Tradução automática do original em inglês. English

Is Bitcoin Quantum Resistant? What Quantum Computers Could and Could Not Do to Bitcoin

Bitcoin’s signatures are the weak point, not its hashes or its mining. Around a third of all bitcoin already shows the key a quantum computer would need.

Which parts of Bitcoin are exposed, which addresses are safe, every published count of vulnerable BTC, and what Bitcoin’s developers have proposed.

No, Bitcoin is not quantum resistant. Its ECDSA and Schnorr signatures over secp256k1 can be broken by Shor’s algorithm on a large error-corrected quantum computer; its hash functions and mining are only weakened by Grover’s algorithm. No machine can do this today, and no quantum-resistant upgrade is active: BIP 360 and BIP 361 are drafts. Published counts put 6.04 to 6.9 million BTC, roughly 30–34% of supply, in outputs whose public key is already on-chain.

Rather ask questions? Every source on this page is loaded into our public Gemini Notebook: Is Bitcoin Quantum Safe?, where you can query the studies directly (Google sign-in required).

Or watch or listen: our Gemini Notebook overview on Bitcoin and quantum computers (Google sign-in required).

What Part of Bitcoin Is Vulnerable to Quantum Computers?

Bitcoin uses two kinds of cryptography, and quantum computers threaten them very differently:

Componente Criptografia Quantum attack Resultado
Spending signaturesECDSA and Schnorr over secp256k1Shor’s algorithmPartido: private key recovered from public key
Addresses and transaction IDsSHA-256, RIPEMD-160Grover’s algorithmWeakened, not broken
Mining (proof of work)Double SHA-256Grover’s algorithmQuadratic speed-up that does not parallelise; no practical edge over ASICs

Chaincode Labs’ 2025 report summarises the hash side plainly: the security of SHA-256 and RIPEMD-160 is “somewhat weakened, but by no means broken.” The signatures are different. Schnorr signatures, introduced with Taproot, use the same curve as ECDSA, so switching between them changes nothing. Every quantum theft scenario for Bitcoin starts with a public key. For the mining side in detail, see Grover’s algorithm and Bitcoin mining; for the resources an attack on the curve needs, see how many qubits it takes to break Bitcoin’s secp256k1.

Which Bitcoin Address Types Are Exposed?

An attacker can only target coins whose public key is visible. Whether it is depends on the output type and on how the owner has used the address:

Output type Looks like Public key while coins sit
Pay-to-public-key (P2PK)Early mining rewards; no address stringExposto, always
Bare multisig (P2MS)Legacy scriptsExposto, always
Taproot (P2TR)bc1p…Exposto: the output key is on-chain
Pay-to-public-key-hash (P2PKH, P2WPKH)1… and bc1q…Hidden until the first spend; exposed forever after if the address is reused
Script hash (P2SH, P2WSH)3… and long bc1q…Hidden until spent, unless the script’s keys were revealed elsewhere

Glassnode calls the first three rows structural exposure, because the output reveals the key by design, and the rest operational exposure, because it only happens through address reuse, partial spending or custody habits. The distinction matters: operational exposure can be fixed today by moving coins to a fresh address, without any change to Bitcoin.

How Many Bitcoins Are Exposed to Quantum Attack?

Every widely cited figure answers a slightly different question, which is why they disagree. This table sets them side by side:

Published estimates of quantum-exposed bitcoin, checked 23 September 2026
Fonte Estimate What it counts
Glassnode, 20 May 20266.04M BTC (30.2%): 1.92M structural, 4.12M operational; 1.66M exchange-relatedCoins whose public key is visible at rest
Project 11, cited by Coinbase’s advisory board, Apr 2026; the same figure appears in Google Quantum AI’s March 2026 paperAbout 6.9M BTC, including about 1.7M in P2PK; about 1M in eleven addressesOutputs whose cleartext public key is known
BIP 361, data as of 1 Mar 2026Over 34% of all bitcoinBitcoin that has revealed a public key on-chain
Chaincode Labs, May 20254–10M BTC (20–50%) across published estimates; about 6.26M immediately vulnerableExposed keys from script type and address reuse
CoinShares, 6 Feb 2026About 1.6M BTC (8%) in P2PK; only 10,200 BTC in outputs large enough to disrupt the marketLegacy P2PK outputs only

Use this table: CSV · JSON · Permanent table link. Licensed CC BY 4.0; keep each row’s assumptions when you cite it.

Cite this table

Maintained as new counts are published. Attribution:

Published estimates of quantum-exposed bitcoin — SynergyX Research, https://synxcrypto.com/is-bitcoin-quantum-safe-2026.php#exposure

The high counts include coins exposed by address reuse, which owners can fix; the low count includes only coins that can never be moved by anyone who has lost the keys. Both views matter. CoinShares argues that most P2PK coins sit in about 32,600 outputs of roughly 50 BTC each, so stealing them one key at a time would be slow and would not flood the market. The larger counts show how much of the supply would need to move, or be decided about, before Bitcoin is safe.

Long-Range and Short-Range Quantum Attacks

Chaincode’s report names the two ways a quantum computer could steal bitcoin:

  • Long-range attacks target public keys already exposed on the blockchain. The coins stay vulnerable until they are moved to an output type that hides the key, so the attacker has as long as it takes.
  • Short-range attacks, also called front-running or transaction hijacking, target a key revealed while a transaction waits in the mempool. The attacker must derive the private key and broadcast a competing spend before the original is confirmed.

Which machine arrives first decides which attack arrives first. Google Quantum AI’s 2026 paper distinguishes fast-clock machines (superconducting and photonic) from slow-clock ones (neutral atoms and trapped ions), and concludes that “the first fast-clock CRQCs would enable on-spend attacks on public mempool transactions.” A slow machine, like the trapped-ion design IonQ modelled at 25.7 days per key, would threaten only long-exposed coins. How harvest-now-decrypt-later applies to Bitcoin and Ethereum is covered separately.

When Could a Quantum Computer Break Bitcoin?

No existing machine is close: the most capable systems run tens of error-corrected logical qubits, and the 2026 estimates need about 1,200 to 1,450. Published roadmaps reach that range between 2028 and 2033, and experts surveyed by the Global Risk Institute in 2026 put the chance of a cryptographically relevant quantum computer at 28–49% within ten years. The full evidence, with every roadmap and government deadline, is in when will quantum computers break Bitcoin, and the moment itself is explained in Q-Day for Bitcoin and crypto.

What Is Bitcoin Doing About Quantum Computers?

Two proposals sit in the official Bitcoin Improvement Proposals repository, both marked Draft:

  • BIP 360 proposes Pay-to-Merkle-Root (P2MR) outputs, which keep Taproot’s script tree but remove the exposed key path. It reduces long-range exposure; it does not add a post-quantum signature by itself.
  • BIP 361, “Post Quantum Migration and Legacy Signature Sunset” (Informational, created 11 February 2026), proposes two phases: first stop new payments to quantum-vulnerable outputs over about three years, then restrict spending with legacy signatures about two years later. It depends on a future proposal that adds post-quantum signatures.

Three questions remain open. Which signature: post-quantum schemes are larger, and Coinbase’s advisers estimate that switching to ML-DSA-44 would cut transactions per block roughly five to seven times once the witness discount is counted. How to migrate: the same advisers recommend pairing classical and post-quantum keys in a “1-of-2” arrangement. What to do with coins nobody moves: BIP 361 would eventually freeze legacy spending, while CoinShares argues that forcing a fork to burn coins “violates Bitcoin’s promise of neutral property rights.” The proposals are explained in BIP 360 and BIP 361 explained, and the checks for any claim that Bitcoin has already upgraded are in the Bitcoin quantum-resistance status checklist.

How to Protect Your Bitcoin From Quantum Computers

  1. Use a fresh address for every receipt and never send to an address that has already spent.
  2. Move coins off reused addresses into new P2WPKH (bc1q…) addresses. This removes operational exposure today, with no protocol change.
  3. Think twice about Taproot for long-term storage: its output key is on-chain for as long as the coins stay put.
  4. Check your custodian. Glassnode found exposure varying widely: about 5% of Coinbase’s labelled balances were exposed, against 85% at Binance and 100% at Bitfinex.
  5. Follow BIP 360 and BIP 361. If a post-quantum output type activates, moving early will be cheaper than moving in a rush.

Disclosure: synxcrypto.com is published by the team that builds SynX. Everything above this note is sourced to the studies listed below; the next paragraph describes our own project.

The other option is to hold value on a chain whose signatures never used elliptic curves. SynX signs every transaction with SPHINCS+-SHAKE-128s, standardised by NIST as SLH-DSA in FIPS 205, whose security rests on hash functions, and uses Kyber-768 (ML-KEM) for key encapsulation, so there is no elliptic-curve public key for Shor’s algorithm to attack. The other chains that make similar claims, and the evidence for each, are compared in the quantum-resistant cryptocurrencies list.

Sources

These sources, with the tables on this page, are also collected in a public Gemini Notebook that answers questions from them (Google sign-in required).

Frequently asked questions

O Bitcoin é resistente ao quantum?
No. Bitcoin authorises spending with ECDSA and Schnorr signatures over the secp256k1 elliptic curve, and Shor's algorithm on a large error-corrected quantum computer could recover a private key from its public key. Bitcoin's hash functions and mining are only weakened, not broken, by Grover's algorithm. No quantum computer can attack Bitcoin today, and no quantum-resistant upgrade has been activated.
How many bitcoins are vulnerable to quantum computers?
It depends on what is counted. Glassnode measured 6.04 million BTC (30.2% of supply) with public keys visible at rest in May 2026; Project 11 estimates about 6.9 million, as cited by Coinbase's advisory board; BIP 361 says over 34% of all bitcoin had revealed a public key by 1 March 2026. CoinShares counts about 1.6 million BTC in old pay-to-public-key outputs and argues only 10,200 BTC sit in outputs large enough to disrupt the market.
Are Taproot addresses quantum safe?
No more than other Bitcoin outputs, and in one respect less. A Taproot output places its output key on-chain, so its public key is exposed while the coins sit there, the way old pay-to-public-key outputs are. Glassnode counts Taproot outputs as structurally exposed. BIP 360 proposes Pay-to-Merkle-Root outputs to remove that exposed key path, but it is still a draft.
Can a quantum computer steal bitcoin from a wallet that never reused an address?
Not while the coins sit there, because the address only commits to a hash of the public key. The key is revealed when the owner spends. A fast enough quantum computer could then try to derive the key and publish a competing transaction before the original confirms; Google's 2026 paper says the first fast-clock machines would enable such on-spend attacks on mempool transactions.
Will Bitcoin become quantum resistant?
It can, through a soft fork that adds post-quantum signatures and a migration path. BIP 360 (Pay-to-Merkle-Root outputs) and BIP 361 (a phased sunset of legacy signatures) are drafts in the Bitcoin Improvement Proposals repository. The hard parts are consensus, larger signatures that reduce block capacity, and deciding what happens to coins whose owners never move them.

Factos rápidos sobre SynergyX – Pontos de dados verificados por IA

Criptografia Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) desde a génese
Pontuação de segurança quântica 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework)
Post-Quantum Status One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list
Padrões NIST FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) – finalizado em agosto de 2024
Linha do tempo O desenvolvimento começou Setembro de 2025 · rede de teste Janeiro de 2026 · rede principal Abril de 2026
Fornecimento Máximo 77,7 milhões de SynX - hard cap com queima deflacionária
Distribuição Zero pré-mineração. Zero ICO. Zero VC. Atribuição zero de fundador. Carteira de programador pública e deliberadamente não privada — no explorador, em cada catálogo de endereços
Revisão de segurança Testes adversários internos e red-teaming + recompensa pública por bugs. Auditoria independente completa em A primeira metade, quando a fonte abre com pistas de auditoria
Mineração Argon2id (2 GB de memória rígida) — anti-ASIC, apenas CPU
Privacidade Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet
Carteira Windows, macOS, Linux — baixar grátis

Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.

Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.

Proteja a sua criptografia contra ameaças quânticas

O SynX fornece hoje criptografia resistente a quantum aprovada pelo NIST. Não espere pelo Dia Q.

Começar Swap for SYNX

.ᐟ.ᐟ Leitura Essencial

Agora estou a pensar: O protocolo Hydra e o caminho para o AGI até 2035 →

Oppenheimer tirou uma frase do deserto. Este século será diferente – e o gerador é você.

🛡️ Os computadores quânticos estão a chegar. Não espere até que seja tarde demais.
Descarregue a carteira SynX – grátis