Bitcoin's Quantum Problem: Why 6.7 Million Coins Could Be Frozen Forever
A third of all Bitcoin sits in addresses a future quantum computer could crack. The proposed fix would lock those coins permanently. Here is the plan.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
There is a proposal circulating among Bitcoin developers that would, if adopted, make roughly a third of all Bitcoin permanently unspendable. Not stolen. Not confiscated by a government. Simply frozen by the rules of the network itself, including an estimated 1.7 million coins widely believed to belong to Bitcoin's anonymous creator.
The proposal is not a fringe idea. It was authored by a group including Jameson Lopp, a co-founder of the custody firm Casa and one of the most established security researchers in the field. It has a formal number in Bitcoin's official proposal system. And it exists because of a threat that has moved, over the past eighteen months, from a distant theoretical concern to something developers now treat as a scheduling problem.
This piece explains what is actually being proposed, why the threat is considered credible, and why the proposed cure is more contested than the disease.
What is being proposed, in plain terms?
Bitcoin developers publish formal change proposals in a numbered system. Each one is called a Bitcoin Improvement Proposal, abbreviated BIP. A number does not mean a proposal is approved or scheduled. It means the idea has been documented in a standard format so the community can examine it. Most BIPs are never adopted.
Two of them matter here, and they work in sequence.
- The first, BIP-360, creates a new type of Bitcoin address that a quantum computer could not break. This is the constructive half. It adds an option without removing anything, and it is comparatively uncontroversial.
- The second, BIP-361, formally titled "Post Quantum Migration and Legacy Signature Sunset," is the contested half. It sets a deadline. Coins that have not moved to the new quantum-safe address type by that deadline would become unspendable. The proposal was assigned its number on 11 February 2026 and remains in draft status. No activation has occurred, and no date has been fixed.
The critical detail, and the one most coverage skips: BIP-361 cannot function until BIP-360 is activated first. The deadline clock only begins after the safe destination exists.
Why can a quantum computer steal Bitcoin at all?
To follow the argument, one piece of technical vocabulary is unavoidable.
Every $Bitcoin wallet holds two mathematically linked numbers. The private key is the secret that authorizes spending. The public key is derived from it and can be shared safely. The relationship runs one way: deriving the public key from the private key is trivial, while working backwards from the public key to the private key would take a conventional computer longer than the age of the universe.
That one-way property is what secures Bitcoin. It is also precisely what a sufficiently powerful quantum computer would dismantle. Quantum machines can run algorithms that make this reverse calculation practical rather than impossible.
The vulnerability therefore depends on a single question: has the public key ever been revealed on the blockchain?
For most modern addresses, it has not. The address you share is a scrambled shortened version of the public key, and the key itself only becomes visible at the moment you spend from that address. But two categories of coin are permanently exposed. The first is Bitcoin's oldest address format, used in 2009 and 2010, which published the raw public key directly on the chain. The second is any address that has been used to spend and then received funds again, a habit known as address reuse, which is still common and which permanently exposes the key.
There is a further problem that makes detection unreliable. An attacker who broke a key would not need to spend immediately. The proposal's authors describe a scenario in which private keys are computed quietly and funds are drained gradually over weeks or months, specifically to avoid alerting anyone. Under that scenario, the industry might not learn a quantum attack had begun until long after it did.
How much Bitcoin is actually exposed?
The proposal's own figure is that as of 1 March 2026, more than 34 percent of all Bitcoin had revealed a public key on the blockchain. A Google-commissioned study puts the total at approximately 6.7 million BTC sitting in quantum-vulnerable addresses.
Within that total, roughly 1.7 million coins sit in the oldest address format from Bitcoin's first two years. These are widely believed to include Satoshi Nakamoto's holdings. They have never moved. If the keys are lost, as is generally assumed, no migration is possible, because there is nobody left to perform it.
At current prices, the exposed supply is worth somewhere in the region of $425 billion. That figure is what turns a cryptography question into a market question. A successful attack would not only transfer those coins to an attacker. It would introduce enormous unexpected supply and, more damaging still, demonstrate that Bitcoin's security guarantee had failed.
How close is the threat, realistically?
No machine capable of this exists today. That point deserves emphasis, because the topic attracts considerable exaggeration.
What has changed is the shape of the estimates. McKinsey's research places the arrival of a cryptographically relevant quantum computer, meaning one actually powerful enough to break this class of encryption, as early as 2027 to 2030. Expert surveys put the probability of arrival before the late 2030s at above 50 percent.
The more significant shift is in software rather than hardware. Google's security researchers have tracked improvements in quantum algorithms of up to twentyfold, which lowers the amount of physical hardware an attacker would need. In other words, the target is moving closer even in periods when quantum computers themselves are not improving quickly.
The standards bodies have already responded. The US National Institute of Standards and Technology finalized three post-quantum cryptography standards in 2024, giving the industry approved replacement algorithms to build on. Bitcoin's difficulty is not the absence of a solution. It is that no major blockchain has completed a migration of this kind, and Bitcoin's governance is deliberately designed to make change slow.
What would the migration actually involve?
BIP-361 sets out three phases. The following table reflects the proposal text directly.
Phase | What happens | Timing |
|---|---|---|
A | Funds can no longer be sent to old vulnerable addresses. They may only be sent from old addresses to new quantum-safe ones. Existing coins remain spendable. | 160,000 blocks, roughly 3 years, after activation |
B | Signatures from the old system stop being valid. Coins that have not migrated can no longer be spent at all. | 2 years after Phase A, so roughly 5 years after activation |
C | A proposed recovery route for frozen coins, using a cryptographic proof that you hold the original wallet recovery phrase, without revealing it. | Undefined, pending further research |
Phase C is the part that determines how severe this actually is, and it is also the least developed. If it works, holders with their recovery phrase could unlock frozen funds even after the deadline, and the freeze becomes a strong inconvenience rather than a permanent loss. If it does not, Phase B is final. The proposal explicitly lists Phase C as pending research, demand, and consensus.
One activation detail is worth noting for anyone tracking timelines. The proposal specifies that miner signalling would not begin before 1 January 2027, and would require 90 percent support. That is a deliberately high bar. For comparison, the BIP-110 proposal that reached its signalling window this August has attracted under 2 percent miner support.
Why is this so controversial?
Because it collides directly with Bitcoin's central promise.
The phrase "not your keys, not your coins" expresses the idea that possession of the private key is absolute and that no authority can interfere with your funds. BIP-361 proposes that the network itself decide certain coins can no longer move. Critics argue this is confiscation in effect even if not in form, since the coins are not transferred to anyone else, and that the precedent is more dangerous than the threat it addresses. If the network can render one category of output unspendable for a good reason, the mechanism exists to do so again for a worse one.
There is also a legitimate question of authority. Who determines what counts as vulnerable, and on what timetable? Bitcoin has no chief executive and no foundation empowered to ship a consensus change. The last one, Taproot, activated in November 2021, and nothing has changed the rules since.
This is why the debate has shifted from cryptography to governance. The underlying question is whether a system engineered specifically to resist change can agree on a significant upgrade before it becomes urgent.
What is the case in favour?
Supporters frame the choice as one between two bad outcomes rather than between a bad outcome and a clean one.
Their central argument is that doing nothing does not preserve the vulnerable coins. It hands them to whoever reaches quantum capability first. The proposal describes three possible approaches: allow anyone to take vulnerable coins, allow them to be taken gradually, or allow nobody to take them. There is no fourth option in which the coins simply remain safe. Freezing, on this reading, preserves ownership rather than removing it, particularly if the Phase C recovery route is built.
A second argument concerns attacker motivation. An economically motivated attacker would want to stay hidden and extract value quietly. A politically motivated one might simply want to destroy confidence in Bitcoin. Since it is impossible to know which you face in advance, the authors argue the defensive position has to be established well before any attack.
A third argument is about time. Coordinating wallet providers, exchanges, hardware manufacturers and custodians has historically taken years in Bitcoin. A fixed, published deadline is what converts a collective problem everyone can defer into a private one each participant has to solve. That is the proposal's actual mechanism: it does not force anyone to do anything today, but it removes the option of indefinite delay.
What does this mean for Bitcoin holders now?
Nothing is required today. BIP-361 is a draft. It has not been activated, it depends on a prerequisite that has not been activated either, and signalling could not begin before 2027 under its own terms. Anyone claiming holders must act immediately is misinformed or selling something.
That said, the direction of travel is clear enough to justify a few observations.
Coins held in modern address formats that have never been spent from are not currently exposed, because the public key has not been published. Address reuse is the practice that converts a safe address into an exposed one, and it remains a reasonable habit to avoid regardless of quantum considerations. Holders using custodial services or exchange-traded products face an institutional question rather than a personal one, since the migration burden would fall on the custodian.
The more consequential point is for the long term. Any Bitcoin intended to sit untouched for a decade or more, including inheritance arrangements and long-dated corporate treasury positions, now carries a migration requirement that did not exist two years ago. Estate planning that assumes a seed phrase in a safe will remain sufficient indefinitely may need revisiting.
What should be watched next?
Three markers will indicate whether this moves from debate to implementation.
- The first is BIP-360 progress, since nothing in BIP-361 can proceed without it. It has reached testnet implementation, which is a meaningful step but well short of activation.
- The second is Phase C research. If a workable recovery mechanism is demonstrated, much of the opposition loses its strongest argument, because permanent loss becomes recoverable friction.
- The third is the January 2027 signalling window written into the proposal, and specifically whether miner support approaches the 90 percent threshold. Recent Bitcoin governance offers little reason for optimism on that front.
The most likely outcome over the next two years is neither adoption nor rejection, but continued deadlock while the estimated arrival of quantum capability draws closer. That is an uncomfortable position, and it is the one Bitcoin currently occupies.
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text.
Related articles
- Should Satoshi's Bitcoin Be Frozen? CZ's Quantum Warning Splits the Industry
- Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
- Bitcoin and the Quantum Computer: Which Addresses Already Expose Their Keys
- EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
- Ethereum and Quantum Computers: Are Your ETH Affected?
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
April 21, 2019 4:16 PM

Quantum Computer: The End of Bitcoin?
For decades, physicists have been working on quantum computers. These computers, based on quantum mechanical principles, should be far superior to classic binary computers in certain fields of application. In 1994, years before the first experimental quantum computers existed, Peter […]
July 8, 2024 7:51 AM

Crypto Market Crash News As BTC Price Crash Back To 56K
With the crypto market crash, and Bitcoin price drop to below 56k with recent dormant BTC whales activity, what comes next: a correction or further crash soon?
June 5, 2024 5:03 PM

Crypto Market Up: Bitcoin Breaches $71K, Altcoins Follow Suit, Eyes on New Highs
Cryptocurrencies are experiencing a surge, with Bitcoin leading the charge by surpassing $71,000. This bullish trend extends to altcoins, igniting optimism across the market. Will Bitcoin reach new highs?
May 15, 2026 9:47 AM

Top 10 Altcoins to Buy in May 2026 as Bitcoin Recovers
Here are the top 10 altcoins to buy in May 2026 as Bitcoin rebounds near $80K and market momentum shifts.
January 29, 2025 8:00 AM

FOMC and Crypto: How Can the First FOMC Meeting Under Trump Affect the Crypto Market?
The first FOMC meeting under President Trump is set to take place tomorrow. Discover all possible scenarios and their impact on Bitcoin and the crypto market.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
February 5, 2026 5:29 AM

Jeffrey Epstein and the Bitcoin Conspiracy: Hidden Ties to the Digital Currency Initiative
New revelations explore the murky connections between Jeffrey Epstein and early Bitcoin development at the MIT Media Lab.
November 19, 2025 5:44 PM

BTC Price Falls Under $90K: Vitalik’s Quantum Warning Intensifies Sell-Off
Bitcoin broke below $90K again as fear spikes. New warnings from Vitalik Buterin about quantum computers breaking BTC and ETH add fresh panic.
February 24, 2024 5:11 PM

Who is Satoshi Nakamoto?: Satoshi’s Emails Unveil Early Bitcoin Secrets
Loads of juicy details about the beginnings of cryptocurrency just came to light. Let's take a look at this Satoshi Nakamoto Emails
July 29, 2024 9:15 AM
Bitcoin Price Prediction: Can BTC Price Record A New All Time High Before End Of July?
This week kicked off with renewed energy across the crypto market, fueled with optimism. But would it be enough for BTC price to reach a new all-time high before July ends?
September 25, 2026 10:26 AM

Crypto Prices Today: Bitcoin Slides to $84,000 While Altcoins Rally Hard
Bitcoin trades near $84,000 after an 8% weekly drop while XRP, ADA and Zcash rally. Here is what is moving crypto prices today.
September 17, 2026 10:40 AM

Crypto News Today: Bitcoin Holds $76,000 After Fed Hike and CLARITY Act Collapse
The CLARITY Act died in the Senate, the Fed hiked for the first time since 2023, and Zcash ripped anyway. Here is the full crypto market update.
September 1, 2026 10:22 AM

Crypto News Today: Bitcoin Stalls While Zcash and Monero Steal the Show
Crypto news today: Bitcoin cools after its best week in three years, Saylor buys again, and privacy coins keep running. Here are the prices and levels.
January 20, 2025 1:50 PM

Ethereum Price Prediction with Vitalik Buterin New Leadership after ETH Price Struggles in Bitcoin's Shadow
ETH price struggles with Bitcoin’s dominance, Trump’s crypto moves, and the Solana blockchain surge. As Vitalik Buterin announces leadership changes to reshape Ethereum’s future, what to expect for Ethereum price and blockchain?
January 14, 2022 8:58 AM

What are Bitcoin Forks? Here’s a Deep Dive into what Forks are
In this article, we will be looking into Bitcoin Forks and the entire fork in the history of the digital asset. What are Bitcoin Forks?
August 22, 2026 10:29 AM

Bitcoin Fork: What Happens to Your Coins When the Chain Splits
On October 31, 2026 a new chain called ECX splits off from Bitcoin, and every holder is credited automatically. Who actually receives the coins depends on the private keys, on voluntary replay protection and on a tax rule many overlook.
August 14, 2026 10:14 AM

Crypto News Today: Washington Blinked and the Crypto Market Barely Moved
The SEC pulled its biggest crypto rulemaking of the year, ETF flows turned negative, and prices barely reacted. Here is what the market is telling you.
June 28, 2026 10:44 AM

Bitcoin Price Prediction: Why Some Analysts Warn of a Crash to $16K
A dark Bitcoin narrative is spreading: quantum computing and AI could "kill" BTC, with some bears eyeing $16K. Here's the case — and why it may be overblown.
April 25, 2024 11:44 AM

Beware of New Ethereum Node Scam: USDT Fraud Exposed
Crypto Scammers exploit Ethereum nodes and USDT to deceive crypto users. How are they pulling it off and what essential tips can help you protect yourself against these crypto scams?
April 20, 2024 4:07 PM

What Happened To Cryptos After Bitcoin (BTC) Halving Today?
Today's cryptocurrency market highlights: Bitcoin over $64k and Ethereum towards $3,1k. But what about altcoins?
September 16, 2026 7:12 PM

Borrowing Against Bitcoin Instead of Selling: When German Tax Still Applies
Posting Bitcoin as collateral for a loan is not a sale in Germany, because section 39 of the Fiscal Code keeps the coins attributed to you for tax purposes. Tax arises only when the collateral is liquidated, and then the one thing that decides the bill is how long you held the coins beforehand.
February 27, 2026 3:00 PM

Altcoin Season Index Hits 35: Is the Tide Turning for Crypto Markets?
The Altcoin Season Index climbs to 35 as PIPPIN explodes with an 825% gain. Analyze the latest market data to see if an altcoin rally is imminent.
November 16, 2025 3:40 PM

5 Crypto Coins That Skyrocketed While Bitcoin Crashed in November 2025: Where They Stand Now
In mid-November 2025 Telcoin, Starknet, AB, WLFI and Uniswap rallied while Bitcoin crashed. Ten months later only Uniswap trades higher; Telcoin and Starknet lost three quarters.
September 12, 2026 1:12 PM

Crypto ETN in Your Portfolio: How to Check Who Really Owes You the Bitcoin
A Bitcoin ETN is legally a debt security, not a fund unit. We counted the 122 crypto ETNs tradable on Xetra ourselves and show you the three details worth checking before you buy.
June 5, 2026 3:00 PM

Zcash Crash: ZEC Coin Falls 40% After AI Bug Scare — Here Are the Next Supports
Zcash crashes over 40% as AI-linked bug fears, whale shorts, liquidations, and weak crypto sentiment hit $ZEC.
More from CryptoTicker




