Millions of BTC Exposed to Quantum Computer Attacks
A recent paper from Google's Quantum AI lab has highlighted a significant risk to millions of Bitcoin and Ethereum addresses, which could be vulnerable to quantum computer attacks. The research found that about 6.9 million BTC are held in addresses where the full public key is already visible on-chain, exposing them to what researchers call an at-rest attack.
According to the study, an at-rest attack targets a key already published on the chain rather than one briefly revealed during a transaction. This means that a future quantum computer would have unlimited time to derive the private key offline and empty the wallet.
The exposure covers roughly a third of Bitcoin's circulating supply and about a sixth of Ether's. The risk depends on two main factors: the type of address used to create the coin, and whether that address has ever been used or spent from.
Specifically, P2PK addresses place the full public key directly in the output script, exposing coins held in these addresses from the moment they were funded. On the other hand, P2PKH addresses store only a hash of the public key, and a quantum computer can't derive a private key from a hash.
However, the first spend from a P2PKH address publishes the full key on-chain, and every coin later sent back to the same address inherits that exposure. This is responsible for most of the 6.9 million figure.
Coinbase's Independent Advisory Board on Quantum estimates that about 1.7 million Bitcoin are locked in keys nobody can move, worth around $131 billion at current prices. These coins are held in early P2PK keys and belong to Satoshi-era or otherwise lost addresses.