Cryptocurrency
What a quantum computer needs is your public key. Some address types show it from day one; the others hide it behind a hash until you spend.
A Bitcoin address is exposed to a future quantum computer when its public key is visible on the blockchain. That is true for three groups: the oldest pay-to-public-key outputs, Taproot addresses that start with bc1p, and any address you have already sent coins from. Addresses starting with 1, 3 or bc1q that have never sent a transaction only show a hash of the key, and a hash is not something a quantum computer can work backwards from.
No machine can do this today. In a benchmark by Sandia with Quantinuum and NVIDIA, published in September 2026, the best machine tested ran programs on 8 error-corrected qubits. Google’s leanest design for breaking the curve Bitcoin uses needs up to 1,200 of them. But a key that is exposed stays exposed until the coins move, so it is worth knowing which kind you hold.
Bitcoin protects coins with elliptic-curve signatures (ECDSA, and Schnorr for Taproot). Your private key signs a payment. Your public key lets everyone check that signature. For an ordinary computer, working out the private key from the public key is practically impossible. A large enough quantum computer running Shor’s algorithm could do it.
Think of the public key as a photo of your front-door lock. Today no locksmith can cut a key from a photo. A large quantum computer could. Most address types keep that photo in a sealed envelope: the address is only a hash, a short fingerprint of the key that cannot be turned back into the key. The envelope opens when you spend, because the network needs the full key to check your signature.
| Starts with | Type | Public key visible? |
|---|---|---|
| bc1p | Taproot (P2TR) | Yes, from the moment coins arrive |
| no address | Pay to public key (P2PK), mostly coins mined in 2009–2010 | Yes, from the moment coins arrive |
| bc1q | SegWit (P2WPKH, 42 characters; P2WSH, 62 characters) | Only after the first spend |
| 1 | Legacy (P2PKH) | Only after the first spend |
| 3 | Script hash (P2SH), often multisig or wrapped SegWit | Only after the first spend |
Based on the vulnerability table in BIP-360 and the Chaincode Labs report. “Only after the first spend” turns into “yes” as soon as an address has sent coins and still holds some, or receives more later.
Built in. Pay-to-public-key outputs and Taproot outputs put the key in the output itself. For Taproot, Chaincode Labs explains that the “tweaked” public key is on the blockchain, so a quantum computer could derive the matching private key and spend the coins.
Address reuse. Once you send from an address, its public key is recorded forever. Any coins left on that address, or sent to it later, are exposed. Chaincode notes that exchanges and custodians have often reused addresses for cold storage.
Less obvious leaks. An extended public key (xpub), which many wallets share with services to generate addresses, reveals public keys too, as BIP-360 points out. And coins spent on a Bitcoin fork such as Bitcoin Cash or Bitcoin Gold revealed their public key there, even if they never moved on Bitcoin. Our article on cold wallets shows how one signed address can put a whole wallet tree at risk.
The most detailed public estimate comes from Chaincode Labs, a Bitcoin research group, in May 2025. It puts the potentially vulnerable share at 20 to 50% of all bitcoin: 4 to 10 million BTC. Old pay-to-public-key outputs hold about 1.72 million BTC, mostly coins mined in 2009 and 2010 that have never moved. Taproot is the opposite: about a third of all unspent outputs, but only about 0.74% of the value, around 146,700 BTC. The other large group is coins on reused addresses.
These figures come from the May 2025 report and the on-chain data it cites. The amounts have shifted since, and we have not checked a newer count.
BIP-360 separates two kinds of attack. A long-exposure attack targets keys that are already public. The attacker has as much time as needed. BIP-360’s authors expect these to be the first quantum attacks on Bitcoin.
A short-exposure attack happens while you spend. Your transaction, including your public key, waits to be confirmed. An attacker would have to compute your private key and get a competing transaction through first, within minutes to hours according to Chaincode. Every address type has this brief window. Here the experts disagree. Google estimates that a future quantum computer with fewer than 500,000 physical qubits could break a key on Bitcoin’s curve “in a few minutes”, and its paper says the first fast machines of that type would enable such attacks on transactions waiting in the queue. BIP-360’s authors think early quantum computers are unlikely to be that fast. Both are estimates about machines that do not exist yet.
This is about how keys are exposed, not about whether to buy or sell. Five steps, from simple to technical:
1. Check how your address starts. Addresses beginning with bc1q, 1 or 3 that have only received coins are in the sealed-envelope group.
2. Use a new receiving address every time, and do not keep a balance on an address you have spent from. Google’s researchers list not exposing or reusing addresses among their recommendations.
3. Move coins that sit on an exposed address. For funds on a reused address or a Taproot address, Chaincode recommends moving them to one of the hash-based types (P2PKH, P2SH, P2WPKH or P2WSH), for example a fresh bc1q address. That costs a normal transaction fee, and it only helps if you do not reuse the new address.
4. Share your xpub only where you must. A service that holds it can see all your public keys.
5. Follow BIP-360. It proposes a new output type, pay-to-Merkle-root (P2MR, addresses starting with bc1z), that works like Taproot without the exposed key. Its status is draft: it is not active and would need a soft fork. It protects against long-exposure attacks; according to BIP-360, full protection against short-exposure attacks may need post-quantum signatures. Our article on the quantum threat to Bitcoin covers the wider debate.
When. Nobody knows when a quantum computer this large will exist. The forecasts in our Q-Day tracker run from 2029 to the mid-2030s, and the countdown on our homepage follows the earliest confirmed one.
How fast the first machines will be. That decides whether short-exposure attacks become possible at the same time as long-exposure attacks, or much later.
What happens to coins that cannot move. The early pay-to-public-key coins will stay exposed unless their owners move them. Google’s researchers list policy options for such abandoned coins. Which one Bitcoin chooses, if any, is open.
Sources