We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Protecting Bitcoin from quantum computers
With a sufficiently powerful quantum computer, an attacker could calculate a private key from its public key and transfer someone else’s coins to themselves. They would not need access to your hardware wallet or seed phrase, because the attack exploits a weakness in the way transactions are signed. Google Quantum AI has estimated what hardware such an attack would require.
Bitcoin quantum protection requires changes to the network itself, including new ways to sign transactions. Until those changes arrive, you can check the addresses holding your funds and choose formats that hide the public key until you send coins. The blockchain initially shows only a hash, a short digital fingerprint of that key. Below, we explain which addresses work this way, why you should retire them after a transfer and what a hardware wallet cannot do in this situation.
Bitcoin quantum protection: why transaction signatures need to change
A private key is the secret number a wallet uses to sign transactions, so anyone who knows it can spend the coins. The public key is calculated from it and lets the network verify the signature. Knowing the public key does not let someone spend your funds using an ordinary computer, but a sufficiently powerful quantum computer could use it to recover the private key. Your wallet handles the routine calculations automatically, so you do not need to work with the keys yourself.
Calculating a public key from a private key is straightforward, but recovering the private key from the public key is practically impossible on a modern conventional computer. Trying the enormous number of possible keys one by one would take far too long to be a practical attack.
Bitcoin and ordinary Ethereum accounts use the same mathematical foundation for their signatures, but expose public keys under different conditions. Understanding the quantum threat therefore means looking at the address type and its past transactions, as well as the network.
How Shor’s algorithm could recover a private key
In 1994, mathematician Peter Shor proposed a quantum algorithm that can calculate a private key from a public key without trying every possible value. An attacker would need a sufficiently powerful and reliable quantum computer to use it.
Qubits are the units of information a quantum computer works with. Physical qubits are the actual hardware elements, which are prone to errors. To make long calculations more reliable, many physical qubits are combined into a logical qubit, with errors corrected within the group.
A thousand physical qubits are not the same as a thousand logical qubits: one logical qubit may require hundreds of physical qubits or more. A processor’s advertised qubit count alone therefore does not tell you whether it could recover a Bitcoin private key.
What quantum hardware would an attacker need?
On March 30, 2026, Google Quantum AI, together with researchers from the Ethereum Foundation and Stanford, published a study of quantum vulnerabilities in cryptocurrencies. The authors revised estimates of how many qubits and how much time would be needed to recover a Bitcoin private key from its public key.
The researchers considered two approaches to the calculation:
The authors estimate that either approach would need fewer than 500,000 physical qubits, provided the hardware achieves the required speed and reliability. That is roughly twenty times fewer than earlier estimates. The result depends on the hardware’s capabilities and how effectively the system corrects errors during the calculation.
The full calculation would take about 18–23 minutes. Some of the work could be done in advance, before obtaining the victim’s public key. If that preparation were preserved on the quantum computer, about 9 or 12 minutes of computation would remain after obtaining the key, depending on the approach.
An attacker could try to steal the coins while your transfer is waiting for confirmation. Sending funds from an address that hid the public key makes that key visible in the transaction. Before being included in a block, the transaction waits in the mempool, the pool of unconfirmed transactions. A fast enough quantum computer could calculate the private key during that wait, allowing the attacker to send the same coins to themselves and offer the miner a higher fee.
Assuming the calculation takes nine minutes and Bitcoin blocks arrive every ten minutes on average, the authors estimated a roughly 41% chance of stealing the coins before the transfer is confirmed. This assumes the attacker obtains the public key immediately, the network is not congested and their transaction can be included in a block instead of yours. In the same model, the chance is below 3% for Litecoin and less than one in eight thousand for Dogecoin. These are possible future attacks that would require the necessary hardware.
When the public key becomes visible on the blockchain
An attack using Shor’s algorithm requires the public key. A Bitcoin address and a public key are different things: some address formats expose the key immediately, while others initially show only its digital fingerprint. Other formats hide the spending rules behind a fingerprint, such as a requirement for multiple signatures.
For P2PKH and P2WPKH addresses, the public key is initially hidden behind a hash and becomes visible when you send coins from the address. Shor’s algorithm needs the public key itself, so its fingerprint alone is not enough for this attack. After a transfer, that advantage is lost: if coins remain at the same address or you receive more funds there, an attacker can already see the public key they would need.
Some coins mined in Bitcoin’s early years are held in P2PK outputs. Taproot also makes the public key visible immediately, although it offers privacy benefits and more flexible spending rules. A newer address format therefore does not necessarily hide the public key, and the bc1q prefix alone cannot distinguish P2WPKH from P2WSH.
In a post published on April 24, 2026, Project Eleven estimated that approximately 6.9 million BTC were held with the public keys used to verify their transfers already visible on the blockchain.
Why Bitcoin wallets create new change addresses
In Ethereum, funds arrive in an account and are spent from it. For an ordinary account controlled by a private key, the first transaction it sends already allows the public key to be recovered from the signature. Moving to a different address means transferring assets and separately managing funds and approvals in DeFi services, so users often keep their existing address.
In Bitcoin, your balance consists of separate amounts received in earlier transactions that have not yet been spent. These are called UTXOs, or unspent transaction outputs. Suppose you received 5 BTC in a single payment and want to send 1 BTC. Your wallet uses that entire amount: 1 BTC goes to the recipient, while slightly less than 4 BTC comes back to you as change because part of the amount pays the fee.
Your wallet can send the change to a new address with a different public key. If it is a P2WPKH address and the key has not been disclosed elsewhere, that key will not yet be visible on the blockchain. This avoids leaving change at the old address you have already spent from.
A new change address does not by itself protect against a quantum attack: Taproot makes the public key visible immediately. If your wallet returns change to an old address you have already spent from, that address’s public key will also be known. Check your account type and change address format in the app, even if you use a Ledger, Trezor, Keystone or BitBox hardware wallet. For example, Trezor Suite generates change addresses automatically, but their format depends on the selected account.
How to check your wallet addresses
For an initial check, you can use quantumrekt.com, which assesses an address using its type and public blockchain data. It only needs the public address: do not enter your seed phrase or private key, connect your wallet or sign messages for this check.
Your wallet may have many addresses, including separate change addresses. Check every address holding coins, because a result for one address does not show the status of the others.
For P2WSH and wallets requiring multiple signatures, known as multisig wallets, check the transfer rules in your app or explorer: quantumrekt.com does not support all these addresses. A multisig transfer requires several signatures, so check which public keys the wallet uses and whether others can access them.
A “Total sent” value of zero does not mean the public key is hidden. Taproot and P2PK make it visible even before any coins are sent. You may also have shared an xpub with a third-party service: an extended public key that lets someone calculate the public keys of many addresses within an account.
If you have shared your xpub with a service or published it, take that into account. Even if a public key is not yet visible on the blockchain, someone with the xpub can calculate it. You do not need an xpub to check an individual address.
Are Solana, XRP and Cardano vulnerable to quantum attacks?
Solana, XRP Ledger and Cardano use somewhat different ways to sign transactions, but they rely on mathematical problems that Shor’s algorithm can also solve. As a result, differences between their current signatures do not make these networks quantum-resistant. They also need post-quantum cryptography: protection designed to withstand quantum computers.
On April 27, 2026, the Solana Foundation reported that Anza and Firedancer had independently researched post-quantum signatures and chosen Falcon for their initial implementations. Falcon is a signature scheme designed to withstand quantum attacks. NIST, the US National Institute of Standards and Technology, selected it for standardization, though the final standard is still being developed. Solana’s plan includes further research and preparing wallets for new signatures if advances in quantum computing make a transition necessary.
The ecosystem also includes Blueshift’s Winternitz Vault, which uses another signing method designed to withstand quantum attacks. Google cited it as an existing example, but it is a separate vault whose protection does not automatically extend to an ordinary Solana wallet.
On Solana, an ordinary account’s address is already its public key, so an attacker does not need to wait for the first transfer to obtain it. Some Bitcoin address formats hide the public key until coins are sent. Despite this difference, both networks need signatures that can withstand quantum computers.
Q-Day and preparing for the quantum threat
Q-Day is the name given to the point when a quantum computer can break widely used forms of cryptographic protection, including digital signatures, in practice. The date is unknown; the frequently cited years 2029 and 2035 concern preparations for that threat:
These dates do not predict when attackers could steal coins using quantum computers. With a slower computer, an attacker could start with addresses whose public keys have long been visible on the blockchain. With fast enough hardware, they could also intercept coins during a transfer, so both forms of theft could become possible at roughly the same time.
In April 2026, Project Eleven awarded the Q-Day Prize to Giancarlo Lelli for recovering a private key on a publicly accessible quantum computer. The experiment used a much simpler 15-bit problem, whereas Bitcoin uses 256-bit keys. It demonstrates the method on a small example, but does not show that existing hardware can recover a Bitcoin private key this way.
Four steps to help keep your coins safer
Changes to Bitcoin’s rules depend on its developers and network participants. You can check the addresses holding your coins, review your wallet settings and watch for updates that support new signature methods.
Step 1. Check the addresses holding your coins
Identify each address type and check whether you have sent funds from it before. Taproot and P2PK make the public key visible immediately; P2PKH and P2WPKH reveal it on the blockchain when coins are sent. Also consider whether you have shared your xpub. Focus on addresses that still hold funds: there is nothing to move from an old, empty address.
Step 2. Move coins to a new address if needed
If the public key for an address holding your coins is already available to others, you can move the funds to a new address that hides a different public key. The old key could then no longer be used to prepare an attack on those coins. For an ordinary single-signature wallet, a new Native SegWit P2WPKH address beginning with bc1q is suitable. Check the account type in your app, because P2WSH addresses also start with bc1q.
If you have shared your xpub, a new address in the same account may not be enough: its public key can also be calculated from that xpub. One way to avoid this is to move the coins to a new wallet with a new seed phrase generated independently of the old one. A different account under the same seed phrase may help only if the shared xpub cannot reveal its public keys; verify that separately. Follow the manufacturer’s instructions when creating a wallet, and check your current backup before resetting the device. Our guide to storing a seed phrase safely explains how to protect that backup. You do not need to enter your seed phrase on a third-party website.
Verify the new address on your hardware wallet’s screen and allow for the transaction fee. Once the coins reach an address with a different public key, the old private key can no longer spend them. However, sending the coins again will reveal the new public key too, so changing addresses does not replace the network’s transition to post-quantum signatures. Taproot makes the public key visible even before a transfer.
Step 3. Follow changes to the Bitcoin protocol
A BIP is a proposal to change how Bitcoin works. BIP-360 describes a new format, Pay-to-Merkle-Root, or P2MR, which would not record a public key on the blockchain when coins are received, unlike Taproot. It would store a hash representing the spending rules instead. The proposed addresses would start with bc1z.
Without the public key, an attacker cannot use it to calculate the private key. P2MR is intended to let coins be held without publishing the public key on the blockchain. It does not add post-quantum signatures, however: once that key appears in a transaction, an attacker with a fast quantum computer could still try to intercept the coins.
A separate proposal, BIP-361, considers a transition to post-quantum protection and restrictions on current transaction-signing methods. Both documents are drafts. Publishing or testing a proposal does not mean Bitcoin already operates under the new rules; users should follow adopted network upgrades and their support in their wallets.
Step 4. Check your wallet settings and device security
Check whether your wallet creates a new change address after a transfer and what format it uses. The hardware wallet itself helps keep private keys safe from malware on your computer or phone. It cannot change how Bitcoin transactions are signed; that requires a network upgrade. Our article on how hardware wallets work explains device security in more detail.
For example, Trezor Safe 7 uses post-quantum signatures to verify genuine firmware, protect the device’s startup process and confirm that the wallet itself is authentic. The “quantum-ready” label refers to device security; it does not change Bitcoin transaction signatures. Whether the wallet can support future signing methods through an update depends on their requirements and the device’s capabilities. Our Trezor Safe 7 review explains these protections in more detail. If you are choosing a wallet, compare supported networks, phone compatibility and transaction verification in our hardware wallet buying guide.
What you can do to protect your coins
Start with the addresses holding your coins: check their types and whether you have sent funds from them before. After a transfer, retire the address for new payments and choose a change address format that hides the public key. If coins remain at an old address, consider moving them to a new P2WPKH address, following the rules above. Also account for any xpub you have shared; in that case, a new address alone may not be enough.
A hardware wallet cannot protect the coins if an attacker can calculate the private key from the public key. As long as an address’s public key is unknown to others, they cannot use it to prepare this attack in advance. Sending coins removes that advantage, so protecting transfers will require the network to adopt post-quantum signatures; the timing remains undecided.
Related Posts
Who is Satoshi Nakamoto? What we know about him in 2026
On April 8, 2026, The New York Times published a 12,000-word investigation by John Carreyrou, the journalist who once buried Theranos. The conclusion: the real Satoshi Nakamoto is Adam Back, CEO of Blockstream and a British cryptographer. Carreyrou says his confidence is “between 99.5% and 100%”. Back responded with a post on X: “I am …