Forbes: 7 Million Bitcoins Exposed to Quantum Computing Risk—Must BTC Change Its "Lock"?

marsbitPublished on 2026-08-03Last updated on 2026-08-03

Abstract

**Forbes: Quantum Computing Threatens 7 Million Bitcoin — Must BTC Change Its "Lock"?** A Forbes article explores the emerging threat quantum computing poses to Bitcoin's cryptography, which secures an estimated 7 million BTC (~$470 billion). While a machine capable of breaking Bitcoin's Elliptic Curve Digital Signature Algorithm (ECDSA) doesn't yet exist, researchers are raising alarms. Google studies suggest the required number of qubits for such an attack is decreasing rapidly. The risk applies to "exposed" public keys, found in early "Satoshi-era" addresses or reused addresses, but exposure does not equal theft. The Bitcoin developer community is divided on solutions. Proposals include BIP-360 for new quantum-resistant address types and the more controversial BIP-361, which would eventually freeze non-migrated, vulnerable coins to prevent future quantum theft. Startups like American Fortress are entering the space, claiming solutions like a backward-compatible soft fork to auto-freeze vulnerable wallets. However, its claims are met with caution as its technical paper is unpublished and its design unaudited. The article frames this as a high-stakes race, weighing urgent security upgrades against Bitcoin's foundational principles and long-term viability.

Author:Boaz Sobrado,Forbes

Compiled by: Shenchao TechFlow

Shenchao Guide: How far is quantum computing from truly breaking Bitcoin? This article breaks down the "$470 Billion Quantum Race": which coins are already at risk, why "exposed ≠ stolen", the timelines given by Google and the Ethereum Foundation, and the fierce debate over BIP-360 / BIP-361 regarding freezing dormant coins. Even more intriguing is the startups' head start—American Fortress claims "quantum resistance without migrating addresses", yet its paper is unpublished, its design unaudited. Is it cold fusion or another crypto narrative? The article offers a cautious judgment.

"That's the End of Bitcoin" — The $470 Billion Quantum Race

A quantum computer might be able to break the cryptography protecting millions of bitcoins. This article delves into the "freeze controversy", the $470 billion exposed to risk, and the startups racing to fix this vulnerability.

"I think Bitcoin is finished in four years," said David McAlvany, CEO of the gold app Vaulted, on the On The Margin podcast. "We will have quantum computing in four years, and that will be the end of Bitcoin. You can solve all the math problems instantly."

"I don't know if it's four years, five years, or two months," he added. As of mid-2026, a machine capable of this does not exist. But now this threat has a concrete timeline.

Attackers Realized This Sooner Than Security Teams

"It's a bit unfortunate that attackers realized this before infrastructure teams, before security teams," said Ido Sofer, founder of key management company Sodot, on the On The Margin podcast. "We are the first to face brand new attack vectors every time."

Galaxy Digital estimated in March 2026 that about 7 million bitcoins were in addresses where public keys had been exposed on-chain, worth approximately $470 billion. Glassnode's figure is 6.04 million, or 30.2% of the supply. Both are estimates, not protocol-level statistics; Galaxy called this risk "real, but far from an existential crisis". These exposed coins include Satoshi-era addresses that leaked their original public keys, and any addresses reused after their first spend. Exposure does not equal theft. It only becomes theft when a machine can reverse the math puzzle—and such a machine does not yet exist.

Bring Your Own Lock

"When you are on Bitcoin, Ethereum, Solana, currently you are locked into the one type of lock they allow you to use, just one," said Yoon Auh, CEO of BOLTS Technologies, on the podcast. "When you see quantum computing progress, those locks can be broken, and that is what they are afraid of."

These locks look increasingly fragile each year. Google researcher Craig Gidney proved in May 2025 that breaking RSA-2048 might require less than 1 million qubits, twenty times less than his own 2019 estimate. A Google whitepaper in April 2026 pushed the required qubit count for breaking Bitcoin's elliptic curve cryptography below 500,000. Ethereum Foundation researcher Justin Drake estimated that by 2032, the probability of a quantum computer cracking a Bitcoin private key from an exposed public key is around 10%. In April 2026, a researcher chasing Project Eleven's "Q-Day prize" cracked a 15-bit key on real quantum hardware. A real key is 256 bits, so this is just a toy—but a year ago, this toy didn't work at all.

Auh's solution is to give the choice of cryptography back to the user, not the chain. "Bring your own lock, choose your own lock," he said. BOLTS demonstrated its per-transaction cryptography scheme to NIST's post-quantum cryptographers and ran a quantum-resilient pilot on the Canton Network in December 2025. NIST finalized its first three post-quantum standards in August 2024.

Bitcoin developers themselves are divided on how to respond. A draft proposal, BIP-360 by Hunter Beast, would add a new quantum-resistant address type. Another, BIP-361 by Jameson Lopp and five co-authors, is chilling: it would phase out old-style signatures in two stages, and any coins never migrated (including those believed to belong to Satoshi) would become unspendable. Proponents argue that freezing dormant coins is better than letting future quantum thieves drain them and dump them on the market. Critics call it confiscation. Algorand has used quantum-resistant Falcon signatures for its state proofs since 2022; Quantum Resistant Ledger and the publicly listed BTQ are attacking the same problem from different angles.

Like Discovering Cold Fusion

Enter American Fortress among these players—an Austin-based company that completed an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. Formerly MatterFi, it claims to offer "quantum resistance across all chains without users needing to migrate any addresses", paired with a backward-compatible Bitcoin soft fork designed to automatically freeze vulnerable dormant wallets before attackers can strike. Its founder, Michal "Mehow" Pospieszalski, is not modest: "This quantum work is so good I couldn't give it away," he said on the On The Margin podcast about the quantum work. "It's like discovering cold fusion."

These claims warrant cautious scrutiny. "This algorithm is not news," Pospieszalski said. "People suggested long ago that you could generate additional proofs around existing addresses. But it was so slow that it was abandoned. We made it 100 times faster on a regular PC." American Fortress has patented a post-quantum transaction signature, but filing establishes priority, not proof; its technical paper is unpublished, and its design is not publicly audited. The company has deployed a beta version on Arbitrum, with a partner manager at Offchain Labs quoted expressing support—though that is one deployment, not a formal endorsement of the cryptography. "Post-quantum security is not a future feature, it's a necessity today," said 0G Labs CEO Michael Heinrich in the funding announcement.

Privacy Is Not Anonymity

The quantum work is only half its pitch. The other half is a compliance and privacy layer, built on the same argument: cryptocurrency has never truly proven who paid whom. "If I send you money, you get a cryptographic proof that it indeed came from my private key," Pospieszalski said. "That was completely impossible before." He points to "address poisoning"—scammers filling a victim's transaction history with look-alike addresses; in May 2024, one such attack drained $68 million in wrapped Bitcoin, though funds were later recovered. His fix is to attach proof of origin to each transaction and let users disclose identity only when they choose. "We don't require you to hold an ID to use the system," he said. "It's like ENS, just private."

Whether a privacy layer with built-in compliance is coherent is exactly what others in the industry are grappling with. "I have always viewed privacy and anonymity as completely different things," said Varun Kabra, Chief Growth Officer at Concordium, on the On The Margin podcast. Concordium uses zero-knowledge proofs to embed identity on-chain, so "because there is selective disclosure, there are zero-knowledge proofs, no one knows it's you". That is the same bet American Fortress is making. Kabra phrases the compliance line identically: "You control what you want to disclose, to whom, but subject to the law," he said. "No one should be above the law."

You Can't Prove It

Pospieszalski's belief that systems should be able to prove their own honesty predates cryptocurrency. The self-described white-hat hacker was CTO of the Election Science Institute around 2006, analyzing ES&S's iVotronic voting machines and warning they lacked cryptographic means to confirm whether a vote was counted once. "As a vote counter, you cannot prove to me that you counted my vote, didn't double-count it, or didn't under-count it," he said. "You can't prove it." Later, he did forensic work for the plaintiff's side in the disputed 2020 Antrim County, Michigan election case. According to his account, the anomalies there traced back to a misconfigured ballot definition file—consistent with an administrative explanation accepted by a bipartisan hand audit and all courts that heard the case; no fraud was proven before dismissal.

None of these funded fixes currently address a deeper concern for a long-term holder. McAlvany, whose business is selling gold, asks whether Bitcoin can last 5,000 years. "Gold, I'm pretty sure it will survive," he said. "Bitcoin, maybe not."

Trending Cryptos

Related Questions

QAccording to the article, how many Bitcoins are estimated to be exposed to quantum computing risks, and what is their approximate value?

AAccording to the article, Galaxy Digital estimates that approximately 7 million Bitcoins, valued at around $470 billion, are located in addresses where the public keys have been exposed on-chain. Glassnode provides a figure of 6.04 million Bitcoins, representing 30.2% of the supply.

QWhat are the two main Bitcoin Improvement Proposals (BIPs) mentioned in the article regarding the quantum threat, and what is the key difference between them?

AThe article mentions BIP-360 proposed by Hunter Beast, which aims to add a new type of quantum-resistant address. The other is BIP-361, proposed by Jameson Lopp and co-authors. The key difference is that BIP-361 proposes a two-phase process to phase out legacy signatures, ultimately making any coins that are never migrated (including those believed to belong to Satoshi Nakamoto) permanently unspendable. Critics describe this proposal as confiscation.

QWhat claims does the company American Fortress make about its quantum-resistant solution, and what reasons does the article give for being cautious about these claims?

AAmerican Fortress claims to provide "quantum resistance across all chains" without requiring users to migrate any addresses, paired with a backwards-compatible Bitcoin soft fork to automatically freeze vulnerable dormant wallets before an attacker can access them. The article advises caution because its technical paper has not been published, its design has not undergone public audit, and while it has filed for a patent, a patent application establishes priority but does not constitute proof of the technology's efficacy.

QWhat does Google researcher Craig Gidney's work, cited in the article, indicate about the progress in quantum computing's threat to cryptography?

ACraig Gidney's work shows significant progress. In May 2025, he demonstrated that cracking RSA-2048 might require less than 1 million qubits, a twenty-fold reduction from his 2019 estimate. Furthermore, an April 2026 Google whitepaper reduced the estimated number of qubits needed to crack Bitcoin's elliptic-curve cryptography to below 500,000.

QBeyond quantum resistance, what is the other major selling point of American Fortress's proposed system according to the article?

AThe other major selling point is a compliance and privacy layer. The system aims to attach a proof of origin to every transaction, allowing users to disclose their identity only when they choose to. It is designed to prevent issues like "address poisoning" by providing cryptographic proof that a payment came from a specific private key, while offering selective disclosure features similar to zero-knowledge proofs for user privacy within legal frameworks.

Related Reads

Bitcoin Short-term Adjustment Continues, HYPE Approaches Critical Support | Guest Analysis

This article provides a technical analysis of Bitcoin (BTC) and HYPE for the current week. For Bitcoin, the daily chart suggests an ongoing b-wave correction within a larger pattern since the May high, currently testing the $60,900-$61,500 support zone. The analysis outlines that if this area holds (with the critical level at $57,820), a potential c-wave rally towards $67,300 could follow. Key resistance levels are identified at $63,600, $65,700-$67,300, and $69,500-$71,000. The author presents both mid-term and short-term trading strategies, including two specific short-term plans (Plan A and B) for potential long entries based on support holds or breaks above resistance. Regarding HYPE, the daily chart indicates it is in the final stages (C-wave) of a correction from its June high, now approaching a crucial support zone of $50-$52. The analysis notes oversold conditions and warns against chasing the downtrend, instead advising to watch for signs of a stabilizing bounce (potential D-wave). Key resistance levels are $58.5-$60, $63.5-$66, and near $72.97. The short-term strategy suggests considering a light long position if the $50-$52 support holds. The article also includes a verification of last week's analysis, noting that BTC's price action aligned with predictions, and details a successful short-term BTC short trade that yielded approximately 2.58% profit using proprietary trading models. General risk management rules for stop-loss placement are reiterated. The author concludes by emphasizing that all analysis is for personal trading purposes and does not constitute investment advice.

Odaily星球日报18m ago

Bitcoin Short-term Adjustment Continues, HYPE Approaches Critical Support | Guest Analysis

Odaily星球日报18m ago

Trading

Spot

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

1.4k Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片