A holder-first threat model

Quantum risk is real. The timeline is not the whole story.

See what a capable quantum computer would actually attack, why Bitcoin migration is slow, and what your own key setup changes.

No countdowns. No invented breakthrough dates. Just the cryptographic and coordination paths.

Start with your public-key exposure.

Bitcoin does not have one uniform quantum risk. The key question is whether the public key controlling an output is already visible, followed by how quickly you could move under a network migration.

Your readiness profile

Adjust the controls. The result updates and saves automatically.

WATCH
Operational habits

WHY THIS PRIORITY

Fresh-address use limits immediate public-key exposure, but a migration playbook still matters.

NEXT MOVES

    Signatures are the sharp edge.

    At sufficient scale, Shor's algorithm threatens the elliptic-curve public-key signatures used to authorize Bitcoin spending.

    Hashing is a different problem.

    Grover's algorithm reduces brute-force security margins quadratically; it does not make SHA-256 instantly disappear.

    The actual path

    Why is the community not moving faster?

    Because this is both a cryptography problem and a coordination problem. Urgency rises only when those paths converge.

    CAPABILITY

    A cryptographically relevant machine must exist.

    Breaking Bitcoin signatures would require a large, fault-tolerant quantum computer able to run a practical attack against secp256k1. Today's uncertainty is about when or whether that engineering threshold arrives, not about whether the mathematics of Shor's algorithm is known.

    PROTOCOL

    The network must agree on new authorization rules.

    Quantum-resistant signatures carry tradeoffs in signature size, verification cost, maturity, and implementation risk. Bitcoin change is deliberately conservative because a rushed cryptographic migration could create a different class of loss.

    HOLDERS

    Coins do not migrate themselves.

    Even after new rules exist, holders, custodians, multisig groups, and lost-key outputs create a long tail. Exposed public keys and inactive holdings make the social question of deadlines or restrictions especially difficult.

    Three distinctions that change the conversation.

    The signature scheme has a known theoretical quantum attack, but theory is not the same as a machine capable of executing it at the required scale. Readiness work can be rational before a break is imminent.

    Common pay-to-public-key-hash and native SegWit key-hash outputs commit to a hash of the public key. The public key is typically revealed when spent. Reuse removes that limited concealment for later outputs sent to the same key.

    Inventorying address types, avoiding reuse, monitoring credible protocol work, and documenting who can authorize a move are operational hygiene. None requires pretending to know a breakthrough date.

    Turn the threat model into a holder memo.

    Your export includes the selected profile, current priority, reasons, next moves, and the assumptions that keep the result honest.

    Readiness memo downloaded.
    Super generates helpful tools and automates fact-checking across the internet proactively. If you enjoyed this tool, build your own with Super and share it with a friend.