Iron is now MoonPay Enterprise: Stablecoin APIs for developers → Learn More

MoonPay
  • Individuals
  • Business
  • Language
  • Get Started
Buy
Buy cryptoUse a card, Apple Pay or Google Pay to buy crypto fast. We also accept bank transfers and wires.
Buy BitcoinBTC
Buy EthereumETH
Buy PolygonPOL
Buy SolanaSOL
Buy DogecoinDOGE
Buy CardanoADA
Buy AvalancheAVAX
Sell
Sell cryptoTurn your crypto into cash. In a flash. Get paid straight to your bank account or Visa card.
Sell BitcoinBTC
Sell EthereumETH
Sell USDCUSDC
Sell SolanaSOL
Sell CardanoADA
Sell DogecoinDOGE
Sell AvalancheAVAX
Trade
Trade cryptoTrade between tokens, even if they’re on different chains (we make bridging seamless too).
Trade EthereumETH
Trade USDCUSDC
Trade AaveAAVE
Trade ChainlinkLINK
Trade Wrapped BitcoinWBTC
Trade DaiDAI
Trade CompoundCOMP
Company
NewsroomNewsroomMediaMediaCareersCareersChangelogChangelogMoonPay DiscoverMoonPay DiscoverNew
Crypto Prices
Bitcoin PriceEthereum PriceSolana PriceDogecoin PriceCardano PriceXRP PriceBNB PriceAll Crypto Prices
Learn
What is Blockchain?What is Blockchain?What are NFTs?What are NFTs?What is Bitcoin mining?What is Bitcoin mining?What is DeFi?What is DeFi?What is crypto staking?What is crypto staking?All Learn Articles
Support
DocumentationDocumentationHelp CenterHelp CenterContact UsContact UsStatusStatus
  • Language
  • Get Started

    All rights reserved. MoonPay USA LLC is a registered money service business (NMLS ID: 2071245). For Law Enforcement requests please direct your official document to our compliance team here.

    English
    • Personal
    • Buy Crypto
    • Sell Crypto
    • Trade Crypto
    • Learn about Crypto
    • Crypto Price
    • MoonAgentsNew!
    • Business
    • Ramps
    • Virtual AccountsNew!
    • MoonPay Discover
    • MoonPay Commerce
    • MoonPay InstitutionalNew!
    • Company
    • About Us
    • CareersWe're hiring
    • Newsroom
    • Media
    • Changelog
    • Support
    • API Docs
    • Help Center
    • Contact Us
    • Status
    • Security
    • Buy
    • Buy Bitcoin
    • Buy Ethereum
    • Buy Solana
    • Buy Cardano
    • Sell
    • Sell Bitcoin
    • Sell Ethereum
    • Sell XRP
    • Sell Solana
    • Trade
    • Trade Ethereum
    • Trade SOL
    • Trade Aave
    • Trade Chainlink
    • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Dogecoin Price
    • XRP Price
    • Cardano Price
    • Learn
    • What is Blockchain?
    • What are NFTs?
    • What is Bitcoin mining?
    • What is DeFi?
    • What is crypto staking?
    • Legal
    • Licenses
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    English

    All rights reserved. MoonPay USA LLC is a registered money service business (NMLS ID: 2071245). For Law Enforcement requests please direct your official document to our compliance team here.

    Iron is now MoonPay Enterprise: Stablecoin APIs for developers → Learn More

    MoonPay
    • Individuals
    • Business
    • Language
    • Get Started
    Buy
    Buy cryptoUse a card, Apple Pay or Google Pay to buy crypto fast. We also accept bank transfers and wires.
    Buy BitcoinBTC
    Buy EthereumETH
    Buy PolygonPOL
    Buy SolanaSOL
    Buy DogecoinDOGE
    Buy CardanoADA
    Buy AvalancheAVAX
    Sell
    Sell cryptoTurn your crypto into cash. In a flash. Get paid straight to your bank account or Visa card.
    Sell BitcoinBTC
    Sell EthereumETH
    Sell USDCUSDC
    Sell SolanaSOL
    Sell CardanoADA
    Sell DogecoinDOGE
    Sell AvalancheAVAX
    Trade
    Trade cryptoTrade between tokens, even if they’re on different chains (we make bridging seamless too).
    Trade EthereumETH
    Trade USDCUSDC
    Trade AaveAAVE
    Trade ChainlinkLINK
    Trade Wrapped BitcoinWBTC
    Trade DaiDAI
    Trade CompoundCOMP
    Company
    NewsroomNewsroomMediaMediaCareersCareersChangelogChangelogMoonPay DiscoverMoonPay DiscoverNew
    Crypto Prices
    Bitcoin PriceEthereum PriceSolana PriceDogecoin PriceCardano PriceXRP PriceBNB PriceAll Crypto Prices
    Learn
    What is Blockchain?What is Blockchain?What are NFTs?What are NFTs?What is Bitcoin mining?What is Bitcoin mining?What is DeFi?What is DeFi?What is crypto staking?What is crypto staking?All Learn Articles
    Support
    DocumentationDocumentationHelp CenterHelp CenterContact UsContact UsStatusStatus
  • Language
  • Get Started
    Back to all articles

    Can Quantum Computers Break Bitcoin? What BIP-360 Changes

    Not today, but the clock has started. What quantum computers can and can't do to Bitcoin, which coins are exposed, what BIP-360 and BIP-361 propose, and what to do with your addresses.

    Team MoonPay

    By Team MoonPay

    Published on Sep 29, 2026

    bitcoincryptocurrencyquantum
    quantum computers bitcoin

    No. Not today, not with any machine that exists, and not with one anybody has credibly scheduled. But 2026 is the year the question stopped being hypothetical, because the researchers who build quantum computers cut their own estimate of what it would take, and Bitcoin's developers responded by publishing the first formal plan to move.

    This article explains what a quantum computer could and couldn't do to Bitcoin, which coins are actually exposed and why, what the two proposals on the table would change, and the handful of things you control today.

    In short: Quantum computers threaten the signatures that prove you own bitcoin, not the mining that secures the chain. The exposure is limited to addresses whose public key is already visible on-chain: very old addresses, reused addresses, and Taproot addresses. Google's 2026 estimate shrank the hardware required by roughly 20 times, which moved the timeline from "someday" to "plan for it." Bitcoin's first quantum-resistant address proposal, BIP-360, was merged in February. Nothing about your holdings changes today, and the best protection is already free: don't reuse addresses.

    What a quantum computer could and couldn't do to Bitcoin

    Bitcoin uses two kinds of cryptography, and quantum computers threaten only one of them.

    The first is hashing. Mining runs SHA-256 trillions of times a second, and the chain's history is linked with hashes. Quantum computers get only a modest speedup against hashing (Grover's algorithm, which roughly halves the effective security), and the resources required to attack SHA-256 are so far beyond anything plausible that no serious proposal treats mining as the problem. When people say quantum computers will "mine all the bitcoin," they have the threat backwards.

    The second is digital signatures. When you spend bitcoin, your wallet signs the transaction with a private key, and the network checks that signature against your public key. Today those signatures use elliptic-curve cryptography, which is secure because deriving a private key from a public key would take a classical computer longer than the universe has existed. A large enough quantum computer running Shor's algorithm could do that derivation in hours or minutes. If it can see your public key, it can compute your private key and spend your coins.

    That last clause is the whole story. The attack needs the public key. Whether your public key is visible on the blockchain depends on what kind of address you use and whether you've spent from it.

    How close are we

    The honest answer is that nobody knows, and the estimates keep moving in one direction.

    In March 2026, Google's quantum team published research showing that breaking the elliptic-curve cryptography used by Bitcoin, Ethereum, and most other major chains could require fewer than 500,000 physical qubits on a superconducting machine, far fewer than earlier estimates. The paper also pointed out that cryptocurrencies are unusually exposed among systems that rely on this cryptography, because elliptic-curve keys are nearly an order of magnitude smaller than RSA keys of comparable strength, so a smaller quantum computer can break them.

    Half a million high-quality, error-corrected qubits is still a long way from today's hardware, and industry estimates for a cryptographically relevant machine mostly run five to fifteen years. But the gap has narrowed faster than projected, and there is a second problem that doesn't wait for the hardware at all. An attacker can record exposed public keys today and derive the private keys later, once a machine exists. For coins sitting in an exposed address, the clock on "harvest now, decrypt later" started a long time ago.

    Which coins are exposed

    A Bitcoin address is not the same thing as a public key. Most modern address types publish a hash of the public key, and the key itself only appears on-chain when you spend. That design, made for other reasons, turns out to be the main line of defense.

    The types of address matter here, so it's worth knowing which one you're looking at.

    Pay-to-public-key, or P2PK, was the format used in Bitcoin's first years. The public key is the address. Every coin in a P2PK output has had its key visible since the day it was received, including the roughly 1.7 million BTC in early addresses that are widely believed to include Satoshi Nakamoto's.

    Pay-to-public-key-hash and its descendants, the addresses that start with 1, 3, or bc1q, publish only a hash. The public key stays hidden until the first time you spend from that address. After that, it's on the chain forever, and any coins sent to the same address afterward are exposed too. This is why address reuse is the single most common way ordinary holders create exposure.

    Taproot addresses, which start with bc1p, are the exception in the wrong direction. They put an internal public key directly in the output so that simple spends can use it, which means a Taproot address is exposed from the moment it receives funds, whether or not you've spent. That design choice, sensible when Taproot activated in 2021, is why one of the main proposals below exists.

    How much is at stake? Project Eleven, a research group focused on this problem, estimates that about 6.9 million BTC, roughly a third of the total supply, sits in addresses whose public key is already exposed. An older Deloitte analysis put the figure at more than 4 million. The exact number depends on when you count and what you count, but a quarter to a third of all bitcoin is a reasonable range, and most of it is either very old, lost, or held by people who reused an address.

    The three ways an attack could work

    Google's paper sorted quantum attacks on cryptocurrencies into three categories, and they're worth separating because they need very different machines.

    An at-rest attack targets coins whose public key is already exposed. The attacker has all the time in the world: derive the key, sweep the coins. This is the attack that matters for old, dormant, and reused addresses, and it's the one a slower quantum computer could carry out.

    An on-spend attack targets a transaction while it's waiting to be confirmed. When you spend from a clean address, your public key appears in the transaction, and there's a window of roughly ten minutes before the block is mined. An attacker who could derive the key inside that window could try to race your transaction with one of their own. This needs a much faster machine and is the scenario that would break Bitcoin for everyone, careless or not.

    An on-setup attack goes after keys during generation or setup, for instance through a compromised device, and is more a general security problem than a Bitcoin-specific one.

    The order matters. The at-rest attack becomes feasible first, and it only touches exposed coins. That's why the practical advice below is mostly about not being in that group.

    Bitcoin's response: BIP-360 and BIP-361

    Bitcoin changes slowly by design, which is why the work started early.

    BIP-360, authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, was merged into Bitcoin's improvement proposal repository in February 2026, the first formal quantum-resistance proposal to reach that stage. It defines a new output type called Pay-to-Merkle-Root, or P2MR. In plain terms, it keeps the flexible script structure that Taproot introduced but removes the exposed key-path spend that makes Taproot addresses vulnerable. On its own, BIP-360 does not add quantum-resistant signatures to Bitcoin. It builds the address structure that later upgrades can plug post-quantum signature schemes into, and it would activate as a soft fork, meaning old software keeps working.

    BIP-361, published in April, is the harder conversation. It proposes a phased migration in which vulnerable address types are gradually retired and coins that never move to quantum-safe addresses eventually become unspendable. The logic is that coins nobody can migrate, including lost coins and possibly Satoshi's, are exactly the coins a future quantum attacker would sweep first, and letting that happen could crash confidence in the whole system. The objection is equally direct: Bitcoin has never frozen anyone's coins, and a proposal that would do so, even for coins whose owners are gone, is a fundamental change to what the network promises. That debate is live, and it will take years to resolve either way.

    What both proposals share is a timeline. Merged is not activated. Bitcoin soft forks need broad agreement among developers, node operators, and miners, and the last one, Taproot, took years from proposal to activation. Any realistic plan to move the network to quantum-safe signatures is a multi-year project, which is the strongest argument for starting it while the threat is still theoretical.

    What Ethereum and the standards bodies are doing

    Ethereum uses the same elliptic-curve signatures and faces the same problem, with one structural advantage: it already has account abstraction, which lets accounts choose their own signature scheme. The Ethereum Foundation runs pq.ethereum.org as a hub for its post-quantum work, with weekly test networks and milestones mapped across four future hard forks. The current fork, Glamsterdam, doesn't touch the problem, but the roadmap after it does.

    The wider world is moving too. The US National Institute of Standards and Technology finalized its first post-quantum standards in 2024, with lattice-based schemes for key exchange and signatures, and released draft updates in June 2026. Those standards are what wallets, custodians, and eventually blockchains will build on. The signatures are larger than today's, which is part of why fitting them into Bitcoin blocks is an engineering problem as much as a policy one.

    What you should consider

    Most of what protects you is free and takes minutes.

    Find out what address type you use. Open your wallet's receive screen. If the address starts with bc1q, it's a modern SegWit address that hides your public key until you spend. If it starts with bc1p, it's Taproot, and the key is exposed from receipt. If it starts with 1 or 3, it's an older format that also hides the key until first spend. Any decent wallet will tell you which it's generating and let you choose.

    Don't reuse addresses. Every time you receive, use a fresh address. Most wallets do this automatically; some let you turn it off, and you shouldn't. A fresh address's public key isn't on the chain until you spend from it.

    For long-term holdings, prefer bc1q over bc1p for now. Taproot has real benefits, but for coins you intend to leave untouched for years, an address that hides its key is the safer default until BIP-360 or its successors come to fruition.

    Be skeptical of "quantum-proof" pitches. There is no major cryptocurrency today whose signatures are quantum-resistant, and a token marketed on that claim is selling a story instead of a solution. The fixes are coming through protocol upgrades and not through switching coins.

    The at-rest risk applies to exposed addresses, and the machine that could exploit even those does not exist yet. Fix your address hygiene and let the developers do the rest.

    What exchanges and custodians are doing

    If your bitcoin sits with a custodian, the address questions above are theirs to answer, and in 2026 the larger ones started answering in public.

    On July 23, nine firms including BlackRock, Coinbase, Fidelity Digital Assets, Strategy, Block, and Blockstream announced the Bitcoin Security Consortium, pledging $15 million over three years to fund open-source security and post-quantum research. Each member directs its own money, and the group has said it takes no position on protocol changes, which is a deliberate line: they fund the work, they don't steer it. Galaxy launched a separate $5 million quantum readiness program the same week.

    Coinbase said the same day that it is building a post-quantum version of the key management system that protects most of the assets it custodies, and that it will assign engineers to open-source work including BIP-360. BlackRock's bitcoin ETF filings have listed quantum computing as a risk factor since 2025. None of this changes the math, but it does mean the institutions holding the most bitcoin have stopped treating the problem as science fiction.

    Questions worth asking any custodian: what address types do you use, do you rotate addresses, and do you have a migration plan for post-quantum signatures? A good one will have answers.

    Frequently asked questions

    How quickly could a quantum computer mine Bitcoin? It couldn't, in any meaningful sense. Mining relies on SHA-256 hashing, and quantum computers offer only a modest speedup against it. The threat is to signatures, not to mining.

    Can quantum computers bring lost Bitcoin back to life? Not to their owners. A quantum computer could let an attacker derive the keys to lost coins in exposed addresses and spend them, which is why BIP-361 proposes freezing coins that can't be migrated. The original owners wouldn't get anything back.

    Can quantum computing break XRP, Ethereum, or Solana? They use the same family of elliptic-curve signatures, so the same class of attack applies. Every major chain is working on a migration; none has completed one.

    Which crypto is quantum proof? No major chain is today. A few smaller projects use hash-based or lattice-based signatures, but "quantum proof" as a marketing claim deserves the same scrutiny as any other. The realistic path is upgrades to existing networks.

    Should I move my Bitcoin now? If you hold coins in an address you've already spent from, or in a Taproot address you plan to leave untouched for years, moving them to a fresh bc1q address is cheap.

    Start with a clean address

    The quantum question comes down to one habit: never let your public key sit on the chain next to coins you still hold. Wallets that generate a fresh receiving address for every deposit give you that for free.

    When you buy bitcoin through MoonPay, it's sent to the address you provide, so you can point every purchase at a fresh address in a wallet you control. Pay with a card, bank transfer, Apple Pay, or Google Pay, and the coins land where only your keys can reach them.

    Quantum computers may change Bitcoin's cryptography someday. They don't change what you should do with your addresses today.

    You might also like

    tokenomics+2
    what are tokenized stocks

    What Are Tokenized Stocks? What You Actually Own When You Buy Apple on a Blockchain

    Tokenized stocks track real shares on a blockchain, but the token is rarely the share. How the four structures differ on dividends, voting, bankruptcy, and redemption, and who can buy them in 2026.

    cryptocurrency+2
    ethereum glamsterdam update

    Ethereum's Glamsterdam Upgrade Explained: Fees, Wallets & L2s

    Glamsterdam is Ethereum's biggest upgrade since the Merge. What ePBS, block-level access lists, and bigger blocks change for fees, wallets, and L2s.

    cryptocurrency+1
    stablecoins and internet payment rails

    Why Stablecoins Are Becoming the Internet's Payment Rails

    Stablecoins settle in minutes, run around the clock, and cross borders for cents. What payment rails are, why stablecoins qualify, and the honest limits.

    cryptocurrency+2
    PayBox agentic payments

    Agentic Payments & How AI Agents Actually Pay for Things

    Agentic payments let an AI agent buy things without holding your money or seeing your card number. How they work, what agents can buy, and how MoonPay's PayBox does it.

    guide+2
    embedded wallets end of seed phrases

    Embedded Wallets and The End of Seed Phrases

    For most of crypto's history, the price of admission was a ritual: write down 12 words, in order, on something that can't catch fire or get wet, and guard them for the rest of your life. Get it right and you're your own bank. Get it wrong o

    cryptocurrency+2
    Accepting Crypto Payments

    How to Accept Crypto Payments: Checkout, Settlement & Merchant Setup

    A customer just bought a $100 hoodie from your online store and paid in crypto. Quick question: where is that $100 right now?

    All rights reserved. MoonPay USA LLC is a registered money service business (NMLS ID: 2071245). For Law Enforcement requests please direct your official document to our compliance team here.

    English
    • Personal
    • Buy Crypto
    • Sell Crypto
    • Trade Crypto
    • Learn about Crypto
    • Crypto Price
    • MoonAgentsNew!
    • Business
    • Ramps
    • Virtual AccountsNew!
    • MoonPay Discover
    • MoonPay Commerce
    • MoonPay InstitutionalNew!
    • Company
    • About Us
    • CareersWe're hiring
    • Newsroom
    • Media
    • Changelog
    • Support
    • API Docs
    • Help Center
    • Contact Us
    • Status
    • Security
    • Buy
    • Buy Bitcoin
    • Buy Ethereum
    • Buy Solana
    • Buy Cardano
    • Sell
    • Sell Bitcoin
    • Sell Ethereum
    • Sell XRP
    • Sell Solana
    • Trade
    • Trade Ethereum
    • Trade SOL
    • Trade Aave
    • Trade Chainlink
    • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Dogecoin Price
    • XRP Price
    • Cardano Price
    • Learn
    • What is Blockchain?
    • What are NFTs?
    • What is Bitcoin mining?
    • What is DeFi?
    • What is crypto staking?
    • Legal
    • Licenses
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    English

    All rights reserved. MoonPay USA LLC is a registered money service business (NMLS ID: 2071245). For Law Enforcement requests please direct your official document to our compliance team here.