On-Chain: $452B in BTC Supply Sits on Exposed Public Keys as Q-Day Estimates Compress
Legacy address formats and reused keys leave $452B of Bitcoin's supply cryptographically exposed as quantum hardware timelines shorten.

$452 billion. That’s the current on-chain tally of Bitcoin sitting in addresses where the public key has already been revealed — the exact data set a sufficiently powerful quantum computer would need to derive a private key and forge a signature. It’s the number desks tracking quantum risk should be watching, not any single hardware milestone.
Why the exposure number moved into focus
A Google whitepaper published in March 2026 pushed forward its estimate for when quantum hardware could break widely used cryptographic systems, compressing prior timelines. IBM’s parallel progress toward fault-tolerant quantum architecture has added to that shift, shortening the perceived runway to “Q-Day” — the theoretical point at which a quantum machine could forge Bitcoin signatures at scale.
None of this reflects a change in present capability. No existing quantum system is close to running the algorithms required to break elliptic-curve cryptography; qubit stability remains far below the threshold fault-tolerant attacks would demand. What moved is the estimate, not the machine.
Where the $452B concentrates
The exposure isn’t spread evenly across the supply. Older address formats, and any address that has ever reused a public key on-chain, already have that key sitting in the open — precisely the data a quantum attacker would need.
Modern address formats keep the public key concealed until a transaction actually broadcasts, cutting exposure but not removing it — the underlying signature scheme would still need replacing to hold up against a credible quantum adversary. In practical terms, that draws a line between dormant legacy UTXOs that have sat untouched for years and actively managed wallets running current address standards.
No migration path, no fixed trigger date
Researchers are evaluating post-quantum signature schemes to eventually replace Bitcoin’s current signing mechanism, but there’s no consensus yet on implementation. Unresolved questions include how a network-wide migration to post-quantum addresses would be sequenced, and what happens to legacy exposed wallets whose holders never move funds before a credible threat exists.
A cryptographic overhaul at this scale would take years to design, test and roll out across the network — which is why developers argue the work needs to start well before any confirmed quantum capability, not after. The bigger planning problem is that there’s no fixed Q-Day estimate to schedule against, only a compressing range.
Read more: US National Debt Hits Record $39.4 Trillion, Fueling Bitcoin-as-Hedge Narrative