Bitcoin Quantum Threat Could Drain 6.9 Million BTC

The bitcoin quantum threat is no longer a distant warning for cryptographers to debate in private forums, it is now a ticking countdown with real coins on the line. Roughly 6.9 million bitcoin, including Satoshi Nakamoto’s early holdings and coins spent since the 2021 Taproot upgrade, are already exposed to future quantum attacks because their public keys are visible on-chain. That is about one-third of all bitcoin ever mined, and it sits there, permanently readable, waiting for whoever builds a quantum machine powerful enough to exploit it.
The urgency sharpened dramatically on April 24, 2026, when an independent researcher named Giancarlo Lelli broke a 15-bit elliptic curve cryptography key using publicly accessible quantum hardware, winning Project Eleven’s one bitcoin Q-Day Prize in the largest public demonstration yet of a quantum attack relevant to cryptocurrencies. Fifteen bits is nowhere near bitcoin’s 256-bit security, but the acceleration is what matters, resource estimates for a full 256-bit break have now fallen below 500,000 physical qubits, a dramatic revision from earlier projections that assumed millions would be needed.
The groundwork for that revision was laid on March 30, 2026, when two landmark papers, one from Google Quantum AI and one from Oratomic/Caltech, dramatically lowered the estimated resources needed to break Bitcoin’s 256-bit elliptic curve cryptography. Google showed that a fast superconducting machine with fewer than 500,000 physical qubits could crack a key in roughly nine minutes, enabling real-time attacks. Oratomic demonstrated that a much smaller neutral-atom system of around 26,000 qubits could achieve the same break in about ten days, making attacks on already-exposed keys far more feasible.
The bitcoin quantum threat does not touch everything. Bitcoin mining, the process by which new blocks get added to the blockchain, uses a type of math called hashing that quantum computers cannot meaningfully break. The ledger itself and the rule that new bitcoin can only be created through mining would survive a quantum attacker. What would not survive is ownership. A quantum attacker would not need to race against a transaction in progress. Rather, they could work through the wallets with already exposed keys at their own pace, one by one.
Satoshi Nakamoto’s estimated one million bitcoin sit squarely in the exposed category. These coins have never moved from their original addresses and serve as a symbol of Bitcoin’s decentralized origins and the creator’s commitment to the project’s principles. That symbolism now doubles as a liability. The 2021 Taproot upgrade widened the exposure pool further. Taproot is a change to how bitcoin addresses work, intended to make transactions more efficient and more private. A side effect was that any bitcoin spent since Taproot activated has published the key protecting whatever remains at that address. This was not a mistake but a reasonable tradeoff at the time, when quantum timelines looked much longer than they do now.
Migrating out of danger is possible in theory, but the decisions required are ones bitcoin’s governance culture has resisted for two decades. Should old address formats be frozen after a certain date to protect coins from future theft? Should exposed coins be allowed to move to new quantum-safe addresses using their original keys? What happens to coins whose owners cannot or will not migrate? Each answer rewrites something fundamental about how bitcoin defines ownership and resists coordinated change.
Bitcoin developers have proposed migration paths including BIP-360, a Bitcoin Improvement Proposal that would add quantum-safe address types. Ethereum, Tron, StarkWare, and Ripple have each published post-quantum transition plans. Bitcoin, notably, has not produced a unified roadmap. Unlike Ethereum, which has a coordinated, well-funded post-quantum migration plan, bitcoin lacks a unified roadmap, and its anti-centralization culture makes it harder to agree on urgent security upgrades before quantum hardware matures.
Some analysts argue the market consequences have been overstated. On-chain analyst James Check contends that even in a worst-case scenario where Satoshi-era coins are hacked and sold, the impact would resemble typical market cycles rather than an existential crisis. He segments the 6.9 million exposed BTC into distinct risk tiers, suggesting the truly high-risk portion shrinks considerably once institutions and living active users are stripped out. During bull markets, long-term holders routinely distribute between 10,000 and 30,000 BTC per day, and in the most recent bear market, more than 2.3 million BTC changed hands in a single quarter with no systemic collapse.
But the governance window may be narrowing faster than the market window. As a Google paper framed it, a successful attack on the math bitcoin uses should not be seen as a wake-up call to adopt post-quantum cryptography as much as a potential signal that PQC adoption has already failed, meaning that by the time the threat becomes visible, the window to respond may already have closed.
The bitcoin quantum threat is not confirmed to arrive tomorrow. But the trajectory of the hardware, the scale of the exposure, and the absence of a coordinated response plan mean the network is effectively running out of excuses — and possibly time.





