The market is not pricing a quantum computer. It is pricing a ledger entry written sixteen years ago that cannot be amended.
In 2009 and 2010, the dominant Bitcoin output type was Pay-to-Public-Key. The script published the public key itself directly into the unspent transaction output. No hash commitment. No layer of indirection. The key has sat there, in plaintext, inside the most durable database in finance, ever since. The ledger remembers what the market forgets.
Current discussion circulates a figure of roughly one million coins spread across approximately twenty thousand Satoshi-era addresses. A separate on-chain analysis from James Check places credible quantum-vulnerable targets higher, at 1.716 million coins, with a broader sweep of stale exposed addresses near 6.9 million. That spread runs from under nine percent of supply to well over a third. It is not a rounding difference. It is a pricing failure nobody has resolved. That spread is where the real story lives.
Context
Bitcoin's cryptography operates on two layers that most coverage conflates. The signature layer is ECDSA over the secp256k1 curve. The address layer is the commitment scheme the chain uses before a coin is spent.
Modern addresses, P2PKH and everything descended from it, commit to a hash of a public key rather than the key itself. The public key only surfaces at the moment of spending. Until then, an attacker holds a digest and nothing else. Shor's algorithm, the quantum routine that breaks elliptic-curve cryptography, requires the public key as input. A hash does not feed it.
Early P2PK outputs work the other way. The public key is in the script. It has been in the script since the block was mined. No protocol upgrade can retroactively insert a hash into a coin that already committed to a different format. This is not a bug that gets patched. It is frozen archaeology, and the chain will carry it permanently.

The structure of that exposure deserves detail. Approximately twenty thousand addresses at roughly fifty coins each maps cleanly onto the early block reward schedule. These are almost certainly mining outputs, not accumulated positions. Nothing about them was optimized for privacy or for key management hygiene. They are the raw product of a consensus rule that published public keys because hash commitments were not yet the default.
One further property matters. Because these outputs have never been spent, no signature has ever been produced against them. The chain contains no secondary leak beyond the public key itself. No key reuse pattern, no exposed nonce, no side channel. The entire risk concentrates into a single mathematical relation that a future machine may invert. That is a clean problem to attack, which is exactly why it is a dangerous one.
The exploit is straightforward in principle: a quantum machine with sufficient logical qubits and fault tolerance runs Shor's against a known public key and recovers the private key. The coin moves. Every practical estimate of sufficient is measured in millions of physical qubits. Nobody has built that machine. The exposure is real. The exploit is hypothetical. Both statements are true, and most coverage picks one.
The narrative itself is not new. Quantum-versus-Bitcoin has cycled roughly every two years since at least 2014, tracking research milestones from IBM and Google. What changed in this cycle is specificity. The threat is now anchored to a named holder and a countable address set, which makes it substantially more transmissible than the abstract version.
The September 21 interview that triggered this round came from Justin Drake. Coverage describes him as a Bitcoin security researcher. He is a core researcher at the Ethereum Foundation, and Ethereum's roadmap already contains post-quantum migration work. That does not make his technical claims wrong. It makes his framing worth cross-checking against Bitcoin-side developers, who have not answered publicly in the coverage reviewed here.
Drake's operational advice was measured: do not rush, post-quantum cryptography is immature, migration surfaces new bugs, and scammers will weaponize the fear. All of it is technically sound. All of it simultaneously strands the market in a window where the threat is acknowledged and no mature mitigation exists.
Two proposals occupy that window. BIP-361 would block transfers out of vulnerable early addresses, then impose a hard deadline two years later. Quantum Safe Bitcoin takes a different route, a transaction system built on post-quantum signatures, currently running through a private mempool associated with MARA's SlipStream relay.
Core Analysis
Start with the relay, because it is the most important detail in the story.
When a transaction runs through a private mempool, it bypasses the open broadcast layer that defines Bitcoin's adversarial model. The transaction still reaches a block, and the signature scheme still faces consensus when it does. What changes is the path. An identifiable operator controls relay. Censorship assumptions shift. Privacy assumptions shift. The design is no longer tested against the environment it claims to serve.
I spent four hundred hours in 2017 reading contract logic on a prototype that carried a reentrancy path capable of draining roughly fifty million dollars. The lesson that survived that audit is the one I apply here. Architecture reveals the true intent more honestly than the documentation that accompanies it. A quantum-resistant transaction system routed through a private channel has demonstrated that post-quantum signatures can be constructed. It has not demonstrated that Bitcoin has a quantum defense. Those are different claims, and the coverage merges them.
Separate the verifiable from the asserted.
The chain verifies exposure. P2PK outputs exist. They hold a countable number of coins. Their public keys are public. This is not interpretation and does not require trust in any analyst.
The chain does not verify severity. There is no machine today running Shor's against secp256k1 at production scale. Every timeline is a projection.
The chain does not verify the supply figure, and this is the fault line. Drake's framing is one million coins across twenty thousand addresses. Check's credible-target figure is 1.716 million. Check's broad stale-address sweep is 6.9 million, close to a third of the roughly 19.4 million coins mined. Each number is defensible under a different definition of vulnerable. The methodological variance is the signal. Signal extraction from the noise floor begins with admitting which readings sit above it.
The market cannot price what it cannot count. A risk band running from under nine percent to over thirty percent of supply is not a risk band. It is a fog, and fog is where mispricing compounds quietly.
Move to supply mechanics.
Early P2PK coins that have never moved carry a cost basis near zero. Their owners, assuming the keys survive, paid nothing beyond 2009-era electricity. A quantum attacker who recovers them acquires the same zero basis. A BIP-361 freeze, if ever lifted, returns the coins at the same zero basis. Any unlock of this supply enters the market with maximum gain motive and no anchoring price.
In 2022 I moved seventy percent of fund assets into short-duration treasuries. The trigger was not a price view. It was the recognition that counterparty and structural fragility, rather than sentiment, drive the cycle. Satoshi-era exposure belongs to the same category. It is a structure risk, not a price event.
Check's own assessment is that full liquidation would create downward pressure but not a catastrophe. That judgment holds in isolation. Coins that have not moved since 2010 are unlikely to liquidate en masse, because whoever can move them has been able to move them for sixteen years and chose not to. The catastrophe case requires the attacker to treat the coins as a strategic strike against the network rather than as a market position. Both cases are live. The market has priced neither.
Then there is BIP-361, the more consequential half of the story.
The proposal freezes transfers out of vulnerable addresses at the consensus layer, then hardens the cutoff two years later. The graduated design is coherent engineering. It gives holders a migration window and removes the option to migrate lazily. As politics, it is something else entirely.
Consensus-level freezing means the network votes to take control of coins it did not mine. That is confiscation by protocol, regardless of the guardrails attached. The precedent is the load-bearing element. Once the network demonstrates it can freeze a class of addresses, immutability stops being an absolute and becomes a property that holds for as long as the network agrees it holds.
The consensus is often the contrarian trap. The consensus this month is that the quantum threat is a technical problem. It is a technical problem only until the first credible proposal to fix it arrives.
Consider the outcome space for any single vulnerable output.
The benign outcome: the network does nothing, no machine breaks the key before the coin becomes economically irrelevant, and the exposure decays as the addresses age out of significance.
The exploit outcome: the network does nothing, a machine breaks the key, and the coin moves. Whether the move is public or covert is unknown. A covert unlock, liquidated slowly through channels that do not advertise themselves, is more damaging than a public drain because it is harder to attribute and harder to price.
The governance outcome: the network freezes the class. The vulnerability disappears. So does the immutability guarantee.
Two of those three outcomes are damaging. The benign one requires sustained inaction plus sustained luck. This is what a tail risk looks like when it has three legs instead of two.
A fourth scenario sits outside the proposals. If a Satoshi-era key still exists under someone's control, that holder can migrate voluntarily ahead of any freeze. The chain will show the move, and the chain will not explain it. A defensive migration and a malicious consolidation look identical in a block explorer. The signaling cost of moving is high enough that it suppresses exactly the behavior the network most needs. Certainty is a liability in this domain โ the more anxious the network, the less the migration window actually tells us.
Deploying post-quantum signatures is not a wallet feature. It is a consensus change. A new signature scheme touches script validation, which touches consensus, which touches every node on the network. The last two consensus-level changes, SegWit in 2017 and Taproot in 2021, took years to activate and left the community scarred by the coordination process. A post-quantum scheme would run through the same machinery at a much higher political temperature, because it arrives in the same package as a freeze proposal.
Widen the frame to the industrial layer.
MARA's participation in quantum-resistant transaction experiments is not incidental. Miners that help establish a post-quantum standard acquire standing in whatever standard emerges. A listed mining company positioned at the center of a safety migration converts technical work into commercial and political capital. That is a rational move and should be read as one.
Custodians and spot ETFs carry the largest disclosure exposure. If a large ETF holds Bitcoin and the quantum risk is real, that risk eventually becomes a material factor that must be described to investors. In early 2024 I modeled ETF rebalancing and predicted a roughly fifteen percent reduction in freely circulating supply from passive accumulation. The trade was expressed through mining equities rather than spot, which produced twenty-two percent alpha across the run. The relevant parallel now is that the same structural mechanics that made institutional accumulation price-positive can make institutional risk disclosure price-negative in a different regime. Asset managers do not need to believe the quantum thesis to disclose it.
DeFi wrappers inherit the exposure. WBTC, tBTC, and equivalent constructions are claims on underlying Bitcoin. If the underlying carries a quantum risk premium, the wrapper carries it too, usually with worse disclosure and thinner liquidity.
The legal layer is largely unwritten. A consensus-level freeze of specific addresses has no mature precedent in any major jurisdiction. Does the holder retain title to frozen coins? Does a quantum recovery of a private key constitute theft under statutes drafted for physical intrusion and credential theft? In jurisdictions that recognize crypto assets as property, a network freeze walks directly into a takings question. None of that has been litigated. It is a grey zone wide enough to hold the entire exposed supply.
The scam surface is the most immediate risk of all, and Drake named it. Fear creates a market for fake solutions. Every quantum-adjacent panic cycle produces wallet software that claims post-quantum security and does not have it. The comparison to proof-of-reserves exercises is unavoidable. A partial disclosure that proves one side of a balance sheet is not transparency; it is the appearance of it. The same logic applies to a migration tool that asks users to move keys on the basis of a threat it cannot coherently describe. Verification is the only defense, and verification is precisely what panicked users abandon first.
Contrarian Angle
Here is the angle most readers have not taken.
The quantum debate is framed as a cryptography contest: Bitcoin's ECDSA is vulnerable, Ethereum has a post-quantum roadmap, therefore Ethereum adapts and Bitcoin does not.
The variable is not cryptographic capability. It is upgrade velocity.
Ethereum ships cryptography changes at the client level and coordinates them through its client teams and the EIP process. It has done this repeatedly. The path is centralized enough to be fast, which is precisely what makes it adaptable and precisely what weakens its claim to neutral settlement. Bitcoin's path is the inverse. Changes require rough consensus across miners, node operators, and users, and the historical record of successful consensus changes is short. SegWit took years of political warfare. Taproot moved only after the prior conflict had exhausted both sides. BIP-361 proposes something far more contentious than a transaction format change.

The conclusion that follows is uncomfortable. The reason Bitcoin is slow to defend itself is the same reason it is credible as neutral infrastructure. A network that cannot freeze coins cannot respond to a threat of this type. The properties that make Bitcoin valuable and the properties that make it fragile are the same properties. Architecture reveals the true intent โ and this architecture was designed to resist exactly the kind of coordinated action the threat now demands.
If that holds, the second-order consequence outranks the first. The quantum threat does not need to break Bitcoin's cryptography to damage Bitcoin. It only needs to fracture the community before any machine arrives. The BIP-361 debate is a live stress test of whether coordinated defense is politically possible in this network at all. If the test fails, the cryptographic risk becomes permanently unhedgeable through consensus, and the market will eventually price the governance failure rather than the hardware.
The signaling around the interview deserves the same scrutiny. A senior Ethereum researcher publicly detailing Bitcoin's quantum exposure, in a framing that resolves to Bitcoin's governance cannot move, reinforces a narrative in which Ethereum is the adaptable chain and Bitcoin is the fossil. The technical content can be accurate while the framing is strategic. When an analyst identifies a threat, the identity of the analyst is data. Cross-verify, and note that an unanswered claim is not a confirmed one. It is latency.
Takeaway
The question the coverage keeps asking is when a quantum computer will break Bitcoin. That question depends on hardware timelines nobody can forecast and that the triggering interview explicitly declined to specify.
The question worth tracking is narrower. BIP-361 is a live proposal inside a network that has never coordinated a change of this character. Its community reception, its miner posture, and its node-adoption curve are the only observable proxies for whether Bitcoin can defend itself at all, independent of when the machine arrives.
Watch the proposal, not the clock. The ledger remembers what the market forgets โ but the ledger only records what the network permits.