Bitcoin’s quantum defenses are preparatory, not active: BIP 360 proposes reducing long term public key exposure, while a 2026 estimate puts a fast attack below 500,000 physical qubits under one hardware model. Exchanges can reduce some exposure through custody practices such as limiting address reuse and reviewing h...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How is the Bitcoin industry preparing for potential quantum-computing attacks through transactions compatible with current rules, protocol u. Article summary: Bitcoin’s quantum preparations have two tracks: reduce public-key exposure using today’s transaction rules, and develop protocol changes for stronger protection. Neither is a complete, activated defense. The practical qu. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Bitcoin’s preparations for a possible quantum threat have two parts: reduce public-key exposure where today’s rules allow, and consider protocol changes that could offer stronger protection. Neither makes Bitcoin universally quantum-resistant today. The challenge is not only designing a defense, but agreeing on an upgrade and giving holders time to move funds. 1
3
7
The concern is Bitcoin’s elliptic-curve signature cryptography: a sufficiently powerful quantum computer could, in theory, derive a private key from a public key. The exposure depends on when that public key becomes visible. Some outputs reveal it on-chain by design; other keys become visible when funds are spent. That creates a longer period of exposure for some coins and a shorter window around a transaction for others. 3
5
A 2026 estimate described a fast attack on an exposed key as requiring roughly 1,200–1,450 logical qubits, translating to fewer than 500,000 physical superconducting qubits under the study’s assumptions. These are modeled resource requirements, not a forecast of when a machine will be built. Reporting in September 2026 said no cryptographically relevant quantum computer capable of breaking Bitcoin’s signatures existed. 1
2
Estimates of how much BTC is associated with exposed public keys vary. One analysis cited roughly 6.99 million BTC, while another cited 6.04 million BTC; the underlying methods and definitions differ, so the figures are best read as an indication of scale rather than a precise tally. Exposure alone does not mean the coins can be stolen with today’s computers. 4
5
Before a network upgrade, custodians can focus on limiting unnecessary public-key exposure. Reported measures include reducing address reuse, reviewing where funds are held, and examining custody and withdrawal procedures. Where practical, moving funds from outputs with exposed keys can reduce long-term exposure—but it does not provide a new signature scheme or protect every coin in every transaction scenario. 1
Developers are also discussing narrower transaction-level approaches, including commit-and-reveal techniques and ways to use hash-based signatures in particular rescue or migration workflows. These approaches are not a universal replacement for Bitcoin’s existing signature rules; their usefulness depends on the specific method and its assumptions. 46
47
BIP-360 proposes Pay-to-Merkle-Root (P2MR), a Taproot-like output that removes Taproot’s key-path spending option. Instead, it commits to a script tree, which is intended to reduce long-term exposure of an always-visible public key. The proposal is designed to address long-exposure attacks, not every possible exposure during a spend. 3
7
Crucially, BIP-360 does not itself introduce a post-quantum signature algorithm. It proposes a new output structure; choosing and deploying post-quantum signatures is a separate problem. The proposal would require a soft fork, and being published as a proposal does not mean the change is active on Bitcoin. 7
17
21
That makes BIP-360 a possible part of a transition, not a complete quantum-proofing plan. Existing funds would not move automatically into a new output type, and owners would need a way to migrate them if they want to use a safer destination. 1
17
Bitcoin’s defenses involve trade-offs as well as cryptography: participants need to assess a proposed change, agree on how it should work and adopt it. Even if an upgrade creates a safer destination, it cannot move dormant or inaccessible coins by itself. Decisions about migration therefore matter alongside the technical design. 3
7
21
The estimates make preparation worth taking seriously, but they do not establish a deadline. The clearest takeaway is that Bitcoin has ways to reduce some exposure now and proposals for broader changes, while neither current practices nor BIP-360 amount to a fully deployed, network-wide post-quantum defense. 1
2
3
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Bitcoin’s quantum defenses are preparatory, not active: BIP 360 proposes reducing long term public key exposure, while a 2026 estimate puts a fast attack below 500,000 physical qubits under one hardware model.
Bitcoin’s quantum defenses are preparatory, not active: BIP 360 proposes reducing long term public key exposure, while a 2026 estimate puts a fast attack below 500,000 physical qubits under one hardware model. Exchanges can reduce some exposure through custody practices such as limiting address reuse and reviewing how funds are held and moved, but these steps do not make every Bitcoin output quantum resistant.
Estimates of Bitcoin linked to exposed public keys range from about 6.0 million to 7.0 million BTC in the cited analyses; the figures use different methodologies and should not be treated as a single precise count.