Go to app

Quantified Risk Assessment

Published 7/21/2026, 10:59:44 PM

Galaxy Digital characterizes Bitcoin's vulnerability to quantum computing as a legitimate but manageable risk rather than an existential threat. According to research led by Alex Thorn, approximately one-third of the Bitcoin supply (~7 million BTC) is currently at risk due to exposed public keys, representing a value of roughly $470 billion [Source: https://www.galaxy.com/insights/research/bitcoin-quantum-computing-vulnerability/].

On July 21, 2026, Galaxy Digital launched the Galaxy Bitcoin Quantum Readiness Initiative, committing $5 million in developer grants to accelerate the implementation of post-quantum cryptography (PQC) solutions like BIP 360 [Source: https://www.galaxy.com/newsroom/galaxy-launches-bitcoin-quantum-readiness-initiative].

Quantified Risk Assessment

Galaxy’s analysis distinguishes between different cryptographic layers and address types, noting that the threat is concentrated on the Elliptic Curve Digital Signature Algorithm (ECDSA) rather than the SHA-256 hashing used in mining.

MetricValue / AssessmentDetails
Vulnerable BTC~7 million BTCPrimarily P2PK (Satoshi-era) and reused addresses with visible public keys [Source: https://www.galaxy.com/insights/research/bitcoin-quantum-computing-vulnerability/].
Safe BTC~12–13 million BTCFunds in addresses that have never broadcast a transaction (public keys remain hashed).
Primary ThreatShor’s AlgorithmCan derive a private key from a known public key in ~9 minutes using a 1,200 logical qubit machine.
Mining ThreatInfeasibleGrover’s Algorithm provides only a square-root speedup; the network can adjust difficulty to compensate.
Estimated Timeline2030–2031Aligning with U.S. federal deadlines for digital signature migration [Source: https://www.galaxy.com/insights/research/bitcoin-quantum-computing-vulnerability/].

Key Vulnerability Vectors

  • At-Rest Attacks: Targeting dormant wallets where the public key is already known. Galaxy notes that ~1.7 million BTC in early wallets are particularly exposed because their public keys were broadcast during the initial mining process [Source: https://www.galaxy.com/insights/research/bitcoin-quantum-computing-vulnerability/].
  • On-Spend Attacks: A quantum attacker could intercept a transaction in the mempool, derive the private key, and broadcast a competing transaction with a higher fee before the original is confirmed.
  • Network Governance: Galaxy identifies decentralized consensus as a major hurdle, as coordinating a "soft fork" to PQC will require years of preparation to avoid network fragmentation.

Mitigation and Progress

Galaxy Digital is actively funding research into BIP 360 (Pay-to-Merkle-Root), which aims to provide a quantum-resistant framework for Bitcoin.

In summary, while Galaxy Digital views the "Q-Day" timeline as compressing (potentially as early as 2030), they maintain that Bitcoin has sufficient time to upgrade its protocol, provided the community begins the transition to quantum-resistant standards immediately.