A study titled "The State of Quantum" from Quantus warns that quantum computing advances have accelerated faster than much of the crypto industry's post-quantum preparations, potentially jeopardizing over $2 trillion in digital assets.
Hardware breakthroughs compress timelines
According to the report, a series of developments from Google, IBM, and Quantinuum between 2024 and 2026 reshaped expert expectations. The most notable is Google Quantum AI's March 2026 paper, which estimated that Shor's algorithm could break Bitcoin's secp256k1 elliptic curve with fewer than 500,000 physical qubits under certain assumptions.
While no existing machine can currently break Bitcoin encryption, the report says resource requirements have dropped sharply. Within roughly one year, three papers reduced the projected quantum resources needed for attacking elliptic curve cryptography by nearly an order of magnitude.
'Harvest now, crack later' risk
Blockchains permanently expose public keys on public ledgers, leaving millions of addresses vulnerable to future attacks. The report describes this as a "harvest now, crack later" scenario — attackers collect data today and wait for powerful quantum systems.
Lost Bitcoin wallets pose another problem. Quantus estimates 2.3 million to 3.7 million BTC are inaccessible due to lost keys, including coins linked to Satoshi Nakamoto. These wallets cannot migrate to quantum-resistant addresses, making them permanent targets once quantum attacks become practical.
Auryn Macmillan, co-founder of Gnosis Guild, suggests in the report: "The only practical solution is to set a hard deadline for account owners to migrate their tokens to quantum safe accounts, after which all tokens held in vulnerable accounts will be permanently frozen."
Crypto industry split on migration
NIST finalized post-quantum encryption standards in August 2024, and firms like Google, Signal, Apple, and Cloudflare have begun deploying protections with migration targets into 2029-2030. But the crypto industry remains divided on how to proceed.
Bitcoin's transition is particularly difficult due to governance coordination, scaling concerns, and the challenge of replacing signature systems without introducing new vulnerabilities. Stanford cryptographer Dan Boneh, a co-author of Google's 2026 paper, warns that "a hasty transition to post quantum is more likely to cause a catastrophic bug than we'll be attacked by a quantum computer," though he supports gradual migration.
Hardware wallets also face constraints. Aaron Chen, CTO of Keystone, notes that algorithms like ML-DSA-87 strain MCU-based devices, creating "additional challenges for hardware wallet development." Matt Swayne of Resonance argues the industry may underestimate how fast quantum tech is advancing: "The quantum industry is underselling its progress."
Quantus concludes that migrating too early mainly causes operational inconvenience, while migrating too late risks fund losses, institutional panic, and regulatory intervention after quantum attacks become feasible.

