Quantum risk is one of the most misunderstood topics in Bitcoin.
Most takes fall into two extremes.
One side says quantum computers will break Bitcoin tomorrow.
The other says quantum risk is pure nonsense.
Both are wrong.
The real answer is more useful:
A meaningful amount of Bitcoin is exposed to future quantum risk, but no quantum computer can exploit it today.
That distinction matters.
As of the uploaded June 2026 research draft, the best-known estimates suggest that roughly 4 million to 6.3 million BTC may sit in categories where public keys are already visible on-chain.
That includes early pay-to-public-key outputs, reused address outputs and other dormant or change-output estimates.
But visibility is not the same as immediate theft.
To steal coins from exposed public keys, an attacker would need a cryptographically relevant quantum computer capable of breaking Bitcoin’s secp256k1 elliptic-curve signatures.
No such machine exists today.
Most expert timelines cluster around the 2030 to 2035 range, with some urgent voices warning sooner.
That means Bitcoin’s quantum problem is not a reason to panic.
It is a reason to migrate calmly, stop reusing addresses, upgrade wallet hygiene and take the post-quantum protocol debate seriously.
That is why Decentralised News built the DN Quantum Exposure Gauge.
It separates the two different quantum threats:
Long-exposure risk
Short-window transaction risk
Those are not the same problem.
And treating them as one problem is why most quantum commentary is either alarmist or dismissive.
As of the uploaded June 2026 draft, no quantum computer can break Bitcoin’s secp256k1 cryptography.
The risk is future-facing, not immediate.
However, the exposed supply is real.
Deloitte’s full-chain analysis estimated roughly 4 million BTC in addresses with revealed public keys, including around 2 million BTC in early pay-to-public-key outputs and around 2.5 million BTC in reused pay-to-public-key-hash addresses.
Project 11’s 2025 analysis estimated the figure could be as high as 6.3 million BTC when broader dormant and change-output categories are included.
The most important exposed category includes roughly 1.1 million Satoshi-era coins linked to the Patoshi mining pattern.
These coins are likely unmovable, which means they cannot easily migrate to safer outputs.
The DN Quantum Exposure Gauge scores two risks separately:
Long-exposure risk: coins already sitting behind visible public keys.
Short-window risk: the brief period when a spender reveals a public key in the mempool before transaction confirmation.
Individual users can reduce long-exposure risk by avoiding address reuse and holding coins in unspent, key-not-revealed outputs.
Only a protocol upgrade can fully address short-window risk.
When people ask whether Bitcoin is vulnerable to quantum computers, they usually skip the most important step.
They do not define the threat.
Bitcoin has more than one quantum risk surface.
The first is old coins or reused addresses where the public key is already visible on-chain.
The second is the moment of spending, when a public key becomes visible before the transaction confirms.
These are different problems.
They have different timelines.
They have different solutions.
The first problem is mostly about old wallet formats and address hygiene.
The second problem is about protocol-level cryptography.
That is why the Q-Day Ledger separates them.
Q-Day is the shorthand term for the arrival of a cryptographically relevant quantum computer.
In Bitcoin’s case, that means a quantum computer capable of deriving a private key from a public key fast enough to steal funds.
Bitcoin uses secp256k1 elliptic-curve cryptography.
A sufficiently powerful quantum computer running Shor’s algorithm could, in theory, break that public-key cryptography.
But “in theory” is not the same as “today.”
The machine would need stable, error-corrected logical qubits and enough reliability to complete a very complex computation.
As of the uploaded June 2026 draft, no public quantum computer can do this.
That is why the honest debate is not whether Bitcoin is currently broken.
It is whether Bitcoin can migrate before a future quantum-capable machine arrives.
The uploaded draft gives two major exposed-supply estimates.
Deloitte’s analysis found roughly 4 million BTC in address categories where public keys are already visible.
This includes:
About 2 million BTC in early pay-to-public-key outputs.
About 2.5 million BTC in reused pay-to-public-key-hash addresses.
Overlap and methodology differences that create the widely cited figure of around 4 million BTC.
This is roughly 25% of supply in the uploaded framework.
Project 11’s 2025 analysis estimated a higher figure when broader dormant and change-output categories are included.
This pushes potential exposure toward 6.3 million BTC.
The key point:
These are estimates.
They are not Decentralised News measurements.
They come from third-party blockchain analysis using different heuristics.
But the broad conclusion is the same:
A large exposed-supply pool exists.
It is not imaginary.
Bitcoin does not always reveal the public key immediately.
Modern Bitcoin address usage typically hides the public key behind a hash until the coin is spent.
But early Bitcoin usage and bad wallet habits can reveal public keys.
Bitcoin’s earliest outputs often used pay-to-public-key.
In this format, the public key is visible directly in the output script.
That means the public key has been visible on-chain since the coins were mined.
Many early-mined coins fall into this category.
This is why old Satoshi-era coins are a focus of quantum-risk discussions.
A pay-to-public-key-hash address is safer before it is spent because only the hash is visible.
But once funds are spent from that address, the public key is revealed.
If the same address is reused and coins remain there after the public key has been revealed, those coins become exposed.
That is why address reuse is dangerous.
It turns a safer output into an exposed one.
Modern outputs are safer when unspent.
But any spending event reveals key material.
That is why transaction timing matters.
A coin can be safe while sitting unspent, then temporarily exposed during spending.
That is the short-window problem.
One of the most sensitive parts of the quantum debate is the Satoshi-era coin pool.
The uploaded draft references roughly 1.1 million coins linked to the Patoshi mining pattern, widely associated with Satoshi Nakamoto.
These coins are believed to sit in early public-key-visible outputs.
That means they may be exposed to a future quantum attacker.
The problem is that they also appear unmovable.
If the private keys are lost, or if the owner is gone, those coins cannot migrate to a safer post-quantum output.
That creates a permanent visible target.
This is not a problem individual users can solve.
It raises a deeper governance question:
Should the Bitcoin network eventually freeze, migrate or leave unmovable exposed coins alone?
There is no easy answer.
Freezing coins would be controversial because it touches property rights and immutability.
Leaving them exposed could create a future supply shock if a quantum attacker can claim them.
That is why the debate matters long before Q-Day arrives.
The uploaded draft’s most important distinction is this:
Bitcoin’s quantum risk is not one risk.
It is two risks.
This is the risk to coins already sitting behind visible public keys.
These coins are exposed now, but only to a future machine that does not yet exist.
Examples:
Old P2PK outputs
Reused P2PKH addresses
Dormant exposed coins
Likely unmovable Satoshi-era coins
This risk is static.
The exposed coins are visible.
The market can count them.
Users who control movable exposed coins can migrate.
This is the risk created when any user spends Bitcoin.
When you spend, your public key enters the mempool before the transaction confirms.
A future quantum attacker with enough speed could, in theory, derive the private key and broadcast a competing transaction during the confirmation window.
This window may be minutes rather than years.
That makes it more systemic.
Individual wallet hygiene cannot fully fix it.
The short-window problem needs a protocol-level upgrade.
This is why the DN Quantum Exposure Gauge weights the short-window problem more heavily.
It is harder to solve individually.
Use the DN Quantum Exposure Gauge to model Bitcoin’s quantum risk by selecting your assumed Q-Day year, exposed-supply estimate, migration progress and post-quantum upgrade status. The tool separates long-exposure risk from short-window transaction risk.
Quantum risk is not binary. Set your own Q-Day year and migration assumption, then see how much supply remains exposed.
The DN Quantum Exposure Gauge scores Bitcoin quantum risk from 0 to 100.
Higher scores mean greater quantum exposure stress.
The model separates two threats.
This score measures how much Bitcoin sits behind already visible public keys.
It rises when the exposed share of supply is higher.
It falls when migration progress increases.
The logic is simple:
If more exposed coins migrate to safer outputs, the long-exposure pool shrinks.
But unmovable exposed coins cannot migrate.
That is why Satoshi-era coins matter so much.
This score measures the systemic risk of spending Bitcoin before a post-quantum protocol upgrade is activated.
It rises as the assumed Q-Day year gets closer.
It falls if a post-quantum upgrade is activated and broadly adopted.
This is the risk individual users cannot fully solve on their own.
The composite score blends both risks.
In the uploaded framework:
Long-exposure risk gets 45% weight.
Short-window risk gets 55% weight.
The short-window risk gets the higher weight because it requires network-level action.
Exposure exists, but the assumed timeline is distant and the system has time to migrate.
Risk is not urgent, but users should improve key hygiene and monitor the protocol debate.
The exposed-supply pool is large or the assumed Q-Day timeline is getting closer.
Migration becomes more important.
The assumed timeline is close enough that network-level action becomes necessary.
Post-quantum upgrade readiness matters.
This is the high-stress scenario.
A credible Q-Day timeline is near, exposed supply remains high and no effective protocol defense is active.
One of the useful frameworks in quantum migration is Mosca’s inequality.
It can be simplified as:
X + Y > Z
Where:
X = time needed to migrate
Y = shelf life of the data or asset
Z = time until a cryptographically relevant quantum computer exists
If X plus Y is greater than Z, migration should already be underway.
Bitcoin has a long shelf life.
People hold coins for years or decades.
A decentralized network also takes time to coordinate major upgrades.
That means Bitcoin does not need Q-Day to be tomorrow for the conversation to be urgent.
If a post-quantum migration could take years, and the asset is meant to be protected for decades, then a Q-Day in the 2030s is already close enough to discuss seriously.
That is not panic.
It is planning.
Individual holders cannot solve the whole quantum problem.
But they can reduce personal exposure.
Address reuse is one of the simplest ways to increase long-exposure risk.
Use wallets that generate a fresh address for every receipt.
If you have spent from an address, its public key has been revealed.
Do not keep meaningful remaining funds there.
Modern unspent outputs are much safer because only the public-key hash is visible.
This does not make them permanently quantum-proof, but it keeps them out of the exposed public-key category.
Use wallets that follow modern address hygiene by default.
A hardware wallet such as Ledger or another reputable device can help users avoid poor key-management habits, provided the user still follows good backup and address-use practices.
The real long-term fix is protocol-level migration.
Users should follow the debate around post-quantum output types and wallet support.
Moving coins can reduce long-exposure risk if done correctly.
But spending also reveals a public key during the transaction.
Today that is not an immediate danger because no quantum attacker exists.
In a future high-risk environment, migration needs to be coordinated carefully.
The right approach is calm migration, not panic.
The long-term fix is not simply better wallet hygiene.
Bitcoin needs a post-quantum migration path.
That means new output types and signature schemes that remain secure even if large quantum computers become practical.
The uploaded draft mentions BIP-360-style proposals, including post-quantum-resistant output types.
The open questions are not only technical.
They are political, economic and social.
How should Bitcoin add post-quantum signature support?
When should users be encouraged to migrate?
Should old exposed coins be left alone?
Should unmovable exposed coins be frozen?
Who decides what happens to Satoshi-era coins?
How long should migration take?
What happens if many users do nothing?
How should wallets and exchanges coordinate?
These questions are difficult.
But they are better answered before Q-Day than during a crisis.
A common response to quantum risk is simple:
Move coins to a fresh address.
That is useful advice for long-exposure risk.
It is not a complete solution.
It helps if:
You control exposed coins.
You can migrate before Q-Day.
You move to an output type that improves protection.
You avoid future address reuse.
It does not solve:
Lost coins.
Satoshi-era unmovable coins.
Exchange-controlled exposed coins.
Short-window transaction risk.
Network-wide post-quantum readiness.
So the better advice is:
Improve address hygiene now.
Migrate exposed coins calmly when appropriate.
Avoid address reuse.
Watch protocol upgrade readiness.
Do not assume individual action solves systemic risk.
Quantum risk sometimes becomes a price catalyst because it is easy to misunderstand.
It sounds existential.
It is technically complex.
It involves uncertain timelines.
It connects to Satoshi’s coins.
It creates dramatic headlines.
That makes it perfect fuel for market panic.
But the uploaded draft’s core point is more balanced:
Quantum risk did not suddenly appear in 2026.
The exposed supply has been visible for years.
The post-quantum standards process is already underway.
The Bitcoin protocol debate is already active.
The real issue is timing and coordination.
Panic headlines make the network less likely to have a careful migration debate.
That is the opposite of what Bitcoin needs.
The DN Quantum Exposure Gauge would become more urgent if:
A credible quantum hardware roadmap moved Q-Day inside five years.
A national lab demonstrated relevant cryptographic progress.
A major exposed-supply estimate rose materially above 6.3 million BTC.
Satoshi-era P2PK coins suddenly moved.
A major exchange disclosed large exposed public-key holdings.
Bitcoin failed to make progress on post-quantum output types.
Wallets and exchanges delayed migration support.
The risk reading would improve if:
A post-quantum output type activated.
Wallets began supporting quantum-resistant migration.
Exchanges published migration plans.
Exposed reusable-address balances declined.
A broad user migration reduced the exposed pool.
The short-window problem received a clear protocol path.
The model does not predict Q-Day.
It measures exposure under whatever Q-Day assumption you choose.
Bitcoin’s quantum risk is neither tomorrow’s apocalypse nor a fake concern.
It is a migration problem.
The exposed supply is real.
Roughly 4 million to 6.3 million BTC may sit in address categories where public keys are already visible.
Some of that supply, including Satoshi-era coins, may never be able to migrate.
No quantum computer can exploit that today.
But a future quantum computer could change the risk landscape.
That is why Bitcoin needs calm preparation.
The right response is not panic selling.
It is not denial.
It is key hygiene, wallet upgrades, post-quantum research, protocol debate and a credible migration path.
The most important takeaway is simple:
Bitcoin has time.
But time is only useful if the network uses it.
The uploaded draft cites estimates ranging from roughly 4 million BTC to 6.3 million BTC in address categories with exposed public keys. Deloitte’s widely cited estimate is around 4 million BTC, while Project 11’s broader analysis estimates up to 6.3 million BTC.
No. As of the uploaded June 2026 framework, no quantum computer can break Bitcoin’s secp256k1 cryptography in practice.
Q-Day is the point at which a cryptographically relevant quantum computer exists and can break current public-key cryptography. For Bitcoin, that would mean deriving private keys from public keys fast enough to steal funds.
In principle, yes. Some Satoshi-era coins are believed to sit in early public-key-visible outputs. If those keys are lost or the owner is absent, they cannot migrate, making them a permanent exposed target in a future quantum scenario.
If your Bitcoin sits in a modern unspent address that has never been spent from, your public key is not yet visible on-chain. You are not in the main long-exposure category. Address reuse or keeping funds in already-spent addresses increases exposure.
When you spend from an address, the public key is revealed. If you later keep using that address or leave funds there, those coins become easier to target in a future quantum scenario.
The short-window risk happens during spending. When a transaction is broadcast, the public key becomes visible before confirmation. A future quantum attacker could theoretically try to steal the funds during that window.
BIP-360-style proposals aim to introduce post-quantum-resistant output types or migration paths for Bitcoin. As of the uploaded June 2026 draft, these ideas are being discussed but are not yet activated.
Users should avoid address reuse and keep coins in modern unspent outputs. If coins are already in exposed addresses, migration may make sense, but it should be done carefully. This is not financial advice.
That is a personal decision, but the framework argues against panic. No quantum computer can break Bitcoin today. The rational response is preparation, not fear-based liquidation.
This article is for educational and research purposes only and does not constitute financial advice, cybersecurity advice or a prediction of Q-Day. Quantum computing timelines are uncertain. Exposed-supply figures are third-party estimates and may differ by methodology. Bitcoin, crypto assets and self-custody carry risk. This content is intended for adults aged 18 and over. Always do your own research and use secure wallet practices.