Bitcoin's Biggest Quantum Risk Isn't Wallet Keys, Warns VC Andrew Gault

Bitcoin's Biggest Quantum Risk Isn't Wallet Keys, Warns VC Andrew Gault

N
News Editor 01
2026-07-22 20:20:14
VC Andrew Gault warns the crypto industry's quantum focus on wallet keys is misplaced; the real threat is encrypted data already flowing across exchanges, bridges, and custodians—harvested now for later decryption once quantum computing matures.
bitcoinquantum computingcryptographic securityharvest now decrypt laterpost-quantum cryptography

Quantum computing's threat to Bitcoin has centered on private keys, but venture capitalist Andrew Gault argues a more urgent vulnerability lies in the encrypted messages already moving between exchanges, bridges, and custodians every day.

Gault, CEO of networking firm ZeroTier and a founding partner at deep-tech VC 7percent Ventures, told CoinDesk: "The financial system's most dangerous vulnerability isn't stored data, it's the data moving between institutions right now." He stressed that interbank messages, payment authentication records, and digital signatures are being collected by sophisticated adversaries who don't need to read them yet—only to decrypt once quantum capability crosses the threshold.

'Harvest Now, Decrypt Later' Targets Live Traffic

The strategy, known in cryptography as "harvest now, decrypt later," assumes adversaries store encrypted traffic cheaply until a sufficiently powerful quantum computer arrives. Google's Quantum AI research in March 2025 showed a quantum computer could derive a Bitcoin private key from an exposed public key in about nine minutes, sparking discussion about the 6.9 million BTC sitting in exposed addresses. But Gault says the bigger threat is authentication data already intercepted on the open internet.

Google's own security engineers aligned with that view. In a March 2025 post, VP of Security Engineering Heather Adkins and senior cryptography engineer Sophie Schmieg reprioritized the company's threat model toward authentication services and digital signatures—the same wire-level signing infrastructure Gault highlighted. The post stated: "The threat to encryption is relevant today with store-now-decrypt-later attacks." Google set 2029 as its target for completing post-quantum cryptography migration.

Cross-Chain Bridges and Exchange APIs Under the Same Threat

Citibank modeled a quantum attack on a top-five U.S. bank's access to Fedwire payment system in February 2025, estimating a cascade of $2 trillion to $3.3 trillion—10% to 17% of real GDP. The Global Risk Institute, cited in the same report, put the probability of a cryptographically relevant quantum computer arriving by 2034 at 19% to 34%.

For crypto, the attack surface at the wire level is broader than wallets. Cross-chain bridge proofs, exchange API authentication packets, signed transactions in public mempools, and cold-storage signing traffic all fall under the same vulnerability spectrum. CoinShares argued in February 2025 that wallet-key risks are overstated, estimating only about 10,200 BTC are concentrated enough to move markets if stolen.

Gault's concern is different: "The authentication records being harvested aren't just sensitive—it's the proof layer that determines who owns what, who authorized which transaction, and who bears legal liability." Ethereum has initiated a coordinated post-quantum migration, but Bitcoin and major exchanges and custodians have not publicly committed to one.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.