How much Bitcoin is exposed to a quantum attacker?
Measured daily from our own Bitcoin node, not quoted from anyone's report: every unspent output whose script reveals a public key on-chain, classified byte-by-byte from the full UTXO set, with the snapshot hash published so anyone can reproduce the number.
As of block 962,212, 1,936,281 BTC sits in outputs whose public key is already visible on-chain (P2PK, bare multisig, Taproot). That is 9.65% of the 20,069,186 BTC held in the UTXO set at that height. By output count the share is 34.35% · the two numbers differ by design and we never blend them. A future cryptographically-relevant quantum computer could target such keys; today none exists, and this page publishes a measurement, not a countdown.
Where does the exposed value sit?
Every bucket is published separately with both count and value, including the ones that make the headline look small. One blended line would hide the fact that 92% of the exposed value is Satoshi-era P2PK.
| Script family | Outputs | BTC | % of set value |
|---|---|---|---|
| P2PK · uncompressed key (2009-2012 era) | 34,345 | 1,709,632.97 | 8.519% |
| P2PK · compressed key | 10,268 | 6,136.66 | 0.031% |
| P2PK · raw script | 0 | 0 | 0.000% |
| Bare multisig (P2MS) | 2,626,723 | 70.4 | 0.000% |
| Taproot (P2TR) | 54,296,500 | 220,441.06 | 1.098% |
| Non-standard with exposed key | 8 | 0.01 | 0.000% |
| P2PKH (hash-locked, not exposed) | 44,337,432 | 4,556,493.05 | 22.704% |
| P2SH (hash-locked, not exposed) | 12,078,573 | 3,897,797.24 | 19.422% |
| P2WPKH (hash-locked, not exposed) | 49,580,535 | 8,224,739.4 | 40.982% |
| P2WSH (hash-locked, not exposed) | 2,761,301 | 1,451,256.43 | 7.231% |
| Witness v2+ (no key semantics yet) | 94,872 | 0.52 | 0.000% |
| Off-curve / threshold-failed (unspendable) | 19,906 | 0.17 | 0.000% |
| Unclassified (value shown, never dropped) | 20,769 | 2,617.61 | 0.013% |
| Exposed total | 56,967,844 | 1,936,281 | 9.65% |
| Whole UTXO set | 165,861,232 | 20,069,186 | 100% |
Count and value tell opposite stories on purpose: Taproot is a third of all outputs but under 1% of exposed value; P2PK is a rounding error by count and 92% of exposed value.
How much of it has not moved in years?
Exposure and dormancy are different axes and we never add them. This grid answers the honest question: of the exposed value, how much sits in outputs that have not moved since each cutoff?
| Untouched for | Exposed BTC | Exposed outputs | All BTC (comparison) |
|---|---|---|---|
| 3+ years | 1,723,283 | 8,804,381 | 8,560,734 |
| 5+ years | 1,715,810 | 404,298 | 6,768,197 |
| 7+ years | 1,715,809 | 399,013 | 5,268,249 |
| 10+ years | 1,715,807 | 383,772 | 3,605,112 |
Dormancy here means the unspent output itself was created before the cutoff block and has never been spent. Age is measured in blocks (52,560 per year).
The dormant-P2PK movement watch
91.8% of all structurally exposed value is Satoshi-era uncompressed P2PK. We watch that exact set of outpoints every day and publish the set itself, so the claim is auditable.
Reference measurement: 34,199 outpoints holding 1,714,163 BTC at block 882,508 (2025-02-06, first-party). The difference between that measurement and today's count IS the realized movement rate over the period, published here before any alert can fire. A watched output leaving the set is a data point against this baseline, not an alarm.
If a watched output moves, this page will state exactly the following, with the blanks filled, and nothing more dramatic:
“An output whose public key has been exposed on-chain since {year} moved: {outpoint} was spent in transaction {txid} at block {height}, Bitcoin mainnet. A spend by the rightful key holder is indistinguishable from any other valid spend; this is a data point against the published baseline movement rate, not evidence of a quantum attack.”
No watched outpoint has left the set since daily recording began.
Why do published numbers range from 1.9M to 10M BTC?
Because they answer different questions. Instead of publishing an eleventh estimate, this table referees the existing ones: definition, date, unit and whether the figure is an independent measurement or a derivative of another row.
| Figure | Source | What it actually counts | As of | Unit / denominator | Independent? |
|---|---|---|---|---|---|
| 1.87M BTC | ByKaranteli (this page) | Structural: outputs whose scriptPubKey contains a curve point (P2PK, P2MS, P2TR), classified from our own node's UTXO snapshot | daily | BTC value, % of UTXO-set value | yes · first-party measurement |
| 1.92M BTC | Glassnode | Structural, by script type, from their supply-by-txout-type series | 2025 | BTC value | yes |
| 6.04M BTC | Glassnode | Structural + operational (address reuse) combined | 2025 | BTC value | yes |
| 6.5M BTC | Presidio | Structural + reuse; ~4.5M of it attributed to reuse | 2025 | BTC value | partly |
| ~6.9M BTC | Google Quantum AI | Address-level; includes an admitted simplification that treats P2SH/P2WSH script compromise as coin theft (5.3M BTC base) | 2025 | BTC value | yes |
| 6.9M BTC | Project Eleven (Risq List v2) | BigQuery census, weekly refresh; agrees with Google to two significant figures and must not be presented as independent corroboration | weekly | BTC value | method shared with Google's frame |
| ~7M BTC | Galaxy | Explicitly built on Project Eleven's data | 2026 | BTC value | no · derivative |
| 6.51M BTC | Human Rights Foundation | 1.72M structural + 4.79M reuse, literature synthesis | 2026 | BTC value | no · derivative |
| “over 34%” | BIP-361 text | Share of coins with a revealed public key; no methodology disclosed in the BIP | 2026 | % (denominator unstated) | unknown |
| 4M-10M BTC | Chaincode Labs | Survey range across the published literature, not a measurement | 2025 | BTC value | no · survey |
| 2.3M BTC | Google Quantum AI | Different axis: vulnerable AND dormant (top-100k-address truncation, bounded near 2.5M for the full set) | 2025 | BTC value | yes, different question |
| 2.3M BTC | arXiv 2606.14484 | Different axis: irreducibly at risk (cannot migrate); a further ~3.7M exposed but migratable | 2026 | BTC value | yes, different question |
Our 1.87M and Glassnode's 1.92M measure the same structural definition 13 months apart on different snapshots; the gap is time and method detail, not disagreement. The 6-7M family adds address-reuse exposure, a different and softer definition that cannot be computed from a UTXO snapshot at all.
Methodology · published in full
The measurement is a pure function of our own node's UTXO snapshot (Bitcoin Core dumptxoutset, format v2). No third-party API touches the number. The classifier is open about every rule it applies, because the product is the reproducibility.
An output is exposed at rest if and only if its scriptPubKey contains an elliptic-curve point rather than a hash digest. Hash-locked families (P2PKH, P2SH, P2WPKH, P2WSH) reveal their key only when spent; that reuse axis is a different measurement and is not included here.
Some coverage states that Taproot hides the public key until spend; this is incorrect. The output key is on-chain by construction, consensus verifies a Schnorr signature against it directly, and a provably-unspendable internal key changes nothing about that. All three serious published methodologies (Glassnode, Google Quantum AI, Project Eleven) count P2TR as structurally exposed, and so do we.
Quantum hardware context, for scale rather than countdown: the authoritative resource estimate for secp256k1 is Babbush et al., arXiv 2603.28846 (2026): under 500,000 physical qubits at 10^-3 error rates in the paper's fast-clock working assumption. No such machine exists; progress is better read as a threshold model than a qubit count.
Exact classification rules (dump script-size codes)
- code 0 → P2PKH (20-byte hash) · not exposed
- code 1 → P2SH (20-byte hash) · not exposed
- codes 2,3 → P2PK compressed key · exposed if the x coordinate lies on secp256k1, else unspendable
- codes 4,5 → P2PK uncompressed key (x stored) · exposed if on-curve, else unspendable
- code ≥6 → raw script: OP_1 <32B> = Taproot, exposed iff lift_x succeeds · OP_0 <20B/32B> = P2WPKH/P2WSH, not exposed · OP_M <keys> OP_N OP_CHECKMULTISIG = bare multisig, exposed iff ≥M keys are on-curve · OP_2..OP_16 <2-40B> = witness v2+, own series · an on-curve 33/65-byte key immediately followed by OP_CHECKSIG = exposed and logged · anything else = unclassified, with its BTC value published, never dropped
Provenance
Every row carries base_height, base_hash, txoutset_hash, coins_written and the classifier version. Acceptance gates run before any row is written: exact end-of-file parse, output count equal to the header count, total value within 0.01% of the subsidy schedule, and a P2PK band check that makes the silent-zero failure mode impossible. A snapshot is refused if the node is in initial sync or lags its own headers.
base_height 962212 · base_hash 000000000000000000004b0d47e50a396a61edff6bad1d8358c45e2f207c6c18 · txoutset_hash 569b5ff7ef54fe0459b2827f0f372ba9e1bbbaef49990cadb025c5ed9ca719a4 · coins 165,861,232 · qclass_v1_20260813
What this measurement does NOT tell you
- It does not include address-reuse exposure (keys revealed by past spends on hash-locked addresses). That is a different, softer definition responsible for most of the 6-7M figures, and it is structurally impossible to compute from a UTXO snapshot.
- It does not say when, or whether, a cryptographically-relevant quantum computer will exist. We publish no countdown and no probability.
- It cannot attribute any specific movement to an attack: a quantum-derived spend would be byte-for-byte identical to an owner's spend.
- The 1.7M BTC of early P2PK is not “Satoshi's stash”: attributed estimates for the Patoshi pattern range from 700k to 1.1M BTC and are themselves contested.
- No Q-Day dates, countdowns or percentages.
- No “quantum signal” and no trading advice derived from this page.
- No labelling of any on-chain movement as a quantum attack.
- No “Satoshi's coins moved” headlines.
Is the 1.7M BTC in early P2PK Satoshi's?
Unknown and overstated when claimed. Total early P2PK is about 1.72M BTC; the subset attributed to the Patoshi mining pattern is contested, with published estimates from 700k to 1.1M BTC. We watch the whole set and attribute nothing.
Why do other sites say 6.9M BTC?
Those figures add address-reuse exposure: coins on hash-locked addresses whose key became visible through past spends. That is a real but different and softer definition, it depends on address-level heuristics, and part of it rests on an admitted simplification about P2SH/P2WSH scripts. The reconciliation table above puts every published figure next to its definition.
Should this number worry me today?
No machine capable of breaking secp256k1 exists. The measured exposure has been roughly stable for years because most of it is dormant early-era P2PK. The honest reading is the threshold model: what would change the picture is not this number moving, but the watch section firing against its published baseline, which is why both exist on the same page.
Dataset · CC0
The daily series and the full watched-outpoint set are public domain. Every row carries the snapshot hash, so a citation can be verified against any Bitcoin node.