1.7 Million BTC Have Exposed Public Keys, and Dragonfly Says Migration Won't Save Them
Dragonfly's Haseeb Qureshi is pushing back on the bunker-mode crowd who think they can just move their coins if AI cracks cryptographic signatures. He's right, and the reason why is buried in Bitcoin's oldest addresses. Here's the mechanics, the numbers, and why the market is pricing this at zero.
I keep a short list of things that could actually end this cycle. It has three entries. Macro liquidity, ETF flows, and the one nobody brings up at dinner. That third one got louder recently.
Haseeb Qureshi over at Dragonfly pushed back on what he calls bunker mode thinking. His argument, stripped down, is this. If AI gets good enough to break cryptographic signatures, moving your coins to a fresh address or a different chain doesn't save you. It hands an attacker a new set of keys to crack. Proactive protocol-level work is the only thing that matters.
That's not a doomer take. It's the opposite of one. And it's correct.
The Mechanics Nobody Bothers To Explain
Here's the part most coverage skips. Bitcoin doesn't hide your public key forever. The moment you spend from an address, the public key is on chain, permanently. ECDSA on secp256k1 assumes you can't reverse a public key back to a private key. That assumption is doing an enormous amount of work.
Older outputs are worse. Early pay-to-public-key addresses broadcast the public key from day one, before a single satoshi moves. Estimates put roughly 1.7 million BTC in those early formats with keys already sitting in the open. Satoshi's own stash, somewhere around 1.1 million coins, is the biggest single chunk of that. Nobody can move it. Nobody can protect it either.
Now separate the two threats, because people mash them together and get sloppy. Grover's algorithm cuts the effective strength of a hash in half. SHA-256 drops to something like 128-bit security. Still out of reach for anything we've built. Shor's algorithm breaks ECDSA outright. That's the real one.
And AI isn't necessarily going to be the thing that runs Shor's. AI shows up earlier, in the messy layer underneath. Automated vulnerability discovery. Side-channel attacks at scale. Finding the weak entropy in a hardware wallet's key generation. Firmware flaws in a signing device. Those attacks don't need a quantum computer. They need a machine that never gets bored.
So when someone says we'll just migrate, ask them a simple question. Migrate to what? The new address uses the same signature math. The new chain uses the same signature math. And now you've published a transaction trail and a fresh public key in one move.
The Market Is Pricing This At Zero
Crypto is a market north of 2 trillion dollars in total value on a quiet day. Institutional allocators are doing diligence on custody, on key management, on insurance. I can tell you from watching the chart on the weekly that tail risks like this get ignored right up until they don't.
Historically speaking, the market reprices slow-moving structural risks about 18 to 24 months before anything actually resolves. Look at how ETH priced the Merge. Look at how miners priced the halving. The crowd is early on narratives and late on plumbing.
Who wins here? Builders who ship hybrid signature support now, without waiting for a consensus fight. NIST finalized three post-quantum standards back in August 2024, FIPS 203, 204 and 205. Lattice-based and hash-based schemes that are sitting there, tested, and barely used in production wallets. A chain that wires those in as an opt-in address type looks paranoid today and looks prescient in a downturn.
Who loses? Anyone whose pitch is bunker mode. Fear sells newsletters. It doesn't sell infrastructure. And the chains that treat this as somebody else's problem are the ones holding the biggest bag of unmovable coins.
The other loser is the just fork it crowd. Bitcoin's last two big upgrades, SegWit in 2017 and Taproot in 2021, took years of argument and coordination. A signature scheme change is harder than both. You're touching every wallet, every exchange, every hardware device, every custody provider on earth. That's not a weekend patch.
So is this a 2026 problem or a 2040 problem? Honest answer, nobody knows, and that's exactly why it's a problem. Surveys of cryptographers have put the odds of a cryptographically relevant quantum machine inside a decade somewhere between 20 and 30 percent. Those same experts have been wrong before in both directions.
What I'd Actually Do With This
If you're trading, add one line to your screening checklist. Does the project have a published, funded path to post-quantum signatures, or is the answer a blog post from 2023? That question will separate real infrastructure from vibes over the next two cycles.
If you're building, don't wait for consensus. Ship hybrid keys in your wallet today. Give users a signing path that doesn't collapse if ECDSA does. The cost is engineering time. The cost of waiting is that you're the last one holding exposed keys.
If you're just holding coins in self-custody, this isn't a reason to panic sell. It's a reason to pay attention to which wallets are actually doing the work.
And if you're long BTC, the invalidation point sits at the protocol level, not the price level. If BTC holds this level of developer attention on signatures, the market won't ever get a chance to price the alternative. If it doesn't, you'll find out what happens when 1.7 million coins with public keys on display become a target instead of a curiosity.
The chart is the chart. But the chart assumes the chain still works. That assumption deserves more scrutiny than it gets.
Explore More
Key Terms Explained
An approval term meaning authentic, bold, or worthy of respect.
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
The net amount of money entering or leaving exchange-traded funds, closely watched in crypto since spot Bitcoin ETFs launched in January 2024.
Who holds and controls your crypto assets.