Loading prices…
🩸BEARISH

M BTC Vulnerable to Quantum Attacks, Coinbase Advisory Warns

The headline 7M figure is split between 1.7M legacy Satoshi-era P2PK coins and 5M reused-key BTC, and it's the second bucket — held by active users and major exchange cold wallets — that the report…

Coinbase's Independent Advisory Board on Quantum Computing and Blockchain said Thursday that roughly 7 million bitcoin sit in addresses exposed to a future quantum attack, and that the majority of that exposure is not lost Satoshi-era coins but active funds, including cold wallets operated by known exchanges. The exchange-exposure point is the sharpest beat in the report, because it puts a structural risk on the largest custodians in the market rather than on wallets the network has already priced as unreachable.

The board splits the 7 million into two buckets. About 1.7 million BTC sit across roughly 20,000 legacy pay-to-public-key (P2PK) addresses, where the public key itself is visible onchain, leaving those coins directly vulnerable to a future attack. Most are assumed to belong to bitcoin's pseudonymous creator or to owners long locked out of their keys. The second bucket is the one tied to address reuse. Citing quantum-security firm Project Eleven, the report puts about 5 million BTC at risk because their public keys have already been revealed, and says most of those coins belong to active users — with large amounts sitting in cold wallets of known exchanges or showing recent onchain activity. The report does not name the exchanges.

Why it matters

The report frames the governance problem, not just the cryptography. It lays out two opposing positions: a hard deadline that freezes any quantum-vulnerable signature (ECDSA, Schnorr) after a set date, or a permissive approach that enables post-quantum addresses and leaves the risk with each owner. Freezing the vulnerable coins protects holders from a flood of seized supply, including any large stash a sanctioned actor like North Korea could capture, but it amounts to confiscation at the protocol level and breaks with bitcoin's property-rights ethos. The permissive approach preserves ownership but has no reliable way to tell a negligent holder from one who is imprisoned, deceased, or temporarily locked out. The board declined to back either side, saying only that migration and the governance fight will each take years and cannot wait for a cryptographically relevant quantum computer to actually exist.

Related tokens
$BTC $ETH

Frequently asked questions

  1. How many bitcoin does Coinbase's quantum report say are at risk?

    The report puts roughly 7 million BTC in addresses exposed to a future quantum attack, split between about 1.7 million in legacy P2PK addresses and around 5 million tied to address reuse where public keys are already visible onchain.

  2. Why are exchange cold wallets specifically flagged?

    Because of address reuse, the public keys for those wallets are already revealed onchain, putting roughly 5 million BTC in the second and larger exposure bucket. The report does not name the exchanges.

  3. Is quantum computing actually a threat to bitcoin today?

    No. The advisory board stressed that no quantum computer can break blockchain cryptography today and the threat timeline remains uncertain. The argument is that migration and the governance debate will each take years to resolve.

  4. What is the two-sided debate the report lays out?

    One position would set a deadline after which quantum-vulnerable signatures like ECDSA and Schnorr are no longer accepted, freezing unmigrated coins. The other would enable post-quantum addresses and leave migration risk with each owner.

  5. What intermediate solutions did the report mention?

    An "Hourglass" cap on P2PK coin movement per block, the draft BIP-361 phased sunset of legacy signatures with a quantum-resistant zero-knowledge proof option, and PACTs originally proposed by Paradigm researcher Dan Robinson.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 46d ago
Open original →