Author: Boaz Sobrado
Compile: Deep潮 TechFlow
Deep潮 Overview: How far are we from quantum computing truly breaking Bitcoin? This article breaks down the "$470 billion quantum race" clearly: which cryptocurrencies are already at risk, why "exposed" does not mean "stolen," the timelines provided by Google and the Ethereum Foundation, and the heated debate surrounding BIP-360 and BIP-361 on freezing dormant coins. Even more intriguing is the early move by startups—American Fortress claims "quantum resistance without address migration," yet its paper remains unpublished and its design unaudited. Is this cold fusion or just another crypto narrative? The article offers a cautious assessment.
"That's the end of Bitcoin"—a $470 billion quantum race
A quantum computer could potentially break the cryptography securing millions of bitcoins. This article delves into the "frozen controversy," the $470 billion at risk, and the startups racing to fix this vulnerability.
"I believe Bitcoin will come to an end in four years," said David McAlvany, CEO of Gold App Vaulted, on the On The Margin podcast. "Within four years, we’ll have quantum computing, and that will be the end of Bitcoin. You’ll be able to solve all the mathematical problems instantly."
"I don't know if it's four years, five years, or even two months from now," he added. As of mid-2026, machines capable of achieving this do not yet exist. But now, this threat has a specific timeline.
Attackers became aware of this before the security team did.
“It’s unfortunate that the attackers realized this before the infrastructure team or the security team did,” said Ido Sofer, founder of key management company Sodot, on the On The Margin podcast. “We’re always the first to face entirely new attack vectors.”
In March 2026, Galaxy Digital estimated that approximately 7 million bitcoins are located in addresses whose public keys have been exposed on-chain, valued at around $470 billion. Glassnode’s figure is 6.04 million bitcoins, representing 30.2% of the supply. Both figures are estimates, not protocol-level statistics; Galaxy describes this risk as "real but far from an existential crisis." These exposed coins include those from the Satoshi era, addresses that leaked their original public keys, and any addresses reused after their first spend. Exposure does not equal theft. Theft would only occur if a machine could reverse-engineer the underlying mathematical problem—and no such machine currently exists.
Bring your own lock
"When you're on Bitcoin, Ethereum, or Solana, right now you're locked into just one of the locks they allow you to use," said Yoon Auh, CEO of BOLTS Technologies, on a podcast. "As you see advancements in quantum computing, these locks could be broken—and that's exactly what they fear."
These locks appear to be growing more fragile each year. In May 2025, Google researcher Craig Gidney demonstrated that breaking RSA-2048 could require fewer than one million qubits—twenty times fewer than his own 2019 estimate. A Google white paper in April 2026 reduced the estimated qubit count needed to break Bitcoin’s elliptic curve cryptography to under 500,000. Ethereum Foundation researcher Justin Drake estimates that by 2032, quantum computers will have about a 10% chance of deriving Bitcoin private keys from exposed public keys. In April 2026, a researcher pursuing Project Eleven’s “Q-Day Prize” successfully broke a 15-bit key on real quantum hardware. While the actual keys are 256 bits—making this merely a toy experiment—it’s worth noting that just a year earlier, this toy wouldn’t have worked at all.
Auh’s solution is to return the choice of cryptography to users, rather than leaving it to the chain. “Bring your own lock, choose your own lock,” he says. BOLTS has demonstrated its per-transaction cryptographic scheme to NIST’s post-quantum cryptographers and ran a quantum-resistant pilot on the Canton Network in December 2025. NIST finalized its first three post-quantum standards in August 2024.
Bitcoin developers themselves are divided on how to address the split. A draft BIP-360 proposed by Hunter Beast introduces a new quantum-resistant address type. Another BIP-361, proposed by Jameson Lopp and five co-authors, is chilling: it would phase out old-style signatures in two stages, rendering any coins that never migrate—including those believed to belong to Satoshi—unspendable. Supporters argue that freezing dormant coins is preferable to letting future quantum thieves drain them and flood the market. Critics call it confiscation. Algorand has been using the quantum-resistant Falcon signature to sign its state proofs since 2022; Quantum Resistant Ledger and publicly traded BTQ are tackling the same issue from different angles.
Like discovering cold fusion
Among these players is American Fortress—a company based in Austin that completed an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. Formerly known as MatterFi, the company claims to offer "quantum-resistant coverage across all chains, with no need for users to migrate any addresses," paired with a backward-compatible Bitcoin soft fork designed to automatically freeze vulnerable dormant wallets before attackers can exploit them. Its founder, Michal "Mehow" Pospieszalski, is unapologetically bold: "This quantum work is so good I can't even give it away," he said on the On The Margin podcast, referring to the technology, "it's like discovering cold fusion."
These claims warrant careful scrutiny. "This algorithm is not new," says Pospieszalski. "People have long suggested generating additional proofs around existing addresses. But it was too slow and was abandoned. We’ve made it 100 times faster on a standard PC." American Fortress has filed a patent for a post-quantum transaction signature, but the filing only establishes priority, not proof; its technical paper has not been published, and the design has not undergone public audit. The company has deployed a test version on Arbitrum, and a partner manager at Offchain Labs has been quoted expressing support—however, this is merely a deployment, not formal cryptographic validation. "Post-quantum security is not a feature of the future—it’s a necessity today," said Michael Heinrich, CEO of 0G Labs, in a funding announcement.
Privacy is not anonymity
Quantum work is only half the selling point. The other half is a compliance and privacy layer built on the same premise: cryptocurrency has never truly proven who paid whom. "If I send you money, you’ll receive a cryptographic proof that it genuinely came from my private key," says Pospieszalski. "That was completely impossible before." He points to "address poisoning"—scammers flood victims’ transaction histories with addresses that look nearly identical; in May 2024, one such attack laundered $68 million in wrapped Bitcoin, though the funds were later recovered. His solution is to attach proof of origin to every transaction and allow users to disclose their identity only when they choose to. "We don’t require you to hold an ID to use the system," he says. "Like ENS, but private."
Whether a built-in compliant privacy layer is self-consistent is precisely the issue others in the industry are grappling with. "I’ve always viewed privacy and anonymity as completely different things," said Varun Kabra, Chief Growth Officer at Concordium, on the On The Margin podcast. Concordium embeds identity on-chain using zero-knowledge proofs, so "because of selective disclosure and zero-knowledge proofs, no one knows it’s you." That’s the same bet American Fortress has made. Kabra’s characterization of the compliance line is identical: "You control what you choose to disclose and to whom, but you’re bound by the law," he said. "No one should be above the law."
You cannot prove it.
Pospieszalski believes that systems should be able to prove their honesty before the advent of cryptocurrency. This self-described white-hat hacker, formerly the Chief Technology Officer of the Election Science Institute, analyzed ES&S’s iVotronic voting machines around 2006 and warned that they lacked cryptographic means to verify whether a ballot had been counted once, not more, not less. "As a counter, you cannot prove to me that your count of my ballot was accurate—neither duplicated nor omitted," he said, "You cannot prove it." Later, he conducted forensic work for the plaintiffs in the controversial 2020 election case in Antrim County, Michigan. According to his own account, the anomalies there traced back to a misconfigured ballot definition file—a finding consistent with the administrative explanation accepted by a bipartisan manual audit and all courts that reviewed the case; no fraud was ever substantiated before the case was dismissed.
None of the current funding-backed solutions address the deeper concerns that long-term holders truly care about. McAlvany, whose business is selling gold, asks whether Bitcoin can survive for 5,000 years. "Gold, I’m confident will endure," he says, "but Bitcoin may not."

