Wallet safety / Updated 2026-08-27

Quantum Computing and Your Coins: What Is Actually at Risk, on What Timeline, and What You Can Do Now

Quantum computing threatens the signatures protecting crypto, not the blockchain itself. Here is which coins are exposed, why address reuse is the variable you control, what Bitcoin is proposing, and the migration scams to expect.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-08-27 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

quantum computing crypto risk matters because Quantum computing arrives in crypto discussion either as an apocalypse or as a joke, and both framings leave you with nothing to actually do — which is a strange outcome for a risk that formal standards bodies and Bitcoin developers are both acting on.

This guide separates what quantum computing would actually break from what it would not, explains why some coins are far more exposed than others, sets out honestly what the timeline evidence supports, and identifies the one habit that materially reduces your exposure at no cost.

You will learn why the signature scheme rather than the blockchain is the target, what an exposed public key means and how many bitcoin have one, the difference between long and short exposure attacks, what BIP-360 and BIP-361 propose including a phase that would freeze unmigrated coins, and how to recognise the migration scams that this topic reliably attracts.

The target is the signature, not the blockchain

Most quantum headlines imply that a sufficiently powerful machine would somehow dissolve a blockchain. That is not the shape of the risk, and getting the shape right is what makes the rest of this tractable. A blockchain's integrity rests on hash functions, and hashing is comparatively resilient to quantum attack — the known quantum speedup against a hash function weakens it without breaking it, and the usual response is simply a longer output. Mining, block validation and the ledger's tamper-evidence are not where the problem sits.

The problem sits in the signature. Ownership of a coin is proved by producing a digital signature from a private key, and the mathematics linking a public key to its private key is exactly the kind of problem a large quantum computer is expected to solve efficiently. Break that link and you do not need to attack the network at all: you derive the private key from the public key and sign a perfectly valid transaction that every node accepts, because it is valid. This is why the standards world moved first and independently of crypto. NIST finalised its first three post-quantum standards on 13 August 2024 — FIPS 203 for general encryption, and FIPS 204 and FIPS 205 for digital signatures, the second intended as a backup should the first prove vulnerable — and urged administrators to begin integrating them immediately, because full integration will take time. The reason the migration starts before the threat materialises is that migration is slow, and that logic applies with unusual force to a system where the vulnerable material is published permanently on a public ledger.

Checklist

  • Hash functions and mining are comparatively resilient to quantum attack.
  • The vulnerable component is the signature scheme proving ownership.
  • A derived private key produces a valid transaction no node would reject.
  • NIST finalised FIPS 203, 204 and 205 on 13 August 2024.
  • NIST advises starting integration now because it takes years.
  • Public ledgers publish the vulnerable material permanently, which compresses the timeline.

Exposed keys: the number that actually sorts holders into risk groups

Here is the detail that turns an abstract debate into something you can act on. In Bitcoin's common address formats, what appears on-chain when you receive funds is not your public key but a hash of it. A hash does not hand an attacker the material they need. Your public key becomes visible at a specific moment: when you spend from that address, because the spending transaction publishes the key so the network can verify your signature. From that instant, the key is public forever, and every satoshi still sitting at that address is protected only by the difficulty of the underlying mathematics rather than by obscurity.

The scale is documented. BIP-361 states that as of 1 March 2026, over 34% of all bitcoin have revealed a public key on-chain, and that those UTXOs could be stolen by an attacker with a sufficiently powerful quantum computer. Roughly a third of the supply, in other words, is in a materially different risk category from the rest — and the difference is not the coin, the wallet brand, or the size of the holding. It is a history of address reuse. This recasts advice that has circulated for years as a privacy matter. Bitcoin.org's guidance is that you should use a new Bitcoin address each time you receive a new payment, and that addresses should only be used once. That was always sound for privacy; under a quantum threat model it becomes a security control, and it is one of the few in this entire subject that an individual can apply today, immediately, at no cost. Modern wallets generate a fresh receiving address automatically, so for most people compliance means not overriding the default — and specifically, not treating a single address as a permanent deposit box to be published, pinned in a profile, or handed out repeatedly.

Checklist

  • Receiving addresses publish a hash of the public key, not the key itself.
  • Spending from an address publishes the public key permanently.
  • Any balance left at a spent-from address sits behind exposed key material.
  • BIP-361: over 34% of all bitcoin have revealed a public key on-chain as of 1 March 2026.
  • Reused addresses, not particular coins or brands, define the exposed group.
  • Bitcoin.org: use a new address for each payment; addresses should be used once.
  • Let your wallet rotate receiving addresses; do not override the default.
  • Never publish one static address for repeated payments.

Two attacks with very different timelines

BIP-360 draws a distinction that explains why the urgency is uneven, and it is worth carrying because it tells you which risk is yours. Long exposure attacks target public keys that have been visible for extended periods; as the proposal puts it, attackers will have ample time — as much time as vulnerable keys are exposed — to carry out quantum key recovery. If a key has been sitting in public since 2013, an attacker who eventually acquires the capability can work on it at leisure. Short exposure attacks are different in kind: they target the brief window while a transaction sits unconfirmed in the mempool with its public key revealed but its spend not yet final. That requires a quantum computer fast enough to derive a key and broadcast a competing transaction within minutes, which BIP-360 describes as requiring faster quantum computers and views as lower-risk than long exposure attacks in the nearer term.

The distinction matters because it maps onto ordinary behaviour. Long exposure is a stored, accumulating risk borne by dormant balances at reused addresses — coins nobody is watching, wallets belonging to people who have died or lost interest, and holdings deliberately left untouched for a decade. Short exposure is a transient risk borne during the act of transacting, and it is far further away. If you rotate addresses and do not leave balances behind at spent-from addresses, you are largely converting a long exposure position into a short exposure one, which is the direction the whole ecosystem is trying to move. On honest timing: no one credibly claims a machine capable of this exists today, and the responsible sources decline to name a date. What the evidence does support is that institutions are planning around a window rather than a certainty — BIP-360 notes that the US federal government plans to disallow elliptic curve cryptography after 2035, with the Commercial National Security Algorithm Suite 2.0 mandating post-quantum upgrades by 2030. Those are procurement deadlines, not predictions, but they indicate what serious planners consider a prudent margin.

Checklist

  • Long exposure: keys visible for years, attackable at leisure.
  • Short exposure: the mempool window, needing a much faster machine.
  • BIP-360 treats short exposure as lower-risk in the nearer term.
  • Dormant balances at reused addresses carry the concentrated long-exposure risk.
  • Rotating addresses converts stored risk into transient risk.
  • No credible source claims a capable machine exists today.
  • CNSA 2.0 mandates post-quantum upgrades by 2030.
  • US federal planning disallows elliptic curve cryptography after 2035.

What Bitcoin is proposing, and the deadline nobody mentions to ordinary holders

Two draft proposals are worth knowing about, not because you need to follow the engineering but because one of them has a direct consequence for anyone holding long-term. BIP-360, authored by Hunter Beast, Ethan Heilman and Isabel Foxen Duke, proposes Pay-to-Merkle-Root: a new output type that behaves like Pay-to-Taproot but removes the quantum-vulnerable key path spend, committing only to a script tree's Merkle root. It is a foundation — somewhere quantum-safe to move to.

BIP-361, authored by Jameson Lopp, Christian Papathanasiou, Ian Smith, Joe Ross, Steve Vaile and Pierre-Luc Dallaire-Demers, is the one with teeth. Titled Post Quantum Migration and Legacy Signature Sunset, it proposes a phased schedule: Phase A, roughly three years after activation, would disallow sending funds to quantum-vulnerable addresses, requiring new transactions to use post-quantum script types; Phase B, two years after that, would restrict ECDSA and Schnorr spends by applying quantum-safe rescue protocols designed to let authentic coin-holders spend while blocking quantum attackers, leveraging knowledge asymmetries such as BIP-32 hardened key derivation that a quantum attacker would lack. Both are drafts, neither is activated, and Bitcoin's consensus process is deliberately slow and contested — a draft BIP is a proposal, not a schedule. But the shape of the debate is now visible, and it has an implication rarely stated to ordinary holders: any sunset design creates a class of coins whose owners did not act in time. That class is not made up of careless people so much as absent ones — inherited keys nobody knew about, wallets set aside for a decade, holders who died without a handover plan. If you hold long-term, the practical takeaway is not to migrate today, because there is nothing to migrate to yet. It is to remain migratable: know where your keys are, keep a record of which addresses hold what, make sure someone you trust can act if you cannot, and stay reachable by the information channels that would tell you when a real migration path activates.

Checklist

  • BIP-360 (P2MR) proposes a quantum-safe destination output type.
  • BIP-361 proposes a phased legacy signature sunset.
  • Phase A: block sends to quantum-vulnerable addresses, roughly three years post-activation.
  • Phase B: restrict legacy spends via rescue protocols, two years later.
  • Both are drafts; neither is activated or scheduled.
  • Any sunset strands coins whose owners are absent rather than careless.
  • Stay migratable: know your keys, your addresses, and your successor plan.
  • Follow a channel that would tell you when a real migration path exists.

The scam wave this subject reliably attracts

Every genuine security transition produces a parallel industry of people monetising the confusion, and this one has unusually fertile ground: a real, technical, widely-reported threat that most people cannot evaluate, plus a genuine future migration that will one day require holders to move funds. That combination is close to ideal for fraud, and the pattern is predictable enough to inoculate against now. Expect quantum-safe wallets sold with urgency and no verifiable engineering behind them; expect migration assistants offering to move your coins to a post-quantum address; expect scanners that will check whether your keys are quantum-vulnerable if you connect a wallet or paste a phrase; expect support staff contacting you first about an upgrade deadline.

The defences are the ordinary ones, and they hold here without modification. Nobody legitimate ever needs your recovery phrase, for any reason, including a security migration — a real migration is something you perform in your own wallet with your own keys, and the entire point of a self-custody system is that no third party can or should do it for you. Direction of contact remains the sharpest single test: the FBI's Internet Crime Complaint Center has repeatedly documented tech-support and organisation impersonation as a major fraud category, and the structural rule that follows is that genuine support answers channels you opened rather than opening them. Urgency is the other reliable tell. A real protocol migration measured in years does not require you to act within the hour, and any message compressing a multi-year engineering timeline into a same-day deadline is telling you what it is. Finally, apply a healthy scepticism to the sales pitch itself: at the time of writing there is no activated post-quantum address type on Bitcoin to migrate to, which means anything marketed today as a completed quantum migration for your bitcoin is describing something that does not yet exist.

Checklist

  • Expect quantum-safe products sold on urgency rather than engineering.
  • Expect migration assistants, vulnerability scanners and upgrade deadlines.
  • No legitimate process ever needs your recovery phrase — including a migration.
  • A real migration is performed by you, in your wallet, with your keys.
  • Direction of contact: real support answers channels you opened.
  • A multi-year timeline never produces a same-day deadline.
  • No activated post-quantum Bitcoin address type exists yet to migrate to.
  • Verify any claimed migration path against primary sources before acting.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

Will quantum computers break Bitcoin?

Not in the way the phrase suggests, and the precision matters because it determines what you should do. A blockchain's integrity rests largely on hash functions, which are comparatively resilient to quantum attack — the known speedups weaken them rather than break them, and the standard remedy is a longer output. What is genuinely vulnerable is the signature scheme that proves ownership: the mathematical relationship between a public key and its private key is exactly the sort of problem a large quantum computer is expected to solve efficiently. An attacker who did that would not need to attack the network at all, because the transaction they produced would be entirely valid and every node would accept it. So the accurate framing is that quantum computing threatens specific coins whose public keys are exposed, rather than the ledger as a system. That is also why the response is a migration to new signature schemes rather than a defence of the chain, and why NIST finalised post-quantum standards in August 2024 and advised administrators to start integrating immediately, because full integration takes time.

How do I know whether my coins are exposed?

The question to ask is not which coin you hold but whether your public key has ever appeared on-chain. In Bitcoin's common address types, receiving funds publishes only a hash of your public key, which does not give an attacker workable material. The key itself becomes visible the moment you spend from that address, because the spending transaction must publish it for the network to verify your signature — and from then on it is public permanently. Any balance still held at an address you have previously spent from therefore sits in the exposed category. BIP-361 quantifies the aggregate: as of 1 March 2026, over 34% of all bitcoin have revealed a public key on-chain, and those UTXOs could be stolen by an attacker with a sufficiently powerful quantum computer. Practically, review whether you have been treating any single address as a permanent deposit box — reusing it for repeated payments, publishing it in a profile or on a donation page — and whether balances remain at addresses you have spent from before. Both are correctable today at no cost.

What can I actually do right now?

One thing matters more than everything else combined, and it is free: stop reusing addresses. Bitcoin.org's long-standing guidance is that you should use a new address each time you receive a payment and that addresses should only be used once. This was framed for years as privacy advice; under a quantum threat model it also becomes the individual control that keeps your public key off the chain. Modern wallets rotate receiving addresses automatically, so for most people this means not fighting the default and not pinning one static address anywhere public. Beyond that, avoid leaving balances at addresses you have already spent from, and — more important than any technical step — stay migratable. Know which wallets you hold, which addresses hold what, and make sure a trusted person could act if you could not, because any eventual sunset of legacy signatures will strand coins belonging to people who were absent rather than careless. What you should not do is buy a product marketed today as a quantum migration for your bitcoin: there is no activated post-quantum address type to migrate to yet.

Is there a date by which this becomes urgent?

No credible source names one, and treat anyone who does with suspicion. What exists instead is institutional planning around a window. NIST finalised its first post-quantum standards on 13 August 2024 and urged immediate integration on the grounds that migration takes years, not because a capable machine exists. BIP-360 notes two concrete governmental markers: the Commercial National Security Algorithm Suite 2.0 mandates post-quantum upgrades by 2030, and the US federal government plans to disallow elliptic curve cryptography after 2035. Those are procurement deadlines rather than forecasts of a breakthrough, but they show what serious planners consider a prudent margin for systems that must stay secure for decades. Bitcoin's own timeline is separate and less certain: BIP-360 and BIP-361 are drafts, neither is activated, and Bitcoin's consensus process is deliberately slow and contested. The honest summary is that this is a real risk on an uncertain multi-year horizon, which is precisely the profile that rewards cheap preparatory habits — address rotation, key records, a succession plan — and punishes both panic and dismissal.

Could my coins really be frozen by a future upgrade?

It is a genuine possibility in one of the live proposals, which is why it belongs in a safety guide rather than only in developer discussion. BIP-361, titled Post Quantum Migration and Legacy Signature Sunset, proposes two phases: Phase A, roughly three years after activation, would disallow sending funds to quantum-vulnerable addresses so that new transactions must use post-quantum script types; Phase B, two years after Phase A, would restrict ECDSA and Schnorr spends by applying quantum-safe rescue protocols, described as preventing theft from legacy UTXOs without requiring knowledge of parent keys and leveraging knowledge asymmetries such as BIP-32 hardened key derivation that a quantum attacker would lack. The intent is protective — to stop a quantum attacker draining old coins — but the side effect is that holders who do not migrate within the window face restrictions on spending legacy outputs. It is essential to keep the status straight: this is a draft proposal, not an adopted schedule, and Bitcoin changes of this magnitude face years of scrutiny. The practical response is not to act now but to remain in a position to act later, which is mostly about records and succession rather than technology.

Someone is selling a quantum-safe wallet. Should I buy it?

Approach it with the same scepticism you would apply to any product sold on a fear you cannot personally evaluate, and apply one specific test first: there is currently no activated post-quantum address type on Bitcoin to migrate coins to. BIP-360's Pay-to-Merkle-Root and BIP-361's migration schedule are both drafts. So a product claiming today to have completed a quantum migration for your bitcoin is describing something that does not yet exist, whatever else it may do competently. Beyond that, the standard defences apply unchanged. No legitimate process — security migration included — ever requires your recovery phrase, and a genuine migration is something you perform yourself in your own wallet, because a system where a third party could move your coins for you is not self-custody. Watch the direction of contact, a test the FBI's Internet Crime Complaint Center guidance on organisation and tech-support impersonation supports: real support answers channels you opened rather than contacting you first. And treat urgency as diagnostic. A multi-year protocol timeline cannot generate a same-day deadline, so any message that manufactures one has told you what it is.