October 11, 2026
How much Bitcoin could a quantum computer steal?
Between about 1.7 million and 7 million bitcoin, or roughly 9% to 35% of all coins mined, depending on what you count. None of it can be taken today. No quantum computer is anywhere near large enough yet. The Q-Day tracker shows how far off it is.
What a quantum attacker needs
Every bitcoin is locked to a private key, a secret number, and its matching public key. Getting the public key from the private key is easy. Going the other way would take an ordinary computer longer than the age of the universe. Shor’s algorithm, run on a large enough quantum computer, could do it in minutes to days.
The algorithm needs the public key as its starting point, and most Bitcoin addresses don’t show it. A typical address holds a hash of the public key, a scrambled fingerprint that can’t be reversed. The public key itself only appears on the blockchain when coins are sent from that address, because the network needs it to check the signature.
So a coin is exposed if its public key is already public. That happens in three ways:
- The earliest coins. Bitcoin’s first outputs, mostly from 2009 and 2010, put the public key directly in the output. These are called P2PK outputs.
- Reused addresses. After coins are sent from an address once, its public key is on the blockchain for good. Anything left there, or sent there later, is exposed.
- Taproot addresses. These start with bc1p and, unlike older types, contain the public key itself, slightly altered.
Check an address
Paste any Bitcoin address to see which type it is and whether that type shows its key. The check happens on this page and the address isn’t sent anywhere. It can’t see whether coins have ever been sent from the address. If they have, the key is public whatever the type.
Checked on this page only. The address isn't sent anywhere.
Why the estimates differ
Different counts include different things, which is why you’ll see figures from tens of thousands to nearly 7 million.
Full width is all bitcoin mined so far, about 19.9 million.
The 1.7 million in P2PK outputs is the figure least open to argument. Their keys have been public since the day the coins were mined, and many have never moved. Researchers at Chaincode Labs estimate that 600,000 to 1.1 million of them were mined by Satoshi Nakamoto.
Totals that include reused addresses change all the time, because people keep reusing addresses and keep moving coins out of them. In February 2026 the asset manager CoinShares argued that most of the P2PK coins are split into about 32,000 outputs of around 50 bitcoin each. Each output has its own key, and each key has to be broken separately, so emptying them all would take a long time on an early quantum computer.
The second kind of attack
Even a coin whose key has never been shown reveals it the moment its owner spends it. The payment waits in a queue for a few minutes until a miner includes it in a block, and during that time the public key is visible to everyone.
In March 2026, researchers at Google, with Justin Drake of the Ethereum Foundation and Dan Boneh of Stanford, estimated that a machine with under 500,000 qubits could break a Bitcoin key in about 9 minutes once it appears, with the rest of the work done in advance. Bitcoin blocks arrive every 10 minutes on average. Under ideal conditions, they put the attacker’s chance of redirecting a payment before it is confirmed at slightly less than 41%.
No address type protects against this. It needs new signature methods that quantum computers can’t break, and Bitcoin doesn’t have them yet.
What Bitcoin is doing about it
Two proposals are being discussed. Neither has been adopted.
- BIP-360 adds a new address type, starting with bc1z, that works like Taproot without showing a public key. It protects coins at rest. It doesn’t add quantum-safe signatures, so it doesn’t stop the attack on payments in the queue.
- BIP-361 sets a schedule. About three years after it is switched on, sending coins to exposed address types would be banned. About five years after, coins still in old types could no longer be spent with ordinary signatures. In practice, coins nobody moves in time would be frozen.
The second proposal is the contentious one, because it is the first time Bitcoin would stop owners from spending coins they hold. The case for it is that the alternative isn’t safety. Coins nobody moves, Satoshi’s included, would eventually be taken by whoever builds the first large enough quantum computer, and could be dumped on the market. Freezing breaks a principle. Not freezing hands those coins to a stranger. Either can be defended, but putting off the choice means it gets made by whoever builds that machine.
Ethereum has a separate plan, published in March 2026, to move to quantum-safe signatures by 2029.
If you hold bitcoin
- Don’t reuse addresses. Most wallets generate a new address for each payment. Use that.
- For coins you plan to leave alone for years, an address type that hides the key keeps them out of the exposed group. That means 1, 3 and bc1q addresses that have never sent coins.
- Mining is not the weak point. Quantum computers would barely speed it up. Chaincode estimates an optimistic quantum miner would be over 1,000 times slower than a single current mining machine.
Sources
- Bitcoin and Quantum Computing, Chaincode Labs, May 2025
- Babbush, Gidney, Drake, Boneh and others, Google Quantum AI, 2026
- Bitcoin Risq List, Project Eleven, a live count of exposed addresses
- CoinShares on P2PK exposure, The Block, February 2026
- BIP-360 and BIP-361
- BitGo’s address check, which also looks up balances