Google Quantum Paper: Bitcoin Keys Cracked in 9 Minutes, 6.9M BTC at Risk

Google Quantum Paper: Bitcoin Keys Cracked in 9 Minutes, 6.9M BTC at Risk

N
News Editor 01
2026-07-22 17:55:14
Google's Quantum AI paper reveals cracking Bitcoin ECDSA requires under 500K qubits in ~9 minutes, exposing 6.9M BTC. Banks and SWIFT share the same vulnerability, but Bitcoin's decentralized upgrade path faces unique hurdles.
quantum computingBitcoinECDSAelliptic curve cryptographyGoogle Quantum AI

Google's Quantum AI team released a whitepaper on March 30 that sent shockwaves through the crypto market. The research found that cracking Bitcoin's elliptic curve cryptography could require fewer than 500,000 physical qubits — a 20-fold reduction from previous estimates. A sufficiently powerful quantum computer could derive a private key in roughly nine minutes, faster than Bitcoin's average ten-minute block confirmation. This puts around 6.9 million BTC, whose public keys are already exposed, directly in the crosshairs. Bitcoin's Taproot upgrade, which makes public keys visible by default, has widened that exposure further.

9 Minutes to Crack a Private Key

The paper details how Shor's algorithm can efficiently factor large integers, directly threatening elliptic curve digital signature algorithms. When a public key is visible, quantum computation can reverse-engineer the private key in minutes. Previously, the industry thought millions of qubits were needed; Google's new method slashes that estimate dramatically. The crypto community reacted swiftly. Dragonfly's Haseeb Qureshi posted on X: "Post-quantum is no longer a drill."

Banks and SWIFT: The Same Math in the Crosshairs

Bitcoin's quantum problem is not unique. SWIFT transfers, stock exchanges, banking infrastructure, military communications — all rely on the same underlying elliptic curve cryptography. If a quantum computer can crack a Bitcoin wallet, it can read your bank's encrypted traffic just as easily. In that sense, Bitcoin is not special.

Bitcoin's Upgrade Dilemma: Decentralization's Achilles' Heel

The paper directly addresses Bitcoin's weakness: centralized systems (banks, SWIFT, governments) can push software updates overnight; Bitcoin cannot. SWIFT is already working on post-quantum protection. U.S. federal agencies are mandated to be quantum-safe by 2035. Google targets 2029 for its own systems. Bitcoin has no equivalent authority. BIP 360, the leading quantum-resistance proposal, is running on testnet. However, a full migration to post-quantum signatures would mean signatures 10 to 100 times larger than current ones, dramatically reducing transaction throughput per block.

Binance founder CZ laid out the challenge: "It's hard to organize upgrades in a decentralized world. There will likely be many debates on which algorithm(s) to use, resulting in some forks." He also raised the question of Satoshi's Bitcoin: if those coins don't migrate to quantum-resistant wallets, they become a sitting target for the first quantum attacker.

Harvest Now, Decrypt Later

The most immediate threat is not a quantum computer cracking wallets today, but the "harvest now, decrypt later" strategy — adversaries collecting encrypted data now, planning to decrypt it once the hardware catches up. For millions of Bitcoin with already-exposed keys, that process may have already begun. StarkWare's Eli Ben-Sasson offered a sober perspective: "FUD is claiming Bitcoin can't adapt. It can adapt. Just need to start working on these solutions today."

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.