Quantum risk to crypto wallets is no longer theoretical
Roughly 6 to 6.9 million BTC sit in addresses whose public keys are already public. Migration to post-quantum signatures has barely started.
The next systemic risk for Bitcoin and Ethereum is no longer regulatory or macroeconomic. It is cryptographic.
Advances through 2026 have compressed the timeline for breaking elliptic-curve cryptography. Research published this year cut the estimated quantum resources needed to attack the problem by roughly 20 times, moving the credible threat window for secp256k1, the curve securing both Bitcoin and Ethereum, out of decades away and into a range that serious security researchers now discuss in years.
The exposure is concentrated and measurable. Google research puts roughly 6.9 million BTC, about a third of circulating supply, in wallets whose public keys have already been revealed on-chain. Glassnode found 6.04 million BTC, or 30.2% of issued supply, splitting it into 1.92 million from structural exposure and 4.12 million from operational exposure, mostly address reuse. A Coinbase advisory board report narrowed the most acute tier to roughly 20,000 keys covering 1.7 million BTC.
Addresses that have never spent, and therefore publish only a hash, stay safer for longer. But the reused-key set is large enough, with researchers putting more than $700 billion at risk, that the market would not need an actual attack to reprice. It would only need to start believing one was close.
Migration to post-quantum signature schemes is technically possible and operationally slow. Every user must move funds. Every hardware wallet must ship new firmware. Every exchange must support new algorithms without opening fresh attack surface. That migration has barely started.
The threat is still not imminent. It is no longer theoretical either. Capital that treats long-term cryptographic security as a free option is mispriced, and unlike most tail risks in crypto, this one has a fix that has to begin years before it is needed.