcoin's current price of approximately $80,000, this represents $552 billion in quantum-vulnerable assets.

Public keys become exposed in two ways:

  1. Legacy address formats (P2PK): Satoshi-era coins used Pay-to-Public-Key outputs, which directly reveal the public key. An estimated 1.1 million BTC in Satoshi-linked addresses alone carry this exposure.

  2. Addresses that have sent transactions: Any address that has broadcast a transaction reveals its public key in the scriptSig or witness data. This includes all post-2021 Taproot (P2TR) addresses that have spent.

The vulnerability operates as follows: if a quantum computer can derive a private key from a public key, it can sign transactions and drain funds. According to Google's March 2026 analysis, a sufficiently powerful CRQC could derive a Bitcoin private key in approximately nine minutes — less than one block confirmation.

However, addresses using Pay-to-Public-Key-Hash (P2PKH) or Pay-to-Script-Hash (P2SH) that have never sent a transaction remain protected: only the hash of the public key is visible, and quantum computers provide no advantage against hash functions.

PACTs: Technical Mechanism

Dan Robinson's Provable Address-Control Timestamps (PACTs) proposal, published May 1, 2026, addresses a specific scenario: if Bitcoin implements a "sunset soft fork" that freezes spending from quantum-vulnerable addresses, how do legitimate dormant holders prove ownership without publicly moving coins?

Step 1 — Commit (performed today, off-chain):

  • Holder generates a 256-bit random salt
  • Uses BIP-322 full message signing to prove control of the vulnerable scriptPubKey
  • Computes commitment: SHA256("PACT/v1 commitment" || salt || SHA256(control_proof))
  • Timestamps commitment via OpenTimestamps (free, batched into Bitcoin OP_RETURN outputs)
  • Stores salt, proof, and OTS file securely

Step 2 — Rescue (post-sunset, requires future protocol support):

  • Holder submits a STARK zero-knowledge proof demonstrating:
    • Knowledge of the salt and BIP-322 proof
    • The commitment was timestamped before CRQCs could derive private keys
    • The proof is bound to the specific rescue transaction (non-transferable)

The STARK proof reveals nothing about which address, amount, or timestamp is involved. The entire process is silent: "Nobody other than the holder knows that the holder made the commitment," according to Robinson.

Limitations identified by Robinson:

  • No guarantee Bitcoin will implement rescue protocols
  • Single-key wallets only; multisig and hardware wallets require additional standardization
  • BIP-322 message-signing authority does not necessarily equal transaction-signing authority
  • Holders must protect salt and proof artifacts indefinitely

PACTs require no Bitcoin fork today. The OpenTimestamps commitment costs nothing. But the rescue mechanism depends on future consensus changes — specifically, STARK verification support and a governance decision to honor pre-quantum timestamps.

BIP-360 and Competing Proposals

BIP-360, originally proposed by developer Hunter Beast in June 2024 and published to Bitcoin's BIP repository on February 11, 2026, introduces Pay-to-Merkle-Root (P2MR) — a quantum-resistant address format using CRYSTALS-Dilithium as the default signature scheme.

Current status: BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 with the first working BIP-360 implementation featuring P2MR transactions and Dilithium signatures in March 2026. The proposal remains in draft status with no activation mechanism proposed and no timeline for mainnet deployment.

BIP-360 and PACTs address different aspects of the problem:

  • BIP-360 provides a quantum-resistant address format for new transactions (forward-looking protection)
  • PACTs provide a rescue mechanism for existing vulnerable holdings (backward-looking protection)

Neither eliminates the need for the other. A complete quantum defense requires both forward migration (BIP-360 or equivalent) and backward rescue (PACTs or equivalent).

NIST finalized its first three post-quantum cryptography standards in August 2024: ML-KEM, ML-DSA, and SLH-DSA, with HQC selected in March 2025 as a backup. NSA's CNSA 2.0 requires all new national security systems to be quantum-safe by January 2027. NIST guidance suggests phasing out quantum-vulnerable algorithms after 2030 and disallowing them after 2035.

Industry Response and Governance Friction

The Bitcoin community remains divided on urgency and approach:

Gradualist camp (Adam Back, Blockstream): Back estimated the practical quantum threat at 20–40 years and advocated optional quantum-resistant features deployed gradually. He cited a 20-person research team and Blockstream's Liquid network as a proving ground. On April 16, CoinDesk reported Back pushed "optional upgrades over forced freeze."

Urgency camp: Google's whitepaper, the Q-Day Prize result, and the 6.9 million BTC exposure figure have energized calls for faster action. The "Year of Quantum Security" designation by FBI, NIST, and CISA in 2026 adds institutional pressure.

Governance challenge: Bitcoin's consensus mechanism makes rapid protocol changes structurally difficult. BIP-360 has been in discussion for nearly two years with no activation timeline. A sunset soft fork — the scenario PACTs presupposes — would require freezing billions in value, an unprecedented governance decision.

Robinson's PACTs proposal sidesteps this gridlock by allowing holders to act unilaterally today. The protocol commitment is free and private. If Bitcoin never implements a sunset fork, the commitment simply goes unused.

Key Takeaways

  • Resource estimates for breaking Bitcoin's cryptography fell 20x between 2023 and March 2026, from 9 million to under 500,000 physical qubits
  • 6.9 million BTC ($552 billion) sit in quantum-vulnerable addresses with exposed public keys
  • Paradigm's PACTs proposal allows silent, free, off-chain timestamping of ownership proofs today, with no fork required
  • PACTs' rescue mechanism depends on future protocol support (STARK verification, sunset consensus)
  • BIP-360 quantum-resistant addresses reached testnet in March 2026 but have no mainnet activation timeline
  • The gap between current hardware (~1,500 qubits) and the threat threshold (~500,000 qubits) remains large but is narrowing at an accelerating rate
  • Bitcoin governance friction means migration timelines will likely lag behind technical readiness

Conclusion

The Bitcoin quantum threat has transitioned from speculative to quantified. Three papers in three months compressed resource estimates by an order of magnitude. A hardware demonstration proved the attack class works, if only at toy scale. One-third of Bitcoin's supply sits in addresses that a sufficiently powerful quantum computer could drain in minutes.

PACTs represents the first credible protocol-compatible mechanism for protecting dormant holdings without forcing public migration. Its value depends entirely on whether Bitcoin's governance can reach consensus on a rescue mechanism before — or after — quantum computers arrive.

The economic stakes are clear: $552 billion in exposed value, no mainnet protection deployed, and a hardware gap that recent research suggests may close faster than the decade-plus timeline many assumed. Whether Bitcoin's governance velocity can match the research velocity remains the open question.

Sources & References

  1. PACTs: Protecting Your Bitcoin From a Quantum Sunset — Paradigm, Dan Robinson, May 1, 2026
  2. Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline — The Quantum Insider, March 31, 2026
  3. 15-Bit ECC Key Broken on Quantum Hardware Wins Q-Day Prize — The Quantum Insider, April 24, 2026
  4. Bitcoin might be at risk from a new quantum math trick that breaks digital ownership — CoinDesk, April 25, 2026
  5. New Bitcoin quantum proposal offers Satoshi Nakamoto a way to prove control without moving BTC — CoinDesk, May 2, 2026
  6. Bitcoin's quantum debate splits as Adam Back pushes optional upgrades over forced freeze — CoinDesk, April 16, 2026
  7. BTQ Technologies Implements BIP 360 Quantum-Resistant Bitcoin Transactions on Testnet — The Quantum Insider, March 20, 2026
  8. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities — Google Quantum AI, March 30, 2026
  9. Researcher wins 1 bitcoin for largest quantum attack on elliptic curve yet — CoinDesk, April 24, 2026
  10. Project Eleven Awards 1 BTC Q-Day Prize — PR Newswire, April 24, 2026