Bitcoin’s quantum debate stopped being academic last week.
On Aug. 18, 2026, CoinMarketCap reported that Bitcoin developers had put forward BIP-361, a proposal to freeze quantum-vulnerable addresses, and Bitnovo coverage on Aug. 13, 2026 detailed the technical plan to protect roughly 6.9 million BTC that sit in wallets whose public keys are already visible on the blockchain. A public key is the address string a network sees; a private key is the secret that authorizes spending from it. In classical cryptography the public key does not give away the private key. A sufficiently powerful quantum computer would change that.
The freeze proposal has revived a comparison that keeps circulating: Glassnode research dated May 20, 2026 pegs Bitcoin’s quantum-exposed supply at 6.04 million BTC, or 30.2% of issued supply, while an XRP Ledger validator audit published April 7, 2026 by the researcher known as @Vet_X0 concluded that only about 21 million XRP, or roughly 0.03% of the roughly 100 billion total supply, sits in dormant large-holder accounts with exposed public keys.
Are these two readings actually measuring the same thing? Has the crowd already drawn the correct conclusion from them?
Our answer, in short: no. Both figures are weaker signals than the headline versions make them look, in different ways.
What the Two Readings Actually Measure
Start with Bitcoin. Glassnode’s 30.2% breaks into 1.92 million BTC (9.6%) that is structurally exposed and 4.12 million BTC (20.6%) that is operationally exposed through address reuse. Structural exposure covers Pay-to-Public-Key (P2PK) outputs from Bitcoin’s first years, when the raw public key was written directly into the transaction output rather than a hash of it; bare multisig; and Taproot outputs, which reveal keys by design. A UTXO, or unspent transaction output, is simply a chunk of bitcoin sitting at an address waiting to be spent. Operational exposure is what happens with address reuse: the moment an address sends a transaction, it reveals its public key on-chain, so any subsequent balance left at that same address is exposed.
Custodian-level exposure is wildly uneven. Glassnode measured Coinbase at roughly 5% exposed, Grayscale near 50%, and Binance, Bitfinex, Robinhood and WisdomTree between 85% and 100%. Sovereign holdings by the U.S., U.K. and El Salvador registered at 0%. The BIP-361 authors reach a similar order of magnitude from a different direction: the March 2026 draft cites over 34% of supply as having exposed public keys, and Tech Times reported on July 4, 2026 that experts were split on the freeze as the threat crossed 34% of supply. Every credible number lands between 30% and 35%. It is not 50%.
Now XRP. The 0.03% figure did not come from Ripple or from the XRP Ledger Foundation. It is an independent third-party audit by a validator operator, and treating it as an official corporate disclosure gets the sourcing wrong. @Vet_X0’s April 7, 2026 analysis of the ledger’s roughly 7.8 million accounts found that about 300,000 accounts had never transacted, and therefore never exposed a public key, holding roughly 2.4 billion XRP. Only two dormant large-holder accounts with exposed public keys were identified, holding a combined roughly 21 million XRP. The audit’s own summary reads: “Dormant, vulnerable XRP whales are almost nonexistent. The rest is active and has their public key exposed, but is also reasonable to expect to rotate keys if needed.”
Why Both Numbers Are Weaker Signals Than They Look
On the Bitcoin side, the 30% headline conflates two different questions. Technically exposed is not the same as realistically exploitable. CoinShares argued on Feb. 9, 2026 that roughly 1.6 million BTC, about 8% of supply, sits in the legacy P2PK addresses it considers genuinely vulnerable, and of those, only about 10,200 BTC is concentrated enough in single addresses to cause meaningful market disruption if stolen. The rest is spread across more than 32,000 UTXOs averaging roughly 50 BTC each, which CoinShares says makes them unattractive, low-value targets. It also estimated the required fault-tolerant hardware is roughly 100,000 times more powerful than anything that exists today, putting a practical threat at least a decade out. The 30% to 35% number and the 10,200 BTC number are answers to different questions. Anyone using them interchangeably is misstating both.
On the XRP side, the low number substantially reflects ledger and supply structure, not cryptographic superiority. Most XRP sits in accounts that simply have not transacted yet, and an account that has never transacted has never revealed a public key. The XRP Ledger uses an account model rather than Bitcoin’s UTXO model, its roughly 100 billion supply is concentrated among Ripple and a relatively small set of large holders, and the validator set is smaller and more centralized than Bitcoin’s mining network. A dormant account is an account that has not moved. It is not a hardened account.
Most trading in XRP, and in bitcoin, happens inside exchange order books where nothing touches the chain, a blind spot the on-chain view has by construction. A ledger that looks quiet looks identical whether real holders are accumulating, doing nothing, or slowly leaving through internal exchange transfers. The 0.03% figure describes what is visible on the ledger, not the total exposure profile of holders whose keys are managed by custodians. On Bitcoin, Glassnode’s own custodian breakdown already shows how sharply that shifts the picture. The 0.03% versus 30% framing is not an apples-to-apples scorecard where XRP wins.
What Would Actually Change the Picture
The money and the code that would move price sit in the migration proposals, not in the sentiment around them. BIP-360, published Feb. 11, 2026 and merged into Bitcoin Core’s proposal repository, creates a quantum-resistant address type called Pay-to-Quantum-Resistant-Hash, with addresses beginning “bc1r”, using NIST-approved post-quantum signature schemes such as ML-DSA, structured as a backward-compatible soft fork. A soft fork is a rule change that older nodes still accept as valid, so upgrades roll out without splitting the network. BIP-360 only protects coins that voluntarily migrate going forward. It does nothing about the supply already exposed.
BIP-361 targets the already-exposed supply. The draft targets activation for Jan. 1, 2027. Phase A, about three years later, would block new payments into quantum-vulnerable address types. Phase B, two years after that, would invalidate old-style ECDSA and Schnorr signatures network-wide, permanently freezing any coins that never migrated. Both are proposals. BIP-360 is merged into the proposal repository but not activated. BIP-361 is explicitly a draft, its activation date is targeted rather than guaranteed, and it is contested within the Bitcoin community. Neither is adopted protocol.
Ripple has published its own plan. Ripple’s official four-phase post-quantum roadmap, published around April 20 and 21, 2026, sets Phase 1 as an emergency Q-Day recovery contingency using post-quantum zero-knowledge proofs, Phase 2 as risk assessment and NIST-algorithm testing during the first half of 2026, including work with Project Eleven on hybrid post-quantum signing, Phase 3 as Devnet integration of candidate post-quantum signature schemes in the second half of 2026, and Phase 4 as a full network-wide transition to post-quantum signatures by 2028. Q-Day is the shorthand for the day a quantum computer can break current public-key cryptography in the wild. Separately, the XRPL AlphaNet developer testnet adopted the NIST-standardized ML-DSA scheme, also known as CRYSTALS-Dilithium, in December 2025, confirmed by XRPL Labs developer Denis Angell.
The threat timeline behind all of this is where the March Google paper belongs, as background rather than as breaking news. Google Quantum AI, on March 31, 2026, estimated that breaking the 256-bit elliptic curve cryptography protecting Bitcoin and Ethereum would require fewer than 500,000 physical qubits, a twenty-fold reduction from prior estimates of several million. Once a public key is exposed during a transaction, a sufficiently powerful machine could derive the private key in about 9 minutes, giving an attacker an estimated 41% chance of succeeding before Bitcoin’s roughly 10-minute block confirmation window closes. The paper estimated approximately 6.9 million BTC, roughly one-third of the roughly 19.9 million circulating supply, sits in wallets where public keys have already been exposed, including an estimated 1.7 million BTC from Bitcoin’s early years and coins believed to belong to Satoshi Nakamoto. Timelines diverge among researchers: Haseeb Qureshi of Dragonfly moved his estimate to the end of the decade rather than the mid-2030s, while Ethereum researcher Justin Drake puts at least a 10% chance on a cryptographically relevant quantum computer arriving by 2032. No hardware today is remotely close to these requirements.
Price behavior is a separate question. Bitcoin (CRYPTO:BTC) traded at $78,978.3 Monday morning, down 31.82% over the past year but up 19.98% over the last week. XRP (CRYPTO:XRP) was at $1.51, down 50.4% over the past year and up 49.74% over the last week. Neither move is a quantum verdict. Our prior coverage of the validator audit is here, and we also covered the Bitcoin freeze conversation in May.
Does the 0.03% Reading Mean XRP Holders Can Relax?
No. It means the visible on-ledger exposure is genuinely small, and it also means the audit is picking up a supply structure and a lifecycle pattern rather than a cryptographic edge. Bitcoin’s 30% headline is real as a technical count and misleading as a market-risk count, and its 10,200 BTC figure is the one that actually maps to disruption. Both networks are running toward post-quantum signatures on different schedules, and neither has finished. Nothing in the current data supports treating the 0.03% figure as a clean win, and nothing supports treating the 30% figure as an imminent loss.
Two triggers are worth watching, and they are the ones that would move price rather than mood. First, on flows and adoption: whether Ripple’s Phase 3 Devnet integration of post-quantum signature schemes actually lands in the second half of 2026, on the way to the 2028 Phase 4 target. If that slips, the roadmap is a marketing document. Second, on levels and rules: whether BIP-361 activates on its Jan. 1, 2027 target or slips. That single date will tell readers whether the Bitcoin community accepted a freeze on old coins, and it is the event that would force the exposed 30% question from a debate into a settled policy.
Contact [email protected] for any questions or corrections.