Which Bitcoin Wallets Are at Risk From Quantum Computers? 6.9 Million BTC Have Exposed Keys

Millions of Bitcoin are sitting in addresses where a quantum computer could drain them without warning, and whether your own coins are exposed comes down to two details most holders have never checked.

Published September 12, 2026, 6:09pm ET · 3 min read

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

Multi exposure of blockchain and crypto economy theme hologram and table with computer background. Concept of bitcoin cryptocurrency.
© Peshkova / Shutterstock.com

Google Quantum AI’s March paper found about 6.9 million Bitcoin in addresses where the full public key is already visible on-chain, exposed to what researchers call an at-rest attack.

Some of those coins are held in early keys nobody can move. The rest belong to holders who could act if they knew which addresses were affected. So how do you know whether your own coins are exposed?

6.9 Million Bitcoin Held in Addresses With Visible Public Keys

Bitcoin gold coins with wallet, close-up. Virtual cryptocurrency concept.

Lukas Gojda / Shutterstock.com

An at-rest attack targets a key already published on the chain rather than one briefly revealed during a transaction, so a future quantum computer would have unlimited time to derive the private key offline and empty the wallet.

The same paper flagged about 20.5 million Ethereum (CRYPTO:ETH) in similarly exposed accounts. Every standard Ethereum account publishes its public key the first time it signs a transaction, and most active balances already have.

The exposure covers roughly a third of Bitcoin’s circulating supply and about a sixth of Ether’s, and it doesn’t depend on the owner doing anything wrong. The address type a coin was created under and whether that address has ever been used set the exposure between them.

Your Address Type Decides When the Key Becomes Visible

A futuristic digital image featuring a prominent, neon-blue Bitcoin logo with internal circuit patterns, outlined in faint red. The logo is centered on a background of glowing blue circuit board traces and abstract white and blue digital code, with data points like "3 9 7 3" and "5 7 5 9" visible. The overall color scheme is electric blue and dark purple, conveying a sense of technology, complexity, and digital currency.

vectorfusionart / Shutterstock.com

P2PK addresses, meaning pay-to-public-key outputs used in Bitcoin’s first years, place the full public key directly in the output script. Any coin in a P2PK address has been exposed from the moment it was funded.

P2PKH addresses, meaning pay-to-public-key-hash outputs, store only a hash of the public key, and a quantum computer can’t derive a private key from a hash. The first spend from a P2PKH address publishes the full key on-chain, and every coin later sent back to the same address inherits that exposure. Reused P2PKH addresses drive most of the 6.9 million figure.

The same protection covers P2WPKH, P2SH and P2WSH addresses, which also store a hash rather than a key. Taproot outputs, Bitcoin’s newest common format since November 2021, put the public key on-chain by design and carry the exposure from creation.

1.7 Million Bitcoin Locked in Keys Nobody Can Move

Crypto Bitcoin One dollar bitcoin, virtual money and one hundred dollar banknotes. Bitcoins on US dollars. Dollar to bitcoin exchange. Background with crypto bitcoins, and dollars. Golden bitcoin.

UVL / Shutterstock.com

Coinbase’s Independent Advisory Board on Quantum estimates about 1.7 million Bitcoin across roughly 20,000 early P2PK keys are Satoshi-era or otherwise lost. At $77,400, those coins are worth about $131 billion, and nobody can migrate them to a quantum-safe address because the private keys are gone.

A migration deadline that freezes any coins not moved by a certain block would protect the chain and permanently confiscate the lost ones. No deadline risks theft by whoever builds the first capable quantum computer, and 1.7 million coins arriving on exchanges at once.

One Check Tells You Where You Stand

Your Bitcoin is exposed if the address holding it has ever been spent from. A P2PKH, P2WPKH, P2SH, or P2WSH address that has never signed a transaction holds a hash and nothing more, so the key stays hidden. A P2PK or Taproot address is exposed either way.

Ethereum targets quantum resistance by December 2029 and Ripple a 2028 mainnet amendment, while Bitcoin has ratified nothing comparable. An upgrade on Bitcoin’s mainnet with a migration mechanism holders can use would change the answer, and no upgrade can be applied retroactively to keys already published. Until then, the wallets at risk from quantum computers are every P2PK, every Taproot, and every hashed address spent even once.

Contact [email protected] for any questions or corrections.

Sam Daodu

Sam Daodu is a crypto analyst who's spent nearly a decade making blockchain understandable—no easy task when most whitepapers read like fever dreams. He writes for 24/7 Wall St., covering Bitcoin, altcoins, and crypto market analysis for investors. Before crypto, he was a tech writer (back when explaining "the cloud" was peak innovation). Since 2018, he's written for CoinTelegraph, Yahoo Finance, The Block, Cryptonews, Zypto, Rain, and more—basically anywhere people want crypto news without the headache. Sam runs MacLabs Marketing, a content agency for crypto brands tired of sounding like AI wrote their website. He also publishes free crypto education on his site for Web3 enthusiasts who think "gas fees" is a typo. When he's not writing or staring at charts, Sam's either: - Watching anime (currently convinced One Piece has better tokenomics than most altcoins) - At the gym sculpting himself into a Greek god - Listening to the music your mum warned you only bad boys listen to Connect: LinkedIn | Email | MacLabs Marketing

All articles →