Exposed Public Keys and Address Reuse: Who Is Actually Vulnerable to Quantum?
The key idea: the public key must be visible
Shor's algorithm, if run on a big enough error-corrected quantum computer, would let an attacker work backwards from a public key to the matching private key (see Shor's algorithm explained). No public key, no easy target. That is why the question is not "which coins are quantum vulnerable" in a yes or no sense, but "which coins have shown their public key, and for how long?"
Long exposure vs short exposure
BIP-360 draws a helpful line. Long exposure means a public key that sits on the chain for a long time, for example forever after an old output was created. Short exposure means the brief window between broadcasting a transaction and having it confirmed, when the key is visible only in the waiting room. A quantum attacker would have far more time with a long-exposed key. Defending against short exposure needs full post-quantum signatures. Defending against long exposure can be done by simply never publishing the key until spend time.
Where keys get exposed
- Old pay-to-public-key (P2PK) outputs. These embed the public key directly in the output. A Cointelegraph feature notes they are a clear example of permanent exposure. BIP-361 says no known rescue method exists for P2PK coins.
- Address reuse. Many Bitcoin addresses hide the key behind a hash until you spend. Once you spend, the key is revealed. If you then receive more coins to that same address, those coins now sit behind an already-exposed key.
- Taproot key-path spends. The same feature calls the tweaked key shown in Taproot key path spends the main theoretical weak point, which is what BIP-360 removes for its new output type.
- Account-based chains. On Ethereum and Solana, an account that has sent a transaction has revealed its public key. Ethereum.org notes that accounts that never sent a transaction have an extra layer of protection.
The reported scale
BIP-361 states that over 34% of all bitcoin had revealed a public key on-chain as of March 1, 2026. Other analysts use narrower definitions, such as only coins that are both exposed and realistically at near-term risk, and get far smaller numbers, which shows how much the answer depends on definitions. Ethereum.org says the Ethereum Foundation estimates quantum-vulnerable dormant fund exposure at about 0.1%, and it frames what to do with dormant wallets as an open governance question with no community consensus.
Why this is good news in disguise
Because the weakness is about exposure, a lot of it is fixable by habit and design rather than waiting for a protocol miracle. Fresh addresses for every receive, wallets that do this automatically, and new output types that never reveal a key until needed all shrink the target. Sui reports that Google Quantum AI estimated in March 2026 that recovering a private key from an exposed public key could take minutes on a fault-tolerant machine with under half a million physical qubits, which is a useful reminder to close the exposure window early. Note that this is a research estimate and the machines do not exist today.
Practical takeaways
Never reuse receive addresses. Prefer wallets that rotate them. Treat very old wallets with exposed keys as the first ones to migrate when quantum-safe options exist. More in what individuals can do today and the protocol view in BIP-360 and BIP-361. For the Solana angle see will quantum computers break Bitcoin and Solana.
Education only, not financial advice. This page makes no prediction about any asset, and the QNT memecoin has no connection to Quantinuum Ltd.
Sources and further reading
- BIP-361 text (Post Quantum Migration and Legacy Signature Sunset), bitcoin/bips
- BIP-360 text (Pay-to-Merkle-Root), bitcoin/bips
- Cointelegraph: Bitcoin's quantum upgrade path, what BIP-360 changes and what it does not
- ethereum.org: quantum resistance roadmap
- Sui: making Sui quantum ready
Reported as of 2026-10-09. Roadmaps and proposals change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
Why does address reuse matter for quantum risk?
Spending from an address reveals its public key. Any coins later received at the same address then sit behind a key that is already public.
Are all bitcoin vulnerable?
No. Coins whose public key has never been revealed are better protected. BIP-361 reports that over 34% of bitcoin had revealed a public key as of March 1, 2026.
Is my Ethereum account exposed?
If it has sent a transaction, its public key is on the chain. Ethereum.org says accounts that never sent one have an extra layer of protection.
Keep reading
- Bitcoin BIP-360 and BIP-361 Explained: The Quantum Upgrade Proposals
What the draft Bitcoin proposals P2MR (BIP-360) and the migration and sunset plan (BIP-361) actually say, and what they leave open. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care. - What Individuals Can Do About Quantum Risk Today: A Calm Checklist
Practical, non-alarmist steps for crypto holders: address hygiene, wallet updates, backups and what to ignore. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change.
All Quantum events, catalysts and roadmap guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary