Is your bitcoin safe from quantum computers if it's on an exchange?
Updated August 6, 2026
A lot of people figure that if their bitcoin sits on an exchange, the whole quantum computing question becomes someone else's problem, quietly handled by a company with more engineers and more urgency than they'll ever have. That's half right. Exchange custody does change who has to act on a quantum threat and how fast they can move, but it doesn't erase the underlying exposure sitting inside the addresses your coins actually live in. It just moves the decision out of your hands.
custody is the real fork in the road
Quantum risk to bitcoin isn't really about the asset. It's about specific addresses and whether their public key is already visible on-chain, since a future sufficiently capable quantum computer running Shor's algorithm could, in theory, work backward from an exposed public key to the private key that controls it. Addresses that have never spent, and Taproot addresses, which commit to a real public key the moment they receive funds, sit at different points on that exposure spectrum. We go through the mechanics of this in more depth in our main explainer on quantum risk, including why nobody's address is in danger today.
When you hold your own keys, that exposure is yours to track and yours to fix, one address at a time, whenever you decide to move funds. When an exchange holds your coins, none of that is visible to you at all. Your balance is a database entry. The actual on-chain addresses holding the exchange's reserves, and their exposure tier, are the exchange's business, not something reflected anywhere on your account page.
what an exchange can do that you can't
There's a genuine advantage to centralization here. An exchange's funds tend to sit across a relatively small, deliberately managed set of hot and cold wallet addresses rather than millions of individually owned ones. If a credible, near-term quantum threat ever materialized and a safer address format existed to move to, an exchange could plan and execute that migration as a handful of large, coordinated transactions. A self-custody holder has to know their address type, understand why it matters, and actually get around to moving funds, and a lot of people never do any of the three. Centralized custody, in that narrow sense, can act faster and more uniformly than millions of scattered individuals ever could.
That's the strongest honest argument for leaving coins on an exchange through a period like this: someone whose job is watching this problem is watching it on your behalf, with the operational ability to respond quickly if it ever becomes urgent.
what you're trusting when you leave it there
The tradeoff is that "someone is watching it" becomes an assumption you're making about a company, not a fact you can verify. You're trusting their engineering priorities, their read of a genuinely uncertain timeline, and their internal security choices, none of which are visible to an outside customer. You can't check the exposure tier of the exchange's actual reserve addresses the way you can check your own. If you self-custody, you can paste your address into a tool like our wallet exposure checker and see, right now, whether it's ever revealed a public key and which exposure tier that puts it in. With an exchange, that visibility simply doesn't exist for you as a customer. You're one balance line among many, inside wallets you'll never get to inspect.
There's also a plainer, older risk sitting alongside the quantum question: pooled exchange hot wallets are already high value targets for conventional hacks, entirely separate from anything involving quantum computers. Concentrating custody solves one class of coordination problem while keeping the other one exactly where it's always been.
| Question | Custodial (exchange) | Self-custody |
|---|---|---|
| Who decides when to migrate address formats | The exchange, on its own schedule | You, whenever you choose |
| Can you check your own exposure tier today | No, reserve addresses aren't visible to customers | Yes, directly on-chain |
| Speed of migrating funds once a safer format exists | Fast, a small number of large sweeps | Depends entirely on you acting |
| What you're depending on | The exchange's competence and priorities | Your own attention and follow-through |
where things actually stand right now
It's worth being plain about the timeline, because there isn't a firm one. No quantum computer that exists today, or that's credibly expected within the next few years, comes close to breaking secp256k1 fast enough to threaten a real address. Serious estimates for when a cryptographically relevant quantum computer might exist range from several years to a decade or more, and treating that as settled in either direction would be dishonest. Meanwhile roughly 5.4 million BTC, about a quarter of all bitcoin that will ever exist, already sits in addresses with an exposed public key, including an estimated 1.1 million BTC tied to Satoshi-era mining that's been dormant since around 2010. Proposals like BIP-360 and BIP-361 are still drafts, not adopted rules, aimed at giving Bitcoin a quantum-resistant address format and a path to get funds into it. Part of that conversation is genuinely uncomfortable: some proposals would eventually restrict spending from long-dormant, exposed addresses if they're never migrated, which cuts against Bitcoin's long-standing norm that nobody gets to decide whose coins are allowed to move. Whichever way that debate lands will apply to exchange-held coins exactly as it applies to everyone else's, since it happens at the protocol level, not the custodian level.
For the fuller mechanics behind why an exposed public key matters in the first place, see our main explainer on quantum risk to bitcoin.