CatBitcoin
A close-up of a paper notebook open on a wooden desk, with handwritten rows of transaction hashes and sat amounts in a ledger, the open page lit by warm daylight from a side window.

P2PKH, the never-revealed pubkey, and who actually owns the bill

The UTXO set still keeps the box closed, even when the key does not

Updated 6 October 2026

That is the UTXO set holding the cryptographic state of a box independent of the key. It is not a question of who has the wallet today.

How a P2PKH box keeps its key hidden

A pay-to-pubkey-hash output locks coins behind OP_DUP OP_HASH160 <pubkeyhash> OP_EQUALVERIFY OP_CHECKSIG. The hash is twenty bytes. The public key, by construction, only enters the witness when somebody tries to spend. Before the spend, the chain carries the hash, the spend condition, and the sat amount. It does not carry the key material. A block explorer that walks historical transactions can read the scriptPubKey of every P2PKH output back to 2010, and none of those scripts contains the public key that opens the box. The key is reconstructed at spend time, inside the signing device, and only the signature, the public key, and the hashed time-lock contract cross the wire.

Compare that with pay-to-pubkey, the original 2009 style. Coinbase rewards in the first eighteen months of Bitcoin paid to raw public keys, not hashes. The key sat in the chain from the moment the output was created. Every full node on earth has carried it for fifteen years, and a sufficiently long-lived quantum adversary could already have recorded it. P2PKH is the moment the protocol decided to keep keys in pockets instead of on coats.

That is the basis of the closed-box framing on this site. A box is closed when the chain does not contain the material an attacker needs to forge a signature. P2PKH outputs whose coins have never moved are still closed at the script level, regardless of who has the wallet today.

A row of sealed manila envelopes on a shelf in a quiet archive interior, each one labelled with a short alphanumeric string, the light falling across the row in soft afternoon glow.

What the 2026 UTXO census actually says

Research published in the second quarter of 2026 by the Bitcoin Research Lab and corroborated by a parallel audit from River put the never-revealed P2PKH set between 1.7 and 2.1 million BTC, depending on the cut-off date and the definition of "revealed". A revealed key, in that audit, is any public key that has been broadcast as part of a valid signature on the longest chain. Outputs that were created after the spend of an earlier P2PKH output can inherit revealed parent keys, but only if the child output itself has been spent.

That number is the floor. It is the amount of bitcoin that the chain itself cannot help an attacker with. It is also a number that can only go down. Every time a P2PKH coin moves, the public key of the spending input joins the chain forever, the box opens, and the new output carries that exposed state forward unless the destination script is a fresh hash.

For the post-quantum conversation, this is the figure that matters. Roughly two million bitcoin is the only remaining stock of boxes that are closed at the script level. Everything else, every P2PKH output that has been spent, every P2WPKH and P2TR output, every SegWit-v0 and SegWit-v1 spend, is already open.

Why the bill falls on the next owner, not the last

This is the part that gets misreported. A common framing in October 2026 commentary is that Bitcoin will need a one-time migration in which old owners move their coins to a post-quantum script before a deadline. The framing is wrong in a specific way: the deadline does not bind old owners, it binds the people who inherit their boxes. The chain does not have a concept of owner continuity. A P2PKH output with a never-revealed key is closed regardless of which custodian, exchange, or descendant wallet now claims the coins. The cryptographic state of the box is the chain's, not the wallet's.

What changes after a quantum break is the economics of staying closed. A box that is closed at the script level is, by the rules of the protocol, a box that can only be opened by the holder of the matching private key. After a quantum break, a holder of the private key is one of two parties: the original signer, or anyone who can run Shor's algorithm against the public key. The latter cannot run Shor against a hash, because the chain has not given them a public key to invert. The closed boxes are, in the post-quantum world, the only ones that the original signer still uniquely controls.

That is why the bill for the open boxes falls on whoever next holds them. An open box is, by definition, a box whose key material is already in the chain. The person who last signed for those coins had no choice about the disclosure; the chain required the signature. The person who accepts the open box in a future transaction has the choice, and the choice is whether to keep the box open or to close it again by sending the coins to a fresh script whose key has not yet been broadcast. The old owner cannot migrate for the new owner. The protocol does not let them.

The 2026 standards fight, in plain custody terms

Two proposals sat on the standards track in October 2026. BIP 360, the P2MR draft that introduces a post-quantum signature scheme at the consensus layer, and QSB, a wallet-level scheme that wraps existing key material without a fork. The two are not in conflict at the script level; they compete at the level of which boxes they can actually close.

P2MR, as drafted in the September 2026 revision, can close a box that is currently open, and it can keep a fresh box closed. It cannot retroactively close a box that was opened in 2014. The only way to close that box is to spend it into a P2MR output, which requires the holder of the current private key to sign. If that holder is a long-lost wallet from a defunct exchange, the coins are, in practice, unmovable, and the box stays open in the only way that matters for the post-quantum ledger: the key material stays on the chain, the coins stay where they are, and the cryptographic state of the box does not change until somebody with a working key appears.

QSB, by contrast, never moves coins. It is a key-rotation scheme that produces new signatures from a combination of classical and post-quantum material, both held by the same wallet. A QSB migration can close an open box in the sense that the next spend uses a post-quantum-friendly signature, but the box is, in the strict script sense, still open: the public key behind the new signature is still on the chain, and a quantum adversary still has the material they need. QSB buys a soft-fork-free upgrade path. It does not buy a closed box.

The honest summary is the one that has not changed on this site since the standards fight began. The closed boxes are the boxes whose owners moved first, or whose owners never moved at all. The open boxes are the boxes whose owners waited, and the wait is now structural.

What an owner of a never-revealed P2PKH box should actually do

Three rules, in priority order, all of them custody mechanics rather than price commentary. First, do not move the coins. The act of spending is the act of opening. Any send, any consolidation, any change-output sweep, any wallet migration that touches a P2PKH input reveals the public key behind the input on the chain for the rest of Bitcoin's life. Until a post-quantum output type is widely deployed and a quorum of economic nodes is signalling for it, the rational custody posture for a never-revealed P2PKH box is to leave it where it sits, in cold storage, on a hardware signer that has never produced a signature for those coins.

Second, verify the script type with a tool that walks the raw chain rather than a wallet's cached database. The 2.1 million BTC figure is a count of outputs whose spending conditions have never been revealed. A wallet that imports a P2PKH address from a reused seed can report a balance that includes outputs whose parent keys have already been broadcast. The Esplora API, the mempool.space backend, and the Bitcoin Core gettxoutsetinfo RPC can all distinguish the two states. The point of the audit is that the chain can.

Third, plan the migration, but not yet. The P2MR draft is not merged. The economic signalling for any post-quantum fork in October 2026 is partial. A migration that happens before the standards are stable moves the box from closed to open without the destination script giving the owner anything they did not already have. A migration that happens after the standards are stable and after a meaningful share of the economy has upgraded moves the box from closed to a new kind of closed. The first is a loss. The second is a swap.

The accounting, and why it cannot be soft

There is a temptation, in the post-quantum discussion, to treat the 2.1 million BTC as a community resource that will eventually be redistributed to active holders. The temptation has a name: the dormant-key claim, sometimes called the quantum recovery proposal. Under the proposal, a future fork would treat any output whose public key has been revealed but whose private key has not produced a recent signature as spendable by a special script, with the proceeds redirected to a treasury or burned.

The proposal fails on custody mechanics before it fails on politics. A box is closed at the script level, not at the wallet level. The chain does not know who owns a box. The chain does not know whether a key has been used recently, because the chain does not know which keys exist until they sign. A fork that tries to identify dormant keys is a fork that has to introduce a new oracle, and the new oracle is, by construction, a trusted third party. The closed-box framing on this site is the opposite of that: the protocol, not the policy, decides which boxes are open. The 2.1 million BTC that is still closed is closed because the chain says so, and the chain says so because the relevant material has never been signed. No committee can decide that differently without breaking the property the boxes were closed under in the first place.

That is the part of the post-quantum story that the price charts do not capture. The closed boxes are closed by the chain, and the open boxes are open by the chain, and the difference is recorded in the UTXO set rather than in any custodian's books. The 2.1 million BTC figure is not a count of lost coins. It is a count of coins whose cryptographic state is still controlled by the same person who first locked them, because the chain has not been forced to reveal who that person is.

Quick answers

How can I tell whether a P2PKH output I control is still closed?
Ask a chain walker whether the address has ever appeared as an input in a confirmed transaction. If it has not, the public key has not been revealed and the box is still closed. If it has, every descendant output is open at the script level.
Does moving coins to SegWit close a box that was already open?
No. A P2WPKH spend requires the public key as part of the witness, and the destination output is a hash of a key, not a key. The destination is closed at the script level, but the parent key is still on the chain, and any future spend of the new output will re-reveal it.
Will a future fork make dormant coins spendable?
Any such fork would require a new oracle to decide which keys are dormant, and the oracle would be a trusted third party by construction. The closed-box framing rejects that move at the protocol level.