Quantum computing is often presented as a future threat that could overpower Bitcoin mining. That framing misses the more direct concern now being debated by Bitcoin developers: a sufficiently capable quantum computer could derive private keys from public keys that are already visible on the blockchain. The most exposed targets would include some early pay-to-public-key outputs, coins held after address reuse, and other outputs whose public keys are revealed for long periods.
The issue has moved from abstract discussion into active protocol research. BIP 360 proposes a new output structure designed to reduce long-exposure risk, while BIP 361 outlines a phased migration away from Bitcoin’s current elliptic-curve signature systems. Bitcoin Optech has continued to document debate through July 2026 over post-quantum signatures, migration incentives, and when vulnerable spending paths might eventually be disabled. None of these proposals proves that a practical attack is imminent, and publication as a Bitcoin Improvement Proposal does not mean community approval or deployment.
Why mining is not the central quantum risk
Bitcoin mining and Bitcoin ownership rely on different cryptographic functions. Mining repeatedly hashes block-header data with SHA-256, while spending bitcoin requires a valid digital signature. The distinction matters because the best-known quantum algorithms affect these functions differently.
Bitcoin Optech explains that an idealized quantum computer using Grover’s algorithm would reduce the effective security strength of SHA-256 search from roughly 256 bits to 128 bits. That is a major theoretical advantage, but it is not an instant reversal of the hash function and does not automatically give an attacker control of the network.
Bitcoin’s signature systems face a more direct problem. Existing ECDSA signatures and the Schnorr signatures used by Taproot rely on elliptic-curve cryptography. Under the assumptions of a sufficiently large, reliable quantum computer, Shor’s algorithm could recover a private key from its public key. An attacker with the derived private key could then produce a valid transaction spending the victim’s coins. In other words, the principal feared event is unauthorized ownership transfer, not simply faster block production.

Calling this an “old wallet” problem is useful for headlines but technically incomplete. Bitcoin value is held in unspent transaction outputs, or UTXOs, with specific spending conditions. The relevant question is whether the data needed for a quantum key-recovery attack is already public, not whether the owner uses an old-looking app or hardware device.
- Early pay-to-public-key outputs: P2PK outputs place the public key directly on-chain. BIP 360 identifies these as fundamentally vulnerable to long-exposure attacks if a cryptographically relevant quantum computer becomes available.
- Reused keys and addresses: P2PKH and P2WPKH normally commit to a hash of a public key, keeping the public key hidden until spending. After a spend reveals the key, sending more funds back to the same key creates long-term exposure. Bitcoin’s developer documentation has long recommended avoiding key reuse for both privacy and security.
- Taproot outputs: P2TR outputs expose an elliptic-curve public key in the output itself. That means quantum exposure is not limited to coins created in Bitcoin’s earliest years, even though dormant early P2PK coins are a prominent part of the debate.
Some related wallet data can also expose public-key information. BIP 360 notes that extended public keys, commonly called xpubs, and wallet descriptors may reveal quantum-vulnerable key material. This does not mean an xpub currently reveals private keys to ordinary computers; it means the public inputs required by the hypothetical quantum attack may already be available.

Long exposure
A long-exposure attack targets a public key that has been visible for an extended period. BIP 360 describes this as the more likely first class of quantum attack because an attacker could work on key recovery for as long as the key remains exposed. Dormant P2PK outputs, reused keys with remaining balances, and Taproot outputs therefore receive particular attention.
Short exposure
For outputs that hide a public key behind a hash, the key is normally revealed when the owner broadcasts a spending transaction. A quantum attacker would then have only the unconfirmed period to recover the private key, create a conflicting spend, and have it confirmed first. BIP 360 calls this a short-exposure attack and notes that it requires a faster quantum computer. Full protection against that scenario would require post-quantum signature schemes rather than only hiding elliptic-curve keys until spending.
This distinction is important for risk communication. A machine capable of attacking a key over months is not necessarily capable of attacking a newly revealed key within minutes. Quantum capability would likely develop through stages, but the speed, secrecy, cost, and reliability of that progression remain uncertain.

What BIP 360 and BIP 361 are trying to solve
BIP 360 proposes Pay-to-Merkle-Root, or P2MR, an output type that removes Taproot’s always-present key-spending path and commits instead to a script tree. Its stated goal is to provide resistance to long-exposure attacks and create a structure that could later support post-quantum signatures. It does not, by itself, solve every short-exposure problem, and its design remains part of an evolving technical discussion.
BIP 361 takes a broader and more controversial approach. It describes a phased migration in which new payments to quantum-vulnerable output types would eventually be restricted, followed later by restrictions on legacy ECDSA and Schnorr spending and a proposed rescue mechanism. The BIP’s authors estimate that more than 34% of bitcoin had revealed a public key on-chain as of March 1, 2026, but that figure is a claim within the proposal and should not be treated as a universally accepted measurement without reviewing its methodology.
The governance problem is difficult because dormant coins may belong to long-term holders, owners who lost their keys, deceased users, or unknown parties. Allowing vulnerable coins to remain spendable could permit quantum theft. Freezing them could prevent legitimate owners from recovering funds after a deadline. Designing a rescue process creates additional questions about proof of ownership, implementation complexity, and consensus legitimacy.
Current discussion therefore covers more than choosing a new signature algorithm. Developers are debating migration costs, larger signature sizes, wallet compatibility, privacy, fallback paths, and the conditions under which elliptic-curve spending could be disabled. NIST finalized three post-quantum cryptography standards in 2024, including two digital-signature standards, but adopting a standardized primitive inside Bitcoin would still require Bitcoin-specific engineering, review, and consensus.
What remains uncertain
- Hardware timing: The cited Bitcoin proposals discuss a future cryptographically relevant quantum computer, not a publicly demonstrated machine that can currently recover Bitcoin private keys. Engineering progress may be gradual, uneven, or partially secret.
- Attack economics: Even if key recovery becomes possible, its cost, throughput, and target selection are unknown. An early attacker might target a few high-value exposed outputs rather than the entire UTXO set.
- Migration design: No cited proposal has established final network consensus. Bitcoin’s BIP repository explicitly states that publication does not indicate approval or imminent adoption.
- Operational execution: Exchanges, custodians, hardware wallets, software wallets, miners, and users would need coordinated upgrades. A technically sound design could still face delays or implementation errors.
Why forex and CFD traders should care
For traders who follow bitcoin alongside currencies, rates, and broader risk assets, the practical issue is headline interpretation. A new quantum paper, hardware announcement, or Bitcoin proposal can create volatility even when it does not change the near-term security of the network. Traders should distinguish among a mining-efficiency claim, a signature-breaking claim, a wallet-migration proposal, and an actually deployed consensus change.
Counterparty context also matters. A trader holding exposure through an exchange, broker, fund, or custodian may not control the underlying addresses. The relevant questions are whether the service monitors protocol changes, avoids address reuse, maintains secure key-management practices, and has a credible migration process if post-quantum standards are adopted. Marketing claims of being “quantum safe” should be checked against specific technical documentation rather than accepted as a general guarantee.
- Check whether the report concerns SHA-256 mining or elliptic-curve signatures.
- Confirm whether the cited development is research, a draft BIP, deployed software, or an activated consensus rule.
- Look for primary documentation and clearly stated assumptions about quantum hardware.
- Avoid treating technical uncertainty as a price forecast or a promise of network failure.
Bottom line
Bitcoin’s most direct quantum-computing risk is not that a future machine suddenly mines every block. It is that sufficiently powerful quantum hardware could forge signatures for coins whose public keys are exposed. Early P2PK outputs and reused keys are central to that concern, although some newer structures, including Taproot outputs, also have long-exposure characteristics.
The risk is real at the level of cryptographic theory, but its timing and practical severity are uncertain. The 2026 wave of proposals shows that developers are actively exploring migration paths rather than declaring an emergency. For market participants, the disciplined response is to follow primary technical sources, separate proposals from adoption, assess custodial preparedness, and avoid turning an unresolved engineering problem into a deterministic trading conclusion. This article is informational and does not constitute financial advice.
