The US government has stepped up its push into quantum computing, and that has put Bitcoin’s long-running quantum security debate back into focus as an engineering problem rather than a purely theoretical one.
On Sept. 8, the US Department of Commerce finalized CHIPS research and development awards for Rigetti, D-Wave, and Quantinuum. Each company is eligible for up to $100 million, putting the combined total at as much as $300 million. The funding is intended for quantum chips, cryogenic systems, error-rate improvements, and fault-tolerant quantum computing technologies.
That $300 million is only part of the latest federal support package for the sector. On the same day, photonic quantum computing company PsiQuantum received an R&D award worth up to $100 million, while GlobalFoundries received up to $375 million, including funding tied to building domestic US quantum wafer foundry capacity. Earlier, in May, the Commerce Department had announced intended quantum industry investments totaling $2.013 billion across nine companies. The policy direction, as described in the source material, is moving from basic research toward manufacturing and larger-scale hardware.
Quantum funding revives attention on Bitcoin’s tail risk
This new round of investment has also amplified a long-tail risk that has shadowed the crypto market for years. If a future quantum computer gains practical code-breaking capability, Shor’s algorithm could in theory derive a private key from a public key, threatening the elliptic curve digital signatures used by Bitcoin.
There is still no evidence that quantum computers are close to breaking Bitcoin in practice. The more immediate issue for the market is different: a full migration across wallets, exchanges, and UTXOs worldwide could take years. Developers cannot wait for a so-called Q-Day to start planning for it.
BIP-360 targets long-term public-key exposure
The first step now drawing more mature discussion is BIP-360, or Pay-to-Merkle-Root (P2MR). The proposal introduces a new Bitcoin output type that keeps script-tree functionality similar to Taproot while removing the key-path spend that directly exposes a public key.
That means P2MR could reduce the risk that a public key exposed for a long period might later be broken by a quantum computer. It is not, however, a complete post-quantum signature solution. The BIP-360 document states clearly that if quantum computers approach the point where they could break a public key in the window between a transaction entering the mempool and being confirmed, Bitcoin would still need true post-quantum signature schemes such as ML-DSA and SLH-DSA.
BIP-361 takes on the harder question of migration
BIP-361 addresses a more difficult issue: how to move the entire network.
Under the current draft, the first phase would gradually stop new funds from flowing into quantum-vulnerable addresses. After that, the proposal would consider restricting spending based on ECDSA and Schnorr signatures, forcing users to migrate to post-quantum addresses before a preset deadline.
Material cited in BIP-361 estimates that, as of March 2026, more than 34% of Bitcoin’s supply had public keys exposed on-chain. That implies a potential impact spanning millions of BTC.
The hardest part is what happens if large amounts of early Bitcoin are never moved. That includes coins with lost private keys, early P2PK addresses, and holdings that could possibly belong to Satoshi Nakamoto. If those funds are not migrated voluntarily, future choices could include freezing them, allowing a quantum attacker to take them, or creating some form of special recovery proof. Each option raises major disputes over property rights and social consensus.
For now, BIP-361 remains only a draft. The proposal also explicitly depends on a post-quantum signature BIP that has not yet been finalized, leaving a long path before any mainnet activation.
NIST has already published post-quantum standards
The National Institute of Standards and Technology, or NIST, formally released three post-quantum cryptography standards in 2024: ML-KEM, ML-DSA, and SLH-DSA. It also called on system operators to begin migration planning. The reason was not that a quantum break is imminent, but that large cryptographic infrastructure changes usually take years.
As of Sept. 10, Bitcoin was still trading around $78,000, and quantum risk had not become a main driver of short-term price action.
From a market perspective, the US government is now directing billions of dollars toward quantum hardware, while Bitcoin developers are starting to debate how millions of BTC could be moved safely. Those two timelines are getting closer. The central risk is not that quantum computers will crack Bitcoin tomorrow, but whether the network can complete what may become the largest cryptographic migration in its history before quantum hardware crosses a meaningful threshold.

