Can Quantum Computers Break Bitcoin? What BIP-360 Changes
Not today, but the clock has started. What quantum computers can and can't do to Bitcoin, which coins are exposed, what BIP-360 and BIP-361 propose, and what to do with your addresses.
By Team MoonPay
Published on Sep 29, 2026

No. Not today, not with any machine that exists, and not with one anybody has credibly scheduled. But 2026 is the year the question stopped being hypothetical, because the researchers who build quantum computers cut their own estimate of what it would take, and Bitcoin's developers responded by publishing the first formal plan to move.
This article explains what a quantum computer could and couldn't do to Bitcoin, which coins are actually exposed and why, what the two proposals on the table would change, and the handful of things you control today.
In short: Quantum computers threaten the signatures that prove you own bitcoin, not the mining that secures the chain. The exposure is limited to addresses whose public key is already visible on-chain: very old addresses, reused addresses, and Taproot addresses. Google's 2026 estimate shrank the hardware required by roughly 20 times, which moved the timeline from "someday" to "plan for it." Bitcoin's first quantum-resistant address proposal, BIP-360, was merged in February. Nothing about your holdings changes today, and the best protection is already free: don't reuse addresses.
What a quantum computer could and couldn't do to Bitcoin
Bitcoin uses two kinds of cryptography, and quantum computers threaten only one of them.
The first is hashing. Mining runs SHA-256 trillions of times a second, and the chain's history is linked with hashes. Quantum computers get only a modest speedup against hashing (Grover's algorithm, which roughly halves the effective security), and the resources required to attack SHA-256 are so far beyond anything plausible that no serious proposal treats mining as the problem. When people say quantum computers will "mine all the bitcoin," they have the threat backwards.
The second is digital signatures. When you spend bitcoin, your wallet signs the transaction with a private key, and the network checks that signature against your public key. Today those signatures use elliptic-curve cryptography, which is secure because deriving a private key from a public key would take a classical computer longer than the universe has existed. A large enough quantum computer running Shor's algorithm could do that derivation in hours or minutes. If it can see your public key, it can compute your private key and spend your coins.
That last clause is the whole story. The attack needs the public key. Whether your public key is visible on the blockchain depends on what kind of address you use and whether you've spent from it.
How close are we
The honest answer is that nobody knows, and the estimates keep moving in one direction.
In March 2026, Google's quantum team published research showing that breaking the elliptic-curve cryptography used by Bitcoin, Ethereum, and most other major chains could require fewer than 500,000 physical qubits on a superconducting machine, far fewer than earlier estimates. The paper also pointed out that cryptocurrencies are unusually exposed among systems that rely on this cryptography, because elliptic-curve keys are nearly an order of magnitude smaller than RSA keys of comparable strength, so a smaller quantum computer can break them.
Half a million high-quality, error-corrected qubits is still a long way from today's hardware, and industry estimates for a cryptographically relevant machine mostly run five to fifteen years. But the gap has narrowed faster than projected, and there is a second problem that doesn't wait for the hardware at all. An attacker can record exposed public keys today and derive the private keys later, once a machine exists. For coins sitting in an exposed address, the clock on "harvest now, decrypt later" started a long time ago.
Which coins are exposed
A Bitcoin address is not the same thing as a public key. Most modern address types publish a hash of the public key, and the key itself only appears on-chain when you spend. That design, made for other reasons, turns out to be the main line of defense.
The types of address matter here, so it's worth knowing which one you're looking at.
Pay-to-public-key, or P2PK, was the format used in Bitcoin's first years. The public key is the address. Every coin in a P2PK output has had its key visible since the day it was received, including the roughly 1.7 million BTC in early addresses that are widely believed to include Satoshi Nakamoto's.
Pay-to-public-key-hash and its descendants, the addresses that start with 1, 3, or bc1q, publish only a hash. The public key stays hidden until the first time you spend from that address. After that, it's on the chain forever, and any coins sent to the same address afterward are exposed too. This is why address reuse is the single most common way ordinary holders create exposure.
Taproot addresses, which start with bc1p, are the exception in the wrong direction. They put an internal public key directly in the output so that simple spends can use it, which means a Taproot address is exposed from the moment it receives funds, whether or not you've spent. That design choice, sensible when Taproot activated in 2021, is why one of the main proposals below exists.
How much is at stake? Project Eleven, a research group focused on this problem, estimates that about 6.9 million BTC, roughly a third of the total supply, sits in addresses whose public key is already exposed. An older Deloitte analysis put the figure at more than 4 million. The exact number depends on when you count and what you count, but a quarter to a third of all bitcoin is a reasonable range, and most of it is either very old, lost, or held by people who reused an address.
The three ways an attack could work
Google's paper sorted quantum attacks on cryptocurrencies into three categories, and they're worth separating because they need very different machines.
An at-rest attack targets coins whose public key is already exposed. The attacker has all the time in the world: derive the key, sweep the coins. This is the attack that matters for old, dormant, and reused addresses, and it's the one a slower quantum computer could carry out.
An on-spend attack targets a transaction while it's waiting to be confirmed. When you spend from a clean address, your public key appears in the transaction, and there's a window of roughly ten minutes before the block is mined. An attacker who could derive the key inside that window could try to race your transaction with one of their own. This needs a much faster machine and is the scenario that would break Bitcoin for everyone, careless or not.
An on-setup attack goes after keys during generation or setup, for instance through a compromised device, and is more a general security problem than a Bitcoin-specific one.
The order matters. The at-rest attack becomes feasible first, and it only touches exposed coins. That's why the practical advice below is mostly about not being in that group.
Bitcoin's response: BIP-360 and BIP-361
Bitcoin changes slowly by design, which is why the work started early.
BIP-360, authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, was merged into Bitcoin's improvement proposal repository in February 2026, the first formal quantum-resistance proposal to reach that stage. It defines a new output type called Pay-to-Merkle-Root, or P2MR. In plain terms, it keeps the flexible script structure that Taproot introduced but removes the exposed key-path spend that makes Taproot addresses vulnerable. On its own, BIP-360 does not add quantum-resistant signatures to Bitcoin. It builds the address structure that later upgrades can plug post-quantum signature schemes into, and it would activate as a soft fork, meaning old software keeps working.
BIP-361, published in April, is the harder conversation. It proposes a phased migration in which vulnerable address types are gradually retired and coins that never move to quantum-safe addresses eventually become unspendable. The logic is that coins nobody can migrate, including lost coins and possibly Satoshi's, are exactly the coins a future quantum attacker would sweep first, and letting that happen could crash confidence in the whole system. The objection is equally direct: Bitcoin has never frozen anyone's coins, and a proposal that would do so, even for coins whose owners are gone, is a fundamental change to what the network promises. That debate is live, and it will take years to resolve either way.
What both proposals share is a timeline. Merged is not activated. Bitcoin soft forks need broad agreement among developers, node operators, and miners, and the last one, Taproot, took years from proposal to activation. Any realistic plan to move the network to quantum-safe signatures is a multi-year project, which is the strongest argument for starting it while the threat is still theoretical.
What Ethereum and the standards bodies are doing
Ethereum uses the same elliptic-curve signatures and faces the same problem, with one structural advantage: it already has account abstraction, which lets accounts choose their own signature scheme. The Ethereum Foundation runs pq.ethereum.org as a hub for its post-quantum work, with weekly test networks and milestones mapped across four future hard forks. The current fork, Glamsterdam, doesn't touch the problem, but the roadmap after it does.
The wider world is moving too. The US National Institute of Standards and Technology finalized its first post-quantum standards in 2024, with lattice-based schemes for key exchange and signatures, and released draft updates in June 2026. Those standards are what wallets, custodians, and eventually blockchains will build on. The signatures are larger than today's, which is part of why fitting them into Bitcoin blocks is an engineering problem as much as a policy one.
What you should consider
Most of what protects you is free and takes minutes.
Find out what address type you use. Open your wallet's receive screen. If the address starts with bc1q, it's a modern SegWit address that hides your public key until you spend. If it starts with bc1p, it's Taproot, and the key is exposed from receipt. If it starts with 1 or 3, it's an older format that also hides the key until first spend. Any decent wallet will tell you which it's generating and let you choose.
Don't reuse addresses. Every time you receive, use a fresh address. Most wallets do this automatically; some let you turn it off, and you shouldn't. A fresh address's public key isn't on the chain until you spend from it.
For long-term holdings, prefer bc1q over bc1p for now. Taproot has real benefits, but for coins you intend to leave untouched for years, an address that hides its key is the safer default until BIP-360 or its successors come to fruition.
Be skeptical of "quantum-proof" pitches. There is no major cryptocurrency today whose signatures are quantum-resistant, and a token marketed on that claim is selling a story instead of a solution. The fixes are coming through protocol upgrades and not through switching coins.
The at-rest risk applies to exposed addresses, and the machine that could exploit even those does not exist yet. Fix your address hygiene and let the developers do the rest.
What exchanges and custodians are doing
If your bitcoin sits with a custodian, the address questions above are theirs to answer, and in 2026 the larger ones started answering in public.
On July 23, nine firms including BlackRock, Coinbase, Fidelity Digital Assets, Strategy, Block, and Blockstream announced the Bitcoin Security Consortium, pledging $15 million over three years to fund open-source security and post-quantum research. Each member directs its own money, and the group has said it takes no position on protocol changes, which is a deliberate line: they fund the work, they don't steer it. Galaxy launched a separate $5 million quantum readiness program the same week.
Coinbase said the same day that it is building a post-quantum version of the key management system that protects most of the assets it custodies, and that it will assign engineers to open-source work including BIP-360. BlackRock's bitcoin ETF filings have listed quantum computing as a risk factor since 2025. None of this changes the math, but it does mean the institutions holding the most bitcoin have stopped treating the problem as science fiction.
Questions worth asking any custodian: what address types do you use, do you rotate addresses, and do you have a migration plan for post-quantum signatures? A good one will have answers.
Frequently asked questions
How quickly could a quantum computer mine Bitcoin? It couldn't, in any meaningful sense. Mining relies on SHA-256 hashing, and quantum computers offer only a modest speedup against it. The threat is to signatures, not to mining.
Can quantum computers bring lost Bitcoin back to life? Not to their owners. A quantum computer could let an attacker derive the keys to lost coins in exposed addresses and spend them, which is why BIP-361 proposes freezing coins that can't be migrated. The original owners wouldn't get anything back.
Can quantum computing break XRP, Ethereum, or Solana? They use the same family of elliptic-curve signatures, so the same class of attack applies. Every major chain is working on a migration; none has completed one.
Which crypto is quantum proof? No major chain is today. A few smaller projects use hash-based or lattice-based signatures, but "quantum proof" as a marketing claim deserves the same scrutiny as any other. The realistic path is upgrades to existing networks.
Should I move my Bitcoin now? If you hold coins in an address you've already spent from, or in a Taproot address you plan to leave untouched for years, moving them to a fresh bc1q address is cheap.
Start with a clean address
The quantum question comes down to one habit: never let your public key sit on the chain next to coins you still hold. Wallets that generate a fresh receiving address for every deposit give you that for free.
When you buy bitcoin through MoonPay, it's sent to the address you provide, so you can point every purchase at a fresh address in a wallet you control. Pay with a card, bank transfer, Apple Pay, or Google Pay, and the coins land where only your keys can reach them.
Quantum computers may change Bitcoin's cryptography someday. They don't change what you should do with your addresses today.





