首页博客7 Million Bitcoins at Risk… Is the Quantum Computing Threat Real?

7 Million Bitcoins at Risk… Is the Quantum Computing Threat Real?

Mar 24 2026

7 Million Bitcoins at Risk… Is the Quantum Computing Threat Real? image

The rapid advancement of quantum computing is posing an unprecedented threat to Bitcoin’s security framework. Theoretically, a sufficiently advanced quantum computer could derive a private key from an exposed public key, allowing an attacker to forge signatures and steal funds. Consequently, concerns are growing that Bitcoin’s encryption system could meet its end due to quantum computing.

Specific Bitcoins are More Vulnerable Exactly how much Bitcoin is directly exposed to this quantum threat? According to an analysis by 'Project Eleven,' a security firm specializing in quantum risk for digital assets, approximately 7 million BTC—valued at about $470 billion—are in a vulnerable state. These holdings are particularly at risk because their public keys are already visible on-chain, a state known as 'long exposure.'

The vulnerable supply identified in the analysis falls into three main categories:

  1. Early Legacy Addresses: In Bitcoin’s early days, public keys were recorded directly on the blockchain without encryption for technical convenience. This makes them highly susceptible to quantum attacks. This includes about 1.1 million BTC estimated to have been mined by Satoshi Nakamoto.

  2. Address Reuse: Even with modern addresses, sending coins requires revealing the public key to the network. If a user sends a portion of their coins and leaves the remaining balance in the same address, the public key remains on-chain and visible to anyone. Currently, many exchanges and individuals reuse addresses for management convenience, accounting for about 70% of the total vulnerable supply.

  3. Taproot Addresses: While Taproot offers high security and efficiency, its design causes the public key to be immediately exposed on-chain, making it potentially vulnerable to quantum attacks. As Taproot adoption grows, so may the amount of exposed Bitcoin.

Developers Preparing for the Quantum Era How is the Bitcoin community preparing? Developers are working on making Bitcoin 'quantum-resistant.'

  • New Address Types: The fundamental solution is introducing new address types based on 'post-quantum cryptography.' Users could move funds from vulnerable old addresses to secure new ones. The BIP-360 proposal is currently under discussion as the first official step toward quantum resistance.

  • The ‘Hourglass’ Proposal: This soft fork proposal aims to prevent lost or legacy coins with exposed keys from flooding the market at once via quantum attacks. It suggests a 'spending speed limit' for vulnerable addresses that haven't moved for a long time, restricting the amount or adding a delay to withdrawals to prevent immediate mass sell-offs even if a theft occurs.

  • Hiding Public Keys: Techniques are being developed to block 'short exposure' threats, where attackers steal public keys from transactions waiting in the mempool. Experiments are underway primarily on BitVM-based sidechains and Layer 2 solutions to prove ownership without revealing public keys.

When Will the Quantum Challenge Become Reality? Opinions are polarized between those who dismiss the threat as decades away and those warning of immediate danger. Alex Thorn, Head of Research at Galaxy Digital, diagnosed that while the future threat is significant, it is not so urgent that it will outpace the response capabilities of Bitcoin developers. He emphasized that Bitcoin’s open-source model is a strength, providing the time, talent, and incentive needed to solve the risk. He concluded that 'Q-Day'—the day modern cryptography could be broken—is still a distant prospect limited to highly specialized research groups, and recent FUD regarding quantum computing is somewhat excessive.

In summary, the Bitcoin community's stance is: "No panic, but the response has begun." Experts estimate a migration period of about seven years will be required for Bitcoin to achieve full quantum resistance.

返回博客立即加入 Lolliback