Bitcoin Quantum Threat: Which Wallets Face Highest Risk

9 min read
3 views
Oct 9, 2026

Millions of Bitcoin already sit behind visible public keys. Experts warn the real danger is not the distant quantum computer itself but how many wallets leave keys exposed today. Find out which ones are most vulnerable and what holders can still do before it is too late.

Financial market analysis from 09/10/2026. Market conditions may have changed since publication.

Imagine waking up one morning and discovering that a chunk of the Bitcoin sitting in older wallets has become fair game for anyone with the right computing power. That scenario still sounds distant to most people, yet the numbers already circulating make it hard to ignore. Roughly 6.7 to 7 million BTC currently rest behind public keys that anyone can already see on the blockchain. That is not a future problem waiting for a sci-fi machine. It is a present-day exposure problem that quietly grows every time someone reuses an address or leaves an old output untouched.

Understanding the Real Bitcoin Quantum Risk Today

I have spent enough time watching security discussions to know that fear travels faster than facts. Quantum computers capable of breaking current elliptic-curve signatures do not exist yet in any practical form. Still, the preparation window is measured in years, not decades, because software upgrades, hardware wallet updates, and user habits move slowly. The core issue is simple: once a public key sits in the open, a sufficiently powerful quantum machine could one day derive the matching private key. Until that machine arrives, the best defense is reducing how many keys remain visible.

Exposure depends far less on whether the owner is an exchange, an institution, or an ordinary holder and far more on three practical factors: the blockchain itself, the address type chosen, and the actual transaction history. Frequent spending tends to reveal keys. Long periods of inactivity can keep them hidden, but only if the original address format never published the key in the first place.

Why Older Outputs Carry the Heaviest Burden

Early Bitcoin transactions used a format known as pay-to-public-key. In those outputs the public key appears right there in the locking script from the moment the coins are received. Many of the coins associated with the earliest years of the network still sit in that format. They have never moved, yet the key has been public the entire time. That creates a permanent target that no amount of careful future behavior can erase.

Contrast that with the more common pay-to-public-key-hash and native SegWit addresses. Those formats hide the actual public key behind a hash until the moment the coins are spent. The first spend reveals the key permanently. Any later coins sent back to the same address then sit behind an already-exposed key. It is a quiet trap that many holders fall into without realizing it.

Taproot outputs introduce yet another nuance. Their public keys are visible at the moment of creation, which means they face the longer-duration style of quantum attack rather than only the brief window between broadcast and confirmation. The distinction matters because the longer a key stays visible, the more time an attacker would eventually have to work on it.

Exposure ultimately comes down to whether the public key is already visible onchain.

That single sentence captures the entire practical problem. Everything else is detail layered on top of it.

How Address Reuse Quietly Multiplies Risk

Most people understand that address reuse is generally discouraged for privacy reasons. Fewer people connect the same habit directly to quantum exposure. Once an address has been spent from, its public key is permanently recorded. Receiving additional funds at that same address places those new coins behind a key that is already known. The exposure score of that UTXO jumps from zero to maximum in a single step.

I have watched institutions struggle with this exact pattern. A treasury team receives a large deposit, later spends a portion, and the change returns to the original address out of operational convenience. Suddenly a much larger balance sits behind a revealed key. The same pattern appears in personal wallets when users rely on a single receiving address for years.

The practical fix is straightforward but requires discipline. New deposits should always arrive at fresh addresses. Change from every transaction should also return to a brand-new address. Over time the exposed balances drain through normal spending while new funds accumulate behind still-hidden keys. It is not a dramatic overnight migration. It is steady operational hygiene.

Gradual Migration Versus Panic Mode

Some voices have called for a sudden “bunker mode” in which large holders race to move everything into new formats the moment quantum timelines look closer. That approach carries its own risks. When many large holders compete for limited block space at the same time, fees spike and confirmation times stretch. Inside institutions the sudden volume of transactions and approval steps increases the chance of simple operational mistakes, including the accidental return of change to an already-exposed address.

A continuous approach looks different. Track every UTXO individually. Maintain a live view of which balances sit behind exposed keys and which remain hidden. Prefer inputs that empty exposed addresses whenever a legitimate spend is needed. Keep destination addresses, approval policies, and trusted communication channels ready long before any sense of urgency appears. When the day comes that a faster migration becomes necessary, the organization is not inventing process under pressure.

  • Send every new deposit to a never-before-used address
  • Route all change outputs to fresh addresses as well
  • Monitor the remaining balance still sitting behind revealed keys
  • Select transaction inputs with exposure status in mind
  • Prepare destination addresses and approval flows in advance

Those five habits already eliminate most of the avoidable exposure without requiring any protocol change.

What BIP 360 Actually Achieves and What It Leaves Open

Proposal BIP 360 focuses on a new output type that removes the exposed key-spending path present in Taproot. By moving to a pay-to-Merkle-root construction, long-term public-key exposure shrinks dramatically. That is genuine progress against the slow, long-duration form of quantum attack. Yet the authors themselves note that protection against the short window after a transaction is broadcast but before it confirms still requires actual post-quantum signature schemes.

Bitcoin cannot simply drop in a new verification contract the way a smart-contract platform might. Supporting a new signature algorithm at the base layer means careful design work around signature size, verification cost, and fee impact. Hash-based signatures offer one promising direction, especially designs that track signing state carefully to keep overhead manageable. Each approach brings trade-offs in wallet complexity and record-keeping requirements.

In my view the most realistic path is a combination of reduced exposure today plus eventual protocol support for quantum-resistant signatures. Neither piece alone is sufficient. Both together give the network a fighting chance.

How Other Chains Handle the Same Underlying Problem

Ethereum accounts reveal their public keys the moment they sign a transaction, because the key can be recovered from the signature itself. Rotating an Ethereum account is far less practical than rotating a Bitcoin address, because token balances, approvals, and application state all attach to the account. Programmable accounts offer a path to change the authorization method while keeping the same address, yet the gas costs of post-quantum verification remain non-trivial even after heavy optimization.

Recent research has brought the verification cost of a standardized post-quantum scheme down from more than eight million gas to roughly 1.23 million gas through careful improvements in hashing, arithmetic, and memory use. Peak memory dropped from nearly a megabyte to about 41 kilobytes. Those numbers matter for treasuries and cold wallets that move funds infrequently. They still leave ordinary high-frequency activity expensive, and they do not magically make the rest of the consensus layer quantum-safe.

On Solana the address is the public key itself, so exposure begins at the moment of creation. Different chains therefore present different operational challenges, yet the underlying principle remains identical: minimize the time any given public key spends in the open.

Custody Providers and Institutional Preparation

Large custodians have begun adding tools that score exposure, prefer non-exposed inputs, and default to fresh addresses. Some systems attempt to spend every UTXO associated with a given address in a single transaction so that nothing is left behind after the key is revealed. These controls are operational preparation rather than a substitute for eventual protocol upgrades. They buy time and reduce the size of the eventual migration problem.

Investors who hold Bitcoin through exchange-traded products never control the private keys themselves. The custodians selected by the fund issuers carry that responsibility. Those custodians are already exploring hardware security modules flexible enough to support multiple post-quantum schemes once the networks settle on preferred algorithms. The work is quiet and technical, yet it will determine how smoothly institutional capital can move when the time comes.

Practical Steps Any Holder Can Take Right Now

You do not need to wait for a protocol upgrade to improve your personal position. Start by listing every address that has ever spent coins. Those public keys are already known. Prefer to empty them through ordinary spending rather than leaving residual balances behind. Route all future receipts and change to addresses that have never appeared in a spending transaction. Keep a simple spreadsheet or use wallet software that surfaces exposure status if available.

Hardware wallets will eventually need firmware that supports new signature schemes. That process takes time for both manufacturers and users. Establishing good address hygiene today means the eventual migration involves far fewer coins and far less urgency.

Perhaps the most useful mindset shift is treating public-key exposure as a continuous risk metric rather than a binary future event. The quantum computer may still be years away. The number of exposed keys grows every day through ordinary address reuse. Reducing that number is work that can begin immediately and continue indefinitely.


Looking Ahead Without Panic

No cryptographically relevant quantum computer currently exists that can break Bitcoin’s signatures. That fact is worth repeating. At the same time, the research, software changes, hardware updates, and user education required for a smooth transition will take years. Starting the operational work now is simply prudent risk management, not alarmism.

The wallets facing the greatest risk are those that still hold significant balances behind keys that have already been published. Older pay-to-public-key outputs sit at the top of that list. Reused addresses that continue receiving funds rank just behind them. Fresh addresses that have never spent remain the safest current option.

I remain cautiously optimistic. The industry has solved harder coordination problems before. The difference this time is that the threat is both technical and temporal. The technical pieces are being researched. The temporal piece is entirely in the hands of holders and custodians who decide whether to treat exposure as a live metric or as someone else’s future problem.

Every coin that moves from an exposed key to a fresh address today is one less coin that will need urgent attention later. That slow, steady reduction is the most realistic form of preparation available right now. The quantum future will arrive on its own schedule. The size of the exposed surface it finds is still a choice we can influence.

For anyone holding meaningful amounts of Bitcoin, the practical takeaway is clear. Review the addresses that have already spent. Stop sending new funds to them. Prefer fresh destinations for every receipt and every change output. Track the remaining exposed balance over time. Those habits cost almost nothing and buy valuable optionality for whatever comes next.

The conversation around quantum risk often jumps straight to distant timelines and exotic algorithms. The more immediate conversation is about ordinary operational discipline. In that sense the quantum threat is already useful. It forces a closer look at habits that should have been tightened years ago for privacy and operational hygiene reasons alone. The quantum angle simply raises the stakes.

Whether the eventual solution involves new output types, post-quantum signatures, or a combination of both, the holders who enter that transition with the smallest possible exposed surface will face the least friction. That surface is still under our control. The time to start shrinking it is now.

Looking across the broader landscape, the same principles apply to other chains even when the technical details differ. Minimizing public-key visibility, planning gradual rather than panicked migrations, and keeping operational processes ready all transfer reasonably well. Bitcoin simply carries the largest absolute number of coins and the longest history of early output formats, which is why the conversation centers there.

In the end the question is not whether quantum computers will eventually threaten current signature schemes. Most cryptographers already treat that as a matter of timing rather than possibility. The open question is how much exposed Bitcoin those machines will find when they arrive. That number is still being written every day through ordinary address choices. It remains one of the few variables we can still influence with relatively simple habits.

Holders who treat public-key exposure as a live operational metric rather than an abstract future concern will sleep better regardless of exact quantum timelines. That mindset alone is worth cultivating long before any hardware breakthrough forces the issue into the open.

❝
If you can actually count your money, you're not a rich man.
— J. Paul Getty
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>