• Home
  • Industry Blog
  • Bitcoin Quantum Readiness: A Guide for Institutional Holders

Bitcoin Quantum Readiness: A Guide for Institutional Holders

Picture2wolfgang.png
Wolfgang Amadeus VitaleCrypto Protocol Expert
30 Sep 20269 Min

Any assessment of Bitcoin's quantum readiness starts from its exposure: a sufficiently powerful quantum computer could derive private keys from public keys, and around 7 million BTC already sit in addresses where those public keys are visible onchain. Credible estimates place such a machine between the end of this decade and the mid-2030s, and the U.S. government has given its own agencies until 2031 to move digital signatures to post-quantum schemes.  

Bitcoin's own migration runs on a different timeline. Developers are still weighing competing output types and signature schemes, every holder will have to move their coins once a design is chosen, and there is no widespread consensus on what should happen to coins whose owners never move them. 

The steps that protect holders stay largely the same across the most plausible paths the transition could take. A family office, foundation or financial service provider holding Bitcoin on behalf of others has to turn those steps into decisions about address formats, digital asset custody arrangements and investment vehicles. Many of these institutions already  have post-quantum roadmaps for the rest of their infrastructure and have begun implementing them.

Which Bitcoin address types are vulnerable to quantum computers?  

Address formats differ in whether coins are exposed while they sit untouched or only from the moment they are spent. Pay-to-public-key (P2PK), the oldest format, places the public key directly onchain, so coins held there could be taken without their owner ever transacting.  

Taproot outputs also carry a public key onchain, because Taproot's key-path spend lets the owner sign directly with that key. BIP-360, merged into the Bitcoin Improvement Proposals repository in February, proposes a new output type, pay-to-Merkle-root (P2MR), that keeps Taproot's scripting flexibility while removing the key-path spend. It is one of several output designs now under evaluation, and until one of them is deployed, I would not use Taproot. 

Hashed formats such as pay-to-public-key-hash (P2PKH) and its native SegWit equivalent, pay-to-witness-public-key-hash (P2WPKH), keep the public key hidden until the coins are spent. That protection holds only if the address is never reused, because once an address has sent a transaction, any coins still on it or sent to it later are exposed.  

Address hygiene protects coins at rest, but a fast enough quantum computer could also attack a transaction between broadcast and confirmation, so it complements the protocol migration without replacing it. An attacker would probably start with the largest balances, so I would spread significant holdings across several addresses.

What should you ask your custodian about quantum readiness? 

Clients who hold Bitcoin through a custodian have most of these choices made on their behalf, which puts them on the custodian's timeline. Self-custodians can act whenever they choose, but they also need to know what to do. 

A custodian should be able to say which output types hold client assets, whether reuse is avoided as a matter of policy, and how large balances are distributed across addresses. Clients should know whether they can see the onchain addresses holding their assets or whether those assets sit in pooled wallets.  

Looking ahead, it helps to ask who initiates the migration once a post-quantum output type activates, and which chain the custodian will support if the network splits. The last question is who on the custodian's team follows the protocol discussion directly, since a provider with that expertise in house can read consensus signals as they form.

What happens to Bitcoin ETF holdings after a chain split?  

I expect the upgrade to arrive through soft forks, but a contested one, particularly over vulnerable coins, could still produce a long-lasting Bitcoin chain split, and I think a chain split is preferable to paralysis. Anyone holding their own keys at the moment of the split would hold a balance on both chains, although using them safely depends on replay protection and on exchanges supporting both chains.  

ETF shareholders would not have that choice. BlackRock's iShares Bitcoin Trust leaves fork decisions to its sponsor, and its prospectus states that the trust will permanently abandon rights to forked or airdropped assets unless a future SEC rule change allows otherwise. 

This year has already tested these arrangements. The eCash hard fork, built around Drivechain and rolling out in stages since August with a permanent mainnet targeted for the end of October, copies Bitcoin's ledger and credits holders one for one. It also reassigns roughly 500,000 dormant coins linked to Satoshi Nakamoto. The fork has nothing to do with quantum computing, but it has already turned the treatment of dormant Satoshi-era coins, the question at the center of the debate over quantum-vulnerable coins, into a live decision for exchanges, custodians and fund sponsors. 

Spot ETFs now hold more than a million BTC, and public companies hold roughly another 1.2 million. These holders gain governance influence along with their positions, and their choices are likely to follow economic incentives. Choosing an ETF over direct holdings also means delegating that choice.

Preparing Institutional Bitcoin Holdings for Quantum Computing 

None of these steps depends on knowing when a cryptographically relevant quantum computer will arrive, and most can be taken today. For every position, an institution should already know who controls the keys, and the transition adds a clarifying question: who will choose the chain. There is no reason to panic, and no reason to relax either. We track these developments every month in the Quantum Update, so our clients can follow the consensus as it takes shape.

Image is AI generated.

Related Articles

  • Quantum Research

    Three Scenarios for Bitcoin's Post-Quantum Transition

    Bitcoin's quantum computing risk could resolve in several ways. Three scenarios for the post-quantum transition, and what each means for holders.

    17 Sep 20269 Min
  • Quantum Research

    Quantum Computing and Bitcoin: The Migration Takes Shape

    Rescue protocols, post-quantum cryptography output types, Ethereum's hash pivot, and Google's 2029 deadline. How Bitcoin's quantum migration is taking shape in August 2026.

    31 Aug 20269 Min
  • Quantum Research

    Bitcoin's Quantum Debate: What Happens to the Coins That Can't Migrate?

    Bitcoin's quantum debate has shifted from urgency to migration. Should vulnerable coins be frozen, left to quantum attackers, or rate-limited? BIP-361 and the three positions explained.

    13 Aug 202610 Min

Personal Support, Every Step

Our team of native experts are here to provide you with the tools, insights and support you need.

Opening hours

24/7 online

Monday to Friday: 9am to 5pm

contact.eu@bitcoinsuisse.com

+423 230 25 55

Call us from abroad