In Bitcoin’s early pay-to-public-key format, many addresses published their public keys on-chain even before the first spend
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Because their public keys were never hidden, these oldest coins, including roughly 1 million Satoshi -era Bitcoin, are exposed to future quantum attacks.
Key facts
- The biggest concern is abandoned coins, about $180 billion worth, including roughly $100 billion believed to be Satoshi’s
- The papers sparked consternation among the crypto community, with Bitcoin security researcher Justin Drake tweeting that "there's at least a 10% chance that by 2032 a quantum computer recovers
- In April 2026, Italian researcher Giancarlo Lelli used a publicly available quantum computer to crack a simplified elliptic curve cryptography key
- Post-quantum versions can be 10 to 100 times larger,” he said
Summary
Today’s quantum computers are far too small and unstable to threaten real-world cryptography. Early Bitcoin wallets with exposed public keys are most at risk in the long term. Quantum computers can’t break Bitcoin’s cryptography today, but advances from Google and IBM suggest the gap is closing faster than expected. Their progress toward fault-tolerant quantum systems raises the stakes for “ Q-Day,” the moment when a sufficiently powerful machine could crack older Bitcoin addresses and expose more than $452 billion in vulnerable wallets. Long seen as a distant threat on the horizon, Q-Day snapped into sharp focus with the publication of a Google whitepaper in March 2026 that suggested quantum computers could break cryptographic systems sooner than expected.