Is your crypto harvestable today?
A quantum computer running Shor's algorithm breaks ECDSA and secp256k1 โ the signatures guarding Bitcoin and Ethereum. Attackers don't need the quantum computer yet: any address whose public key is already on-chain can be harvested now and broken later. This lab audits your addresses โ Bitcoin, Ethereum, and Quantus โ and tells you exactly where you stand before Q-Day.
Q-Day estimates live in the Threat Lab. Post-quantum cryptography, explained, lives in Quantum Shield.
How an address becomes harvestable
โข Exposed
The public key is on-chain today. Harvest now, break at Q-Day.
- Bitcoin: any address that has spent โ P2PKH/P2WPKH spends publish the key. P2PK and Taproot (P2TR) outputs carry the key from funding โ no spend needed.
- Ethereum: any address that has sent โ the ECDSA signature reveals the key via the recovery id.
- Other Substrate chains: the SS58 account id is the raw 32-byte public key. Exposed by design.
โ Latent
Funded, but the key is still hidden behind a hash. Safe โ until the first spend.
- A fresh P2PKH/P2WPKH address that has only ever received.
- An Ethereum address with inbound transfers but zero outgoing transactions.
- Fragile by design: one spend/send publishes the key permanently. Terrible for cold storage measured in years.
โ Clean
Never touched on-chain. Nothing to harvest โ there is no public key anywhere yet.
- Freshly generated addresses with zero history.
- Stays clean only until first use. Generate, fund, and then don't spend โ or better, move to the safe column.
โฌข Safe
Post-quantum signatures. Shor's algorithm has nothing to chew on.
- Quantus (SS58 prefix 189): ML-DSA-65/87 (NIST FIPS 204) from the genesis block.
- Checksum-verified locally โ no chain lookup needed to prove it.
Scan your addresses
Paste Bitcoin, Ethereum, or Quantus addresses โ one per line (up to 25). Validation runs locally in your browser; chain history is fetched from public APIs. Nothing is signed, nothing leaves except the lookups you asked for.
From harvestable to quantum-safe
Audit everything
Run every address you control through the auditor above โ including old cold-storage addresses you haven't touched in years. Address reuse is the #1 exposure source.
Rank by risk
Exposed + funded first, then latent + funded. An exposed address with a balance is harvestable today; a latent one becomes exposed the moment you spend from it.
Generate fresh Quantus keys
Use the Key Forge to mint ML-DSA keypairs and checksum-verified SS58 (prefix 189) addresses. Post-quantum from the first block โ no ECDSA anywhere in the stack.
Move in stages
Send a small test amount, verify arrival in the Block Explorer, then move the rest. For large migrations, Reversal Desk scheduled transfers add a cancellable safety window.
Retire, don't reuse
Never spend from the old addresses again โ every spend re-publishes the key. Treat retired addresses as radioactive: look, don't touch.
What this lab claims โ and what it doesn't
What is exact
- Address validation is computed locally: SS58 checksum = blake2b-512(
"SS58PRE"โbody)[0..2] (crypto vendored from the Address Toolkit, verified 2026-09-29 against the Quantus genesis vesting table); bech32 per BIP-173 and bech32m per BIP-350; Base58Check via double-SHA-256. 40/40 node tests green. - The exposure rules: spent Bitcoin outputs reveal the key (P2PKH/P2WPKH); P2PK and P2TR outputs carry the key at funding; Ethereum signatures leak the key via the recovery id; non-Quantus SS58 account ids are raw public keys.
What is estimated
- USD "at risk" uses CoinGecko
simple/priceat audit time; if the feed is offline the estimate is skipped, never guessed. - The P2PK/P2TR output scan covers the first page of address history (25 txs) from mempool.space; deeper history relies on the spent-output counts, which are complete.
- Q-Day itself is unknowable โ see the Threat Lab for the estimate range, not a date.
What we did not do
- No signing, no key handling, no wallet connection โ this lab is read-only. It cannot move your funds and never asks for secrets.
- No verdict without chain data: if an API is unreachable the address gets UNKNOWN, not a guess. Sample mode is always labeled SAMPLE DATA with illustrative figures.
- Not financial advice. A "safe" verdict means quantum-safe โ it says nothing about price, custody, or counterparty risk.
Sources: mempool.space REST API (address + txs), BlockCypher Ethereum API (Blockscout v2 fallback), CoinGecko simple/price, NIST FIPS 204 (ML-DSA), BIP-173 / BIP-350, Quantus-Network/chain (SS58 prefix 189).