Google's 9-Minute Quantum Bitcoin Claim Points to a Bigger Threat Than Mempool Attacks

Google's 9-Minute Quantum Bitcoin Claim Points to a Bigger Threat Than Mempool Attacks

N
News Editor 01
2026-07-22 19:45:13
Google's Quantum AI team said a future quantum computer could derive a Bitcoin private key in about nine minutes. The deeper risk is not just intercepting pending transactions, but the 6.9 million BTC already sitting in wallets with exposed public keys.
BitcoinQuantum ComputingGoogleTaprootPost-Quantum Cryptography

Google's Quantum AI team said this week that a future quantum computer could derive a Bitcoin private key from a public key in about nine minutes. That figure spread fast and rattled markets, but it does not mean Bitcoin would suddenly fail in nine minutes. It describes a narrow attack window tied to transactions waiting in the mempool before they are confirmed on-chain.

The nine-minute claim is about racing Bitcoin's confirmation clock

When a user sends bitcoin, the wallet signs the transaction with a private key to prove ownership. That signature reveals the public key, and the transaction is then broadcast to the network and held in the mempool until a miner includes it in a block. The source notes that Bitcoin's average confirmation time is roughly 10 minutes.

The security link between a private key and a public key rests on the elliptic curve discrete logarithm problem. Classical machines cannot reverse that math on a useful timescale. A sufficiently capable future quantum computer running Shor's algorithm could. Google's paper argues that an attacker could pre-compute the parts of the attack that do not depend on a specific public key, then wait for a target transaction to appear in the mempool and complete the last stage in roughly nine minutes.

That creates a chance to derive the key before the original transaction confirms and redirect the funds. Based on the source material, the odds of success in that average 10-minute window are about 41%.

Exposed public keys are the larger long-term vulnerability

The mempool scenario is alarming, but it depends on a quantum computer that does not exist today. Google's paper estimates that such a machine would need fewer than 500,000 physical qubits. The largest quantum processors today are at around 1,000.

The source says the larger concern is the stock of bitcoin already held in wallets whose public keys are permanently exposed. That pool totals about 6.9 million BTC, roughly one-third of total supply. Those coins do not require a race against block confirmation. With a powerful enough quantum computer, an attacker could process exposed keys one by one with no time pressure.

This group includes early Bitcoin addresses that used the pay-to-public-key format, where the public key is visible on the blockchain by default. It also includes wallets that reused addresses, because spending from an address exposes the public key for any funds still left there.

Taproot widened the future exposure on-chain

The source also says Bitcoin's 2021 Taproot upgrade changed address behavior so that public keys are visible on-chain by default, which expanded the set of wallets that could be vulnerable to a future quantum attack.

That does not mean the Bitcoin network itself would stop operating. Mining relies on SHA-256, and the source says current quantum approaches cannot meaningfully accelerate that process. Blocks would still be produced and the ledger would still exist. The break happens at the level of ownership guarantees: if private keys can be derived from public keys, any wallet with an exposed key becomes vulnerable to theft.

Post-quantum cryptography is the stated path forward

The proposed fix is post-quantum cryptography, replacing the mathematics vulnerable to quantum attacks with algorithms that quantum computers cannot crack. The source says Ethereum has spent eight years preparing for that kind of migration, while Bitcoin has not yet begun. That is why the phrase "cracking bitcoin in 9 minutes" has drawn so much attention: the core issue is not block production, but the durability of Bitcoin's key security model in a quantum era.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.