Hardy Index Quantum readiness benchmark

Chain profile

Bitcoin

BTC Debating

Two post-quantum BIPs reached Draft status in February 2026, but neither introduces a post-quantum signature, no activation path is agreed, and roughly a third of supply sits in addresses with exposed public keys.

Is Bitcoin quantum-safe?

No, and Bitcoin has the hardest position of any chain in this index. Bitcoin signs with ECDSA and Schnorr on the secp256k1 curve, both broken by Shor's algorithm. Two proposals reached Draft status in the BIPs repository on 11 February 2026: BIP-360, which defines Pay-to-Merkle-Root, a Taproot-like output type with the quantum-vulnerable key path removed, and BIP-361, which proposes sunsetting legacy signatures in two phases. Neither is activated, and BIP-360 explicitly states that it does not introduce post-quantum signature schemes. It removes exposed keys from new outputs rather than replacing the signature algorithm. The deeper problem is not cryptographic but political and historical: independent estimates put between 4 million and 7 million BTC in addresses whose public keys are already visible on-chain, and BIP-361's remedy for those coins is to stop them being spendable with classical signatures, which is a proposal to freeze other people's money and is contested accordingly.

Where we are making a judgement call Bitcoin's low Hardy Score reflects quantum readiness alone and should not be read as a statement about Bitcoin's security in any other respect, its monetary properties or its value. Bitcoin's conservatism is a deliberate design choice that has served it well elsewhere; on this specific measure it is the thing holding it back.

At a glance

On mainnet today

ECDSA and Schnorr on secp256k1

Post-quantum scheme

None selected. BIP-360 removes the quantum-vulnerable key path from new outputs without specifying a post-quantum signature scheme.

NIST standard

None adopted. ML-DSA and SLH-DSA are referenced in BIP-360 as examples only.

Readiness tier

Tier 4: Debating. Post-quantum work on the chain’s own signatures is documented by people with authority over it, in a formal improvement proposal or a public research programme, but no scheme is agreed and no timeline is published.

Score breakdown

Each dimension scored 0 to 10. The weight beside it is its share of the total score.
Show the weighted arithmetic and the sourced note for each dimension
Bitcoin Hardy Score by dimension, with weights and weighted contributions
No. Dimension Score Weight Contribution
1 Signature scheme 0 30% 0.0
2 Deployment stage 2 25% 5.0
3 NIST alignment 3 15% 4.5
4 Migration path 2 15% 3.0
5 Exposure 1 10% 1.0
6 Verification 7 5% 3.5
Hardy Score 17.0

1 Signature scheme 0/10, weighted 30%

Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.

Bitcoin mainnet uses ECDSA and Schnorr on secp256k1, both broken by Shor's algorithm. BIP-360 is a Draft and states it does not introduce post-quantum signature schemes; it mentions ML-DSA and SLH-DSA only as examples worth scrutinising. source

2 Deployment stage 2/10, weighted 25%

Band 2: Tier 4: Debating.

Tier 4: Debating. The threat is acknowledged and two proposals are formally documented, but both are Draft, neither is activated, and there is no consensus on an activation path or a timeline. source

3 NIST alignment 3/10, weighted 15%

Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.

No post-quantum scheme has been selected. BIP-360 references ML-DSA and SLH-DSA only as examples of quantum-resistant algorithms worth scrutinising, explicitly declining to propose them for integration. source

Placement in the band At the floor of the band rather than a 4 or a 5: BIP-360 does not merely leave a scheme unchosen, it explicitly declines to propose ML-DSA or SLH-DSA for integration. Naming algorithms in order to set them aside is the least committed form this band describes.

4 Migration path 2/10, weighted 15%

Band 0 to 2: No agreed migration path, or the proposals on the table would strand or freeze holder funds.

The hardest migration problem in the index. Bitcoin has no mechanism to move coins whose keys are already exposed without their owners acting, and BIP-361's answer is to make legacy signatures unspendable at a fixed block height: Phase A at roughly three years after activation, Phase B two years after that. Coins whose owners never migrate are lost by design. Activation itself requires soft-fork consensus that does not currently exist. source

Placement in the band A 2 rather than a 0 because a concrete mechanism is on the table: BIP-361 sets out phased sunset heights, which is more than an acknowledgement. It can go no higher because that mechanism makes unmigrated coins permanently unspendable, which is the stranding case this band names.

5 Exposure 1/10, weighted 10%

Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

The largest measured exposure in the index. Deloitte's analysis of the full chain found roughly 2 million BTC in original pay-to-public-key addresses and 2.5 million in reused pay-to-public-key-hash addresses, over 4 million BTC or about 25% of supply, every coin of it with the public key already visible on-chain. Later estimates from Galaxy Digital and Glassnode run higher still and are set out in the exposure note below. source

Placement in the band Not a 0, because the address model still protects never-spent pay-to-public-key-hash coins, and not a 2, because the measured exposed share of over 4 million BTC is the largest in the index by a wide margin.

6 Verification 7/10, weighted 5%

Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.

Bitcoin's process is maximally open: the proposals are public documents in a public repository, subject to years of adversarial review, and a functional testnet implementation exists in BTQ Technologies' Bitcoin Quantum testnet v0.3.0 from March 2026. Openness is not the same as progress, but it is real verification. source

Placement in the band A 7 rather than an 8 because the open review covers proposals rather than a deployed component. The testnet implementation is third-party and unaudited, so there is no named audit of anything Bitcoin itself runs.

The deployment dimension is not a separate judgement. It is Tier 4 expressed as a number. See the tier mapping.

How it compares

All 31 rated chains on the 0 to 100 scale. Bitcoin is marked. Select any point to open that profile.

Nearest chains in the ranking

The 9 chains Bitcoin sits among, out of 31 rated. The last column is the gap in Hardy points from Bitcoin.

Chains ranked immediately around Bitcoin, with tier, Hardy Score and the gap to Bitcoin
Rank Chain Tier Hardy vs BTC
18 Tron 4: Debating 34.5 +17.5
19 BNB Chain 4: Debating 22.5 +5.5
20 Monero 4: Debating 21.0 +4.0
21 IOTA 5: Exposed 18.5 +1.5
22 Bitcoin this chain 4: Debating 17.0
23 Internet Computer 5: Exposed 14.5 -2.5
24 TON 5: Exposed 13.0 -4.0
25 Litecoin 5: Exposed 12.5 -4.5
26 Bittensor 5: Exposed 11.0 -6.0

Roadmap

  1. June 2024 shipped

    BIP-360 circulates as Pay-to-Quantum-Resistant-Hash (P2QRH), version 0.1. source

  2. 11 February 2026 shipped

    BIP-360 is merged into the Bitcoin BIPs repository with status Draft, renamed Pay-to-Merkle-Root (P2MR). Merging signals documentation quality, not endorsement or imminent activation. source

  3. 11 February 2026 shipped

    BIP-361, Post Quantum Migration and Legacy Signature Sunset, is documented with status Draft. source

  4. March 2026 shipped

    BTQ Technologies releases Bitcoin Quantum testnet v0.3.0, the first functional validation of the P2MR design. source

  5. No activation date proposed

    BIP-361 Phase A would disallow sending funds to quantum-vulnerable addresses 160,000 blocks (about three years) after activation, with Phase B restricting ECDSA and Schnorr spends two years after that. Neither BIP has an agreed activation path. source

Said and done

A chain can announce post-quantum work indefinitely without shipping any. This is the record of what was publicly committed to and what arrived, published beside the score rather than inside it.

1 of 4 dated public commitments have shipped, 2 shipped in part, 1 did not.

Dated public commitments by Bitcoin or its foundation over the period from June 2024, when the first post-quantum BIP began circulating, to August 2026, and what followed on mainnet.

  1. March 2026 In part

    BTQ Technologies releases Bitcoin Quantum testnet v0.3.0 as a functional validation of the P2MR design. source

    A working testnet exists and is real evidence, but it is third-party, unaudited, and not a Bitcoin deployment. Nothing followed it on mainnet.

  2. 11 February 2026 Shipped

    BIP-360 is merged into the BIPs repository with status Draft, defining Pay-to-Merkle-Root. source

    Shipped as a document. Merging a BIP means it meets the documentation standard for formal discussion, and BIP-360's status field still reads Draft. Nothing about it is active on mainnet.

  3. 11 February 2026 Not shipped

    BIP-361 documents a two-phase sunset of legacy signatures, with Phase A roughly three years after activation and Phase B two years after that. source

    There is no activation, and the phases are counted from an activation date that does not exist. Soft-fork consensus for it has not formed.

  4. June 2024 In part

    BIP-360 circulates as Pay-to-Quantum-Resistant-Hash, proposing an output type that keeps public keys off-chain until spend. source

    The document arrived and was subsequently developed, but the name and the scope both changed: by the time it was merged it was Pay-to-Merkle-Root and it no longer claimed to be quantum-resistant in the signature sense.

This record is published beside the score and does not enter it. Nothing here is weighted and nothing here moves the Hardy Score, which is the six dimension scores and the six published weights and nothing else. See the methodology for why.

Exposure

Exposure measures how much of the chain's value already sits behind a public key that an attacker can record today and break later. This is the part of the threat that a future upgrade cannot undo.

Bitcoin's exposure is the largest and best-measured in this index, and it is irreversible for the coins concerned. Public keys are revealed on-chain in two ways: original pay-to-public-key outputs from the earliest years publish the key directly, and address reuse publishes it as soon as an address spends and then receives again. Deloitte's analysis of the full chain found roughly 2 million BTC in P2PK addresses and 2.5 million in reused P2PKH addresses, about 25% of supply. Galaxy Digital put the figure at roughly 7 million BTC worth about $470 billion in March 2026, and Glassnode at 6.04 million, or 30.2% of supply. Estimates differ because they draw the line between exposed and unexposed differently, but all of them describe a share of supply measured in millions of coins that cannot be un-exposed.

How much is exposed

Published estimates of exposed Bitcoin run from over 4 million BTC to about 7 million, somewhere between a quarter and a third of all supply. The estimates differ on where the line between exposed and unexposed falls, not on the order of magnitude.

Published measurements of quantum-exposed BTC on Bitcoin
What is exposed Amount Measured by
Original pay-to-public-key (P2PK) outputs The earliest output type publishes the public key directly, so these coins were exposed the moment they were paid. About 2 million BTC Deloitte undated
Reused pay-to-public-key-hash (P2PKH) addresses An address publishes its key the first time it spends. Receiving again afterwards leaves the balance sitting behind a key that is already on-chain. 2.5 million BTC Deloitte undated
Both categories combined Over 4 million BTC Deloitte undated
All addresses with a public key already on-chain The highest-share estimate published. Glassnode splits it into 1.92 million BTC of structural exposure in pay-to-public-key outputs and 4.12 million BTC of operational exposure created by address reuse. 6.04 million BTC Glassnode May 2026
All addresses with a public key already on-chain Valued at roughly $470 billion at the time of the estimate, under what Galaxy calls a long exposure definition, covering coins whose public keys are already visible on-chain. Galaxy states no share of supply. About 7 million BTC Galaxy Research March 2026

The part no migration can reach A large share of the exposed total can never be moved by anyone, whatever Bitcoin decides. The Satoshi-era P2PK coins have not moved in more than fifteen years and are generally presumed lost, which means no migration, however well designed, can rotate them to a quantum-safe key. They are the reason BIP-361's sunset is a proposal about other people's money rather than a technical cleanup: the only two outcomes available for those coins are that they stay frozen or that they eventually become spendable by whoever first breaks the key.

What this rating means for you

If you hold Bitcoin

Bitcoin has two draft proposals and no agreed post-quantum signature, and it carries the largest measured exposure in this index. Neither of those changes anything you need to do today.

Editorial guidance from the Hardy Index. Nothing on this profile is sponsored and nothing on it is an affiliate link. The guides carry disclosed affiliate links, which never affect a rating. How we make money.

From the newsroom

What we have published about this chain

Embed this rating

Paste this anywhere to show Bitcoin's current rating. It renders live from the index, so it updates when the rating does, and the review date is written into the image. There is nothing to sign up for and nothing to pay.

<a href="https://hardyindex.com/chains/bitcoin"><img src="https://hardyindex.com/badge/bitcoin.svg" width="260" height="76" alt="Quantum readiness rated by the Hardy Index"></a>

The image is /badge/bitcoin.svg. It is a plain SVG with no script and no tracking, it sets no cookie, and it records nothing about whoever loads it.

Questions

Is Bitcoin quantum-safe?

No. Bitcoin uses ECDSA and Schnorr signatures on the secp256k1 curve, both of which are broken by Shor's algorithm on a sufficiently large quantum computer. No post-quantum signature scheme has been selected for Bitcoin, and the two relevant proposals, BIP-360 and BIP-361, are both Draft and unactivated.

What does BIP-360 actually do?

BIP-360 defines Pay-to-Merkle-Root, a script tree output type similar to Pay-to-Taproot but with the quantum-vulnerable key path spend removed, so no public key appears on-chain when the output is created. It does not introduce a post-quantum signature scheme. The specification states this explicitly and mentions ML-DSA and SLH-DSA only as examples worth scrutinising.

How much Bitcoin is vulnerable to a quantum attack?

Estimates range from about 4 million to about 7 million BTC. Deloitte found roughly 4 million BTC, around 25% of supply, across original P2PK addresses and reused P2PKH addresses. Galaxy Digital estimated roughly 7 million BTC worth about $470 billion in March 2026, and Glassnode put it at 6.04 million, or 30.2% of supply. The estimates differ on where to draw the line, not on the order of magnitude.

What is BIP-361 and why is it controversial?

BIP-361 proposes sunsetting legacy signatures in two phases: Phase A would disallow sending funds to quantum-vulnerable addresses roughly three years after activation, and Phase B would restrict ECDSA and Schnorr spends two years later. It is controversial because coins whose owners never migrate, including lost coins and early P2PK holdings, would become unspendable. The choice it forces is between coins being frozen and coins being stolen.

Was BIP-360 being merged a sign that Bitcoin is fixing this?

Not on its own. Merging a BIP into the repository means the proposal meets the documentation standard for formal discussion. It is not an endorsement, not an activation, and not a commitment to a timeline. BIP-360's status field still reads Draft.

Sources

  1. BIP-360: Pay-to-Merkle-Root (P2MR) Bitcoin Improvement Proposals · primary · checked 11 August 2026
  2. BIP-361: Post Quantum Migration and Legacy Signature Sunset Bitcoin Improvement Proposals · primary · checked 11 August 2026
  3. Quantum computers and the Bitcoin blockchain Deloitte · primary · checked 13 August 2026
  4. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly Google Research · primary · checked 11 August 2026
  5. Measuring Bitcoin's Quantum-Exposed Supply Glassnode · primary · checked 12 September 2026
  6. Bitcoin Is Rising to the Challenge of Quantum Readiness Galaxy Research · primary · checked 12 September 2026
Cite this rating

A rating is only true as of the day it was reviewed, so both forms below carry the review date and the methodology version. If you are quoting the score, quote those too.

Plain text

The Hardy Index (2026). Bitcoin: quantum readiness assessment. Hardy Score 17.0 of 100, Tier 4: Debating. Methodology v1.4. Reviewed 2 October 2026. https://hardyindex.com/chains/bitcoin

BibTeX
@misc{hardyindex_bitcoin_2026,
  author       = {{The Hardy Index}},
  title        = {Bitcoin: quantum readiness assessment},
  year         = {2026},
  howpublished = {\url{https://hardyindex.com/chains/bitcoin}},
  note         = {Hardy Score 17.0 of 100, Tier 4: Debating. Methodology v1.4},
  urldate      = {2026-10-02}
}

The whole dataset is reusable under the terms on the about page. A machine-readable version of this page is at /chains/bitcoin.md.

This is a security-readiness assessment, not investment advice.