Dr Kamran Jalali

The Quantum Clock Is Ticking on Bitcoin - What 6.9 Million BTC at Risk Means for Your Wallet

Is quantum computing coming for your Bitcoin? Google says 9 minutes could change everything. Here is what you need to know.

Google dropped a bombshell in March 2026. A quantum computer with about 500,000 physical qubits could crack a Bitcoin private key in roughly nine minutes. That is just under Bitcoin's average ten-minute block time.

The number made headlines. It spooked traders. And then most people moved on.

But the story did not end there. On September 3, 2026, the G7 Cybersecurity Working Group issued a formal call to action on post-quantum cryptography. Europe set deadlines. BlackRock added quantum risk to its Bitcoin ETF filings. And researchers keep refining the numbers.

Here is the uncomfortable truth: the quantum threat to Bitcoin is not a doomsday prediction for 2050. It is a governance problem, a custody problem, and a timeline problem. And it affects your Bitcoin more than you probably realize.

This article breaks down what actually changed in 2026, which Bitcoin addresses are genuinely at risk, and what you can do about it right now.

What Actually Changed in 2026

Google's 20x Reduction

For most of Bitcoin's history, the quantum threat felt comfortably distant. Breaking Bitcoin's elliptic curve digital signature algorithm (ECDSA) was estimated to require millions of physical qubits, a machine decades away.

Then came March 30, 2026. Google Quantum AI, in collaboration with Ethereum Foundation researcher Justin Drake and Stanford cryptographer Dan Boneh, published a whitepaper showing the same attack could be accomplished with fewer than 500,000 physical qubits. That is roughly a 20-fold reduction in required resources.

The team designed two quantum circuits implementing Shor's algorithm against secp256k1, the specific elliptic curve Bitcoin uses. On a fast-clock superconducting architecture, the estimated time to derive a private key from a public key dropped to approximately nine minutes.

That number matters because Bitcoin's average block time is ten minutes. An attacker could potentially intercept a live transaction, derive the private key during the confirmation window, and broadcast a competing transaction with a higher fee. Google estimated the success rate for this "mempool hijack" at roughly 41%.

The Hardware Reality Check

Here is what the headlines often miss. No quantum computer capable of attacking Bitcoin's cryptography exists today. The 500,000 physical qubit estimate is a threshold for future systems, not current ones.

Experts from Argentum AI, Coin Bureau, and other institutions stated in interviews that the 2026 threat remains theoretical rather than imminent. Nic Puckrin, Co-Founder of Coin Bureau, put it bluntly: 90% of the quantum threat theory is for marketing purposes, and it will be at least another decade before a computer capable of breaking existing cryptography appears.

But the gap between "theoretical" and "imminent" is closing faster than anyone expected five years ago. In April 2026, researcher Giancarlo Lelli claimed a 1 BTC bounty from Project Eleven after breaking a 15-bit elliptic curve key using publicly accessible quantum hardware. Bitcoin uses 256-bit keys – the gap remains enormous, but the 512-fold improvement over September 2025 results illustrated how quickly the frontier is moving.

The G7 Just Made It Real

On September 3, 2026, the G7 Cybersecurity Working Group, chaired by France, published a joint statement titled "Preparing for the Post-Quantum Era: A Call to Action". The message was clear: do not wait for the first capable quantum machine. Start migrating now.

The G7 document does not mention cryptocurrencies specifically. But the implications are direct. Cryptocurrency transactions and fund management are based on public-key cryptography, exactly what quantum computers threaten.

Europe has already set deadlines. All EU member states must begin transitioning to post-quantum cryptography by the end of 2026, with high-risk systems completing the transition by 2030. This shifts quantum readiness from a technical issue to a regulatory and competitive necessity.

Which Bitcoin Addresses Are Actually at Risk

The 6.9 Million BTC Problem

Not all Bitcoin addresses face the same level of quantum risk. The vulnerability depends on one simple question: has your address ever revealed its public key on the blockchain?

Addresses that have never sent funds do not show their public key. They remain protected by a hash function, SHA-256, which quantum computers cannot easily break.

Addresses you have spent from show their public key permanently. Once a quantum computer capable of running Shor's algorithm exists, those addresses become vulnerable.

According to industry estimates, approximately 6.9 million BTC sit in quantum-vulnerable addresses. This breaks down into two categories:

P2PK addresses (about 1.7 million BTC): These early Bitcoin addresses store public keys directly on the blockchain in plain text. No guessing required. A quantum computer can start working immediately.

Addresses with exposed public keys due to reuse (about 5.2 million BTC): Any address you have spent from once has its public key permanently recorded on the chain. About 25% to 30% of all BTC – roughly 4 million coins, is stored in addresses where the public key has been exposed.

The Satoshi Question

Then there is the elephant in the room. Satoshi Nakamoto's estimated 1.1 million BTC use P2PK scripts. The private keys are almost certainly lost. Nobody can migrate these coins to quantum-resistant addresses.

Once a quantum computer capable of breaking ECDSA exists, those coins effectively become unclaimed treasure on the high seas. Whoever builds the machine first could take them.

This creates a strange incentive. The first entity to reach the quantum threshold could claim the largest Bitcoin bounty in history. That is not a comforting thought for a system built on decentralized trust.

The Taproot Irony

Here is a twist most people miss. Taproot, Bitcoin's major 2021 upgrade, was designed to improve privacy and support complex smart contracts. But it uses Schnorr signatures, which expose public keys on the chain in a way that previous P2PKH addresses did not.

Under classical computing, this is fine. Under quantum computing, it is a security regression. By 2025, Taproot transactions accounted for 21% of Bitcoin network volume, and that share keeps growing.

Harvest Now, Decrypt Later -The Threat That Is Already Happening

Why Waiting Is a Mistake

State-level intelligence agencies do not need a quantum computer today to extract value from Bitcoin transactions. They need storage, which is cheap, and patience, which institutions have in abundance.

The strategy is straightforward. Record encrypted blockchain data now. Run decryption later once the hardware catches up. In security circles, this is known as "Harvest Now, Decrypt Later" HNDL for short.

The G7 statement explicitly references this threat: "In these attacks, threat actors collect encrypted data now, with the intention of decrypting it in the future using quantum computing capabilities".

For a public blockchain, the problem is even more uncomfortable. Nobody needs to capture anything. Every transaction, every public key, and every signature has been visible to everyone on the chain since the beginning.

What This Means for You

If you have ever spent Bitcoin from an address, your public key is already public. It has been public since the moment you made that transaction. A future quantum computer could derive your private key from that public key, not in 2050, but potentially in the early 2030s or sooner.

The NSA and the UK National Cyber Security Centre have both identified HNDL as a threat requiring immediate attention. This is not speculative. This is current intelligence doctrine.

What Bitcoin Developers Are Doing About It

BIP-360 and Quantum-Resistant Addresses

In February 2026, Bitcoin developers proposed BIP-360, also known as Pay-to-Merkle-Root. It introduces a new quantum-resistant address type, "bc1z" addresses, that removes the quantum-vulnerable spending path.

This is a soft fork. It does not force anyone to migrate. It simply gives users the option to move funds to quantum-resistant addresses.

BIP-361 and the Controversy

BIP-361 goes further. It proposes to force-migrate, and potentially freeze, the roughly 6.9 million BTC sitting in vulnerable legacy addresses. This includes Satoshi's coins.

The proposal is deeply contentious. Freezing addresses contradicts Bitcoin's core principles of permissionless ownership. But leaving 6.9 million BTC exposed to quantum attack also contradicts the network's security guarantees.

The debate is ongoing. And it exposes a fundamental tension: Bitcoin's decentralized governance moves slowly. Quantum hardware may not.

The Governance Speed Problem

If quantum computing threatens Bitcoin, it threatens everything. TLS, SWIFT, RSA-protected banking infrastructure, and every public-key system underpinning modern finance are vulnerable.

The difference is governance speed. Centralized systems can mandate upgrades. Bitcoin cannot. The community must reach consensus. That takes time, potentially more time than the quantum clock allows.

What You Can Do Right Now

Stop Reusing Addresses

This is the single most important action you can take. Every time you send Bitcoin from an address, you expose that address's public key permanently.

Use a new address for every transaction. Modern wallets do this automatically. Make sure yours does.

Move Funds to Fresh Addresses

If you have old addresses with significant balances, consider moving them to fresh addresses. This does not make them quantum-proof, any future transaction will expose the new public key. But it resets the clock.

For long-term holdings, consider moving to addresses that have never sent a transaction. These addresses remain protected by SHA-256 hashing, which quantum computers cannot easily break.

Watch for Quantum-Resistant Wallets

Quantum-resistant wallets are coming. Projects like Qastle announced plans in November 2025 to provide quantum-grade security protection for hot wallets. When these become available, migrate your funds.

Experts recommend that users avoid address reuse and promptly move funds when quantum-resistant wallets become available.

Stay Informed

The quantum threat timeline is not fixed. It moves with hardware developments, algorithmic improvements, and regulatory deadlines. Follow developments in BIP-360 and BIP-361. Pay attention to G7 and EU deadlines. And treat "harvest now, decrypt later" as a real threat, not a theoretical one.

The Bottom Line

The quantum threat to Bitcoin is real, but it is not imminent. No quantum computer capable of attacking Bitcoin's cryptography exists today. The 500,000 qubit threshold is likely years away, perhaps a decade or more.

But the timeline is compressing. Google's March 2026 paper reduced estimated resource requirements by a factor of 20. Researchers keep refining the numbers. And the G7 just told the world to start preparing now.

The real risk is not a quantum computer appearing tomorrow. The real risk is doing nothing while the clock ticks down. Address reuse, exposed public keys, and slow governance are the vulnerabilities that matter today.

Your Bitcoin does not need to be quantum-proof right now. But it does need to be quantum-aware. Stop reusing addresses. Watch for quantum-resistant upgrades. And understand that the lock on your wallet is only as strong as the cryptography protecting it, and that cryptography has an expiration date.

The question is not whether quantum computers will break Bitcoin's cryptography. The question is whether you will move your coins before they do.

FAQ’s

Q: Can quantum computers break Bitcoin right now?

No. No quantum computer exists today that is capable of attacking Bitcoin's ECDSA cryptography. The estimated hardware requirements, roughly 500,000 physical qubits, remain far beyond current capabilities.

Q: How long until quantum computers can break Bitcoin?

Estimates vary, but most experts place the timeline at 10 to 20 years. However, Google's March 2026 paper reduced estimates by a factor of 20, and the timeline continues to compress as researchers refine their algorithms.

Q: Which Bitcoin addresses are most at risk?

Addresses that have revealed their public keys, either because they are P2PK addresses (about 1.7 million BTC) or because they have been reused for transactions (about 5.2 million BTC). Addresses that have never sent a transaction remain protected by SHA-256 hashing.

Q: What is "harvest now, decrypt later"?

It is a strategy where attackers collect encrypted data today and store it for future decryption once quantum computers become capable. For public blockchains like Bitcoin, all data is already public, making this threat particularly relevant.

Q: What is BIP-360?

BIP-360, or Pay-to-Merkle-Root, is a Bitcoin improvement proposal that introduces quantum-resistant address types (starting with "bc1z"). It is a soft fork that gives users the option to migrate to quantum-resistant addresses.

Q: Should I move my Bitcoin now?

You should stop reusing addresses and consider moving funds from old, exposed addresses to fresh ones. This does not make them quantum-proof, but it reduces your exposure. When quantum-resistant wallets become available, migrate your funds to them.

Key Takeaways

  • Google's March 2026 research reduced the estimated qubit requirements to break Bitcoin's cryptography by a factor of 20, from millions to roughly 500,000 physical qubits.
  • Approximately 6.9 million BTC sits in quantum-vulnerable addresses, including about 1.7 million in P2PK addresses and 5.2 million in addresses with exposed public keys due to reuse.
  • The G7 issued a formal call to action on post-quantum cryptography on September 3, 2026, urging immediate migration.
  • "Harvest now, decrypt later" is a real threat. Your public keys are already public. A future quantum computer could derive your private key from them.
  • Stop reusing addresses. Move funds to fresh addresses. Watch for quantum-resistant wallets and BIP-360 adoption.
  • The quantum threat is not imminent, but the timeline is compressing faster than most people realize. Doing nothing is the real risk.

Disclaimer

This article is for informational and educational purposes only. It does not constitute financial advice, investment advice, or trading advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any financial decisions. The quantum threat timeline is subject to change based on hardware developments, algorithmic improvements, and other factors beyond the scope of this article.

How do you rate this article?

2


Crypto Strategist
Crypto Strategist

I am Dr. Kamran Jalali, Crypto researcher & educator. Deep analysis on crypto trends, AI tokens, RWA, and smart money, in plain language. No hype. Just honest research to help you make smarter decisions.


Dr Kamran Jalali
Dr Kamran Jalali

Most people lose money in crypto not because the market is against them — but because nobody ever taught them the rules of the game. I am Dr. Kamran Jalali. I write about crypto in plain, simple language that anyone can understand — no confusing jargon, no hype, no false promises. Here you will find honest breakdowns of how crypto really works, why traders fail, how to protect your money, and how to make smarter decisions in the digital asset world. Whether you are completely new to crypto or have been in

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?