Bitcoin Devs Race to Quantum-Proof $1.3T Blockchain

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Google researchers published a report this week claiming a sufficiently powerful quantum computer could break Bitcoin's core cryptography in under nine minutes, with some analysts estimating the threat could materialize as soon as 2029
- About 6.5 million bitcoin tokens sit in addresses a quantum computer could directly target, including roughly 1.7 million BTC in old P2PK addresses that already expose their public keys—coins attributed to Satoshi Nakamoto and early miners
- BIP 360 proposes a new Pay-to-Merkle-Root (P2MR) output type that would remove the public key permanently embedded on-chain in new Taproot addresses, though it would not protect the 1.7 million BTC already sitting in exposed addresses
- SPHINCS+ (SLH-DSA), a hash-based post-quantum signature scheme standardized by NIST as FIPS 205 in August 2024, is being considered as an ECDSA replacement, but its 8-kilobyte-plus signatures would sharply increase block space demand and transaction fees
- Tadge Dryja, Lightning Network co-creator, proposed a commit/reveal soft fork that timestamps a sealed hash of a transaction before broadcast, giving senders a pre-registered "alibi" against quantum-forged competing transactions stealing funds from the mempool
- Hourglass V2, proposed by developer Hunter Beast, would limit spending from the 1.7 million already-exposed BTC to one bitcoin per block—an explicit acknowledgment that some coins will be stolen and a deliberate brake on mass liquidation
Why it matters: Roughly 1.7 million BTC in old P2PK addresses—including coins attributed to Satoshi Nakamoto—already expose their public keys on-chain, meaning a quantum attacker has a permanent target list worth hundreds of billions of dollars. Because every proposed defense must clear Bitcoin's decentralized governance across developers, miners, and node operators, the gap between Google's 2029 threat estimate and actual deployment leaves the network's oldest and most valuable coins structurally exposed.



