---
title: What Bitcoin is, and is not, doing about quantum
description: Bitcoin has two draft proposals for the quantum threat and no activated defence. What BIP-360 actually does, and why most coverage of it is wrong.
url: "https://hardyindex.com/news/bitcoin-bip-360-reality"
section: Readiness history
type: readiness-history
published: 2026-08-12
updated: 2026-08-12
chains: bitcoin
methodology_version: 1.4
---

# What Bitcoin is, and is not, doing about quantum

**Bitcoin has no post-quantum defence deployed today. It signs with ECDSA and Schnorr on secp256k1, both breakable by Shor's algorithm. Two proposals exist, BIP-360 and BIP-361, and both are drafts. Neither introduces a post-quantum signature scheme, which is the detail most coverage of BIP-360 gets wrong.**

*Published 12 August 2026. The rating below is current as of 2 October 2026. This is a security-readiness assessment, not investment advice.*

The most widely held chain in the world is defended by a draft, and not by the draft most people think.

## What signs a Bitcoin transaction today

Every Bitcoin spend is authorised by one of two signature schemes: ECDSA, there since the beginning, or Schnorr, added with Taproot. Both are built on the same elliptic curve, secp256k1, and both rest on the same hard problem, which is that recovering a private key from a public key requires solving a discrete logarithm.

Shor's algorithm solves that problem efficiently on a sufficiently large quantum computer. There is no version of this where Schnorr saves you and ECDSA does not, because the weakness is in the curve rather than in the signature construction on top of it.

> **Where the exposure actually is.** A Bitcoin address is a hash of a public key, so a coin that has never been spent has not published the key protecting it. Spending publishes the key. Coins in addresses that have already been spent from, and in the very old pay-to-public-key outputs from Bitcoin's first years, are the exposed set. We have seen many figures quoted for how large that set is, and we could not confirm any of them against a primary source, so this piece does not repeat one.

## What BIP-360 actually does

This is the part worth getting right, because most coverage does not. BIP-360 is titled Pay-to-Merkle-Root, and it is a consensus soft fork proposal with status Draft. It circulated earlier under the name Pay-to-Quantum-Resistant-Hash, which is where a lot of the confusion started, because that name suggests something the proposal does not claim.

BIP-360 does not add a post-quantum signature scheme to Bitcoin. What it does is define a new output type that commits only to a script tree's Merkle root, removing Taproot's key path spend, so that a public key is never sitting on chain waiting to be harvested. In its own words, it proposes "a script tree output that is resistant to long exposure attacks as a first step".

The proposal is explicit about what remains undone. It states that protection against more sophisticated quantum attacks "may require the introduction of post-quantum signatures in Bitcoin". So BIP-360 buys time by hiding keys. It does not replace the cryptography that a quantum computer would break.

From the Bitcoin Improvement Proposals themselves, and from Google's published research.

- **December 2024**: BIP-360 is assigned its number as a consensus soft fork proposal with status Draft. Its changelog records the earlier working name Pay-to-Quantum-Resistant-Hash before it became Pay-to-Merkle-Root.
  Source: https://github.com/bitcoin/bips/blob/master/bip-0360.mediawiki
- **February 2026**: BIP-361, Post Quantum Migration and Legacy Signature Sunset, is documented with status Draft. Its header lists a dependency on a "TBD Post Quantum Signature BIP", a proposal that does not yet exist.
  Source: https://bips.dev/361/
- **March 2026**: Google Quantum AI publishes resource estimates for running Shor's algorithm against 256-bit elliptic curves, describing circuits using "less than 1,200 logical qubits" and suggesting fewer than 500,000 physical qubits could do the job in a few minutes.
  Source: https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/

## The proposal that would actually force the issue

BIP-361 is the more consequential document, and it gets a fraction of the attention. It proposes sunsetting Bitcoin's legacy signatures in two phases. Phase A would disallow sending funds to quantum-vulnerable addresses roughly 160,000 blocks, or about three years, after activation. Phase B would then restrict spending from them, about two years after that.

It is candid about the mechanism, describing the aim as turning "quantum security into a private incentive: fail to upgrade and you will encounter additional friction to access your funds". That is a serious proposal with a serious cost attached, and it is the kind of thing Bitcoin argues about for years.

There is a catch that makes the timing plain. BIP-361 depends on a post-quantum signature BIP that has not been written. You cannot migrate people to a scheme nobody has specified, so the sunset clock cannot start until that missing piece exists, is reviewed, and is activated.

## What this means if you hold Bitcoin

Bitcoin is not asleep on this. Two drafts, active research and published resource estimates from a serious quantum lab are more than most chains have. What Bitcoin does not have is a single line of activated consensus code that changes anything about how your coins are protected today.

That gap between attention and deployment is what the rating measures, and it is why a chain can be the most scrutinised in the world and still not rate well here.

**Where this stands today.**

- [Bitcoin](https://hardyindex.com/chains/bitcoin): Tier 4: Debating, Hardy Score 17.0 of 100.

As rated by the Hardy Index, current as of 2 October 2026. Ratings change when the evidence does, and every change is recorded at https://hardyindex.com/changelog.md.

The practical read is unglamorous. Nothing needs doing this week. If you hold coins in addresses you have already spent from, those are the ones whose keys are public, and when a post-quantum output type does eventually activate, moving to it is the step that will matter. Until then, be suspicious of anyone telling you BIP-360 has already solved this.

## Where to go next

- [Bitcoin: the full rating](https://hardyindex.com/chains/bitcoin.md): every dimension score, with the source behind each one.
- [Will quantum computers break Bitcoin?](https://hardyindex.com/guides/will-quantum-computers-break-bitcoin.md): This is the mechanism, explained without the maths. How a quantum computer would actually take coins, how much of Bitcoin is in reach, and what Bitcoin is doing about it.
- [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers.md): If you hold crypto and the quantum headlines have been bothering you, this is the practical version. Four steps, in order, with the limits of each one stated.

## Sources

Every dated event above carries its own primary source. These are those sources, checked on the dates shown.

1. [BIP-360: Pay-to-Merkle-Root (P2MR)](https://github.com/bitcoin/bips/blob/master/bip-0360.mediawiki): Bitcoin Improvement Proposals (primary, checked 12 August 2026)
2. [BIP-361: Post Quantum Migration and Legacy Signature Sunset](https://bips.dev/361/): Bitcoin Improvement Proposals (primary, checked 12 August 2026)
3. [Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly](https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/): Google Quantum AI (primary, checked 12 August 2026)
4. [BIP-340: Schnorr Signatures for secp256k1](https://github.com/bitcoin/bips/blob/master/bip-0340.mediawiki): Bitcoin Improvement Proposals (primary, checked 12 August 2026)

---
Cite as: The Hardy Index, "What Bitcoin is, and is not, doing about quantum", https://hardyindex.com/news/bitcoin-bip-360-reality, published 12 August 2026.
