What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Bitcoin is not quantum-proof today, and not every bitcoin is equally exposed. A sufficiently capable quantum computer running Shor’s algorithm could recover a private key from an exposed public key, but when—or whether—such a computer will be viable is uncertain. Block 950,000 is a historical chain-height marker, not a quantum milestone or a measured snapshot of exposed bitcoin: the block explorer records it as mined on May 18, 2026, at 21:54:29 UTC.
What does quantum computing threaten in Bitcoin?
The concern is Bitcoin’s elliptic-curve signature system. Shor’s algorithm, running on a sufficiently capable quantum computer, could solve the underlying discrete logarithm problem and derive a private key from its public key. That would threaten control of funds associated with the exposed key; it would not amount to one operation that simply “breaks Bitcoin.” The timing and viability of such computers are not established. BIP-360 describes the threat and its uncertainty.
There are two relevant attack windows:
- Long exposure: A public key already visible on-chain gives an attacker time to try to recover its private key while the key remains exposed.
- Short exposure: A public key revealed when a transaction is broadcast can be targeted during the interval before confirmation. This requires a much faster attack than a long-exposure scenario.
Neither window means every bitcoin is currently equally vulnerable. Exposure depends on the output type and its history.
Which Bitcoin outputs can expose a public key?
| Output or history | What is exposed | Why it matters |
|---|---|---|
| P2TR (Taproot) | The public key is visible on-chain. | This creates long exposure while the output remains unspent. |
| Hashed-public-key output not yet spent or reused | The public key is hidden behind a hash in the output. | Spending the output reveals the public key; address or key reuse can also expose it. |
| Previously spent or reused hashed-public-key output | The public key may already have been revealed on-chain. | Past transaction history matters, so an address label alone is not enough to judge exposure. |
The authors of BIP-361 report that over 34% of all bitcoin had revealed a public key on-chain as of March 1, 2026. That is the proposal’s estimate for that date—not a block-950,000-specific calculation, and not an independently recalculated figure here.
#1 Best Overall
- BITCOIN EXCLUSIVE, PHONE VERIFICATION: Bitkey is designed from the ground up exclusively for bitcoin — a dedicated hardware wallet for secure bitcoin storage. Approve transactions with a tap using your phone and NFC. No device screen is required.
- SELF-CUSTODY, NO EXCHANGE OR CUSTODIAN REQUIRED: You hold two of the three keys in the Bitkey system – one on your phone and one on your Bitkey device. The third is stored on Bitkey’s server and cannot move your bitcoin on its own.
- NO SEED PHRASE: Set up and use Bitkey without creating or storing a seed phrase.
- 2-of-3 MULTISIG: Three keys are stored separately across your phone, Bitkey device, and Bitkey’s server. Any two keys are required to move your bitcoin.
- BUILT-IN RECOVERY: Encrypted backup and recovery tools can help you regain access if you lose your phone or Bitkey device. You can also designate a Recovery Contact.
What does block 950,000 tell holders about exposure?
The explorer’s record establishes the block’s height and mining time: May 18, 2026, at 21:54:29 UTC. It does not establish how many coins had exposed public keys at that height. The 34% figure above is dated March 1, 2026, and comes from BIP-361’s authors; it should not be treated as a measurement at block 950,000. View block 950,000.
What do BIP-360 and BIP-361 propose?
These proposals address different parts of the problem. BIP-360 proposes a new output type; BIP-361 outlines a broader migration and staged restrictions on legacy signatures.
Rank #2
- Unparalleled Security: Protect your assets NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Rest assured with Multi-share Backup, eliminating single points of failure for secure cold wallet recovery
| Proposal | Approach and intended coverage | Status and implications |
|---|---|---|
| BIP-360: Pay-to-Merkle-Root (P2MR) | Removes Taproot’s key-path spend and leaves a script-tree output. It is intended as a first step against long-exposure attacks, not a solution to short-exposure attacks. | The BIPs index lists it as draft. A new output type would require wallet and service support; it is not established as active network policy. |
| BIP-361: staged migration and sunset | Proposes an initial period allowing sends from legacy scripts to post-quantum scripts, followed by tighter ECDSA/Schnorr verification requirements. | The BIPs index lists it as draft informational. Its proposed schedule is conditional on hypothetical activation, not a live deadline. |
For BIP-361, the illustrative schedule places Phase A 160,000 blocks after activation and Phase B two years after Phase A. Those intervals are part of the draft proposal; they are not calendar dates currently in force. The BIPs index cautions that listing a BIP does not imply adoption, consensus, or endorsement.
BIP-360’s authors describe their proposal as an option for people seeking this protection: “While it is unclear when or if CRQCs will become viable in the future, we propose the addition of a quantum-resistant, script tree output type for those interested in this level of protection.” P2MR by itself does not provide comprehensive protection from a fast attack during a transaction’s unconfirmed interval; BIP-360 says that may require post-quantum signature schemes.
Rank #3
- Unparalleled Security: Protect your assets with EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Multi-share Backup eliminates single points of failure for secure cold wallet recovery
Has Bitcoin adopted post-quantum cryptography?
No adoption is established by the standards cited here. The National Institute of Standards and Technology (NIST) released three finalized post-quantum cryptography standards by August 13, 2024, and recommends that organizations begin migrating systems to quantum-resistant cryptography. That guidance is not evidence that Bitcoin has adopted those standards. NIST’s post-quantum cryptography page provides the standards information.
Quick Recap
Best Value
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
Rank #4
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
What should a bitcoin holder do now?
- Do not judge an address by its format alone. Output type, spending history, and reuse affect whether a public key has been exposed.
- Follow the proposal and implementation status. Check the BIP pages and BIPs index, then look for explicit support in wallet release information before relying on a new output type or migration process.
- Do not treat a proposed schedule as a deadline. BIP-361’s timing starts from hypothetical activation; it is not a current instruction to move funds by a specified date.
- Avoid assuming a wallet product fixes protocol-level exposure. The proposals depend on network and wallet support, and no particular product is established here as a quantum mitigation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




