Bitcoin was at block 950,000 on May 18, 2026, at 21:54:29 UTC, according to the block explorer. That is a historical chain-height marker, not a quantum-computing milestone or a measured count of exposed bitcoin. The central concern is narrower: a sufficiently capable quantum computer could use Shor’s algorithm to recover a private key from an exposed public key, but when—or whether—such a computer will be practical remains uncertain.
What does “quantum exposure” mean for Bitcoin?
Bitcoin transactions are authorized with digital signatures. The relevant quantum threat is that a sufficiently capable quantum computer running Shor’s algorithm could derive a private key from its corresponding public key, potentially allowing an attacker to spend funds controlled by that key. The threat is not that a quantum computer would instantly break every part of Bitcoin at once. The timing and feasibility of a cryptographically relevant quantum computer are not established by the sources cited here.
Exposure depends on the output and its history. Some output types conceal the public key behind a hash until the output is spent; spending reveals the key in the transaction. Reusing keys or outputs can also leave public keys visible. Taproot (P2TR) outputs expose a public key for long-term exposure, according to BIP-360. This is why it is inaccurate to say that every bitcoin is equally exposed, or to declare an individual address safe without examining its output type and history.
Why block 950,000 is not an exposure snapshot
The explorer records block 950,000 as mined on May 18, 2026, at 21:54:29 UTC. The height gives a point of reference in Bitcoin’s history; it does not, by itself, measure how many coins had exposed public keys at that moment. No independent block-950,000 exposure count is established here.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
A separate figure appears in the BIP-361 draft: its authors report that over 34% of all bitcoin had revealed a public key on-chain as of March 1, 2026. That is the proposal authors’ estimate for that date, not a calculation for block 950,000, and its methodology is not independently verified here. Read it as a dated estimate rather than a live network statistic.
How long-exposure and short-exposure attacks differ
Long exposure
A long-exposure attack targets a public key that is already visible on-chain. The attacker may have an extended period to attempt key recovery while the key remains exposed. P2TR is relevant because its output structure exposes a public key, making it a long-exposure concern in BIP-360’s threat model.
Rank #2
Short exposure
A short-exposure attack targets a public key revealed when a transaction is broadcast but has not yet been confirmed. The attacker would need to recover the key quickly enough to act during the mempool interval. BIP-360 says its proposed design does not itself prevent this class of attack; comprehensive protection may require post-quantum signature schemes.
What BIP-360 proposes—and what it does not
BIP-360 proposes Pay-to-Merkle-Root (P2MR), a script-tree output type that removes Taproot’s key-path spend. Its stated aim is to mitigate long-exposure attacks by avoiding that key-path public-key exposure. It is a proposed first step, not a complete quantum-proofing solution: it does not prevent short-exposure attacks by itself, and it would require wallets and services to support the new output type.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteRank #3
The proposal’s authors describe the uncertainty directly: “While it is unclear when or if CRQCs will become viable in the future, we propose the addition of a quantum-resistant, script tree output type for those interested in this level of protection.” That is the rationale for a proposal, not a claim that the design is deployed or that quantum risk has a known deadline.
What BIP-361 proposes for migration
BIP-361 takes a broader approach: a staged migration from legacy signatures toward post-quantum scripts, followed by tighter requirements for ECDSA and Schnorr verification. Its draft describes an initial period in which spending from legacy scripts to post-quantum scripts is permitted, then a later phase that restricts legacy signature verification.
Rank #4
| Proposal element | What the draft describes | What it means for users |
|---|---|---|
| Phase A | Begins 160,000 blocks after hypothetical activation. | A proposed migration period, not a calendar date currently in force. |
| Phase B | Begins two years after Phase A. | A proposed later tightening of legacy-signature acceptance, also dependent on activation. |
The schedule is illustrative and measured from hypothetical activation; it is not an active Bitcoin deadline. Any such change would require network adoption and would involve holders and services moving funds and changing how legacy signatures are accepted.
Are these proposals active Bitcoin rules?
No. The BIPs index lists BIP-360 as draft and BIP-361 as draft informational. The index cautions that being listed does not imply adoption, community consensus, or endorsement. Neither proposal should be treated as current consensus rules or as a wallet feature that is already available.
Free tools Windows power users keep installed
One-click scans. No signup required.
What NIST’s post-quantum standards mean for Bitcoin
The U.S. National Institute of Standards and Technology (NIST) has released three finalized post-quantum cryptography standards. NIST recommends that organizations begin migrating systems to quantum-resistant cryptography. That is general guidance for cryptographic systems; it does not mean Bitcoin has adopted those standards or that a Bitcoin migration is already underway.
NIST’s guidance is: “Organizations should begin applying these standards now to migrate their systems to quantum-resistant cryptography.” Bitcoin’s protocol and wallet ecosystem would still need their own proposals, implementations, and adoption process.
What Bitcoin holders should do now
- Do not infer that a particular address is categorically safe or vulnerable from its appearance alone; exposure depends on output type and transaction history.
- Do not treat P2MR or BIP-361’s migration stages as available protection or active deadlines. Both proposals remain drafts in the BIPs index.
- Follow official proposal status and wallet release information before making a change based on quantum-risk claims. The evidence here does not establish a specific wallet’s compatibility.
- Be skeptical of claims that identify a date for “Q-day.” The cited sources do not establish when a cryptographically relevant quantum computer will exist.
Bottom line
At block 950,000, the quantum issue was a protocol-design and migration question—not evidence that Bitcoin had been broken or that a fixed deadline was approaching. The specific concern is key recovery from exposed public keys; exposure varies with output type and history. BIP-360 and BIP-361 outline possible responses, but both are drafts, and neither is current network policy.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

