Bitcoin’s exposure to future quantum attacks is becoming a more concrete infrastructure concern as post-quantum standards move into deployment and researchers refine estimates of vulnerable coins. Project Eleven’s Bitcoin Risq List identified 7,748,972 BTC with already exposed public keys as of August 24, worth roughly $603.6 billion at the tracker’s reference price. The figure represents coins that could theoretically become targets once a quantum computer capable of breaking Bitcoin’s elliptic-curve signatures exists, not assets that are vulnerable to theft with current machines.
Earlier estimates placed the exposed balance between 6.65 million and 7 million BTC, explaining the lower figures that continue circulating in market analysis. The number changes as addresses spend funds, reuse keys or move balances. Quantum exposure is therefore a dynamic on-chain measurement rather than a fixed share of Bitcoin supply. Project Eleven’s methodology focuses on addresses whose public keys are already visible and does not include the separate risk faced when previously hidden public keys are revealed during spending.
Shor’s Algorithm Threatens Exposed Bitcoin Keys
Bitcoin relies on elliptic-curve cryptography for transaction authorization. A sufficiently capable fault-tolerant quantum computer running Shor’s algorithm could theoretically derive a private key from its corresponding public key, enabling forged signatures. The underlying cryptographic risk is established, but the timetable for a machine powerful enough to execute the attack remains deeply uncertain.
Progress in experimental attacks is still far removed from Bitcoin’s 256-bit security. Project Eleven reported in April that a researcher broke a 15-bit elliptic-curve key on publicly accessible quantum hardware, improving on earlier demonstrations but remaining nowhere near a practical Bitcoin attack. Laboratory progress demonstrates the attack mechanism rather than an imminent ability to recover production Bitcoin keys.
Standards bodies nevertheless argue that migration should begin well before that capability exists. The U.S. National Institute of Standards and Technology finalized ML-KEM, ML-DSA and SLH-DSA in 2024 and now says organizations should begin replacing quantum-vulnerable public-key cryptography. NIST’s transition strategy targets deprecation of vulnerable algorithms beginning around 2030 and their removal from standards by 2035, making post-quantum planning a current infrastructure requirement.
Migration Cost Is Large but Often Misstated
A frequently cited $7.1 billion migration estimate requires careful qualification. The White House Report on Post-Quantum Cryptography projects approximately $7.1 billion in 2024 dollars to migrate prioritized U.S. federal civilian information systems between 2025 and 2035. That figure is not an estimate for upgrading Bitcoin, Ethereum, exchanges or crypto custody infrastructure, and the government itself describes it as a rough projection with substantial uncertainty.
Blockchain networks face their own migration challenges. Bitcoin must address exposed legacy keys, dormant holdings, wallet compatibility and larger post-quantum signatures, while Ethereum is exploring cryptographic agility through mechanisms including native account abstraction. The hardest problem is not proving that quantum-resistant signatures exist, but coordinating millions of users, wallets, custodians and infrastructure providers before vulnerable keys become exploitable.
For institutional holders, the operational work includes identifying exposed keys, testing new signing schemes, updating hardware and recovery procedures and preparing migration policies for long-duration cold storage. The relevant risk-management window is already open even though “Q-Day” itself cannot be reliably dated. Quantum computing remains a future threat, but cryptographic migration is a multi-year process that becomes considerably harder if institutions wait until the threat is immediate.

