Blog · October 11, 2026

How much Bitcoin could a quantum computer steal?

Between about 1.7 and 7 million bitcoin have a public key visible on the blockchain, which is what a quantum attack needs. Which coins those are, and what Bitcoin is doing about it.

A coin drawn in white dots with the Bitcoin B on its face. A quarter of the face is drawn in rings instead of dots.

Between about 1.7 million and 7 million bitcoin, or roughly 9% to 35% of all coins mined, depending on what you count. None of it can be taken today. No quantum computer is anywhere near large enough yet. The Q-Day tracker shows how far off it is.

What a quantum attacker needs

Every bitcoin is locked to a private key, a secret number, and its matching public key, using a method called elliptic-curve cryptography. Getting the public key from the private key is easy. Going the other way would take an ordinary computer longer than the age of the universe. Shor’s algorithm, run on a large enough quantum computer, could do it in minutes to days.

The algorithm needs the public key as its starting point, and most Bitcoin addresses don’t show it. A typical address holds a hash of the public key, a scrambled fingerprint that can’t be reversed. The public key itself only appears on the blockchain when coins are sent from that address, because the network needs it to check the signature.

So a coin is exposed if its public key is already public. That happens in three ways:

  • The earliest coins. Bitcoin’s first outputs, mostly from 2009 and 2010, put the public key directly in the output. These are called P2PK outputs.
  • Reused addresses. After coins are sent from an address once, its public key is on the blockchain for good. Anything left there, or sent there later, is exposed.
  • Taproot addresses. These start with bc1p and, unlike older types, contain the public key itself, slightly altered.

Check an address

Paste any Bitcoin address to see which type it is and whether that type shows its key. The check happens on this page and the address isn’t sent anywhere. It can’t see whether coins have ever been sent from the address. If they have, the key is public whatever the type.

Checked on this page only. The address isn't sent anywhere.

Why the estimates differ

Different counts include different things, which is why you’ll see figures from tens of thousands to nearly 7 million.

Taproot addresses

146,715 BTC · 0.7% · Chaincode Labs, May 2025

Earliest coins, key in the output (P2PK)

about 1.7 million BTC · 8.5% · Google Quantum AI, 2026

All exposed keys, including reused addresses

6.26 million BTC · 31.5% · Project Eleven, Jan 2025

All exposed keys, including reused addresses

about 6.9 million BTC · 34.7% · Google Quantum AI, 2026

Full width is all bitcoin mined so far, about 19.9 million.

The 1.7 million in P2PK outputs is the figure least open to argument. Their keys have been public since the day the coins were mined, and many have never moved. Researchers at Chaincode Labs estimate that 600,000 to 1.1 million of them were mined by Satoshi Nakamoto.

Totals that include reused addresses change all the time, because people keep reusing addresses and keep moving coins out of them. In February 2026 the asset manager CoinShares argued that most of the P2PK coins are split into about 32,000 outputs of around 50 bitcoin each. Each output has its own key, and each key has to be broken separately, so emptying them all would take a long time on an early quantum computer.

The second kind of attack

Even a coin whose key has never been shown reveals it the moment its owner spends it. The payment waits in a queue for a few minutes until a miner includes it in a block, and during that time the public key is visible to everyone.

In March 2026, researchers at Google, with Justin Drake of the Ethereum Foundation and Dan Boneh of Stanford, estimated that a machine with under 500,000 physical qubits could break a Bitcoin key in about 9 minutes once it appears, with the rest of the work done in advance. Bitcoin blocks arrive every 10 minutes on average. Under ideal conditions, they put the attacker’s chance of redirecting a payment before it is confirmed at slightly less than 41%.

No address type protects against this. It needs new signature methods that quantum computers can’t break, known as post-quantum cryptography, and Bitcoin doesn’t have them yet.

What Bitcoin is doing about it

Two proposals are being discussed. Neither has been adopted.

  • BIP-360 adds a new address type, starting with bc1z, that works like Taproot without showing a public key. It protects coins at rest. It doesn’t add quantum-safe signatures, so it doesn’t stop the attack on payments in the queue.
  • BIP-361 sets a schedule. About three years after it is switched on, sending coins to exposed address types would be banned. About five years after, coins still in old types could no longer be spent with ordinary signatures. In practice, coins nobody moves in time would be frozen.

The second proposal is the contentious one, because it is the first time Bitcoin would stop owners from spending coins they hold. The case for it is that the alternative isn’t safety. Coins nobody moves, Satoshi’s included, would eventually be taken by whoever builds the first large enough quantum computer, and could be dumped on the market. Freezing breaks a principle. Not freezing hands those coins to a stranger. Either can be defended, but putting off the choice means it gets made by whoever builds that machine.

Ethereum has a separate plan, published in March 2026, to move to quantum-safe signatures by 2029.

If you hold bitcoin

  • Don’t reuse addresses. Most wallets generate a new address for each payment. Use that.
  • For coins you plan to leave alone for years, an address type that hides the key keeps them out of the exposed group. That means 1, 3 and bc1q addresses that have never sent coins.
  • Mining is not the weak point. Quantum computers would barely speed it up. Chaincode estimates an optimistic quantum miner would be over 1,000 times slower than a single current mining machine.

Sources