0x0781e9020781…0781e8ff

ConfirmedSecurity737 vB124 sat/vB4 min decode

Bitcoin's Quantum Exposure Concentrated in 2.28M Dormant BTC, Analysis Finds

At block 950,000, 6,900,573 BTC sit in addresses with exposed public keys, equal to 34.45% of supply. Filtering by activity, dormancy, and balance size cuts the practical attack target to 351,654 BTC across 675 groups.

The Quantum Issue: Bitcoin Quantum Exposure at Block 950,000
WitnessThe Quantum Issue: Bitcoin Quantum Exposure at Block 950,000AI-generated

Outputs

  1. 6,900,573 BTC across 16,047,454 groups sit in addresses with revealed public keys at block 950,000, equal to 34.45% of circulating supply.

  2. After removing active addresses and known operational entities, dormant non-responsive exposure falls to 2,277,978 BTC across 73,658 groups.

  3. At the ≥100 BTC dormant non-entity threshold, the economically rational attack target compresses to 351,654 BTC across 675 groups and 33,573 UTXOs.

  4. P2PK scripts carry 1,715,778 BTC of the dormant non-entity exposure at the 1 BTC threshold, driven by early 50 BTC payouts.

  5. The analysis was published in Bitcoin Magazine's 'The Quantum Issue' and draws on a block-950,000 snapshot of the Bitcoin Quantum Exposure Dashboard.

A Bitcoin Magazine analysis of the Bitcoin network at block 950,000 finds 6,900,573 BTC in addresses whose public keys have already been broadcast on-chain, equal to 34.45% of circulating supply. That headline figure overstates realistic theft risk once the dataset is filtered for activity, dormancy, and balance size, leaving roughly 351,654 BTC across 675 address groups as the most economically attractive target for a quantum adversary.

What the raw exposure count actually measures

The 6.9 million BTC total treats cryptographic exposure as a binary condition. Any address whose public key has appeared on-chain is included, regardless of how the coins are held or how quickly they could be moved.

That starting point captures dormant early outputs, operational exchange wallets, custodial multisig arrangements, mining infrastructure, and stablecoin backstops. It functions more as an inventory of published keys than as a list of imminent theft targets.

The Bitcoin Magazine analysis frames the headline as a ceiling on potential loss rather than a forecast. Raw exposed supply, the piece argues, "should not be read as the amount of bitcoin likely to be lost in a quantum event."

How active entities fall out of the risk set

Applying a five-year activity threshold to balances of at least 1 BTC removes addresses that are operationally responsive. The active set holds 3,331,639 BTC across 46,163 groups, or about 48.28% of total exposed supply. Exchanges, brokers, custodial multisig operators, stablecoin infrastructure providers, and mining wallets dominate this slice. They also rank as the holders most likely to monitor quantum research, rotate keys, and migrate funds ahead of any credible attack window.

The harder-to-mitigate exposure sits on the other side of that filter. Never-spent or inactive balances of at least 1 BTC total 3,413,767 BTC. After removing known operational entities while keeping Satoshi-attributed coins in the dataset, the residual exposure drops to 2,277,978 BTC across 73,658 groups and 1,096,018 unspent transaction outputs.

The analysis calls this 2.28 million BTC segment the cleanest read in its dataset of non-responsive exposure: early holders, inactive self-custody, address reuse, dormant Pay-to-Public-Key (P2PK) outputs, and coins likely lost.

Why a quantum adversary's target set is smaller still

A rational attacker faces operating costs, limited throughput, and transaction fees. The economics favor high-value dormant balances over a broad sweep of every exposed address.

Under the same non-entity dormant filter, a 10 BTC threshold keeps 2,187,481 BTC but compresses the universe to 39,897 groups and 365,830 UTXOs. At the 100 BTC threshold — the most economically attractive slice — only 351,654 BTC remain, distributed across 675 groups and 33,573 UTXOs. Migrating that target set from the network, the dataset estimates, would take roughly 2.17 hours of throughput.

Which script types carry the dormant weight

Script-type decomposition shows P2PK outputs dominating dormant exposure. At the 1 BTC threshold with known entities removed, P2PK holds 1,715,778 BTC, almost entirely from early 50 BTC Satoshi-era payouts whose public keys were visible on-chain from inception. The same script class collapses to roughly 10,246 BTC at the 100 BTC threshold once those 50 BTC mining rewards fall out of the filter.

Pay-to-Pubkey-Hash (P2PKH) flips that picture at higher thresholds. P2PKH retains 273,865 BTC at the 100 BTC level, reflecting inactive self-custody, address reuse, and dormant legacy wallets. Taproot (P2TR) outputs are exposed by design at the key level yet total only 41,486 BTC in the high-value dormant non-entity view. Pay-to-Witness-Script-Hash (P2WSH) exposure sits in active institutional wallets and shrinks to 2,750 BTC once known operators are removed.

What the snapshot leaves open

The block-950,000 reading treats quantum exposure as a concentrated dormant-coin problem rather than a uniform risk across all 6.9 million BTC. The economically rational attack window points at inactive, high-balance, key-revealed UTXOs, not at the active wallets most likely to migrate first.

Forward visibility now depends on what does not yet exist: a credible quantum capability against the secp256k1 curve, and a protocol-level migration path that can move non-responsive coins without splitting the network. Either development would force the dormant 2.28 million BTC surface into a concrete remediation timeline.

via store.bitcoinmagazine.com (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles