At block 950,000 on the Bitcoin blockchain, a quiet crisis is already baked in. A new analysis published in Bitcoin Magazine's dedicated "Quantum Issue" — authored by the pseudonymous researcher known as Wicked — maps precisely how much of Bitcoin's circulating supply sits in addresses that a sufficiently powerful quantum computer could plunder, and then confronts the thornier question: what, realistically, could the network do about it?
The framing around block 950,000 is deliberate. It is not a future hypothetical pinned to a date no one can predict. It is a snapshot taken at a concrete, verifiable point in Bitcoin's ledger history — a way of grounding an abstract technological threat in the hard arithmetic of satoshis already allocated, addresses already used, and keys already exposed to the mathematical leverage that quantum computation could eventually provide. The methodology forces the conversation away from science fiction and toward engineering reality.
The Nature of the Exposure
Bitcoin's security rests on two cryptographic pillars: the Elliptic Curve Digital Signature Algorithm (ECDSA), which protects private keys, and the SHA-256 hashing algorithm, which secures the proof-of-work mining process. Quantum attacks on these two pillars are not equivalent in urgency or difficulty. A sufficiently scaled quantum computer running Shor's algorithm could, in theory, derive a private key from an exposed public key — and that is where Wicked's analysis cuts deepest.
The vulnerability is not uniform across the entire Bitcoin supply. Coins sitting in addresses where the public key has never been broadcast to the network — standard practice under modern Segregated Witness (SegWit) address formats — present a meaningfully harder target. The dangerous cohort is older: pay-to-public-key (P2PK) outputs, where the public key is permanently visible on-chain, and pay-to-public-key-hash (P2PKH) addresses from which at least one transaction has been sent, exposing the public key in the process. Satoshi Nakamoto's own earliest mined coins fall squarely into the P2PK category, as do large tranches of early-era Bitcoin that have never moved.
This distinction matters enormously when sizing the actual threat. The analysis at block 950,000 draws a hard line between coins that are passively exposed through address reuse or legacy output types and coins that remain shielded by an additional layer of hashing. The former group represents a finite but significant slice of supply — one that becomes increasingly attractive as quantum hardware matures and the cost of attack falls.
The Logistics Problem Is the Hard Part
Identifying vulnerable coins is, in a perverse way, the easier half of the problem. The governance and engineering challenge of actually moving or quarantining that exposure is where the analysis becomes genuinely uncomfortable. Any credible response requires Bitcoin to change — either through a soft fork that deprecates vulnerable address types, a migration window that incentivizes holders to move funds to quantum-resistant outputs, or some combination of both. Each path carries its own landmines.
A forced migration raises immediate philosophical objections in a network that treats immutability and property rights as foundational values. Coins that have not moved in a decade or more — including, potentially, Satoshi's holdings — would need to be handled by a community that has never reached consensus on anything close to this scale of intervention. The question of what happens to coins whose owners are dead, lost, or simply unreachable is not academic. It is a multi-billion-dollar arithmetic problem with no clean answer.
A voluntary migration, meanwhile, depends on user education and urgency at a scale Bitcoin has never demonstrated the ability to mobilize. The history of upgrade cycles — from the years-long SegWit activation saga to the prolonged debates over Taproot — does not inspire confidence that the network could coordinate a quantum migration before a capable adversary acted. Wicked's framing at block 950,000 implicitly underscores this: the exposure exists now, the timeline for quantum capability remains uncertain but is compressing, and the governance machinery for response is slow by design.
Why This Moment, Why This Issue
Bitcoin Magazine's decision to dedicate an entire issue to quantum risk signals that this conversation has moved from the cryptography mailing lists into the mainstream of serious Bitcoin discourse. Post-quantum cryptography standardization efforts from the U.S. National Institute of Standards and Technology (NIST) have accelerated, with several algorithms now finalized. The existence of production-ready post-quantum standards removes one excuse for delay — the alternative cryptographic primitives exist; the question is purely one of implementation and political will within the Bitcoin ecosystem.
Wicked's contribution is valuable precisely because it refuses to catastrophize or dismiss. The analysis at block 950,000 is not a prediction of imminent collapse. It is a precise accounting of existing exposure, designed to give developers, researchers, and serious holders a grounded baseline from which to reason. The threat is neither tomorrow nor never — it sits in the uncomfortable middle ground where preparation is urgent but panic is premature. That is exactly the kind of nuanced framing the Bitcoin development community needs to begin moving toward a credible response, before the block height at which the question becomes much less academic.
Written by the editorial team — independent journalism powered by Bitcoin News.