Forbes: 7 Million Bitcoins Exposed to Quantum Computing Risk—Must BTC Change Its "Lock"?

marsbitPublished on 2026-08-03Last updated on 2026-08-03

Abstract

**Forbes: Quantum Computing Threatens 7 Million Bitcoin — Must BTC Change Its "Lock"?** A Forbes article explores the emerging threat quantum computing poses to Bitcoin's cryptography, which secures an estimated 7 million BTC (~$470 billion). While a machine capable of breaking Bitcoin's Elliptic Curve Digital Signature Algorithm (ECDSA) doesn't yet exist, researchers are raising alarms. Google studies suggest the required number of qubits for such an attack is decreasing rapidly. The risk applies to "exposed" public keys, found in early "Satoshi-era" addresses or reused addresses, but exposure does not equal theft. The Bitcoin developer community is divided on solutions. Proposals include BIP-360 for new quantum-resistant address types and the more controversial BIP-361, which would eventually freeze non-migrated, vulnerable coins to prevent future quantum theft. Startups like American Fortress are entering the space, claiming solutions like a backward-compatible soft fork to auto-freeze vulnerable wallets. However, its claims are met with caution as its technical paper is unpublished and its design unaudited. The article frames this as a high-stakes race, weighing urgent security upgrades against Bitcoin's foundational principles and long-term viability.

Author:Boaz Sobrado,Forbes

Compiled by: Shenchao TechFlow

Shenchao Guide: How far is quantum computing from truly breaking Bitcoin? This article breaks down the "$470 Billion Quantum Race": which coins are already at risk, why "exposed ≠ stolen", the timelines given by Google and the Ethereum Foundation, and the fierce debate over BIP-360 / BIP-361 regarding freezing dormant coins. Even more intriguing is the startups' head start—American Fortress claims "quantum resistance without migrating addresses", yet its paper is unpublished, its design unaudited. Is it cold fusion or another crypto narrative? The article offers a cautious judgment.

"That's the End of Bitcoin" — The $470 Billion Quantum Race

A quantum computer might be able to break the cryptography protecting millions of bitcoins. This article delves into the "freeze controversy", the $470 billion exposed to risk, and the startups racing to fix this vulnerability.

"I think Bitcoin is finished in four years," said David McAlvany, CEO of the gold app Vaulted, on the On The Margin podcast. "We will have quantum computing in four years, and that will be the end of Bitcoin. You can solve all the math problems instantly."

"I don't know if it's four years, five years, or two months," he added. As of mid-2026, a machine capable of this does not exist. But now this threat has a concrete timeline.

Attackers Realized This Sooner Than Security Teams

"It's a bit unfortunate that attackers realized this before infrastructure teams, before security teams," said Ido Sofer, founder of key management company Sodot, on the On The Margin podcast. "We are the first to face brand new attack vectors every time."

Galaxy Digital estimated in March 2026 that about 7 million bitcoins were in addresses where public keys had been exposed on-chain, worth approximately $470 billion. Glassnode's figure is 6.04 million, or 30.2% of the supply. Both are estimates, not protocol-level statistics; Galaxy called this risk "real, but far from an existential crisis". These exposed coins include Satoshi-era addresses that leaked their original public keys, and any addresses reused after their first spend. Exposure does not equal theft. It only becomes theft when a machine can reverse the math puzzle—and such a machine does not yet exist.

Bring Your Own Lock

"When you are on Bitcoin, Ethereum, Solana, currently you are locked into the one type of lock they allow you to use, just one," said Yoon Auh, CEO of BOLTS Technologies, on the podcast. "When you see quantum computing progress, those locks can be broken, and that is what they are afraid of."

These locks look increasingly fragile each year. Google researcher Craig Gidney proved in May 2025 that breaking RSA-2048 might require less than 1 million qubits, twenty times less than his own 2019 estimate. A Google whitepaper in April 2026 pushed the required qubit count for breaking Bitcoin's elliptic curve cryptography below 500,000. Ethereum Foundation researcher Justin Drake estimated that by 2032, the probability of a quantum computer cracking a Bitcoin private key from an exposed public key is around 10%. In April 2026, a researcher chasing Project Eleven's "Q-Day prize" cracked a 15-bit key on real quantum hardware. A real key is 256 bits, so this is just a toy—but a year ago, this toy didn't work at all.

Auh's solution is to give the choice of cryptography back to the user, not the chain. "Bring your own lock, choose your own lock," he said. BOLTS demonstrated its per-transaction cryptography scheme to NIST's post-quantum cryptographers and ran a quantum-resilient pilot on the Canton Network in December 2025. NIST finalized its first three post-quantum standards in August 2024.

Bitcoin developers themselves are divided on how to respond. A draft proposal, BIP-360 by Hunter Beast, would add a new quantum-resistant address type. Another, BIP-361 by Jameson Lopp and five co-authors, is chilling: it would phase out old-style signatures in two stages, and any coins never migrated (including those believed to belong to Satoshi) would become unspendable. Proponents argue that freezing dormant coins is better than letting future quantum thieves drain them and dump them on the market. Critics call it confiscation. Algorand has used quantum-resistant Falcon signatures for its state proofs since 2022; Quantum Resistant Ledger and the publicly listed BTQ are attacking the same problem from different angles.

Like Discovering Cold Fusion

Enter American Fortress among these players—an Austin-based company that completed an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. Formerly MatterFi, it claims to offer "quantum resistance across all chains without users needing to migrate any addresses", paired with a backward-compatible Bitcoin soft fork designed to automatically freeze vulnerable dormant wallets before attackers can strike. Its founder, Michal "Mehow" Pospieszalski, is not modest: "This quantum work is so good I couldn't give it away," he said on the On The Margin podcast about the quantum work. "It's like discovering cold fusion."

These claims warrant cautious scrutiny. "This algorithm is not news," Pospieszalski said. "People suggested long ago that you could generate additional proofs around existing addresses. But it was so slow that it was abandoned. We made it 100 times faster on a regular PC." American Fortress has patented a post-quantum transaction signature, but filing establishes priority, not proof; its technical paper is unpublished, and its design is not publicly audited. The company has deployed a beta version on Arbitrum, with a partner manager at Offchain Labs quoted expressing support—though that is one deployment, not a formal endorsement of the cryptography. "Post-quantum security is not a future feature, it's a necessity today," said 0G Labs CEO Michael Heinrich in the funding announcement.

Privacy Is Not Anonymity

The quantum work is only half its pitch. The other half is a compliance and privacy layer, built on the same argument: cryptocurrency has never truly proven who paid whom. "If I send you money, you get a cryptographic proof that it indeed came from my private key," Pospieszalski said. "That was completely impossible before." He points to "address poisoning"—scammers filling a victim's transaction history with look-alike addresses; in May 2024, one such attack drained $68 million in wrapped Bitcoin, though funds were later recovered. His fix is to attach proof of origin to each transaction and let users disclose identity only when they choose. "We don't require you to hold an ID to use the system," he said. "It's like ENS, just private."

Whether a privacy layer with built-in compliance is coherent is exactly what others in the industry are grappling with. "I have always viewed privacy and anonymity as completely different things," said Varun Kabra, Chief Growth Officer at Concordium, on the On The Margin podcast. Concordium uses zero-knowledge proofs to embed identity on-chain, so "because there is selective disclosure, there are zero-knowledge proofs, no one knows it's you". That is the same bet American Fortress is making. Kabra phrases the compliance line identically: "You control what you want to disclose, to whom, but subject to the law," he said. "No one should be above the law."

You Can't Prove It

Pospieszalski's belief that systems should be able to prove their own honesty predates cryptocurrency. The self-described white-hat hacker was CTO of the Election Science Institute around 2006, analyzing ES&S's iVotronic voting machines and warning they lacked cryptographic means to confirm whether a vote was counted once. "As a vote counter, you cannot prove to me that you counted my vote, didn't double-count it, or didn't under-count it," he said. "You can't prove it." Later, he did forensic work for the plaintiff's side in the disputed 2020 Antrim County, Michigan election case. According to his account, the anomalies there traced back to a misconfigured ballot definition file—consistent with an administrative explanation accepted by a bipartisan hand audit and all courts that heard the case; no fraud was proven before dismissal.

None of these funded fixes currently address a deeper concern for a long-term holder. McAlvany, whose business is selling gold, asks whether Bitcoin can last 5,000 years. "Gold, I'm pretty sure it will survive," he said. "Bitcoin, maybe not."

Trending Cryptos

Related Questions

QAccording to the article, how many Bitcoins are estimated to be exposed to quantum computing risks, and what is their approximate value?

AAccording to the article, Galaxy Digital estimates that approximately 7 million Bitcoins, valued at around $470 billion, are located in addresses where the public keys have been exposed on-chain. Glassnode provides a figure of 6.04 million Bitcoins, representing 30.2% of the supply.

QWhat are the two main Bitcoin Improvement Proposals (BIPs) mentioned in the article regarding the quantum threat, and what is the key difference between them?

AThe article mentions BIP-360 proposed by Hunter Beast, which aims to add a new type of quantum-resistant address. The other is BIP-361, proposed by Jameson Lopp and co-authors. The key difference is that BIP-361 proposes a two-phase process to phase out legacy signatures, ultimately making any coins that are never migrated (including those believed to belong to Satoshi Nakamoto) permanently unspendable. Critics describe this proposal as confiscation.

QWhat claims does the company American Fortress make about its quantum-resistant solution, and what reasons does the article give for being cautious about these claims?

AAmerican Fortress claims to provide "quantum resistance across all chains" without requiring users to migrate any addresses, paired with a backwards-compatible Bitcoin soft fork to automatically freeze vulnerable dormant wallets before an attacker can access them. The article advises caution because its technical paper has not been published, its design has not undergone public audit, and while it has filed for a patent, a patent application establishes priority but does not constitute proof of the technology's efficacy.

QWhat does Google researcher Craig Gidney's work, cited in the article, indicate about the progress in quantum computing's threat to cryptography?

ACraig Gidney's work shows significant progress. In May 2025, he demonstrated that cracking RSA-2048 might require less than 1 million qubits, a twenty-fold reduction from his 2019 estimate. Furthermore, an April 2026 Google whitepaper reduced the estimated number of qubits needed to crack Bitcoin's elliptic-curve cryptography to below 500,000.

QBeyond quantum resistance, what is the other major selling point of American Fortress's proposed system according to the article?

AThe other major selling point is a compliance and privacy layer. The system aims to attach a proof of origin to every transaction, allowing users to disclose their identity only when they choose to. It is designed to prevent issues like "address poisoning" by providing cryptographic proof that a payment came from a specific private key, while offering selective disclosure features similar to zero-knowledge proofs for user privacy within legal frameworks.

Related Reads

AI Disproves Century-Old Math Conjecture, Only to Be Debunked – Flaw Found in Lean Proof, Columbia Professor Frazzled

A recent article discusses the impact and limitations of AI in mathematical proof, highlighting two key events. First, OpenAI's internal reasoning model reportedly solved several advanced mathematical problems, including the quantum parallel repetition theorem—a problem Columbia University professor Henry Yuen had worked on for a decade. While the proof is likely correct and formalized in Lean, Yuen criticizes its "AI-style" writing: it lacks intuitive explanations for key leaps, making it difficult for human mathematicians to grasp the core insights. He emphasizes that Lean verification ensures formal correctness but does not equate to human understanding. Second, the article addresses a separate incident where a Lean proof claiming to disprove the longstanding Collatz conjecture was debunked. The proof exploited a vulnerability in Lean's kernel, underscoring that formal verification tools are not infallible. Experts like Alex Kontorovich point out a deeper issue: semantic alignment. Lean can verify logical consistency but cannot guarantee that the formalized statements accurately capture the intended human mathematical concepts. This alignment still requires expert human oversight. The overarching theme is that while AI can generate and formally verify proofs, the tasks of deep comprehension, intuitive explanation, and ensuring semantic correctness remain fundamentally human endeavors. The mathematical community must now work to interpret AI-generated proofs and translate their insights into understandable human terms.

marsbit8m ago

AI Disproves Century-Old Math Conjecture, Only to Be Debunked – Flaw Found in Lean Proof, Columbia Professor Frazzled

marsbit8m ago

Making the Silent Oracle Bones Speak for Three Thousand Years: The First AI-Assisted Interpretation System Mimicking Human Expert Workflow

Breaking the silence of three-thousand-year-old oracle bone inscriptions (OBI) poses immense challenges for researchers, who traditionally rely on laborious cross-referencing across fragmented historical materials. To address this, researchers from Huazhong University of Science and Technology and collaborating institutions have developed AlphaOracle, the first AI system designed to simulate the expert workflow for deciphering OBI. The system integrates a four-step, evidence-based pipeline: 1) parsing and reading-order reconstruction of oracle bone rubbings; 2) morphological analysis of character evolution across historical scripts; 3) contextual verification using large-scale OBI corpora and a specialized masked language model; and 4) literature validation against classical texts and modern scholarly works. AlphaOracle generates comprehensive, traceable reports with candidate interpretations, confidence scores, and source citations for expert review, functioning as an intelligent assistant rather than a final arbiter. In evaluations involving 86 domain experts, 78.7% found the system helpful, estimating an average 64% reduction in analysis time. The system achieved a top-1 accuracy of 23.1% on deciphering withheld known characters and significantly outperformed general-purpose large language models in contextual reasoning tasks. AlphaOracle successfully analyzed several controversial characters, with some results incorporated into authoritative OBI databases. This work demonstrates a promising paradigm where AI enhances the breadth and efficiency of material retrieval and hypothesis generation, while human experts retain the crucial role of deep scholarly judgment, paving the way for systematic AI-assisted research in paleography.

marsbit9m ago

Making the Silent Oracle Bones Speak for Three Thousand Years: The First AI-Assisted Interpretation System Mimicking Human Expert Workflow

marsbit9m ago

Cyber Godfather Tibo Reveals: Google Had ChatGPT a Year Earlier but Dared Not Release It

In a recent revelation, Thibault "Tibo" Sottiaux, the Codex lead at OpenAI, confirmed that Google developed a ChatGPT-like chatbot called "LMChat" a full year before OpenAI's launch. According to Tibo, who was part of the Google team at the time, the company was too cautious to release it, fearing it might disrupt its core search and advertising business. DeepMind, where the project was housed, was also restricted from launching products that could compete with Google's existing services. This account aligns with past statements from former Google Brain head Jeff Dean, who mentioned an internal chatbot that was deemed inferior to Google Search at the time. The article highlights this as a classic case of "innovator's dilemma," comparing Google's hesitation to Xerox's failure to commercialize groundbreaking technologies like the graphical user interface in the 1970s. The piece further notes a recent wave of high-profile departures from Google's AI teams to rivals like OpenAI and Anthropic, including key figures such as Transformer co-author Noam Shazeer and AlphaFold lead John Jumper. It concludes that Google's excessive caution and internal constraints, driven by the need to protect its lucrative search business, ultimately cost it a pioneering position in the generative AI revolution, allowing OpenAI to seize the initiative with ChatGPT's public release in November 2022.

marsbit18m ago

Cyber Godfather Tibo Reveals: Google Had ChatGPT a Year Earlier but Dared Not Release It

marsbit18m ago

Trading

Spot

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

1.4k Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片