cd /news/ai-research/which-bitcoin-wallets-are-at-risk-fr… · home topics ai-research article
[ARTICLE · art-127944] src=247wallst.com ↗ pub= topic=ai-research verified=true sentiment=↓ negative

Which Bitcoin Wallets Are at Risk From Quantum Computers? 6.9 Million BTC Have Exposed Keys

Google Quantum AI's March paper found about 6.9 million Bitcoin, roughly a third of the circulating supply, sitting in addresses whose full public keys are already visible on-chain and thus exposed to an at-rest quantum attack, with about 20.5 million Ethereum similarly exposed. Coinbase's Independent Advisory Board on Quantum estimates roughly 1.7 million of those Bitcoin, spread across about 20,000 early P2PK keys, are Satoshi-era or lost and worth about $131 billion at $77,400 per coin, unmigratable because the private keys are gone. Exposure depends on address type and spend history: P2PK and Taproot addresses are exposed from creation, while P2PKH, P2WPKH, P2SH and P2WSH addresses stay protected until their first spend, and Ethereum targets quantum resistance by December 2029 while Bitcoin has ratified no comparable upgrade.

by read3 min views2 publishedSep 12, 2026
Which Bitcoin Wallets Are at Risk From Quantum Computers? 6.9 Million BTC Have Exposed Keys
Image: 247Wallst (auto-discovered)

Millions of Bitcoin are sitting in addresses where a quantum computer could drain them without warning, and whether your own coins are exposed comes down to two details most holders have never checked.

This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.

Google Quantum AI’s March paper found about 6.9 million Bitcoin in addresses where the full public key is already visible on-chain, exposed to what researchers call an at-rest attack.

Some of those coins are held in early keys nobody can move. The rest belong to holders who could act if they knew which addresses were affected. So how do you know whether your own coins are exposed?

6.9 Million Bitcoin Held in Addresses With Visible Public Keys #

An at-rest attack targets a key already published on the chain rather than one briefly revealed during a transaction, so a future quantum computer would have unlimited time to derive the private key offline and empty the wallet.

The same paper flagged about 20.5 million Ethereum (CRYPTO:ETH) in similarly exposed accounts. Every standard Ethereum account publishes its public key the first time it signs a transaction, and most active balances already have.

The exposure covers roughly a third of Bitcoin’s circulating supply and about a sixth of Ether’s, and it doesn’t depend on the owner doing anything wrong. The address type a coin was created under and whether that address has ever been used set the exposure between them.

Your Address Type Decides When the Key Becomes Visible #

P2PK addresses, meaning pay-to-public-key outputs used in Bitcoin’s first years, place the full public key directly in the output script. Any coin in a P2PK address has been exposed from the moment it was funded.

P2PKH addresses, meaning pay-to-public-key-hash outputs, store only a hash of the public key, and a quantum computer can’t derive a private key from a hash. The first spend from a P2PKH address publishes the full key on-chain, and every coin later sent back to the same address inherits that exposure. Reused P2PKH addresses drive most of the 6.9 million figure.

The same protection covers P2WPKH, P2SH and P2WSH addresses, which also store a hash rather than a key. Taproot outputs, Bitcoin’s newest common format since November 2021, put the public key on-chain by design and carry the exposure from creation.

1.7 Million Bitcoin Locked in Keys Nobody Can Move #

Coinbase’s Independent Advisory Board on Quantum estimates about 1.7 million Bitcoin across roughly 20,000 early P2PK keys are Satoshi-era or otherwise lost. At $77,400, those coins are worth about $131 billion, and nobody can migrate them to a quantum-safe address because the private keys are gone.

A migration deadline that freezes any coins not moved by a certain block would protect the chain and permanently confiscate the lost ones. No deadline risks theft by whoever builds the first capable quantum computer, and 1.7 million coins arriving on exchanges at once.

One Check Tells You Where You Stand #

Your Bitcoin is exposed if the address holding it has ever been spent from. A P2PKH, P2WPKH, P2SH, or P2WSH address that has never signed a transaction holds a hash and nothing more, so the key stays hidden. A P2PK or Taproot address is exposed either way.

Ethereum targets quantum resistance by December 2029 and Ripple a 2028 mainnet amendment, while Bitcoin has ratified nothing comparable. An upgrade on Bitcoin’s mainnet with a migration mechanism holders can use would change the answer, and no upgrade can be applied retroactively to keys already published. Until then, the wallets at risk from quantum computers are every P2PK, every Taproot, and every hashed address spent even once.

Contact [email protected] for any questions or corrections.

── more in #ai-research 4 stories · sorted by recency
── more on @google quantum ai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/which-bitcoin-wallet…] indexed:0 read:3min 2026-09-12 ·