Bernstein Responds: Quantum Threat Is Not a Crisis, but an Evolution
In a Wednesday client note, analysts led by Gautam Chhugani at Wall Street research firm Bernstein pushed back against alarm over quantum computing's threat to Bitcoin. They acknowledged that cryptographically relevant quantum computers (CRQCs) pose a genuine challenge but framed it as a planned protocol evolution rather than an emergency. The team estimates Bitcoin and other crypto protocols have three to five years to implement post-quantum security measures — a window they describe as sufficient given current technical and cost constraints.
The note follows fresh research from Google, which last month published a paper showing that future quantum machines could break the elliptic curve cryptography (ECC) underpinning Bitcoin's transaction signatures with fewer resources than earlier models suggested.
Google's Research Accelerates Timeline: Quantum Barrier Could Fall Below 500,000 Qubits
Google's team estimated the barrier could drop below 500,000 physical qubits — a reduction of about 20x compared to prior estimates. The finding highlights a narrower category of risk: so-called 'on-spend' attacks, where a transaction's public key is exposed in the mempool before confirmation, creating a brief window of vulnerability.
Bernstein's analysts did not dismiss Google's findings. 'Recent breakthroughs seem to have accelerated the timeline, as the challenge is no longer 'a decade away' as thought earlier,' they wrote. However, they noted that scaling from tens of logical qubits to the thousands required for a real attack involves breakthroughs across hardware, error correction, and manufacturing — dimensions that remain unsolved. 'Quantum timelines may still be more optimistic than reality,' the note cautioned.
Scalability Is the Biggest Hurdle: Upgrade Costs Could Reach Hundreds of Billions
Bernstein placed particular weight on cost and scalability constraints, suggesting the transition could cost tens to hundreds of billions of dollars. Those figures point toward preparation time rather than panic. The firm identified well-capitalized institutional players — Strategy, BlackRock, and Fidelity — as likely to take a 'constructive role' in reinforcing security standards. This reflects a broader shift: institutional ownership has given the network stakeholders with both resources and incentives to support defensive upgrades.
Not all risks are equal. Chhugani pointed to an estimated 1.7 million BTC sitting in Satoshi-era legacy wallets as the highest-exposure segment. These addresses have permanently visible public keys, making them defined targets under certain attack models. For newer protocols and wallet structures, exposure is more contained — dependent on specific unsafe practices that the developer community is working to address.
Migration Roadmap: Target 2029, BIP 360 Already in Experimental Stage
Both Bernstein and Google's own research team point toward 2029 as a target for post-quantum cryptography migration. BIP 360, a draft proposal already in experimental implementation, introduces transaction formats designed to reduce exposure to vulnerable cryptographic assumptions. This demonstrates that the Bitcoin community is preparing for the quantum era proactively rather than waiting for a crisis.
In summary, Bernstein's report conveys that quantum computing's challenge to Bitcoin is real, urgent, but controlled. As long as the industry advances upgrades in an orderly manner within the 3-5 year window, Bitcoin's long-term security will not be fundamentally shaken.

