Roughly 5.6 million bitcoin, according to on-chain data tracked by firms like Chainalysis and Glassnode, have not moved in more than a decade. At current prices, that dormant supply is worth hundreds of billions of dollars. It sits in wallets protected by the same elliptic-curve cryptography that a sufficiently powerful quantum computer could, in theory, break wide open.
Over the past several months, the possibility of preemptively freezing those coins before they can be stolen has surfaced in Bitcoin developer discussions, research forums, and public commentary. Longtime Core contributor Peter Todd has discussed the implications of lost and dormant coins in public interviews and on social media, while security researcher Jameson Lopp has written about quantum risk to Bitcoin wallets on his personal blog and in conference talks. No formal freeze proposal has been submitted to Bitcoin’s improvement process. But the conversation itself has rattled traders and long-term holders, because it forces the market to reconsider a foundational assumption: that every bitcoin ever mined will remain spendable by whoever controls the private key.
The quantum threat is no longer theoretical
The debate is grounded in measurable progress. A May 2025 paper on projected quantum factoring costs modeled how quickly the resources needed to break widely used cryptographic schemes are falling as both hardware and algorithms improve. Rather than treating quantum risk as a far-off abstraction, the researchers framed it as a cost curve that can be tracked year by year and that is declining faster than many cryptographers expected a decade ago.
Bitcoin’s exposure is specific. The network uses the Elliptic Curve Digital Signature Algorithm (ECDSA) to prove ownership of funds. A quantum machine powerful enough to run Shor’s algorithm could, in principle, derive a private key from an exposed public key. Research examining quantum attack timelines against elliptic-curve systems has explored exactly this scenario, though estimates of when such an attack becomes practical still span from under a decade to several decades.
Washington is not waiting for certainty. On August 14, 2024, the National Institute of Standards and Technology published FIPS 203, a module-lattice-based post-quantum cryptography standard, alongside companion standards FIPS 204 and FIPS 205. This was not advisory guidance. It was a formal federal directive, a signal that the U.S. government considers existing public-key cryptography to be on a countdown clock. The same family of math protects Bitcoin wallets.
Security analysts also point to the “harvest now, decrypt later” threat: adversaries can record encrypted data and exposed public keys today, then crack them once quantum hardware matures. That model is a core reason NIST acted years before any quantum machine can break production-grade keys, and it applies directly to Bitcoin’s permanently recorded blockchain.
Why dormant coins are uniquely exposed
Not every bitcoin wallet faces the same level of risk. Wallets that have never sent a transaction expose only a hashed version of their public key, which adds a meaningful layer of defense. But wallets that have broadcast at least one outgoing transaction have their full public key permanently recorded on the blockchain. A quantum attacker would not need to break the hash; the raw key is already visible, waiting to be reversed.
Many of the oldest and largest dormant wallets fall into that second category. Among them are addresses widely attributed to Bitcoin’s pseudonymous creator, Satoshi Nakamoto. Researcher Sergio Demian Lerner’s Patoshi pattern analysis estimates that Satoshi mined roughly 1.1 million coins, none of which have ever moved. If quantum hardware eventually reaches the threshold needed to crack ECDSA keys, those exposed wallets would be the lowest-hanging fruit. The prospect of a sudden, massive transfer of long-dormant coins onto the open market is what drives the repricing fear.
One critical gap in the debate: no widely cited, Bitcoin-specific audit has publicly quantified how the dormant supply splits between hashed-only addresses and those with fully exposed public keys. Without that breakdown, estimates of actual quantum-vulnerable supply remain rough.
It is also worth noting that newer Taproot outputs, introduced in Bitcoin’s November 2021 upgrade, use Schnorr signatures. These keep the public key hidden until the moment of spending, but Schnorr is also vulnerable to Shor’s algorithm. Taproot buys time; it does not solve the underlying problem.
The governance problem may be harder than the math
Even if the quantum threat timeline shortened dramatically, freezing dormant coins would require changing Bitcoin’s consensus rules. That means a hard or soft fork, agreement among miners, node operators, and the broader user base, and a willingness to override what many in the community consider an inviolable property right: if you hold the key, you control the coins.
Bitcoin’s history offers little precedent for this kind of intervention. The network has never retroactively restricted access to valid unspent transaction outputs. Developers have discussed lost and dormant coins publicly for years, but proposals to act on them have consistently met fierce resistance. The philosophical core of Bitcoin, that it operates without a central authority capable of seizing or freezing funds, makes any such move politically explosive regardless of the technical justification.
Among security-focused researchers, the more common recommendation is voluntary migration: wallet holders would move their funds to quantum-resistant address formats once those formats are available, rather than having old outputs disabled by protocol fiat. A 2024 draft proposal known as BIP-360 (QuBit), authored by Hunter Beast, sketches out a pay-to-quantum-resistant-hash address type designed for exactly this kind of migration. It does not propose freezing dormant coins, but it represents the most concrete step toward quantum readiness that has entered Bitcoin’s formal improvement process.
The challenge is obvious: owners of truly dormant wallets, whether the keys are lost, the holders deceased, or the accounts simply forgotten, cannot migrate voluntarily. That is the gap a freeze would theoretically fill, and the gap that makes the idea so contentious.
What the market is actually pricing
For traders, the immediate risk is not a quantum computer breaking Bitcoin tomorrow. It is the narrative shift. Markets reprice assets on changing assumptions, and the assumption that all 21 million bitcoin (minus those provably burned) will eventually circulate is embedded in every valuation model. If a credible proposal to freeze even a fraction of the dormant supply gained traction, the effective circulating cap would shrink, potentially pushing prices sharply higher for liquid coins while raising existential questions about censorship resistance.
The opposite scenario carries its own shock. If the freeze debate stalls or is rejected and quantum-capable machines arrive before the network migrates to post-quantum signatures, the sudden unlocking of billions of dollars in previously inaccessible bitcoin could flood exchanges with sell pressure. Either outcome represents a discontinuity, a break from the steady-state assumptions that underpin current pricing.
Where the debate stands in spring 2026
As of May 2026, no Bitcoin Improvement Proposal specifically targets dormant-coin freezing. BIP-360 addresses quantum-resistant addresses but leaves the question of unmigrated coins open. The quantum cost curves are declining, yet no publicly documented machine has broken a cryptographic key anywhere near the size Bitcoin uses in production.
Two signals are worth watching closely. The first is progress in NIST’s post-quantum rollout across federal systems, which will set the pace for how urgently the broader technology industry, including open-source projects like Bitcoin Core, treats migration timelines. The second is any formal discussion that surfaces on Bitcoin’s development mailing list or within the BIP process proposing concrete action on exposed dormant outputs.
Until one of those channels produces something tangible, the freeze scenario functions less as imminent policy and more as a stress test, one that reveals just how difficult it will be for a decentralized network to make collective decisions when the stakes involve rewriting the rules of ownership itself.