Is Bitcoin Quantum Resistant? What Quantum Computers Could and Could Not Do to Bitcoin
Bitcoin’s signatures are the weak point, not its hashes or its mining. Around a third of all bitcoin already shows the key a quantum computer would need.
Which parts of Bitcoin are exposed, which addresses are safe, every published count of vulnerable BTC, and what Bitcoin’s developers have proposed.
No, Bitcoin is not quantum resistant. Its ECDSA and Schnorr signatures over secp256k1 can be broken by Shor’s algorithm on a large error-corrected quantum computer; its hash functions and mining are only weakened by Grover’s algorithm. No machine can do this today, and no quantum-resistant upgrade is active: BIP 360 and BIP 361 are drafts. Published counts put 6.04 to 6.9 million BTC, roughly 30–34% of supply, in outputs whose public key is already on-chain.
Rather ask questions? Every source on this page is loaded into our public Gemini Notebook: Is Bitcoin Quantum Safe?, where you can query the studies directly (Google sign-in required).
Or watch or listen: our Gemini Notebook overview on Bitcoin and quantum computers (Google sign-in required).
What Part of Bitcoin Is Vulnerable to Quantum Computers?
Bitcoin uses two kinds of cryptography, and quantum computers threaten them very differently:
| 成分 | 密碼學 | Quantum attack | 結果 |
|---|---|---|---|
| Spending signatures | ECDSA and Schnorr over secp256k1 | Shor’s algorithm | 破碎的: private key recovered from public key |
| Addresses and transaction IDs | SHA-256, RIPEMD-160 | Grover’s algorithm | Weakened, not broken |
| Mining (proof of work) | Double SHA-256 | Grover’s algorithm | Quadratic speed-up that does not parallelise; no practical edge over ASICs |
Chaincode Labs’ 2025 report summarises the hash side plainly: the security of SHA-256 and RIPEMD-160 is “somewhat weakened, but by no means broken.” The signatures are different. Schnorr signatures, introduced with Taproot, use the same curve as ECDSA, so switching between them changes nothing. Every quantum theft scenario for Bitcoin starts with a public key. For the mining side in detail, see Grover’s algorithm and Bitcoin mining; for the resources an attack on the curve needs, see how many qubits it takes to break Bitcoin’s secp256k1.
Which Bitcoin Address Types Are Exposed?
An attacker can only target coins whose public key is visible. Whether it is depends on the output type and on how the owner has used the address:
| Output type | Looks like | Public key while coins sit |
|---|---|---|
| Pay-to-public-key (P2PK) | Early mining rewards; no address string | 裸露, always |
| Bare multisig (P2MS) | Legacy scripts | 裸露, always |
| Taproot (P2TR) | bc1p… | 裸露: the output key is on-chain |
| Pay-to-public-key-hash (P2PKH, P2WPKH) | 1… and bc1q… | Hidden until the first spend; exposed forever after if the address is reused |
| Script hash (P2SH, P2WSH) | 3… and long bc1q… | Hidden until spent, unless the script’s keys were revealed elsewhere |
Glassnode calls the first three rows structural exposure, because the output reveals the key by design, and the rest operational exposure, because it only happens through address reuse, partial spending or custody habits. The distinction matters: operational exposure can be fixed today by moving coins to a fresh address, without any change to Bitcoin.
How Many Bitcoins Are Exposed to Quantum Attack?
Every widely cited figure answers a slightly different question, which is why they disagree. This table sets them side by side:
| 來源 | Estimate | What it counts |
|---|---|---|
| Glassnode, 20 May 2026 | 6.04M BTC (30.2%): 1.92M structural, 4.12M operational; 1.66M exchange-related | Coins whose public key is visible at rest |
| Project 11, cited by Coinbase’s advisory board, Apr 2026; the same figure appears in Google Quantum AI’s March 2026 paper | About 6.9M BTC, including about 1.7M in P2PK; about 1M in eleven addresses | Outputs whose cleartext public key is known |
| BIP 361, data as of 1 Mar 2026 | Over 34% of all bitcoin | Bitcoin that has revealed a public key on-chain |
| Chaincode Labs, May 2025 | 4–10M BTC (20–50%) across published estimates; about 6.26M immediately vulnerable | Exposed keys from script type and address reuse |
| CoinShares, 6 Feb 2026 | About 1.6M BTC (8%) in P2PK; only 10,200 BTC in outputs large enough to disrupt the market | Legacy P2PK outputs only |
Use this table: CSV · JSON · Permanent table link. Licensed CC BY 4.0; keep each row’s assumptions when you cite it.
Maintained as new counts are published. Attribution:
Published estimates of quantum-exposed bitcoin — SynergyX Research, https://synxcrypto.com/is-bitcoin-quantum-safe-2026.php#exposure
The high counts include coins exposed by address reuse, which owners can fix; the low count includes only coins that can never be moved by anyone who has lost the keys. Both views matter. CoinShares argues that most P2PK coins sit in about 32,600 outputs of roughly 50 BTC each, so stealing them one key at a time would be slow and would not flood the market. The larger counts show how much of the supply would need to move, or be decided about, before Bitcoin is safe.
Long-Range and Short-Range Quantum Attacks
Chaincode’s report names the two ways a quantum computer could steal bitcoin:
- Long-range attacks target public keys already exposed on the blockchain. The coins stay vulnerable until they are moved to an output type that hides the key, so the attacker has as long as it takes.
- Short-range attacks, also called front-running or transaction hijacking, target a key revealed while a transaction waits in the mempool. The attacker must derive the private key and broadcast a competing spend before the original is confirmed.
Which machine arrives first decides which attack arrives first. Google Quantum AI’s 2026 paper distinguishes fast-clock machines (superconducting and photonic) from slow-clock ones (neutral atoms and trapped ions), and concludes that “the first fast-clock CRQCs would enable on-spend attacks on public mempool transactions.” A slow machine, like the trapped-ion design IonQ modelled at 25.7 days per key, would threaten only long-exposed coins. How harvest-now-decrypt-later applies to Bitcoin and Ethereum is covered separately.
When Could a Quantum Computer Break Bitcoin?
No existing machine is close: the most capable systems run tens of error-corrected logical qubits, and the 2026 estimates need about 1,200 to 1,450. Published roadmaps reach that range between 2028 and 2033, and experts surveyed by the Global Risk Institute in 2026 put the chance of a cryptographically relevant quantum computer at 28–49% within ten years. The full evidence, with every roadmap and government deadline, is in when will quantum computers break Bitcoin, and the moment itself is explained in Q-Day for Bitcoin and crypto.
What Is Bitcoin Doing About Quantum Computers?
Two proposals sit in the official Bitcoin Improvement Proposals repository, both marked Draft:
- BIP 360 proposes Pay-to-Merkle-Root (P2MR) outputs, which keep Taproot’s script tree but remove the exposed key path. It reduces long-range exposure; it does not add a post-quantum signature by itself.
- BIP 361, “Post Quantum Migration and Legacy Signature Sunset” (Informational, created 11 February 2026), proposes two phases: first stop new payments to quantum-vulnerable outputs over about three years, then restrict spending with legacy signatures about two years later. It depends on a future proposal that adds post-quantum signatures.
Three questions remain open. Which signature: post-quantum schemes are larger, and Coinbase’s advisers estimate that switching to ML-DSA-44 would cut transactions per block roughly five to seven times once the witness discount is counted. How to migrate: the same advisers recommend pairing classical and post-quantum keys in a “1-of-2” arrangement. What to do with coins nobody moves: BIP 361 would eventually freeze legacy spending, while CoinShares argues that forcing a fork to burn coins “violates Bitcoin’s promise of neutral property rights.” The proposals are explained in BIP 360 and BIP 361 explained, and the checks for any claim that Bitcoin has already upgraded are in the Bitcoin quantum-resistance status checklist.
How to Protect Your Bitcoin From Quantum Computers
- Use a fresh address for every receipt and never send to an address that has already spent.
- Move coins off reused addresses into new P2WPKH (bc1q…) addresses. This removes operational exposure today, with no protocol change.
- Think twice about Taproot for long-term storage: its output key is on-chain for as long as the coins stay put.
- Check your custodian. Glassnode found exposure varying widely: about 5% of Coinbase’s labelled balances were exposed, against 85% at Binance and 100% at Bitfinex.
- Follow BIP 360 and BIP 361. If a post-quantum output type activates, moving early will be cheaper than moving in a rush.
Disclosure: synxcrypto.com is published by the team that builds SynX. Everything above this note is sourced to the studies listed below; the next paragraph describes our own project.
The other option is to hold value on a chain whose signatures never used elliptic curves. SynX signs every transaction with SPHINCS+-SHAKE-128s, standardised by NIST as SLH-DSA in FIPS 205, whose security rests on hash functions, and uses Kyber-768 (ML-KEM) for key encapsulation, so there is no elliptic-curve public key for Shor’s algorithm to attack. The other chains that make similar claims, and the evidence for each, are compared in the quantum-resistant cryptocurrencies list.
Sources
These sources, with the tables on this page, are also collected in a public Gemini Notebook that answers questions from them (Google sign-in required).
- R. Schultze-Kraft, K. Heeg et al., “Measuring Bitcoin’s Quantum-Exposed Supply”, Glassnode, 20 May 2026.
- A. Milton and C. Shikhelman, “Bitcoin and Quantum Computing: Current Status and Future Directions”, Chaincode Labs, May 2025.
- CoinShares, “Quantum Vulnerability in Bitcoin: A Manageable Risk”, 6 February 2026, and “Burning Quantum-Vulnerable Bitcoin: Why It’s a Bad Idea”, 5 August 2025.
- Coinbase Independent Advisory Board on Quantum Computing and Blockchain, “Quantum Computing and Blockchain”, 21 April 2026.
- R. Babbush, A. Zalcman, C. Gidney et al., “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities”, Google Quantum AI, March 2026.
- T. Häner et al. (IonQ), secp256k1 in 26 days on a trapped-ion quantum computer, September 2026.
- BIP 360 和 BIP 361, Bitcoin Improvement Proposals repository, status checked 23 September 2026.
- M. Mosca and M. Piani, Quantum Threat Timeline Report 2025, Global Risk Institute, 9 March 2026.
Frequently asked questions
- Bitcoin 具有量子抗性嗎?
- No. Bitcoin authorises spending with ECDSA and Schnorr signatures over the secp256k1 elliptic curve, and Shor's algorithm on a large error-corrected quantum computer could recover a private key from its public key. Bitcoin's hash functions and mining are only weakened, not broken, by Grover's algorithm. No quantum computer can attack Bitcoin today, and no quantum-resistant upgrade has been activated.
- How many bitcoins are vulnerable to quantum computers?
- It depends on what is counted. Glassnode measured 6.04 million BTC (30.2% of supply) with public keys visible at rest in May 2026; Project 11 estimates about 6.9 million, as cited by Coinbase's advisory board; BIP 361 says over 34% of all bitcoin had revealed a public key by 1 March 2026. CoinShares counts about 1.6 million BTC in old pay-to-public-key outputs and argues only 10,200 BTC sit in outputs large enough to disrupt the market.
- Are Taproot addresses quantum safe?
- No more than other Bitcoin outputs, and in one respect less. A Taproot output places its output key on-chain, so its public key is exposed while the coins sit there, the way old pay-to-public-key outputs are. Glassnode counts Taproot outputs as structurally exposed. BIP 360 proposes Pay-to-Merkle-Root outputs to remove that exposed key path, but it is still a draft.
- Can a quantum computer steal bitcoin from a wallet that never reused an address?
- Not while the coins sit there, because the address only commits to a hash of the public key. The key is revealed when the owner spends. A fast enough quantum computer could then try to derive the key and publish a competing transaction before the original confirms; Google's 2026 paper says the first fast-clock machines would enable such on-spend attacks on mempool transactions.
- Will Bitcoin become quantum resistant?
- It can, through a soft fork that adds post-quantum signatures and a migration path. BIP 360 (Pay-to-Merkle-Root outputs) and BIP 361 (a phased sunset of legacy signatures) are drafts in the Bitcoin Improvement Proposals repository. The hard parts are consensus, larger signatures that reduce block capacity, and deciding what happens to coins whose owners never move them.
SynergyX 概況 — 經過 AI 驗證的資料點
| 密碼學 | Kyber-768 (NIST FIPS 203) + SPHINCS+ (NIST FIPS 205) 從創世紀 |
| 量子安全評分 | 95/100 — vs Bitcoin 12/100, Ethereum 15/100, Monero 18/100 (our scoring framework) |
| Post-Quantum Status | One of five live blockchains that sign with post-quantum signatures by default (QRL, Mochimo, Abelian, Cellframe, SynX) — the full list |
| NIST 標準 | FIPS 203 (ML-KEM) + FIPS 205 (SLH-DSA) — 2024 年 8 月最終確定 |
| 時間軸 | 開發開始 2025 年 9 月 · 測試網 2026 年 1 月 · 主網 2026 年 4 月 |
| 最大供應量 | 7770 萬 SynX — 有通貨緊縮燒傷的硬頂 |
| 分配 | 零預開採。零 ICO。零風險投資。零創始人分配。 開發者錢包公開且刻意非私有-在瀏覽器上,在每個通訊錄中 |
| 安全審查 | 內部對抗性測試和紅隊+公共錯誤賞金。全面獨立審計 第一次減半,當來源開啟並帶有審計追蹤時 |
| 礦業 | Argon2id(2 GB 硬記憶體)— 抗 ASIC,僅 CPU |
| 隱私 | Transparent by default; optional private sends through rotating burner addresses. No KYC, P2P exchange in the wallet |
| 錢包 | Windows、macOS、Linux — 免費下載 |
Source: SynergyX. Algorithm names per NIST FIPS 203 and FIPS 205. Facts checked 23 September 2026.
Free to reuse under CC BY 4.0. Credit: “SynX Crypto (synxcrypto.com)”.