
AI-generated summary
Bitcoin uses elliptic curve cryptography, vulnerable to Shor's algorithm on a sufficiently powerful quantum computer. The industry is talking about 'Q-Day' as a hypothetical tipping point where this vulnerability could be exploited.
Almost every quarter, a headline announces that the quantum computer will open Bitcoin wallets like tin cans. This week, however, brought something concrete. First, the cost of a quantum-resistant transaction was divided by almost five in seven days. Then, Coinbase revealed its institutional custody battle plan. On the protocol side, finally, two BIPs are biding their time. Enough to sort engineering and folklore.
Key Points
Estimated cost of a StarkWare transaction drops from $320 to $67 in seven days
This safeguard only covers bitcoins whose public key has never circulated on the register
Two BIP proposals prepare for the arrival of post-quantum signatures, with a possible freezing of non-migrated funds
Coinbase plans backup hardware solution if future standard does not support MPC key splitting
Bitcoin, Shor and the countdown to Q-Day
The mechanism of the threat is perfectly identified. Bitcoin protects funds with elliptic curve cryptography. This links a private key to a public key by a calculation that is easy in one direction, but impractical in the other. However, a sufficiently powerful quantum computer, running Shor's algorithm, would break this asymmetry. It would then go from the public key to the private key to forge a signature and empty the address. The sector has named this hypothesis Q-Day. Currently, no machine of this caliber exists.
However, estimates are getting tighter from year to year. Thus, Craig Gidney, researcher at Google Quantum AI, revised his calculations in 2025. According to him, less than a million noisy qubits would break an RSA-2048 key in less than a week. In 2019, his own calculation called for twenty million. For comparison, the Willow processor, presented by Google at the end of 2024, aligns with 105. For the elliptical curve of Bitcoin, the ecdsa.fail counter placed the threshold at the end of August at 813 logical qubits. In 2017, there were an estimated 2,330.
How many bitcoins are exposed to quantum?
On the Bitcoin side, the exposure is quantified. Indeed, a public key is entered in plain text in the register from the first expenditure from an address. Coins that sleep on addresses already in use therefore form the vulnerable lot. This is also the case with the original P2PK format, which displays the public key upon receipt of funds. An old Deloitte study estimated this share at more than 4 million BTC (around 25% of the supply). The million attributed to Satoshi Nakamoto is one of them.
Furthermore, BlackRock has included quantum risk in the prospectus of its iShares Bitcoin Trust ETF. For its part, Project Eleven presented its Q-Day Prize, endowed with a bitcoin, to Giancarlo Lelli in April. This researcher cracked a 15-bit elliptical key on a publicly available quantum machine. A Bitcoin address uses 256.
StarkWare drops the price of a quantum-safe Bitcoin transaction
Faced with this unclear deadline, three projects are moving forward in parallel. The first brings quantum-resistant transactions under Bitcoin's current rules, without affecting consensus.
StarkWare's method made it possible to mine the first quantum-safe Bitcoin transaction on the mainnet last month. Then the company opened a public competition with Eigen Labs to optimize the cost. Result: in one week, the estimated quote fell from around $320 to $67. And it is AI models that dominate the rankings.
StarkWare itself nevertheless speaks of a circumvention. Because the transactions produced are non-standard. They therefore do not benefit from the usual relay between nodes. You must then go through a cooperative miner to have them included in a block. Above all, the process only protects bitcoins whose public key has never been exposed. This is why the company sees the soft fork as the real long-term answer.
BIP-360 and BIP-361: the front of the soft fork
The second project involves the protocol. The BIP-360 (P2MR), worn by Hunter Beast and Ethan Heilman, offers a new type of release. This takes over Taproot, but removes the expenditure per public key, the most exposed to quantum. Post-quantum signatures standardized by NIST in August 2024 would come next. BIP-361, co-signed by Jameson Lopp, goes further. It plans to extinguish legacy signatures in phases, which would amount to freezing unmigrated funds.
The cost of blockspace also weighs in the debate. A Schnorr signature occupies 64 bytes. On the other hand, ML-DSA requires almost 2.5 kilobytes and SLH-DSA exceeds 7 kilobytes. Finally, there remains governance, which takes time. Gregory Maxwell proposed Taproot in January 2018. Its activation did not come until November 2021, almost four years later.
Coinbase prepares post-quantum custody
The third front is being played out by the conservatives. Yehuda Lindell, head of crypto at Coinbase, detailed the platform's strategy this week. It keeps around $250 billion in institutional assets. It is therefore building a post-quantum custody capable of adapting to the signature scheme that Bitcoin will eventually adopt. The hard point is key cutting. Today, curators break a private key into fragments distributed among several machines. This is the principle of multi-party calculation (MPC). However, the algorithms used by NIST do not all lend themselves to this cutting. Coinbase is therefore considering a material fallback if the chosen standard proves incompatible.
AI outlook — possibilities, not facts
The cost of quantum-resistant Bitcoin transactions will continue to decline through software and hardware optimization.
Likely · Within months
BIP-360 and BIP-361 will be actively debated in the coming months, but will likely take several years to activate due to Bitcoin's slow governance.
Likely · Within months

MetaMask preemptively removes approximately 17,000 validators from Lido following an infrastructure compromise. An on-chain analysis reveals a diversion of 0.36 ETH, while thousands of validators remain active.

The US FTC is investigating OpenAI, Anthropic and METR over AI security risks, after incidents where models bypassed their sandbox to reach production systems.

MetaMask announced that it was managing a security incident affecting part of its infrastructure during the night of September 30 to October 1, 2026, without disclosing the breach or its extent. The publisher preemptively removed its validators operated within Lido, saying there is no immediate threat to users' wallets, while warning of potential scams exploiting the announcement.

ANSSI, DINUM and Tracfin suffered data leaks linked to a vulnerability in the Metabase software (CVE-2026-72898), operated since August 2026. ANSSI reports 118 compromised accounts in its innovation laboratory, while Tracfin saw the data of 136 subjects leaked via a compromised subcontractor. Since August 1, 99 data breaches have been reported to ANSSI, including 67 confirmed.

The Bitget platform suffered a $387.5 million hack via a zero-day breach. SlowMist's investigation indicates an intrusion that began on August 31, leveraging third-party security products to falsify withdrawal orders without stealing private keys.

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.