VERSE PRESS

Crypto News, Global First.

Trump's Quantum Orders Put up to $500 Billion in Bitcoin on a Tighter Clock

President Trump signed two executive orders on June 22 accelerating federal quantum computing investment and demanding government agencies migrate to quantum-resistant cryptography by the end of 2030. For Bitcoin holders worldwide, the orders intensify an already urgent debate: roughly 6.9 million BTC, worth somewhere between $440 and $500 billion, sits in addresses whose public keys are already exposed on-chain and readable by a sufficiently powerful quantum computer, though a quantum computer of a scale not yet built would be required to execute such an attack.

|

The two orders operate on parallel tracks. The first, Executive Order 14411, commits $2 billion to quantum computing development across nine companies, including IBM, and requires the Department of Energy to build a research-grade quantum computer at a national laboratory by 2028, with technical specifications to be finalized within 90 days. The second shortens the federal government's post-quantum cryptography (PQC) migration deadline from 2035 to December 31, 2030 for cryptographic standards adoption and December 31, 2031 for digital signature systems. A Commerce Department pilot must be completed by the end of 2027.

The White House framed the move in geopolitical terms. "Adversarial nations seek quantum capabilities that would use quantum to undermine U.S. economic and national security," the accompanying fact sheet stated. Analysts at Tokenist noted that the compliance pressure will not stop at federal agencies: regulated financial institutions, including cryptocurrency exchanges and custodians operating under US law, will face downstream pressure to upgrade their infrastructure on a similar timeline.

Why Bitcoin's Exposure Is Structural

Bitcoin's security relies on elliptic curve cryptography, specifically the secp256k1 curve, which generates the digital signatures used to authorize every transaction. The timing of when a public key becomes visible on-chain determines which coins are at risk. In the legacy Pay-to-Public-Key (P2PK) format used in Bitcoin's earliest years, a public key is exposed from the moment funds arrive at an address. In the more common Pay-to-Public-Key-Hash (P2PKH) and SegWit formats, the public key appears on-chain only when funds are first spent from that address, at which point it becomes permanently readable. The underlying assumption securing all these formats is that deriving a private key from a known public key is computationally infeasible. Shor's algorithm, run on a fault-tolerant quantum computer, would break that assumption entirely. This is not a matter of needing more classical computing power; it represents a qualitative shift in what is mathematically possible.

The exposure is not hypothetical or uniform. Research group Project Eleven maintains what it calls the Bitcoin Risq List, a real-time tracker of quantum-vulnerable addresses. Their current count is approximately 6.9 million BTC, around 33% of total supply. Of that, roughly 4.99 million BTC (72.3% of the exposed total) comes from address reuse. When an address is first spent from, its public key is recorded permanently on-chain; reusing the same address for additional deposits keeps those funds perpetually associated with an already-exposed key.

A further 1.7 million BTC sits in legacy P2PK addresses, where public keys are exposed from the moment funds arrive. Satoshi Nakamoto's estimated 1.1 million BTC across roughly 22,000 early addresses falls into this category.

Project Eleven projects that Q-Day, the point at which a quantum computer can actually execute this attack, falls somewhere between 2030 and 2033. A March 2026 paper from Google Quantum AI, Stanford, and the Ethereum Foundation found that breaking Bitcoin's elliptic curve cryptography would require fewer than 500,000 physical qubits. Researchers at Caltech and Oratomic placed that threshold as low as 10,000 qubits using neutral-atom architectures.

Separately, Google researchers estimated the attack itself could theoretically be completed in under nine minutes, shorter than Bitcoin's average block confirmation time, meaning a transaction could be hijacked while still in flight before the next block confirms it.

In April 2026, Project Eleven awarded 1 BTC to Italian researcher Giancarlo Lelli, who broke a 15-bit elliptic curve key using publicly available cloud quantum hardware. Bitcoin's secp256k1 curve operates on 256-bit keys, so the demonstration was far from a practical attack, but it marked the largest elliptic curve key broken by a quantum computer to date.

What Is Being Done, and What Remains Undone

The standards that agencies are migrating to are already published. The National Institute of Standards and Technology finalized its core post-quantum cryptography standards, FIPS 203, FIPS 204, and FIPS 205, in August 2024, with a fourth standard, HQC, added in March 2025. The 2030 federal deadline is a mandate to adopt frameworks that already exist.

Bitcoin developers have not been inactive. BIP-360, which introduces a quantum-safe output type called Pay-to-Merkle-Root (P2MR), was merged into Bitcoin's codebase on February 11, 2026. The proposal specifically removes the quantum-vulnerable key-spend path present in Taproot, Bitcoin's major 2021 upgrade, addressing a risk that even relatively recent outputs carry under the current protocol. BIP-360 protects newly created outputs, but to benefit from it, holders with funds in existing vulnerable addresses must actively move those funds to new-format addresses. The roughly 6.9 million BTC already sitting in exposed addresses is not automatically protected.

Project Eleven's May 2026 report put the core problem plainly: "The gap is not technical. The gap is entirely coordination, urgency, and willingness to accept migration costs."

Additional proposals in development include a commit-reveal transaction scheme by Lightning Network co-creator Tadge Dryja, designed to prevent mempool interception of in-flight transactions, and the Hourglass V2 proposal by Hunter Beast, which would limit spending from legacy P2PK addresses to 1 BTC per block to prevent a sudden large-scale drain. Further protocol-level and application-layer approaches are also under active development, including reduced-size hash-based signature schemes and a full mainnet-targeted cryptography replacement currently in testnet, reflecting a development landscape that extends well beyond any single proposal.

Regional Stakes: India, Nigeria, and Kenya

The exposure is not evenly distributed globally, and the regions with the most to lose from delayed action are those with the least institutional protection. India ranked first in the 2026 Chainalysis Global Crypto Adoption Index with approximately 127 million crypto users.

The Indian government has a formal National Quantum-Safe Ecosystem plan under its National Quantum Mission, announced in February 2026. Even so, most Indian retail holders use custodial exchange accounts, meaning their quantum security will largely depend on whether platforms like WazirX and CoinDCX upgrade backend infrastructure. Self-custody holders who migrate to quantum-safe wallet formats would have independent protection, but they represent a smaller fraction of the overall user base. India's financial regulators have not yet issued any quantum-specific requirements for crypto service providers, including the Virtual Digital Asset Service Providers that fall under the oversight of SEBI and the Ministry of Finance.

Nigeria ranked second in the global adoption index, with around 47% of adults holding crypto. Kenya entered the top 20 of the same index for the first time in 2026. Across Sub-Saharan Africa more broadly, stablecoin adoption grew 180% in the past year, and Bitcoin-based remittance networks serve millions of people in the region. AZA Finance, formerly BitPesa, processes cross-border remittances via Bitcoin rails for approximately 6.5 million people across those markets.

These markets tend to have higher rates of peer-to-peer transactions, older wallets, and more address reuse than Western markets, which collectively increases the share of holdings likely sitting in already-exposed addresses.

No government across Sub-Saharan Africa has integrated quantum cryptographic risk into its fintech regulatory framework as of mid-2026.

What Comes Next

The federal deadline of December 31, 2030 now sits just inside Project Eleven's lower bound for Q-Day. If both timelines hold, the margin between "government has migrated" and "quantum computers can break ECDSA" could be very thin, or nonexistent. The federal PQC mandate applies to the US government's own systems, but the implication is broader: the same window that governs sovereign infrastructure is the one in which Bitcoin's most vulnerable holdings must also migrate.

For Bitcoin specifically, the technical solutions exist in early form, but deploying them network-wide requires a coordinated protocol upgrade with broad miner and node operator buy-in. Historically, Bitcoin governance has moved slowly: the SegWit upgrade took over two years and precipitated a chain split that produced Bitcoin Cash.

With the 2030 window closing, the pace of that coordination will determine whether the 6.9 million exposed BTC gets moved to safety or remains a target. For individual holders, the most direct near-term action is to move funds from legacy or reused addresses to new-format addresses once quantum-safe standards are finalized on the network. That migration must be an active choice; it will not happen automatically. African wallet providers including Yellow Card, Paxful, and Bitget Africa have announced no quantum-migration roadmaps as of this writing, leaving a large share of regional users dependent on platforms that have not yet begun preparing.