Forbes Special Report: 7 Million Bitcoins Exposed to Quantum Computing Risks, Does BTC Need a New "Lock"?

CN
1 hour ago
Bear market Fud classic material.

Author: Boaz Sobrado

Translation: Shenchao TechFlow

Shenchao Introduction: How far is quantum computing from truly cracking Bitcoin? This article breaks down the "$470 billion quantum race": which coins are already exposed to risks, why "exposure ≠ theft," the timeline given by Google and the Ethereum Foundation, and the intense disagreements over BIP-360 / BIP-361 regarding the freezing of dormant coins. More intriguingly is the head start of startups—American Fortress claims "no need to migrate addresses to be quantum-resistant," but its paper is unpublished, and its design is unaudited; is it cold fusion or just another crypto narrative? The article offers a cautious judgment.

"That’s the end of Bitcoin"—The $470 billion quantum race

A quantum computer might be able to crack the cryptography protecting millions of Bitcoins. This article delves into the "freezing controversy," the $470 billion at risk, and the startups striving to fix this vulnerability.

"I believe Bitcoin will end in four years," said David McAlvany, CEO of Gold App Vaulted, in the On The Margin podcast. "In four years, we will have quantum computing, and that will be the end of Bitcoin. You could instantly solve all mathematical problems."

"I don’t know if that’s four years from now, five years from now, or two months from now," he added. As of mid-2026, machines capable of this do not yet exist. But now this threat has a specific timeline.

Attackers realized this sooner than security teams

"Somewhat unfortunately, attackers realized this sooner than infrastructure teams and security teams," said Ido Sofer, founder of key management company Sodot, in the On The Margin podcast. "We are always the first to face new attack vectors."

Galaxy Digital estimated in March 2026 that about 7 million Bitcoins are located at addresses that have exposed public keys, worth approximately $470 billion. The figures provided by Glassnode are 6.04 million, accounting for 30.2% of the supply. Both are estimates and not protocol-level statistics; Galaxy describes this risk as "real but far from a survival-level crisis." The exposed coins include addresses from the Satoshi era that leaked original public keys, and any addresses reused after their first spending. Exposure does not equal theft. Only when a machine can reverse-engineer this mathematical problem will it become theft—and such machines do not currently exist.

Bring your own lock

"When you are on Bitcoin, Ethereum, or Solana, you are currently locked into the kind of lock they allow you to use, just one kind," said Yoon Auh, CEO of BOLTS Technologies, in the podcast. "When you see advancements in quantum computing, these locks could be broken, and that's what they fear."

These locks seem to be becoming more vulnerable each year. Google researcher Craig Gidney proved in May 2025 that breaking RSA-2048 might require less than 1 million qubits, reducing his own estimate from 2019 by twenty-fold. A Google white paper in April 2026 reduced the qubit requirement to crack Bitcoin’s elliptic curve cryptography to below 500,000. Ethereum Foundation researcher Justin Drake estimated that by 2032, the probability of a quantum computer recovering Bitcoin private keys from exposed public keys would be approximately 10%. In April 2026, a researcher chasing the Project Eleven "Q-Day Prize" cracked a 15-bit key on real quantum hardware. The actual key is 256 bits, so this is just a toy—but a year ago, this toy was completely non-functional.

Auh’s solution is to return the choice of cryptography to the users, rather than letting it rest on the chain. "Bring your own lock, choose your own lock," he said. BOLTS has demonstrated its per-transaction cryptographic scheme to NIST’s post-quantum cryptographers and ran a quantum resilience pilot on the Canton Network in December 2025. NIST finalized the first three post-quantum standards in August 2024.

Bitcoin developers themselves are divided on how to respond. A draft BIP-360 proposed by Hunter Beast would introduce a new type of quantum-resistant address. Another BIP-361 proposed by Jameson Lopp and five co-authors is chilling: it would phase out old-style signatures in two stages, rendering any coins that have never migrated (including those believed to belong to Satoshi) unspendable. Supporters argue that freezing dormant coins is better than allowing future quantum thieves to drain them and dump them on the market. Critics call it confiscation. Algorand has used quantum-resistant Falcon signatures to sign its state proofs since 2022; Quantum Resistant Ledger and publicly traded company BTQ are pursuing the same issue from different angles.

Like discovering cold fusion

Among these players is American Fortress—a company based in Austin that completed an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. The company, formerly known as MatterFi, claims to provide "quantum resistance across all chains with no need for users to migrate any addresses," paired with a backward-compatible Bitcoin soft fork proposal aimed at automatically freezing vulnerable dormant wallets before attackers can act. Its founder, Michal "Mehow" Pospieszalski, is not modest: "This quantum work is so good that I can’t give it away," he said while discussing this quantum work on the On The Margin podcast, "it’s like discovering cold fusion."

Such claims deserve cautious consideration. "This algorithm is not news," Pospieszalski said. "People have long suggested that additional proofs can be generated around existing addresses. But it was so slow that it was abandoned. We’ve improved its speed by 100 times on a regular PC." American Fortress has patented a post-quantum trading signature, but the application only establishes priority, not proof; their technical paper has not yet been published, and its design has not been publicly audited. The company has deployed a test version on Arbitrum, and a partner manager from Offchain Labs was quoted expressing support—but that was just a deployment, not a formal endorsement of the cryptography. "Post-quantum security is not a future feature, but a current necessity," said Michael Heinrich, CEO of 0G Labs, in the fundraising announcement.

Privacy is not anonymity

Quantum work is just half of its selling point. The other half is a compliance and privacy layer built on the same argument: cryptocurrencies have never truly proven who paid whom. "If I send you money, you get a cryptographic proof that indeed comes from my private key," Pospieszalski said, "which was completely impossible before." He pointed to "address poisoning"—scammers filling victims’ transaction histories with addresses that look very similar; in May 2024, one such attack washed away $68 million worth of wrapped Bitcoin, though the funds were later recovered. His fix is to attach provenance proofs to each transaction and let users disclose their identity only when they choose. "We don’t require you to hold ID to use the system," he said, "just like ENS, only private."

Whether a built-in compliance privacy layer is coherent is precisely the question others in the industry are grappling with. "I always view privacy and anonymity as completely different things," said Varun Kabra, Chief Growth Officer of Concordium, in the On The Margin podcast. Concordium uses zero-knowledge proofs to embed identity on-chain, so "because there is selective disclosure and zero-knowledge proofs, no one knows it’s you." That’s exactly the same bet American Fortress is placing. Kabra’s articulation of compliance lines echoes: "You control what you want to disclose, to whom you disclose it, but you are bound by the law," he said. "No one should be above the law."

You cannot prove

Pospieszalski believes the system should be able to prove its own honesty, predating cryptocurrency. This self-described white-hat hacker, who was the Chief Technology Officer of the Election Science Institute, analyzed ES&S’s iVotronic voting machines around 2006 and warned that they had no cryptographic means to confirm whether a ballot was counted once. "As a counter, you can't prove to me that you counted my vote, without duplicates or omissions," he said, "you cannot prove." Later, in the disputed election case in Antrim County, Michigan in 2020, he worked as an expert for the plaintiffs. According to him, the anomalies there could be traced back to a misconfigured ballot definition file—which is consistent with a bipartisan manual audit’s findings that were accepted by all courts handling the case; no fraud was proved before the case was dismissed.

None of these funded solutions address the deeper concerns of a long-term holder. McAlvany’s business is selling gold, and he asks whether Bitcoin can exist for 5,000 years. "Gold, I am sure will persist," he said, "but Bitcoin may not."

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink