The ledger remembers what the hype forgets. Over the past week, crypto Twitter has burned through two narratives at the speed of a CNBC segment: IBM CEO Arvind Krishna's assertion that quantum computers could crack Bitcoin's secp256k1 encryption within three to four years, and Jim Cramer's announcement that he is selling his Bitcoin. Both stories generated headlines. Neither survived contact with the data. Bitcoin's price barely moved — a one-to-two percent wobble that traders absorbed within hours — and funding rates stayed flat across major exchanges. The market was not scared. It was annoyed. And buried beneath both stories sat a number that matters far more than either man's words.
As of March 1, 2026, more than 34% of all Bitcoin in circulation has already exposed its public keys on-chain.
That figure comes from BIP-361, a draft improvement proposal authored by Casa CTO Jameson Lopp and five co-authors. It is not a worst-case projection. It is not a hypothetical model. It is an audit of what the blockchain already reveals to anyone with a node and a weekend. Every P2PK output from Bitcoin's earliest era, every spent P2PKH address that reused a change output, every legacy transaction that broadcast its public key as a necessary step in spending — all of it sits in the permanent record, waiting for a computational capability that does not exist anywhere on Earth yet.
Bridging the gap between code and community means starting from what is verifiable. What is verifiable is this: the quantum threat to Bitcoin is real but distant, the current panic is misdirected, and the actual urgency lies in a governance problem this ecosystem has never successfully solved — coordinating a protocol-level cryptographic migration without a central authority to impose a deadline.
The Panic Began With an Earnings Story
The chain of events began in the executive suite, not the laboratory. In a CNBC appearance, Krishna linked IBM's quantum computing roadmap to the company's revenue acceleration, predicting that quantum systems would deliver meaningful commercial returns by 2028 or 2029 and suggesting Bitcoin's cryptography would fall within a comparable window. It was a forecast tied to capital markets, not a peer-reviewed paper. The conflict of interest is worth stating plainly: IBM's quantum division is a multi-billion-dollar investment that needs a revenue narrative, and nothing sells quantum computing to corporate boards like the possibility of breaking Bitcoin. Krishna's timeline aligns suspiciously well with IBM's financial calendar. Academic estimates from Google Quantum AI and Stanford are considerably more conservative.
Cramer, a longtime Bitcoin skeptic, reacted in character — announcing he was dumping his Bitcoin. The market barely flinched. There was good reason. Cramer did not confirm the sale had been executed. He did not disclose position size. He offered no wallet address. As an on-chain event, the declaration had zero verifiable weight. As a sentiment event, it rippled across a media ecosystem that still treats late-night cable opinion as institutional signal.
The irony was instantaneous and measurable. A segment of traders view Cramer's bearishness as a guaranteed contrarian buy signal — the famous "Inverse Cramer" trade. The empirical record says that strategy is broken. Tuttle Capital's Inverse Cramer ETF, which systematically bets against Cramer's recommendations, has lost approximately 15.7% since inception while the S&P 500 has climbed 25.4%. If systematically mirror-flipping Cramer worked, the product would be profitable. It is not.
A more useful finding comes from a 2012 Management Science study: stocks featured on Cramer's show rally roughly 2.4% overnight, then surrender the entire move within twelve trading days. The durable edge, if one exists, is not in betting against Cramer's long-term views. It is in fading the overnight retail bump his commentary produces. That is a market-maker's trade, not a retail thesis. Cramer's track record on Bitcoin specifically is no better. In December 2022, at the absolute depths of the bear market, he dismissed Bitcoin with contempt — at $16,796, within a whisper of the cycle bottom. His instincts are not a contrarian signal. They are a lagging indicator of retail sentiment extremes. The sprint ends, but the chain remains.

The Actual Threat, Quantified
Let me be precise, because precision is the only adequate antidote to quantum FUD.
Secp256k1, the elliptic curve securing every Bitcoin private key, is safe today. An actual break demands approximately 1,200 to 1,450 logical qubits and between 70 million and 90 million Toffoli gates, per a collaborative estimate from Google Quantum AI, Stanford University, and the Ethereum Foundation. That is a serious research coalition, and their numbers are the current industry benchmark. For the non-specialists reading this: a logical qubit is an error-corrected qubit — the meaningful unit of computation. Physical qubits, the noisy hardware in cryostats, number in the thousands already. The gap between physical and logical is exactly why quantum computing still lives in laboratories rather than in production systems.
Compare the attack estimate to IBM's recent experiment with the University of Chicago: a 70-logical-qubit error-corrected circuit executing 468 T-gates over roughly sixteen minutes. This was a hardware fidelity milestone, proving that error-corrected circuits can execute at a statistical lower bound of reliability. It demonstrated nothing about cracking a 256-bit curve. The gap between IBM's demonstration and a genuine attack is approximately twenty times in logical qubits and five orders of magnitude in gate count. Five orders of magnitude is the difference between one second and eleven and a half days. People who tell you Bitcoin is on the verge of quantum collapse have either not read the estimates or are selling a different narrative entirely.
That said, the honest assessment is not comforting. The gap will close. IBM's own roadmap assumes error correction scales aggressively over the coming years. Google has signaled its own timeline. And the technology is advancing faster than the ecosystem's ability to migrate. I have seen this dynamic before — in my audit of ICO tokenomics in 2017, I learned that the most dangerous risks are not the ones announced in whitepapers, but the ones embedded in timelines nobody checks. The same lesson applies here. The question is not whether quantum computing will eventually threaten Bitcoin's cryptography. The question is whether Bitcoin's governance will have prepared the migration path before the threat arrives.
That migration path is not simple. A quantum-resistant Bitcoin would need a signature scheme that can withstand Shor's algorithm — candidates include hash-based constructions like Lamport signatures, lattice-based schemes, and variants of FALCON or SPHINCS+. Each comes with tradeoffs in signature size, verification speed, and consensus complexity. Each would require a soft fork, a full node upgrade, and years of ecosystem coordination. BIP-361 does not even attempt to solve this entire problem. It focuses on the first, narrowest step: labeling and identifying addresses at risk so migration can be measured and planned.
The 34% Question
This is where BIP-361 becomes the most underreported story in the entire quantum discussion.
The proposal does not attempt to solve quantum resistance outright. It addresses the immediate vulnerability window: the 34% of Bitcoin supply sitting in addresses whose public keys are already public. Should a quantum adversary capable of breaking secp256k1 ever arrive, those funds fall first. Not simultaneously, and not by some sudden chainwide event. But first. Bitcoin that has never moved from an address whose public key has never been revealed retains a meaningful obscurity advantage. Exposed public keys have permanently surrendered that advantage.

This creates an ordering problem that almost no mainstream coverage has acknowledged. Quantum risk is not uniformly distributed across Bitcoin. It is concentrated in the oldest, most historically active layers of the supply — UTXOs spent from at least once, legacy addresses with reuse patterns, and the P2PK outputs of the 2010-2012 era. That means mitigation is not a single coordinated event. It is a per-holder decision to migrate into new address formats, executed across a user base that includes long-dormant whales, institutional custodians, and retail investors who may not know what a public key is.
Based on my experience translating DeFi primitives in the 2020 "DeFi Decoded" series, the hardest part of any migration is not the technology — it is the education. A migration requires millions of users to understand why moving funds matters, how to do it safely, and when. Bitcoin has no support desk. No forced updates. No central bank circular. It has documentation, community, and time. That time is the scarcest resource in the entire equation.
The regulatory clock makes that scarcity explicit.
NIST's draft guidance proposes prohibiting 128-bit curves like secp256k1 in federal systems after 2035. The Hong Kong Monetary Authority requires banks to be quantum-ready by 2030. These deadlines are not binding on Bitcoin — a decentralized protocol cannot be ordered to upgrade — but they bind the institutions that custody, lend, and trade Bitcoin. Here is the structural mismatch no one is discussing: a full migration to quantum-resistant signatures requires the BIP process, wallet and SDK updates across every client, exchange deposit and withdrawal infrastructure changes, hardware wallet firmware revisions, and user action across millions of addresses. Realistic timeline: five to ten years. HKMA deadline: 2030. If custodians take that deadline seriously, they will begin demanding quantum-ready addresses from the Bitcoin ecosystem within the next two to three years. It will not be a quantum computer that forces the issue. It will be an auditor.
The Contrarian Read: Compliance as Catalyst
Now the contrarian angle. The same narrative pressuring Bitcoin could become the most bullish governance story of the decade.
Bitcoin has never executed a security-critical upgrade under external regulatory pressure. SegWit and Taproot emerged from years of internal deliberation, contested but ultimately organic. A quantum-preparedness migration would require the same BIP process but with an external clock — and would force the network to confront a failure mode it has never faced. If Bitcoin successfully coordinates a cryptographic upgrade against a regulatory deadline, it would deliver the strongest possible proof of its governance resilience. The network that cannot be ordered around would demonstrably respond to a shared existential threat. That is the kind of autonomous, self-preserving behavior that institutional allocators pay a premium for. Culture is the new collateral, and a demonstrated capacity for coordinated security migration would be the ultimate proof of that culture's value.
The second contrarian point concerns the 34% figure itself. I suspect it is a floor, not a ceiling. BIP-361's methodology captures what is visible on-chain, but legacy address usage among long-term holders — P2PK outputs, reused addresses, exchange change-address habits — likely means the true exposed percentage runs higher. The draft is honest about its limitations. That honesty is exactly why the BIP process still works. Transparency is the only consensus that lasts, and the more complete the accounting, the more credible the eventual migration plan becomes. If the true exposure is, say, 40% or 45%, the urgency is not marginally higher — it is categorically higher, because the migration queue gets longer and the window gets tighter.
There is also a third point that mainstream coverage has entirely missed: the Ethereum Foundation's involvement in the quantum risk estimates. The same research coalition that produced the secp256k1 numbers did so with Ethereum's cryptography in view. Any post-quantum migration framework that Bitcoin adopts will likely become the template for Ethereum and every other major chain. Bitcoin, the most conservative network in the industry, is effectively the beta test for the entire cryptocurrency ecosystem's quantum response. That is a burden — and an opportunity — that has not been priced into any token.
What to Watch
The next 12 to 24 months will reveal more than Krishna's 2028 revenue forecast or Cramer's next exit announcement. Watch three signals.
First, BIP-361's progression from draft to formal review — whether Bitcoin Core maintainers signal openness to a quantum-resistant output type, and whether the discussion produces developer consensus or stalls in bikeshedding. The pace of that conversation is the single best leading indicator of Bitcoin's quantum readiness.
Second, whether U.S. spot ETF custodians begin publishing quantum risk disclosures in periodic filings. The moment a Coinbase or a Fidelity compliance document mentions post-quantum preparedness, the narrative stops being theoretical and becomes a line item in institutional risk frameworks. Given Bitcoin's clear commodity status under CFTC precedent, custodians carry the compliance burden — and that burden will translate into protocol pressure.
Third, whether on-chain migration to Taproot (P2TR) addresses accelerates as a measurable metric. Rising P2TR usage is the clearest signal that actual behavior is shifting, not just commentary. Right now, migration is proceeding at a trickle. Watch whether it becomes a flood.
Narratives move markets faster than blocks. The quantum story will return in waves — with every research milestone, every regulatory update, every cable segment where a host asks a CEO about the end of cryptography. The ledger remembers what the hype forgets. And right now, what the hype is forgetting is that 34% of Bitcoin is already standing in the first line of a migration queue that Bitcoin has not yet agreed to form.
The sprint ends, but the chain remains. That is not a threat model for today. It is a coordination problem for a decade. The chain is already telling us who goes first. The only question left is whether Bitcoin's governance will catch up to its own ledger before the clock does.