On paper, Bitcoin is moving. In February 2026, BIP-360 — a proposal for quantum-resistant addresses — was merged into the Bitcoin BIP repository. The same month, BIP-361 began circulating with a number that should have stopped the industry cold: roughly 6.8 million BTC, 34% of the entire supply, sits in addresses whose public keys are already exposed. At current market prices, that is $437 billion of immediately quantum-addressable value. IBM’s CEO has pointed to 2028–2029 as the window for meaningful commercial quantum impact. Google Quantum AI has cut the estimated qubit requirement for breaking elliptic curve cryptography from over ten million to under 500,000.

These facts do not mean Bitcoin will fall by 2028. They do mean the network is now negotiating a race between cryptographic migration and quantum engineering — with no agreed-upon signature scheme, no activated code, and a governance process that struggles to coordinate a hard fork, let alone a trillion-dollar asset protection plan.
I have spent my career tracing stolen funds on-chain. The hardest part of any forensic reconstruction is not finding the endpoint of theft. It is proving which public key authorized the first illegitimate signature. Quantum computers do not need to break Bitcoin’s execution layer. They need to break the one assumption every P2PKH transaction has been leaning on since 2009: that a private key cannot be derived from a public key in polynomial time.
Hype is a mask; the ledger is the face beneath it. Let’s look at the ledger.
The Threat Is Not What Most People Think
The popular image of a quantum attack against Bitcoin involves a malicious entity rewriting the blockchain. That is wrong. The attack vector is cryptographic, not consensus-level. Shor’s algorithm, when run on a sufficiently powerful quantum computer, solves the discrete logarithm problem underlying ECDSA/Secp256k1. From a known public key, an attacker can reconstruct the private key. Grover’s algorithm, in contrast, merely provides a square-root speedup to brute-forcing SHA-256. That weakens mining security margins but does not break them. The immediate danger is Shor, not Grover.
The nuance buried in most coverage is the word “known.” A public key is exposed in three ways: P2PK addresses from Bitcoin’s early era, the public keys of any spent outputs that remain referenced, and addresses where a public key has been reused across multiple transactions. Private keys have never been published. But once a public key is exposed, a quantum adversary can theoretically reverse the math to the private key. BIP-361 attempts to quantify that exposure. The 34% figure, therefore, is not a claim that 34% of Bitcoin’s private keys are floating around. It is a claim that 34% of the supply is one Shor implementation away — if and when hardware catches up.
How far away is that? Google Quantum AI’s recent reduction from “over 10 million qubits” to “under 500,000 qubits” is not a breakthrough announcement. It is an algorithm improvement estimate. The signal is meaningful: researchers are still chipping away at the constants. The reality is still distant. IBM’s roadmap had a 1,121-qubit chip in 2023. Building 500,000 physical qubits with error correction capable of running Shor’s algorithm for a 256-bit curve is generally considered a mid-2030s problem, at best. IBM’s 2028–2029 prediction about “commercial impact” refers to fields like materials science, drug discovery, and financial risk modeling — not Bitcoin.
I have spent enough time reading academic papers and auditing production systems to know the difference between a demonstration and a weapon. A NISQ-era narrow advantage is not a cryptographic apocalypse. However, it is also not the right question. The right question is not “when can a quantum computer break ECDSA?” The right question is “how long will it take Bitcoin to move 6.8 million UTXOs after a migration standard is activated?”
That is where the analysis becomes uncomfortable.

The Migration Bottleneck Is Not Cryptographic. It’s Physical.
Here is the number most analyses skip: Bitcoin processes roughly seven transactions per second. To migrate 6.8 million UTXOs to new quantum-resistant addresses, each UTXO requires at least one new transaction. In an idealized world, with no other traffic, that math yields about 11 days. In the real world, it is months to years.
Why? Because large UTXOs are often encumbered by multisig scripts, timelocks, and hierarchical custody structures. Converting those requires careful planning, coordination among signers, and often additional preparatory transactions. Meanwhile, the network must continue processing regular economic traffic, ETF settlement flows, exchange hot wallet movements, and whatever new inscription craze the market invents next. The result is a severe migration congestion window — a period during which the entire Bitcoin supply is, in effect, trying to move through a straw.
Every transaction leaves a scar on the chain. A mass migration would leave millions of scars, with fee pressure as the immediate consequence. Based on my experience simulating network conditions for large-scale protocol migrations, fee spikes similar to the BRC-20 craze but one to two orders of magnitude larger are not just possible; they are near-inevitable. That creates a class of second-order victims: small holders. Large holders can batch transactions and hire engineers. Small holders face transaction fees that may exceed the value of their holdings, effectively locking them into legacy addresses.
There is also a tax angle that is rarely discussed. Moving Bitcoin to a new address requires spending it, and under U.S. tax rules, spending is a taxable event. Long-term holders who have never sold would be forced into a realization decision simply to protect their assets. That friction alone could delay migration for a significant portion of the ecosystem.
BIP-360, meanwhile, is in the “proposal repository,” not the Bitcoin Core codebase. BIP-361 is contested. The Bitcoin community has not selected a signature scheme — SPHINCS+, Lamport, and SQIsign are all candidates. Even after selection, a soft fork activation via miner signaling and user activation has historically taken one to three years. And even after activation, there is a race window: before all holders migrate, an attacker with a quantum computer could target the remaining exposed UTXOs. That is the race. That is why the 2026 draft is dangerous.
Let me make the migration economics concrete. If 6.8 million UTXOs enter the mempool at a rate of seven transactions per second, the theoretical minimum is 11 days of pure block space. But that assumes zero other transactions, zero failed replacements, zero multisig coordination delays. Historical large-scale UTXO movements have shown that complex scripts require multiple preparatory and post-process transactions. A reasonable planning assumption is 18 to 36 months from activation to meaningful migration. During that period, miners are in a position of extraordinary power. They could, in theory, prioritize quantum-resistant transactions and orphan legacy spends. That is a system-level governance rupture waiting to happen.
There is also the fragmentation problem. Large UTXOs will likely be split into smaller quantum-safe outputs, bloating chain state and raising future fees. And ordinary users, overwhelmed by the technical complexity, may simply deposit their BTC to an exchange and let the custodian handle migration. That would increase centralized custodial concentration at precisely the moment decentralization matters most. The BIP-361 controversy is not merely academic either. If an official standard defines which addresses are “exposed,” custodians and exchanges will carry a clear legal duty of care to protect those assets. That is a massive compliance burden. The fights over migration thresholds are also fights over liability.
The Economics of Defense Are Absurdly Small
Numbers have no emotions, only consequences. Consider the exposure: $437 billion in known-public-key addresses. Consider the defense: a Bitcoin Security Alliance with $15 million in committed funds and Galaxy Digital offering up to $5 million in developer grants. That is $20 million against a $437 billion at-risk pool — one twenty-thousandth of the value at risk.
This is not a criticism of the alliance’s intention. It is a structural mismatch. The funding is a public good, but public goods in decentralized networks are chronically underfunded because no single actor captures the full return on defensive spending. Nine founding entities — BlackRock, Fidelity, Galaxy, Coinbase, Strategy, among them — are acting rationally in routing resources to a problem that threatens their long-term product. But the free-rider problem remains: every non-participating BTC holder benefits from their work without contributing.
The market, of course, prices none of this. Quantum risk has been a “near-zero” priced tail risk for a decade. Spot prices respond to macro liquidity and ETF flows, not to cryptographic futures. Historical precedent supports this: Google’s Willow chip announcement in late 2023 produced a 1–2% dip in BTC that quickly recovered. The market treats quantum as a plot point in a sci-fi movie, not as a supply shock.
That may be rational for a one-day trading horizon. It is not rational for a multi-decade store-of-value thesis. Over time, options markets may begin pricing tail-risk skew into longer-dated contracts. OTC desks may start discounting coins tied to known-public-key addresses. None of that will appear in the headlines until a real migration order is announced.
What the Bulls Get Right
The contrarian case is not empty.
First, there is no evidence that a quantum computer capable of breaking ECDSA will exist in the next three years. IBM’s 2028–2029 language is about commercial quantum value, not Bitcoin key recovery. Google’s 500,000-qubit estimate is still two orders of magnitude beyond current engineering. The probability of an actual attack by 2028 is low.
Second, Bitcoin’s conservative governance — often criticized for slowness — may prove beneficial. I have seen what happens when protocol-level security is sacrificed for speed. In 2017, I parsed raw Geth logs to reconstruct the Parity multisig freeze, watching months of careful design dissolve in a single library update. Rushed changes kill networks. A deliberate, BIP-driven process forces the kind of adversarial review that a hasty hard fork would skip. The fact that BIP-360 is still in the proposal phase is not a failure; it is a feature of a system that values security over speed.
Third, quantum risk is not Bitcoin-specific. Ethereum has a similar exposure and no formal BIP. Cosmos has a larger public-key exposure surface, though its modular design makes replacing signature schemes easier. Quantum-native L1s exist, but they lack liquidity, network effects, and battle-testing. Bitcoin’s migration problem is larger, but its institutional staying power is also larger. The race is not just against quantum computers. It is against every competing chain’s ability to coordinate.
Takeaway
The cryptographic community already has answers — SPHINCS+, Lamport, and other schemes are mature. The blockchain community does not. The bottleneck is governance: how do you coordinate the migration of 6.8 million UTXOs without fracturing the network, excluding small holders, or triggering a taxable event for every HODLer?
The next two years will determine whether the alliance’s $15 million is seed capital or a rounding error in history’s largest asset protection failure. We will see the answer not in press releases, but in BIP activation status, in the emergence of a chosen signature standard, and in the first testnet migration of a significant UTXO bundle.
Hype is a mask; the ledger is the face beneath it. Watch the repository, not the timeline. The question is no longer whether Bitcoin can write quantum-safe code. The question is whether a decentralized network can move $437 billion in exposed value before an adversary with a big enough machine decides to cash in someone else’s scars.