Quantum Risk: Check Your Bitcoin Addresses for Exposed Keys
A recent paper from the G7 Cybersecurity Working Group has highlighted the need for immediate action to address potential vulnerabilities in current cryptographic methods. The group's statement, published on September 3, 2026, emphasizes that public authorities and companies should begin migrating to post-quantum cryptography as soon as possible.
For Bitcoin holders, this means checking if their addresses have ever revealed their public key. This can be done using a block explorer by looking for P2PK (Pay-to-public-key) or reused addresses. The G7 statement notes that an attacker does not need to collect data in advance; instead, they can simply use the information already present on the blockchain with a quantum computer.
The Bitcoin address is secured using a key pair: the private key and public key. A quantum computer would exploit Shor's algorithm to solve factorization and discrete logarithms efficiently, making current signature schemes vulnerable. However, a classic Bitcoin address is not a public key but its hash, which remains secure as long as only the hash is known.
According to an estimate from River, approximately 6.8 million BTC are at risk due to P2PK outputs and reused addresses in other formats. This includes substantial portions of early mining payouts, including those attributed to Satoshi Nakamoto. To check if your address's key is exposed, you can use a block explorer such as mempool.space or blockstream.info.