A quantum computer could crack the cryptography guarding millions of Bitcoin. Inside the freeze debate, the $470 billion exposed, and the startups racing to fix it.
The Quantum Threat Looms
"I think we're four years away from Bitcoin going away," David McAlvany, CEO of gold app Vaulted, said on the On The Margin podcast. "Within four years we have quantum computing, and that is the end of Bitcoin. You can solve all the math problems instantly."
He added, "I have no idea if it's four years from now, five years from now, or two months from now." No machine that could do it exists in mid-2026, but the threat now carries a number.
Attackers Understood That Before Security Teams
"What's a bit unfortunate about it is that attackers understood that before infrastructure teams and before security teams," said Ido Sofer, founder of key-management firm Sodot, on the podcast. "We're meeting every new attack vector first."
Galaxy Digital estimated in March 2026 that roughly 7 million Bitcoin sit in addresses that have already exposed their public key on-chain, worth about $470 billion. Glassnode put it at 6.04 million, or 30.2% of supply. Both are estimates, not protocol counts. Galaxy called the risk "real, but far from an existential crisis." Exposed coins are Satoshi-era addresses that reveal the raw public key, plus any address reused after its first spend. Exposure is not theft; it becomes theft only when a machine can reverse the math—and that machine does not exist yet.
Bring Your Own Locks
"When you're on Bitcoin, when you're on Ethereum, when you're on Solana, right now, you're locked into whatever lock they permit you to use, which is just one kind," said Yoon Auh, CEO of BOLTS Technologies. "When you see quantum advances, these locks can be broken, and that's what they're scared of."
Those locks look more breakable every year. Google researcher Craig Gidney showed in May 2025 that breaking RSA-2048 might take fewer than a million qubits, a twentyfold cut from his 2019 figure. An April 2026 Google whitepaper put cracking Bitcoin's elliptic-curve cryptography at fewer than 500,000. Ethereum Foundation researcher Justin Drake estimates a 10% chance a quantum computer could pull a Bitcoin key from an exposed public key by 2032. In April 2026, a researcher broke a 15-bit key on real quantum hardware. Real keys are 256 bits, so it's a toy, but it's a toy that didn't work at all a year before.
Auh's answer is to hand the choice of cryptography to the user instead of the chain. "Bring your own locks, choose your own locks," he said. BOLTS demonstrated its per-transaction cryptography to NIST's post-quantum cryptographers and ran a quantum-resilience pilot on Canton Network in December 2025. NIST finalized its first three post-quantum standards in August 2024.
Bitcoin's own developers are split on what to do. One draft proposal, BIP-360 from Hunter Beast, would add a quantum-resistant address type. A second, BIP-361 from Jameson Lopp and co-authors, would retire legacy signatures in two phases—any coins that never migrated, including those thought to be Satoshi Nakamoto's, would become unspendable. Freezing dormant coins, supporters argue, beats letting a future quantum thief drain them and dump them on the market. Critics call it confiscation. Algorand has signed its state proofs with quantum-resistant Falcon signatures since 2022; the Quantum Resistant Ledger and the publicly listed BTQ are chasing the same problem from other angles.
It's Like Discovering Cold Fusion
Into that crowd steps American Fortress, an Austin company that raised an $8 million seed round in May, co-led by 0G Labs, SAVA Digital Asset Fund, and Moon Pursuit Capital. Formerly MatterFi, it pitches quantum resistance "for all chains without users having to migrate any addresses at all," paired with a backward-compatible Bitcoin soft fork designed to auto-freeze vulnerable dormant wallets before an attacker reaches them. Founder Michal "Mehow" Pospieszalski doesn't undersell it: "It's so good I can't give it away," he said on the podcast. "It's like discovering cold fusion."
Those claims are worth reading with care. "This style of algorithm is not new news," Pospieszalski said. "People have suggested there's this way to create extra proofs around existing addresses. But it was so slow that people abandoned it. We made it work 100 times faster on a regular PC." American Fortress has filed a patent for post-quantum transaction signing, but a filing establishes priority, not proof; its technical paper hasn't been published, and the design hasn't been publicly audited. The company has deployed a beta on Arbitrum, with a partnerships manager at Offchain Labs quoted supportively, though that's a deployment rather than a formal endorsement. "Post-quantum security isn't a future feature, but a present necessity," said Michael Heinrich, CEO of 0G Labs, in the funding announcement.
Privacy Is Not Anonymity
The quantum work is only half the sell. The other half is a compliance-and-privacy layer, built on the same argument that crypto never actually proves who paid whom. "If I send money to you, you get a cryptographic proof that actually came from my private key," Pospieszalski said. "That's been completely impossible before." He points to address poisoning, where scammers seed a victim's history with lookalike addresses; one such attack drained $68 million in wrapped Bitcoin in May 2024, though the funds were later recovered. His fix attaches a provenance proof to every transaction and lets users disclose an identity only when they choose. "We don't make you get an ID to use the system," he said. "It's like ENS, except private."
Whether a privacy layer with built-in compliance is coherent is exactly the question others are wrestling with. "I always think of privacy and anonymity as completely different things," said Varun Kabra, chief growth officer at Concordium, on the podcast. Concordium builds identity into the chain using zero-knowledge proofs, so "because there is selective disclosure, there is zero knowledge proof, nobody knows it is you." That's the same bet American Fortress is making. Kabra frames the compliance line the same way: "You are in control of what you want to disclose and to whom, but within the constraints of law," he said. "Nobody should be above the law."
You Can't Prove It
Pospieszalski's conviction that systems should prove their own honesty predates crypto. A self-described white-hat hacker, he was CTO of the Election Science Institute and around 2006 analyzed ES&S iVotronic voting machines, warning they had no cryptographic way to confirm a ballot was counted once. "You as the vote counter can't prove to me that you counted my vote, that you didn't double count it or under count it," he said. "You can't prove it." He later did forensic work for plaintiffs in the disputed 2020 Antrim County, Michigan case. By his own account, the anomaly traced to a misconfigured ballot-definition file, the same clerical explanation a bipartisan hand audit reached and every court accepted before the suit was dismissed; no fraud was ever substantiated.
None of the fixes now being funded settle the deeper question a long-term holder actually cares about. McAlvany, whose business is selling gold, asks whether Bitcoin will be here in 5,000 years. "Gold, I'm pretty sure will be," he said. "Bitcoin may or may not be."






Comments
Join Our Community
Sign up to share your thoughts, engage with others, and become part of our growing community.
No comments yet
Be the first to share your thoughts and start the conversation!