By: Ava Amelio

The Quantum Threat: And Why It Is Growing 

Bitcoin’s security rests on a simple promise: only the owner of a private key can spend the coins tied to it. A cryptographically relevant quantum computer, or CRQC, could break that promise by working backward from an exposed public key to the private key behind it. New research from Google Quantum AI cut the estimated hardware needed to pull this off by roughly 20x, down to fewer than 10,000 physical qubits.1 The same research puts nearly 7 million BTC, close to a third of the supply, in addresses where the public key is already out in the open and ready to attack.2 Two Bitcoin Improvement Proposals, BIP-360 and BIP-361, lay out how the network closes that gap. 

Why This Matters Now More Than Ever  

Bitcoin has no CEO who can push a patch. Every rule change needs miners, node operators, and users to separately choose to adopt it – a process that took years even for widely-supported upgrades like SegWit and Taproot. That slow clock is exactly why the runway needs to open now: the hardware estimates keep shrinking, but the migration path doesn’t get any shorter. A quantum attacker also doesn’t need to hit every wallet at once. One exposed key is enough, and nothing stops the attacker from sitting on stolen funds for months before moving them, timing the theft to avoid drawing notice from chain watchers.3 

  • BIP-360 introduces a new output type, Pay-to-Merkle-Root (P2MR), so newly minted coins never expose a raw public key in the first place. 
  • BIP-361 sets a public deadline for moving already-exposed coins to quantum-resistant addresses, after which the network stops honoring spends from the old, vulnerable signature types. 
  • Together, they cover both the coins Bitcoin hasn’t minted yet and the coins already sitting in the open. 

TDC’s View 

We recommend implementing both BIP-360 and BIP-361. Bitcoin’s coordination problem is also its risk-distribution problem: no central authority can force anyone to upgrade, so the burden of acting falls unevenly. Well-capitalized exchanges and miners can migrate on their own timeline. Retail holders and dormant accounts, including an estimated 1.7 million BTC in wallets whose owners are lost, dead, or simply gone, cannot act at all, no matter how much warning they get. Waiting for a crisis to force the industry’s hand doesn’t spread that exposure more fairly; instead, it leaves ordinary and absent holders exposed while everyone with the resources to move fast does exactly that. A public timeline is what makes the migration workable instead of a scramble, and it’s the best option the network has to protect the self-custody promise that makes Bitcoin worth defending. 

What Happens Next 

BIP-360 and BIP-361 are proposals, not settled code. They still need the community to build consensus, wallets and exchanges to support the new address types, and node operators to adopt the rules that enforce them. We will continue to track the process and keep members briefed as it moves through review, pressing the industry to treat this as a planning problem to solve now, rather than an emergency to manage later.