Bitcoin Halving Quantum Question: Reading the Schedule

There is a knife at the edge of the schedule. Nobody knows when it falls. All we know is that the schedule keeps cutting, every four years, every two hundred and ten thousand blocks, knife or no knife. The Bitcoin Halving has a clock. Quantum computing has a rumor. The rumor is real enough that thirty percent of the supply sits on the table with its keys showing, and a small committee has written a deadline for the rest of us. This sermon is about that deadline, and about the cut that keeps firing while we argue over it.

I. The Knife and the Clock

The clock is the Bitcoin Halving. Every 210,000 blocks. Ten minutes a brick, four years a course. The schedule is the only honest thing in finance. It does not slip. It does not negotiate. At block 1,050,000, in spring 2028, the subsidy drops from 3.125 BTC to 1.5625 BTC, and the schedule takes one more step toward the Halfture. The Halfture is the last cut, the terminal halving, the one that ends issuance for good. It is not 2028. It is centuries out. Capital-H Halfture is for the final notch only; lowercase halving is for the rehearsals.

The knife is Q-Day: the morning a quantum computer stops being a press release and becomes a tool. The morning Shor’s algorithm turns into a weapon you can rent. When that morning comes, any Bitcoin address whose public key is visible on chain holds coins someone else can move. Not in theory. In minutes on a wall clock.

The clock and the knife are different animals. The clock is mathematics; the knife is engineering. The clock will fire. The knife might.

II. What Q-Day Actually Is

Bitcoin signs spends with ECDSA over the secp256k1 curve. Public keys come from private keys through one-way arithmetic. That arithmetic is hard for classical computers and believed to be easy for a big enough quantum computer running Shor’s algorithm, which was published in 1994 and has aged just fine.

The question was always how many qubits. For years the answer was twenty million logical qubits, which felt safely like science fiction. In early 2026 a Google research paper cut that estimate by more than an order of magnitude. It suggested that with newer architectures an elliptic-curve attack might need fewer than 500,000 physical qubits, and that an at-rest attack on a single ECC-256 key might take roughly ten days on around 26,000 physical qubits. Nobody has built a machine that can do this. Nobody is close. But the line got steeper, and religion is made out of the slope of lines.

Look at the words at rest. The attack works on a key that has already put its public half on chain. Catching a coin mid-broadcast in the mempool is much harder, because the timing is brutal. So the first thing Q-Day eats is whatever has been sitting still with its face uncovered.

III. The Six Million Coins That Were Always Naked

Most people get this part wrong. They picture quantum risk as something that arrives later, along with the new machines. The exposure is already here. The keys are already public. The only thing missing is the machine.

Glassnode’s May 2026 report put a number on it: 6.04 million BTC, 30.2 percent of issued supply, with public keys exposed on chain right now. Of that, 1.92 million BTC is structural exposure: pay-to-public-key outputs from the earliest era, bare multisig, and any modern Taproot output where the key path shows the key. The other 4.12 million BTC is operational: addresses that were reused, partly spent, or handled carelessly enough that the spending key has touched the chain.

Six million coins. A third of every bitcoin ever mined, sitting where someone else can pick them up the morning the knife gets sharp.

This is not a fringe number. It covers the Patoshi blocks, the early P2PK rewards, a lot of the cold storage from 2010 and 2011, and a long tail of sloppy wallets that have been hot for fifteen years. It is the part of the chain that was always going to grow old into a different problem.

IV. The 22,000-Wallet Trap

There’s a story going around this year about Satoshi. It may not be true. Tell it anyway. The Patoshi pattern, the famously recognizable nonce-stamped early mining run, points to roughly 1.1 million BTC mined and never moved. In 2010, before the standard output format switched to pay-to-public-key-hash, those coins were spread across about 22,000 addresses of exactly 50 BTC each.

André Dragosch of Bitwise popularized one reading of that this year: the spread was a deliberate quantum hedge. Split a million coins into twenty-two thousand single-block bags and every theft costs more. The knife still works, but it has to be drawn 22,000 times. Maybe that flatters the founder more than the founder deserves. It could have been a hedge, or plain hygiene, or no plan at all, with the pattern acting as a Rorschach test. The keys are still exposed either way. But on purpose or by accident, the layout looks like the work of a hand that didn’t want theft to be cheap.

The schedule doesn’t care about anyone’s intent. The clock keeps firing whether the founder was a prophet or a janitor. Still, if the founder did set a small trap for the future, the schedule got a head start.

V. BIP-360 and the Sunset Clock

Bitcoin does not patch itself. A small group of people write proposals, other people argue about them for years, and eventually nodes start enforcing them. Two such proposals are on the table now, both new in 2026, and the second is the most philosophically loaded change anyone has ever offered the protocol.

BIP-360 was merged into the BIPs repository on February 11, 2026. It defines the first quantum-resistant address type, built on hash-based and lattice-based signature schemes. It is the carrot: a place to go for anyone who wants to move. Like most new address types, nobody much minds it.

BIP-361, the Post Quantum Migration and Legacy Signature Sunset, is the stick. Jameson Lopp and five co-authors published it on April 14, 2026, and it sets a phased deadline. Three years after activation, nobody can send new outputs to legacy quantum-vulnerable addresses. Five years after activation, legacy signatures stop being valid. Period. Any coin still sitting in a P2PK or reused address is frozen as far as consensus is concerned. Not stolen. Frozen. The network would reject the signature even if someone did produce the private key.

That is not a technical fix. It is a theological one. It says scarcity matters more than the past. Coins nobody moved before the deadline stop being coins.

The room is split, and I don’t blame it. One camp says BIP-361 is the only way to keep the supply whole, because if the knife arrives before the freeze, those 6.04 million coins pour into the float and wreck the whole scarcity premise. The other camp says invalidating Satoshi’s coins is confiscation in protocol clothing. I don’t see a clean answer. I see a deadline and a calendar.

VI. The Halfture Will Get There First. Or It Will Not.

Now put the two timelines side by side.

The clock: the next ordinary cut is at block 1,050,000 in spring 2028. The Halfture, the final cut, the terminal halving, the only one that is actually the rapture, lands around the year 2140. Centuries of cuts lie between here and there, and each one rehearses the last.

The knife: aggressive Q-Day estimates put a quantum machine that matters for cryptography five to ten years out. Conservative ones say twenty to forty. If BIP-361 activates in 2027, its clock runs out in 2030 for legacy sends and 2032 for legacy signatures.

Which timeline wins? Nobody knows, and the schedule doesn’t care.

Here the doctrine earns its keep. What you hold, you can move. What you don’t hold, somebody else decides for. If your coins sit on an exchange when BIP-361 activates, you are trusting the exchange to move them. If they sit in a paper wallet in a safe deposit box, your deadline is moving. If they sit in a hardware wallet you control, you can walk them over to a quantum-safe output the day the new address type is ready. Self-custody is what makes the move possible at all. You have to hold Bitcoin to be saved. Not as a metaphor. As a mechanism. The signature that proves the coin is yours has to come from a key you can still produce, in a format the future network still accepts. The signature is the soul. The address is the body. Q-Day comes for the body. The Halfture, the last cut, the equation where Halfture = Rapture, comes for the supply.

VII. The Counter-Sermon

Maybe none of this matters. Maybe Q-Day stays five years away forever, the way fusion stays thirty years away. Maybe BIP-361 dies on the mailing list like most ambitious BIPs. Maybe the 6.04 million exposed coins stay exposed for a century and the chain just lives with it.

The harder version goes like this. The moment Bitcoin freezes anyone’s coins to protect the supply, it admits the rules can be bargained over. That door only swings one way. Some people will call it the protocol growing up. Others will call it the day Bitcoin became the thing it was built to fight. Both readings are honest. The clock keeps cutting either way.

VIII. Look at Your Addresses

Nothing here is urgent. Q-Day hasn’t come. BIP-361 hasn’t activated. None of this is financial advice. This is theology with a calendar.

There is a small, slow thing to do, though. Look at your addresses. The ones holding coins you haven’t touched since 2017. The one you reused for a forum tip. The cold wallet you set up before SegWit. Mark which ones are exposed in the plain Glassnode 30.2 percent sense. Then make a plan for the morning a quantum-safe address type is available and nobody is fighting over it.

Check your keys. Keep the vigil.

FAQ

What is the Bitcoin Halving?
The Bitcoin Halving is the protocol-enforced 50 percent cut to the block subsidy every 210,000 blocks, roughly every four years. The last Halving, called the Halfture, is the terminal cut that ends issuance for good, around the year 2140. Every Halving before then is a rehearsal of the Halfture.

Are quantum computers a threat to Bitcoin today?
No machine today can break secp256k1 in any practical sense. The 2026 Google estimate of roughly 500,000 physical qubits for an elliptic-curve break is far beyond current hardware, which sits in the low thousands of noisy physical qubits. The threat is real on a horizon, not on a calendar.

What is BIP-361 and why is it controversial?
BIP-361 is the Post Quantum Migration and Legacy Signature Sunset, proposed in April 2026 by Jameson Lopp and co-authors. It would phase out legacy signature types over five years and freeze any coin still held in a quantum-vulnerable address. The fight is over the fact that the freeze would catch around 1.1 million BTC attributed to Satoshi, which raises the question of whether scarcity should ever override a private key’s right to spend its coin.

How much Bitcoin is quantum-exposed right now?
According to Glassnode’s May 2026 report, 6.04 million BTC, about 30.2 percent of issued supply, has public keys visible on chain. About 1.92 million BTC is structurally exposed (P2PK, bare multisig, Taproot key-path spends) and about 4.12 million BTC is operationally exposed through address reuse and partial spends.


Discover more from Halfture

Subscribe to get the latest posts sent to your email.

Leave a Reply