Every few months a government cybersecurity document lands, crypto commentators read the word "encryption," and Bitcoin's obituary gets drafted again. The G7's post-quantum warnings are the latest case — and the primary documents say something narrower, and more useful, than the headlines they produced.
Does the G7's quantum warning actually apply to Bitcoin?
No — not directly. The G7 Cyber Security Working Group's Preparing for the Post-Quantum Era: A Call to Action, published 3 September 2026 , is a general-purpose cryptography document aimed at governments and regulated institutions. It names five priorities and mentions cryptocurrency, blockchain or digital assets zero times. The Bitcoin connection is an inference made by commentators, not a G7 finding.
Quick Answer: The G7's post-quantum documents warn the regulated financial sector, not crypto specifically. The September 2026 "Call to Action" and the January 2026 Cyber Expert Group roadmap contain no reference to Bitcoin, blockchain or digital assets, and set 2035 as the outside migration target — with critical systems addressed around 2030–2032.
The September document was co-released by the UK's NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO and Italy's ACN, with support from the European Commission and ENISA — roughly eight pages of national-strategy guidance rather than a technical assessment of any particular ledger . Its five priorities are the same five that appear in most national PQC playbooks:
- Awareness — make leadership understand quantum risk as a governance issue, not an IT footnote.
- National strategy — publish country-level migration timelines and align them across borders.
- Research and development — sustain work on post-quantum algorithms and implementation testing.
- Public-private partnership — coordinate between regulators, vendors and critical infrastructure operators.
- Procurement — require cryptographic agility in new purchases so migration rides existing refresh cycles.
The threat model the G7 names is also specific, and it is not "someone steals your Bitcoin." The June 2026 migration statement, jointly published by CSE, BSI, ACN, ANSSI, CISA, NCSC/DSIT and Japan's NCO with the European Commission, defines harvest now, decrypt later (HNDL) as "a scenario, where adversaries store encrypted data for decryption once a cryptographically relevant quantum computer emerges" . That is a data-confidentiality problem — intercepted traffic, archived records, stored contracts. The second named risk is authentication: forged signatures on digitally signed agreements once the underlying math is breakable. Bitcoin's exposure sits in that second category, and it arrives through a different door than HNDL, because a public blockchain publishes its signatures rather than encrypting anything.
The financial-sector document most often cited as "the G7 quantum warning" is separate again: the G7 Cyber Expert Group statement on a coordinated post-quantum roadmap, released January 2026 through the U.S. Treasury and mirrored by the Bundesbank and the UK government . The CEG has coordinated G7 cyber policy since 2015 and is co-chaired by U.S. Treasury Deputy Assistant Secretary Cory Wilson and Bank of England Executive Director Duncan Mackinnon . Treasury's framing sets the tone:
"The introduction of quantum computers that can break our encryption tools presents a significant risk to the safety and soundness of our financial ecosystem." — G7 Cyber Expert Group statement, U.S. Department of the Treasury, January 2026 (source: Treasury, 2026-01)
The operational advice across all three documents is consistent and unglamorous: build a cryptographic inventory first — know which algorithms run where, in which systems, from which suppliers — then fold quantum-safe upgrades into refresh cycles that were already budgeted . The G7 explicitly frames this as a slow-moving migration rather than an emergency patch, noting that "unlike some cyber security threats which require rapid changes that can be disruptive and expensive, an advantage of PQC migration is its relatively long timeframe for implementation" . For a bank, that inventory step is actionable this quarter. For a Bitcoin holder, the equivalent step depends on protocol changes that do not yet exist — which is where the rest of this guide goes.
Three separate G7 quantum work streams — and crypto Twitter conflated all of them
There is no single "G7 quantum warning." Three distinct documents, produced by three different bodies on three different dates, circulated as one headline: a June 2026 migration statement from the G7 Cybersecurity Working Group, a January 2026 financial-sector roadmap from the G7 Cyber Expert Group, and a 3 September 2026 call to action from the G7 Cybersecurity Working Group . They differ in audience, authority, and how binding they are — and conflating them is what turned a procurement timeline into a Bitcoin emergency.
The June 2026 migration statement is the operational one. Published 1 June 2026 jointly by Canada's CSE, Germany's BSI, Italy's ACN, France's ANSSI, U.S. CISA, the UK's NCSC and DSIT, and Japan's NCO, in collaboration with the European Commission , it defines the vocabulary everyone else borrowed. A cryptographically relevant quantum computer (CRQC) is the machine capable of breaking today's public-key cryptography. Harvest-now-decrypt-later (HNDL) is defined in the text as "a scenario, where adversaries store encrypted data for decryption once a cryptographically relevant quantum computer emerges" . Crypto-agility — designing systems so cryptographic primitives can be swapped without re-architecting — is the recommended end state. Private-sector migration is projected to complete "during the 2030s," with dates varying by country .
The January 2026 Cyber Expert Group roadmap is narrower and aimed squarely at regulated finance. Released by the U.S. Treasury and mirrored by the Deutsche Bundesbank and the UK government , it is co-chaired by U.S. Treasury Deputy Assistant Secretary Cory Wilson and Bank of England Executive Director Duncan Mackinnon . Critically, it sets no guidance and no regulatory expectations; it is explicitly not prescriptive, framed instead as informing a "timely, secure, and harmonized transition" . The CEG itself dates to 2015 and coordinates cyber policy across Canada, France, Germany, Italy, Japan, the UK and the US, with the EU participating through three institutions .
The 3 September 2026 call to action, Preparing for the Post-Quantum Era, is the one behind the current news cycle. Its substantive position is modest: the exact CRQC timeline remains uncertain, and organizations should begin their PQC transition "as soon as possible" .
| Document | Date | Issuing body | Audience | Binding force |
|---|---|---|---|---|
| PQC migration statement | 1 June 2026 | G7 Cybersecurity Working Group (CSE, BSI, ACN, ANSSI, CISA, NCSC/DSIT, NCO + European Commission) | All organizations, public and private | Advisory; migration "during the 2030s" |
| Coordinated PQC roadmap | January 2026 | G7 Cyber Expert Group (co-chaired U.S. Treasury / Bank of England) | Financial sector institutions | Explicitly not prescriptive; no regulatory expectations |
| Preparing for the Post-Quantum Era: A Call to Action | 3 September 2026 | G7 Cybersecurity Working Group | General; awareness-level | Advisory; "as soon as possible" |
| Preparing for Quantum Technologies (reference report) | Announced June 2026 (file dated 13 May 2026) | G7 central banks' Quantum Technologies Working Group (Banque de France / Bank of Canada) | Financial sector participants | Reference material, ~20 pages |
A fourth strand adds to the noise. The G7 central banks' Quantum Technologies Working Group, established in 2025 and co-chaired by the Banque de France and the Bank of Canada, published its first reference report — roughly 20 pages, hosted by the Bundesbank with a 13 May 2026 file date and announced by the Bank of Canada in June 2026 . Bank of Canada Governor Tiff Macklem's line from that release — "With continuing advances in quantum computing, the window to being quantum-ready is narrowing" — was widely quoted alongside September's call to action, three months after it was actually said.
The point that survives all four: on every first-party G7 page readable in full, there is no mention of Bitcoin, cryptocurrency, crypto-assets, blockchain or distributed ledger technology. The scope is cryptographic infrastructure across banks, insurers, exchanges, payment protocols and vendor supply chains. One caveat is worth stating plainly — the CEG roadmap PDF itself returned as compressed binary from both the Treasury and UK mirrors , so an in-document reference to digital assets cannot be ruled out from the readable text alone. The read-through to Bitcoin is an inference drawn by commentators. It may still be a reasonable inference — the next section tests how reasonable — but it is not a G7 statement.
How close is a Bitcoin-breaking quantum computer, really?
No quantum computer capable of breaking Bitcoin's signatures exists today, and none has been publicly demonstrated. What changed in 2026 is the estimated cost of building one. Google Quantum AI's 31 March 2026 cryptocurrency paper estimates that solving the 256-bit elliptic-curve discrete logarithm problem over secp256k1 — the assumption Bitcoin ownership rests on — could require no more than 1,200 logical qubits and 90 million Toffoli gates, or alternatively no more than 1,450 logical qubits and 70 million Toffoli gates . Under the paper's stated superconducting assumptions, the computation runs in minutes with fewer than 500,000 physical qubits.
Three qualifiers keep that number in proportion. First, a logical qubit is not a physical qubit: it is an error-corrected abstraction assembled from many noisy physical qubits, and the ratio depends entirely on the error-correction architecture and physical error rates assumed. Google's own framing — fewer than 500,000 physical qubits for roughly 1,200 logical ones — implies a multiplier in the hundreds, and a different code or a worse error rate moves that figure by orders of magnitude. Second, this is a resource estimate, a floor on attack cost derived from circuit analysis, not an announcement of a working machine. Third, Google deliberately did not publish the attack circuits. It used a zero-knowledge proof to disclose the resource estimate while withholding the construction, and paired the release with a warning that unsubstantiated capability claims generate market-damaging noise around cryptocurrency .
That restraint sits oddly next to the timelines circulating in Bitcoin's own standards process. BIP-361, the draft Post Quantum Migration and Legacy Signature Sunset proposal assigned 11 February 2026 and last updated 8 September 2026, cites McKinsey research placing a cryptographically relevant quantum computer (CRQC) as early as 2027–2030 . That is a proposal-sourced citation used to justify a migration schedule, not an independent forecast, and it sits at the aggressive end of the published range.
Official bodies are markedly less specific. The G7 Cybersecurity Working Group's 3 September 2026 paper, Preparing for the Post-Quantum Era: A Call to Action, states that the exact CRQC timeline remains uncertain while advising organizations to begin transitioning "as soon as possible" . NIST, which approved FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) on 13 August 2024, plans deprecation and removal of quantum-vulnerable algorithms by 2035, with high-risk systems moved earlier . Neither institution names a break date; both name a migration date.
"With continuing advances in quantum computing, the window to being quantum-ready is narrowing," — Tiff Macklem, Governor, Bank of Canada, announcing the G7 central banks' Quantum Technologies Working Group report (source: Bank of Canada, 2026-06).
Read together, the useful framing is a spread, not a date. Institutional planning targets cluster on 2030–2032 for the most critical systems and 2035 for broad migration . The aggressive private-sector end reaches back to 2027. Google's contribution narrows the engineering gap between "theoretically possible" and "expensively buildable" without closing it. For a Bitcoin holder, that spread matters less than a structural fact the next section takes up: exposure is not uniform across the chain, so the question of when is inseparable from the question of which coins.
Which Bitcoin addresses are already quantum-exposed?
A Bitcoin address is quantum-exposed once its public key has appeared on-chain, because Shor's algorithm attacks the key, not the address hash. BIP-360 splits exposure into two classes, and roughly a third of circulating supply sits in the exposed bucket: BIP-361 records that over 34% of all bitcoin had revealed a public key on-chain as of 1 March 2026 .
The taxonomy in BIP-360 — the Pay-to-Merkle-Root draft, version 0.12.1, requiring BIPs 340, 341 and 342 — is the cleanest way to sort your own coins :
- Long exposure (key visible by design, indefinitely): P2PK and multisig outputs that carry raw public keys, Taproot P2TR outputs whose 32-byte x-only key is the output itself, and any address that has already been spent from and then reused. An attacker with historical chain data and unlimited time can work on these offline .
- Short exposure (key hidden until you spend): P2PKH, P2SH, P2WPKH and P2WSH outputs commit only to a hash. The public key is revealed at spend time, so the attack window is the seconds-to-minutes a transaction sits in the mempool. BIP-360 states plainly that P2MR mitigates long-exposure attacks only, and that full protection against short-exposure attacks may require post-quantum signatures in Bitcoin itself .
- Leakage outside the chain: extended public keys (xpubs) and wallet descriptors can hand over quantum-vulnerable public-key information for an entire account tree without a single on-chain spend .
Taproot deserves a flag here, because it inverts the intuition many holders carry. Modern usually means safer; in this case, BIP-340 Schnorr outputs publish the 32-byte x-only public key directly, with security explicitly resting on the hardness of the elliptic-curve discrete logarithm problem . That is exactly the assumption Shor's algorithm targets. A 2013-era P2PKH address that has never been spent from is, on this one axis, in a better position than a freshly funded P2TR address.
The headline percentages vary by scan, and the spread is methodology rather than disagreement about the chain. A ChainQuery snapshot at block 960,681 (2 August 2026) counted 7,052,314 BTC exposed against 20,081,095 BTC circulating — about 35.1% — split into 1,934,419 BTC in always-exposed output types and 5,117,895 BTC exposed through address reuse. A competing full-chain walk posted to Bitcointalk in June 2026, at block 952,694, reported 5,071,264 BTC or 25.3%, rising to roughly 34.55% once broader counting of spent P2SH and P2WSH scripts was applied. Neither figure is a consensus metric; BIP-361's own number is described as proposal-sourced and methodology-dependent . Treat the ten-point gap as the honest error bar around "about a third."
The distribution inside that third is the part worth acting on. Only about 1.9 million BTC sits in the always-exposed legacy bucket — the Satoshi-era P2PK coins that dominate the folklore. The larger share, over five million BTC, is exposed because a key was revealed by spending and the address kept receiving. That is not an archaeological problem. It is produced by exchanges, payment processors, mining pools and individuals who publish one deposit address and reuse it, and it grows every block. Address reuse is a live operational habit among active users and custodians, which also means it is the one exposure category holders can reduce today without waiting on a consensus change.
BIP-360 vs BIP-361: what Bitcoin developers actually propose
Bitcoin's two post-quantum proposals do different jobs: BIP-360 creates a quantum-hardened place to put coins, and BIP-361 proposes forcing everyone to move there. BIP-360, Pay-to-Merkle-Root (P2MR), was assigned 18 December 2024 and is authored by Hunter Beast, Ethan Heilman and Isabel Foxen Duke; it sits at version 0.12.1 with status Draft and requires BIPs 340, 341 and 342 . Structurally it is Taproot with the quantum-vulnerable key-path spend removed, deployable as a soft fork on SegWit witness version 2. Neither proposal is active on mainnet.
What P2MR does not do is the part most summaries skip. BIP-360 distinguishes long-exposure attacks — where an attacker holds historical chain data and unlimited time to derive a private key from a published public key — from short-exposure "on-spend" attacks, where the key is visible only while a transaction sits in the mempool. P2MR mitigates the former. BIP-360 itself concedes that full protection against short-exposure attacks may require post-quantum signatures in Bitcoin . The actual PQ signature algorithms — ML-DSA and SLH-DSA — were deliberately deferred to a companion BIP rather than bundled in.
The document was merged into the bitcoin/bips repository on 11 February 2026 via PR #1670, carrying 139 commits . Merged is not activated. A merge signals only that the document meets BIP editorial standards for formal discussion — it implies no consensus, no signalling period and no deployment schedule.
BIP-361, Post Quantum Migration and Legacy Signature Sunset, is the enforcement half. Assigned 11 February 2026 and last updated 8 September 2026, it is a draft informational proposal that depends on a still-unspecified "TBD Post Quantum Signature BIP" — meaning it assumes an output type that does not yet exist . Its mechanism is two-phase: Phase A, roughly 160,000 blocks (approximately three years) after activation, disallows sends to quantum-vulnerable addresses; Phase B, two years later, tightens ECDSA and Schnorr spending alongside a quantum-safe rescue protocol .
| Attribute | BIP-360 (P2MR) | BIP-361 (Legacy Sunset) |
|---|---|---|
| Assigned | 2024-12-18 | 2026-02-11 (updated 2026-09-08) |
| Status | Draft, version 0.12.1; merged to bitcoin/bips 2026-02-11 | Draft, informational |
| What it creates | New output type: Taproot minus key-path spend, witness version 2 | No new output type — a migration schedule |
| Dependencies | BIPs 340 / 341 / 342 | "TBD Post Quantum Signature BIP" (unwritten) |
| Threat covered | Long-exposure attacks only | Ongoing ECDSA/Schnorr exposure via sunset |
| Deployment | Soft fork; no activation scheduled | Phase A ~160,000 blocks post-activation; Phase B +2 years |
| Coercive? | Opt-in — holders choose to move | Enforced — non-migrated coins lose spendability |
BIP-361 flags its own consequences rather than hiding them. Wallets that never add support eventually cannot receive funds, because Phase A blocks outputs to vulnerable script types. Dormant legacy coins — including the early P2PK balances widely attributed to Satoshi — become effectively unspendable, since no one is present to migrate them. That is the structural point worth sitting with: lost keys cannot be upgraded by anyone, so some share of exposure is permanent regardless of which proposal wins.
The unresolved question is recovery. BIP-361 proposes a rescue protocol that would let legitimate holders of exposed dormant coins prove ownership without exposing a quantum-vulnerable key — zero-knowledge recovery proofs are the leading suggestion. They are proposed, not built. BIP-361 states plainly that it remains unknown how much legacy supply such a protocol could actually cover . Until that gap closes, the choice sitting in front of Bitcoin is not technical but political: leave vulnerable coins exposed, freeze them, or accept a rescue mechanism that cannot fully distinguish a patient owner from a patient attacker.
Decision framework: how urgent is this for your Bitcoin holdings?
Urgency is not uniform across Bitcoin holders — it is a function of three measurable variables: what address type holds your coins, whether your public-key material is already visible, and how long those coins are likely to sit untouched. BIP-361 reports that more than 34% of all bitcoin had revealed a public key on-chain as of 1 March 2026 , a proposal-sourced and methodology-dependent figure rather than a consensus metric. The practical question is whether your coins sit inside that share, and how many years they will remain there.
Criterion 1 — address type. BIP-360 classifies vulnerability by output type: P2PK and P2TR expose a public key directly in the output, making them long-exposure vulnerable; P2PKH, P2SH, P2WPKH and P2WSH stay unexposed until a spend or script reveals a key; reused addresses become vulnerable after their first spend . If your balance sits on legacy P2PK outputs, multisig scripts that already published keys, or any address you have spent from and then refunded, the exposure clock is already running and no future spend changes that. A never-spent P2WPKH balance is in a different category — the attacker needs your transaction to hit the mempool before the key is visible at all, which BIP-360 calls a short-exposure attack and explicitly notes P2MR does not mitigate .
Criterion 2 — custody model. Self-custody does not automatically mean lower exposure. BIP-360 flags that xpubs and wallet descriptors can leak quantum-vulnerable public-key information — meaning an extended public key pasted into a portfolio tracker, a block explorer watch-only import, or a tax tool can expose the key material for every derived address at once, including addresses that have never transacted. Custodial exposure is the inverse problem: the key hygiene is professional but unauditable from outside. You cannot inspect an exchange's output-type distribution or address-reuse policy, so custodial urgency is a counterparty-diligence question, not an on-chain one. Ledger's June 2026 SDK added ML-KEM and ML-DSA APIs , and Trezor states the Safe 7 uses SLH-DSA-128 for firmware verification and ML-DSA-44 for device attestation while noting full crypto-asset protection still requires blockchain upgrades — device-level hardening is real, but it is not chain-level protection.
Criterion 3 — size and time horizon. The asymmetry here is structural. BIP-361's proposed Phase A runs 160,000 blocks — roughly three years after activation — before sends to quantum-vulnerable addresses would be disallowed, with Phase B arriving two years later . That is a five-year clock that has not started, since nothing is activated. A holder who checks their wallet quarterly will comfortably clear any such window. A holder whose coins sit in cold storage untouched for a decade, on an address type that already published its key, is carrying the full duration of the risk with none of the optionality — and dormant or lost coins cannot be migrated by anyone at all.
- High urgency: large balances on P2PK, P2MS, or reused addresses; xpubs shared with third-party services; holding horizon measured in years, not months.
- Moderate urgency: mixed address types, some spend history, active but infrequent use; audit which UTXOs have revealed keys before doing anything else.
- Low urgency: fresh, never-spent P2WPKH or P2TR outputs, no address reuse, no published descriptors, and a trading cadence that keeps you present for any future migration window.
The user-fit read is counterintuitive: active traders cycling through fresh receive addresses face materially lower long-exposure risk than patient long-term holders. Frequent rotation limits how long any single public key sits published on-chain, and an engaged holder will be available to act when a migration path exists. The higher-risk profile is the disciplined saver on a pre-2013-era address who has not moved coins in a decade — the exact behavior Bitcoin culture has spent fifteen years encouraging.
What to actually do now: a phased migration checklist
The correct first action is an audit of your own address history, not a bet on when a cryptographically relevant quantum computer arrives. Public-key exposure is the variable you control today: BIP-360 classifies P2PK and P2TR outputs as long-exposure vulnerable because a public key sits visible in the output, while P2PKH, P2SH, P2WPKH and P2WSH become vulnerable only once a spend reveals a key — and reused addresses are exposed from the first spend onward . Every item below is executable now, with no protocol change required.
Phase 1 — inventory (do this week). Walk your own outputs and label them by exposure class rather than by wallet nickname:
- Flag any UTXO sitting in a P2PK output or a Taproot key-path output — the public key is already published .
- Flag any address you have spent from more than once; the change balance behind a revealed key is in the same bucket.
- Check where your extended public keys and wallet descriptors have travelled — block explorers, tax tools, watch-only apps. BIP-360 notes that xpubs and descriptors can leak quantum-vulnerable public-key information .
- Separate coins you can move from coins you cannot. Anything on a lost key is permanently unmigratable by anyone, which caps how much of the exposed supply any future fix can cover.
Phase 2 — track, don't trade on it. BIP-360 was merged into the bitcoin/bips repository on 11 February 2026 through PR #1670, carrying 139 commits , and BIP-361 was assigned the same day and last updated 8 September 2026 . Both remain Drafts. BIP-361's phase clock — Phase A at 160,000 blocks, roughly three years, then Phase B two years later — counts from an activation that has not occurred, and the proposal still depends on an unspecified "TBD Post Quantum Signature BIP" . There is nothing to opt into yet. Set a review reminder rather than restructuring holdings around a draft.
Phase 3 — borrow the institutional cadence. The dates regulated finance is already working to are a reasonable personal calendar. NIST approved FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) on 13 August 2024 and advises beginning migration now, with quantum-vulnerable algorithms deprecated and removed by 2035 and high-risk systems handled earlier . The G7 Cyber Expert Group roadmap uses the same shape: 2035 as the outside target, with the most critical systems addressed around 2030–2032 , and the June 2026 G7 migration statement frames completion as occurring "during the 2030s," with dates varying by country . Practically: a 2030 checkpoint for anything you would call critical, 2035 for the rest.
Phase 4 — change your spending habits, not your address type. Moving coins between today's address formats does not make them post-quantum safe, because the chain has no quantum-safe spending path to move them into. What does help is discipline around consolidation: batch consolidations reveal multiple public keys in a single transaction, so treat every consolidation as a permanent exposure decision and never re-send funds back to a key that has already been revealed. Beyond that, keep firmware current and check whether your vendor supports upgradeable primitives — Ledger's June 2026 SDK added ML-KEM and ML-DSA APIs , and Trezor's Safe 7 uses SLH-DSA-128 for firmware verification and ML-DSA-44 for device attestation while stating plainly that full crypto-asset protection still requires blockchain upgrades . Device-level hardening is real and shipping; chain-level protection is not.
What could go wrong: the sunset controversy and open risks
The largest open risk in Bitcoin's quantum debate is not the attack — it is the defense. BIP-361's proposed legacy signature sunset would, by design, make coins sitting in quantum-vulnerable outputs unspendable if their owners never migrate: Phase A at roughly 160,000 blocks (about three years) after activation disallows sends to quantum-vulnerable addresses, and Phase B two years later tightens ECDSA and Schnorr spending behind a quantum-safe rescue protocol . Dormant or lost coins cannot be migrated by anyone, which means a portion of supply — plausibly including Satoshi-era holdings — would be frozen by protocol rule rather than taken by an attacker. BIP-361 itself concedes it remains unknown how much legacy supply a rescue protocol could actually cover .
A second risk is conceptual borrowing. The G7 migration statement defines harvest-now-decrypt-later as "a scenario, where adversaries store encrypted data for decryption once a cryptographically relevant quantum computer emerges" . That model assumes ciphertext at rest. A public blockchain has no ciphertext to decrypt — it has a permanently published public key that a future adversary could forge a signature against. The practical consequence is that switching a chain to post-quantum signatures protects future ledger integrity but cannot retroactively un-publish keys already written to the chain, which is why exposure is a one-way ratchet and why migration must be initiated by holders rather than applied by a protocol patch.
A third risk is the numbers themselves. Hardware timelines and exposed-supply figures both vary enough by methodology that single-number headlines deserve skepticism. Google Quantum AI's 31 March 2026 estimate that breaking ECDLP-256 over secp256k1 could require no more than 1,200 logical qubits and 90 million Toffoli gates is a lower theoretical attack cost, not an announcement that such a machine exists — and Google used zero-knowledge proof disclosure rather than publishing full attack circuits . On the exposure side, BIP-361's figure of over 34% of all bitcoin having revealed a public key on-chain as of 1 March 2026 is proposal-sourced and methodology-dependent, not a consensus metric . Different definitions of "exposed" — whether reused addresses, unspent P2PK outputs, or leaked descriptors count — move that number by several percentage points in either direction.
Finally, nothing here is settled. BIP-360 was merged into the bitcoin/bips repository on 11 February 2026 via PR #1670, but merging signals only that the document meets BIP standards for formal discussion . There is no mainnet activation, post-quantum signature algorithms were deliberately deferred to a companion BIP, and BIP-361 still depends on an unspecified "TBD Post Quantum Signature BIP" . Any migration plan built today is provisional until Bitcoin Core consensus actually activates a post-quantum output type.
The concrete takeaway: treat this as a hygiene problem now and a consensus problem later. Stop adding new public-key exposure — no address reuse, no unnecessary xpub or descriptor sharing — because that is the only step available today that is not contingent on a future soft fork. Keep hardware firmware current, favor vendors with upgradeable cryptographic primitives, and revisit your plan when a post-quantum output type reaches activation discussion rather than draft status. The G7's timelines — critical systems around 2030–2032, broad migration by 2035 — describe regulated finance, not your wallet. Your wallet's clock starts when Bitcoin's does.
Frequently asked questions
Does the G7's 2026 quantum warning mention Bitcoin or cryptocurrency?
No. Across every first-party G7 document readable in full — the Cybersecurity Working Group's "Preparing for the Post-Quantum Era: A Call to Action" of 3 September 2026 , the joint migration statement of 1 June 2026 , and the Cyber Expert Group financial-sector roadmap released in January 2026 — the words Bitcoin, cryptocurrency, crypto-asset, blockchain and distributed ledger technology do not appear. The documents address cryptographic infrastructure at banks, insurers, exchanges, payment protocols and vendor supply chains. One caveat: the roadmap PDF itself returned as compressed binary from both the Treasury and UK mirrors, so an in-document reference cannot be ruled out by direct reading. The crypto framing is an inference drawn by commentators from general post-quantum cryptography guidance, not a G7 statement about digital assets.
How much Bitcoin is quantum-vulnerable right now?
Published estimates cluster between roughly 25% and 35% of circulating supply, and the spread is a methodology artifact rather than a factual dispute. BIP-361 states that over 34% of all bitcoin had revealed a public key on-chain as of 1 March 2026 — a proposal-sourced figure, not a consensus metric. Lower counts and higher counts differ mainly on how they treat reused and previously spent P2SH and P2WSH outputs, not on the raw set of keys visible in the chain. The practical read: a substantial minority of supply sits in long-exposure territory, and no single number should be treated as authoritative. Note also that dormant or lost coins cannot be migrated by anyone, so part of that exposure is permanent regardless of what the protocol eventually adopts.
What's the difference between BIP-360 and BIP-361?
They solve two different halves of the same problem. BIP-360, "Pay-to-Merkle-Root (P2MR)" — retitled from "Pay-to-Quantum-Resistant-Hash," authored by Hunter Beast, Ethan Heilman and Isabel Foxen Duke, assigned 18 December 2024, version 0.12.1 — defines a new, quantum-safer output type: Taproot with the vulnerable key-path spend removed, deployable as a soft fork on SegWit witness version 2. BIP-361, "Post Quantum Migration and Legacy Signature Sunset," assigned 11 February 2026 and updated 8 September 2026, defines the migration timetable that assumes such an output type already exists: Phase A at 160,000 blocks (roughly three years after activation) disallowing sends to quantum-vulnerable addresses, and Phase B two years later tightening ECDSA and Schnorr spending . Both carry Draft status. BIP-360 was merged into the bitcoin/bips repository on 11 February 2026 via PR #1670 , but merging only confirms the document meets BIP standards for formal discussion — there is no mainnet activation.
When could a quantum computer actually break Bitcoin's signatures?
No cryptographically relevant quantum computer exists publicly, and no official body has committed to a date. Google Quantum AI's March 2026 cryptocurrency paper estimates that breaking ECDLP-256 over secp256k1 could require no more than 1,200 logical qubits with up to 90 million Toffoli gates, or 1,450 logical qubits with up to 70 million Toffoli gates — executable in minutes with fewer than 500,000 physical qubits under stated superconducting assumptions . That is a lower resource estimate for a hypothetical attack, not an announcement that such hardware has been built; Google used zero-knowledge proof disclosure rather than publishing full attack circuits. Industry projections cited in BIP-361 place the window in the late 2020s, while the G7 Cybersecurity Working Group states plainly that the timeline remains uncertain and advises starting the transition as soon as possible . For calibration, NIST plans deprecation and removal of quantum-vulnerable algorithms by 2035, with high-risk systems moving earlier .
What should I do with my Bitcoin holdings today?
Focus on hygiene you control, not on proposals that have not been finalized. Stop reusing addresses, since a reused address exposes its public key after the first spend. Check whether any holdings sit in long-exposure output types — P2PK, bare multisig, reused addresses, or Taproot outputs whose keys are already visible on-chain, the categories BIP-360 classifies as vulnerable to long-exposure attacks . Avoid unnecessary sharing of xpubs and wallet descriptors, which can leak quantum-vulnerable public-key information. Keep hardware firmware current: Ledger's June 2026 SDK added ML-KEM and ML-DSA APIs, and the Trezor Safe 7 uses SLH-DSA-128 for firmware verification and ML-DSA-44 for device attestation — though Trezor itself notes that full crypto-asset protection still depends on blockchain-level upgrades. Moving coins between today's address types does not make them post-quantum safe on its own. Track BIP-360 and BIP-361 status and revisit your plan if either reaches activation discussion.
Enjoyed this article? Subscribe to get new stories by email whenever they're published.