Quantum computing poses a potential risk to every system built on cryptography, including large banks and government networks. Still, some industry participants argue that crypto may be the first sector where that risk is tested in practice.
"Crypto is the canary in the coal mine," Quantum Xchange CEO Eddy Zervigon said in comments to CoinDesk. Quantum Xchange builds cybersecurity infrastructure designed to withstand quantum attacks across finance and other sectors. In his view, crypto networks are likely to be the earliest place where problems emerge because they are decentralized by design.
Zervigon said that if this kind of event appears first in crypto, it would signal that a cryptographically relevant quantum computer exists somewhere.
A 2029 timeline is gaining attention
In this context, a cryptographically relevant quantum computer means a machine capable of running Shor’s algorithm effectively enough to break the elliptic-curve cryptography used by Bitcoin and other cryptocurrencies. Bitcoin relies on ECDSA over secp256k1. If the elliptic-curve discrete logarithm problem can be solved efficiently, an attacker could derive a private key from a public key and take control of the associated wallet funds.
No such machine exists today. But estimates for its arrival are moving closer rather than farther away. Zervigon said companies such as Microsoft and IBM, along with others spending billions of dollars on quantum computing, broadly place commercially and cryptographically relevant machines around 2029. He added that this was not his own invention and cited public statements from figures including IBM CEO Arvind Krishna.
That timeline lines up with recent progress in both hardware and algorithms. Earlier this year, research from Google Quantum AI indicated that breaking the elliptic-curve cryptography protecting major cryptocurrencies such as Bitcoin and Ethereum may require fewer than 500,000 physical qubits. That is about 20 times lower than the multi-million-qubit estimates often cited in the past.
The same research said that, if some fixed parameters are precomputed, an attack on an exposed public key could take roughly 9 minutes. Bitcoin’s average block interval is about 10 minutes. That creates a scenario in which an attacker could, in theory, forge a signature and move funds after a transaction enters the mempool but before confirmation. Based on findings like these, observers including Google have moved their estimate for "Q-Day" — the point when cryptographically relevant quantum computers become usable in practice — closer to 2029.
At the same time, the White House is pushing to develop a powerful quantum computer by 2028 and plans to move high-value assets and federal data to post-quantum cryptography by 2030. Zervigon said that this effectively sets a timetable and raises the sense of urgency.
The bigger issue may be governance speed
Zervigon is not the only one arguing that Bitcoin’s central weakness lies less in cryptography itself than in the pace of governance.
Deutsche Digital Assets made the same point in a July 23 analysis, describing the gap as a difference in speed between traditional finance and decentralized systems. The firm wrote that the real distinction — and the most honest answer to the claim that Bitcoin is uniquely vulnerable — is governance speed.
Its argument was direct. An investment bank such as JPMorgan does not need approval from millions of pseudonymous participants around the world before upgrading its cryptographic infrastructure. It needs a board decision, a budget and vendors. Large financial institutions can and will move to post-quantum standards faster, more quietly and with more predictability than decentralized public blockchains. Deutsche Digital Assets said this was not an argument against Bitcoin, but a call to take its governance process seriously.
Research points to a hard migration problem
Academic work supports that view. A 2024 arXiv paper titled The downtime required for Bitcoin to become quantum-safe argued that Bitcoin’s own upgrade history should be read as a warning.
The researchers wrote that before any upgrade can begin, 90% consensus on the details must be reached among Bitcoin miners. Major changes to the Bitcoin network have historically faced strong resistance. They pointed to the 2017 SegWit upgrade as a clear example.
That upgrade triggered deep disagreement in the community and ended with hard forks that split the Bitcoin blockchain into multiple versions, including Bitcoin Cash and Bitcoin Gold.
The paper also estimated that even under ideal conditions — with all network bandwidth dedicated to the upgrade and no added overhead — migrating all currently quantum-vulnerable unspent transaction outputs, or UTXOs, to post-quantum-safe addresses would still require at least 76 days of processing time. Spreading the migration over a longer period would materially slow normal transaction throughput.
There is another constraint. Once a user initiates a transaction and exposes a public key, an attacker may be able to break it before the next block is mined. That so-called immediate attack risk means the migration would need to be completed before a cryptographically relevant quantum computer arrives. If not, already held assets could remain exposed.
In other words, post-quantum cryptographic schemes themselves — including ML-DSA, which has already been standardized by the National Institute of Standards and Technology — may be ready in time. The uncertain part is whether Bitcoin governance can reach a high enough level of agreement quickly enough to deploy those changes across the network.
Q-Day may be a trend, not a single moment
Markets often treat the quantum threat as a binary event: cryptography works until one date, then suddenly fails after it. Zervigon said that framing misses how the risk can begin to matter earlier.
He said the conversation is too focused on the exact moment an algorithm can be broken. In practice, an attacker does not need an instant break to achieve the same outcome. If decrypting valuable data takes three months or six months, but the data is still useful, the objective has still been met.
That compresses the usual timetable. A quantum machine does not need enough throughput to break signatures in real time before it becomes dangerous. It only needs enough capacity to finish the job before the underlying data or funds lose value.
There is already a large pool of Bitcoin with public keys permanently exposed on-chain. Research cited in the report estimated that this accounts for roughly one-third of the supply, or millions of coins. If quantum computers become usable, those holdings could face what is often described as a static attack, where an attacker can work slowly and does not need to race the block clock.
Crypto may be the first warning signal
For the broader crypto industry, this is both a warning and a stress test. Traditional financial institutions can migrate faster through centralized decision-making. Public blockchains such as Bitcoin draw strength from decentralization, but the same feature can become an implementation obstacle when the threat demands tightly coordinated action.
The sources and research cited in the report point in the same direction. Technical options are not entirely missing. The harder question is whether governance can keep pace with the available time window.
If crypto becomes the first sector to sound the alarm in the quantum era, the rest of the financial system may have to confront the same challenge soon after.

