← Builder hub
QTC Exposure LabThe quantum-exposure auditor
Read-only Never signs
Apps

Is your crypto harvestable today?

A quantum computer running Shor's algorithm breaks ECDSA and secp256k1 โ€” the signatures guarding Bitcoin and Ethereum. Attackers don't need the quantum computer yet: any address whose public key is already on-chain can be harvested now and broken later. This lab audits your addresses โ€” Bitcoin, Ethereum, and Quantus โ€” and tells you exactly where you stand before Q-Day.

โ˜ข EXPOSED โ€” key on-chain โš  LATENT โ€” safe until first spend โ—‹ CLEAN โ€” never used โฌข SAFE โ€” post-quantum

Q-Day estimates live in the Threat Lab. Post-quantum cryptography, explained, lives in Quantum Shield.

Threat model

How an address becomes harvestable

โ˜ข Exposed

The public key is on-chain today. Harvest now, break at Q-Day.

  • Bitcoin: any address that has spent โ€” P2PKH/P2WPKH spends publish the key. P2PK and Taproot (P2TR) outputs carry the key from funding โ€” no spend needed.
  • Ethereum: any address that has sent โ€” the ECDSA signature reveals the key via the recovery id.
  • Other Substrate chains: the SS58 account id is the raw 32-byte public key. Exposed by design.

โš  Latent

Funded, but the key is still hidden behind a hash. Safe โ€” until the first spend.

  • A fresh P2PKH/P2WPKH address that has only ever received.
  • An Ethereum address with inbound transfers but zero outgoing transactions.
  • Fragile by design: one spend/send publishes the key permanently. Terrible for cold storage measured in years.

โ—‹ Clean

Never touched on-chain. Nothing to harvest โ€” there is no public key anywhere yet.

  • Freshly generated addresses with zero history.
  • Stays clean only until first use. Generate, fund, and then don't spend โ€” or better, move to the safe column.

โฌข Safe

Post-quantum signatures. Shor's algorithm has nothing to chew on.

  • Quantus (SS58 prefix 189): ML-DSA-65/87 (NIST FIPS 204) from the genesis block.
  • Checksum-verified locally โ€” no chain lookup needed to prove it.
The auditor

Scan your addresses

Paste Bitcoin, Ethereum, or Quantus addresses โ€” one per line (up to 25). Validation runs locally in your browser; chain history is fetched from public APIs. Nothing is signed, nothing leaves except the lookups you asked for.

Ctrl/โŒ˜ + Enter to run
Migration playbook

From harvestable to quantum-safe

1

Audit everything

Run every address you control through the auditor above โ€” including old cold-storage addresses you haven't touched in years. Address reuse is the #1 exposure source.

2

Rank by risk

Exposed + funded first, then latent + funded. An exposed address with a balance is harvestable today; a latent one becomes exposed the moment you spend from it.

3

Generate fresh Quantus keys

Use the Key Forge to mint ML-DSA keypairs and checksum-verified SS58 (prefix 189) addresses. Post-quantum from the first block โ€” no ECDSA anywhere in the stack.

4

Move in stages

Send a small test amount, verify arrival in the Block Explorer, then move the rest. For large migrations, Reversal Desk scheduled transfers add a cancellable safety window.

5

Retire, don't reuse

Never spend from the old addresses again โ€” every spend re-publishes the key. Treat retired addresses as radioactive: look, don't touch.

Methodology

What this lab claims โ€” and what it doesn't

What is exact

  • Address validation is computed locally: SS58 checksum = blake2b-512("SS58PRE"โ€–body)[0..2] (crypto vendored from the Address Toolkit, verified 2026-09-29 against the Quantus genesis vesting table); bech32 per BIP-173 and bech32m per BIP-350; Base58Check via double-SHA-256. 40/40 node tests green.
  • The exposure rules: spent Bitcoin outputs reveal the key (P2PKH/P2WPKH); P2PK and P2TR outputs carry the key at funding; Ethereum signatures leak the key via the recovery id; non-Quantus SS58 account ids are raw public keys.

What is estimated

  • USD "at risk" uses CoinGecko simple/price at audit time; if the feed is offline the estimate is skipped, never guessed.
  • The P2PK/P2TR output scan covers the first page of address history (25 txs) from mempool.space; deeper history relies on the spent-output counts, which are complete.
  • Q-Day itself is unknowable โ€” see the Threat Lab for the estimate range, not a date.

What we did not do

  • No signing, no key handling, no wallet connection โ€” this lab is read-only. It cannot move your funds and never asks for secrets.
  • No verdict without chain data: if an API is unreachable the address gets UNKNOWN, not a guess. Sample mode is always labeled SAMPLE DATA with illustrative figures.
  • Not financial advice. A "safe" verdict means quantum-safe โ€” it says nothing about price, custody, or counterparty risk.

Sources: mempool.space REST API (address + txs), BlockCypher Ethereum API (Blockscout v2 fallback), CoinGecko simple/price, NIST FIPS 204 (ML-DSA), BIP-173 / BIP-350, Quantus-Network/chain (SS58 prefix 189).