How Quantum Computing Could Break Bitcoin
A new report from Galaxy Digital offers the Bitcoin community a sobering picture: the risk posed by quantum computing is real, but so is the work underway to protect the network. The research frames the issue as a long-term engineering and governance challenge rather than an imminent crisis. Developers are already building tools that could reshape how the network secures trillions in value.
At the heart of the concern is a simple premise. Bitcoin relies on cryptographic signatures to prove ownership. Those signatures, based on elliptic curve cryptography, are secure against classical computers. But a sufficiently advanced quantum machine could break that assumption, allowing an attacker to derive a private key from a public one and spend funds without authorization. The scenario has a name: “Q-day,” the moment a cryptographically relevant quantum computer becomes viable. The timeline remains uncertain, with estimates ranging from years to decades. The report stresses that uncertainty is the problem: Bitcoin’s decentralized structure means upgrades take time, often measured in years, not months. Risk is uneven: most Bitcoin is not exposed today. Wallets only reveal public keys when funds are spent, meaning coins sitting untouched behind hashed addresses remain shielded. Vulnerability emerges in two main cases: coins whose public keys are already visible on-chain, and coins in transit during a transaction.
Which Bitcoin Is Actually at Risk?
Galaxy cites estimates that millions of bitcoin could fall into the first category, including funds tied to early network activity and long-dormant wallets. These coins, often associated with early adopters and even Satoshi Nakamoto, present a unique challenge. If quantum capabilities arrive before protective measures are deployed, such holdings could become prime targets. The implications extend beyond individual losses: a sudden unlocking of dormant supply could ripple through markets, placing pressure on price and mining incentives. The report frames this as systemic risk, not just a technical flaw. Yet the tone is measured. It points to a growing body of preparatory work. One prominent proposal is a new transaction structure called Pay-to-Merkle-Root, outlined in BIP-360. The design removes a key exposure point by eliminating always-visible public keys, reducing the attack surface. Other ideas take a broader approach. “Hourglass” attempts to manage fallout from vulnerable coins by limiting how quickly they can be spent in a worst-case scenario. There is also movement toward new cryptography: hash-based signature schemes like SPHINCS+ have emerged as candidates for a post-quantum future, relying on different mathematical assumptions.
Post-Quantum Cryptography Brings Tradeoffs
The tradeoff is efficiency: larger signatures could increase transaction sizes and strain network resources. In parallel, developers are exploring contingency plans. One proposal introduces a commit-and-reveal process to protect transactions even if a quantum breakthrough occurs before new cryptography is deployed. Another line looks at zero-knowledge proofs to allow users to verify ownership without exposing sensitive data. Together, these efforts suggest a layered defense. No single fix solves the problem; the strategy resembles a toolkit with protections aimed at different stages of exposure. The harder question may be governance. Bitcoin has no central authority. Every upgrade requires coordination among developers, miners, exchanges, and users. Past changes like SegWit and Taproot took years and sparked debate. Quantum preparedness could prove even more complex. Some proposals touch on sensitive issues: whether coins that fail to migrate to safe formats should lose spendability. Such ideas raise philosophical questions about property rights and the network’s social contract. However, the report notes a key difference: quantum risk is external. It does not divide the community along economic lines or competing visions. Instead, it presents a shared threat. Every participant, from holders to infrastructure providers, has an incentive to maintain security. The outcome will hinge less on when quantum computers arrive and more on whether a decentralized network can coordinate in time. The answer, as with much of Bitcoin’s history, will emerge through slow consensus rather than sudden change.

