On March 31, Google issued a security warning revealing that quantum computers may crack the elliptic curve cryptography (ECC) securing Bitcoin and other cryptocurrencies with far fewer resources than previously thought — from roughly 20 million qubits down to under 500,000. The company urged the entire crypto industry to migrate to post-quantum cryptography (PQC) by 2029.
Quantum threat accelerating
Classical computers would take longer than the age of the universe to break SHA-256, but quantum bits (qubits) exploit superposition to achieve exponential speedup. Using novel error-correction methods, Google has slashed the logical qubits needed to solve the 256-bit Elliptic Curve Discrete Logarithm Problem (ECDLP-256) by nearly a factor of 20. This means major governments, tech firms, and eventually even small organizations could wield such power.
Google stated: "We demonstrate that future quantum computers could break elliptic curve cryptography — used to protect cryptocurrencies and other systems — using fewer qubits and gates than previously anticipated. We want to raise awareness and offer the crypto community guidance for enhancing stability and security before such an event occurs."
Migration timeline and industry collaboration
Google has set 2029 as the target for migration, partnering with Coinbase, the Stanford Blockchain Research Institute, and the Ethereum Foundation. The company used zero-knowledge proofs to responsibly disclose the vulnerability to the U.S. government, allowing validation without providing a roadmap for attackers. Google emphasized that while no cryptocurrency cryptography has been broken yet, technological progress is rapidly lowering the attack threshold.
SHA-256's broader impact
SHA-256 underpins not only Bitcoin digital signatures but also website certificates, password storage, digital signatures, firmware updates, and general internet security. A quantum break of SHA-256 would threaten far more than cryptocurrencies — government secrets, banking infrastructure, and cloud services would be at risk. Google noted that dormant Bitcoin holdings are not the most immediate target, but proactive mitigation is critical.
Ethereum and Bitcoin readiness
Ethereum's development team has already included quantum resistance in its roadmap, with full upgrades expected before 2029. Bitcoin faces a harder consensus challenge due to rigid interpretations of immutability — as seen with Taproot and Ordinals controversies. However, the community's long-term survival drive is likely to eventually adopt SHA-512 or more advanced algorithms. Industry experts agree that building quantum-resistant cryptography is easier than building quantum computers, and both BTC and ETH can transition smoothly if the industry acts in time.

