Bitcoin's Quantum Problem Is Closer Than You Think

By Wolfgang Vitale, Bitcoin Suisse

In December 2024, a paper published by Google in the journal Nature on its Willow quantum chip made waves across the global technology community.

The finding was significant: for the first time, researchers demonstrated that scaling up physical qubits actually improves the reliability of a logical qubit, rather than degrading it. The strategic implications are foundational. They mark the transition from the era of error-prone quantum hardware toward machines that can correct their own errors at scale.

What Is Secure Today May Not Stay That Way

Classical cryptography protects bank accounts, communications, and digital assets through mathematical barriers that are insurmountable for today's hardware. Quantum computers, however, attack these foundations with entirely new algorithms. What is secure today may not stay that way tomorrow.

Since the most recent breakthroughs, the major industry players have aligned their roadmaps: reliable quantum computers operating with several thousand logical qubits are targeted by 2032.

The Threat Is Drawing Closer

But the threat is drawing closer. In late March 2026, Google and Caltech researchers independently published analyses concluding that breaking Bitcoin's cryptography would require significantly fewer resources than previously thought. Leading cybersecurity firms are already revising their timelines. The threat is no longer a distant horizon. The preparation window is open now.

Bitcoin and other networks rely on elliptic curve cryptography (ECDSA) for digital signatures. It is the technical foundation of property rights in decentralized systems. If ECDSA is compromised, an attacker can work backwards from a public key to derive the private key. Ownership, as it currently exists in these systems, would stop being technically enforceable.

What Is Actually at Stake

The scale of potential exposure can already be measured. Estimates put roughly 6.9 million Bitcoin, worth nearly $483 billion at current prices, at risk from a cryptographically relevant quantum computer (CRQC). That vulnerability has two sources: outdated address formats that leave public keys directly exposed, and address reuse, which has the same effect.

Much of the Bitcoin at risk is believed to be permanently lost, including an estimated one million Bitcoin attributed to Satoshi Nakamoto, the pseudonymous founder of Bitcoin.

The Most Complex Upgrade in Blockchain History

For institutional players, this raises a critical due diligence question: how resilient is your custody infrastructure if the cryptographic foundation shifts? This concern runs up and down the entire chain, from sub-custodians to exchanges.

The Bitcoin network is not standing still. In February 2026, BIP-360 became the first concrete proposal for quantum resistance to enter the Bitcoin Improvement Proposals repository. At its core is a new address type called Pay-to-Merkle-Root (P2MR), which preserves programmability without exposing the public key.

Governance Questions

But beyond the technical challenges, contentious social questions remain:

  • What happens to coins whose owners have permanently lost their keys?
  • Should unmigrated holdings be frozen after a deadline to prevent quantum theft?
  • How should the network handle the politically sensitive question of Satoshi's holdings?

These governance questions must be resolved by consensus across a decentralized ecosystem of miners, node operators, and holders. That is a process that takes time.

Why Early Action Is Decisive

Waiting for definitive proof of an imminent threat before acting would be a strategic mistake. Migrating vulnerable holdings is constrained by network throughput, and building the social consensus needed for a protocol change takes time. Bitcoin should therefore take its first steps toward quantum resistance well before CRQCs become a reality.

The More Likely Path

The alternative scenario is far worse: panic selling, rushed protocol decisions made under pressure, and the real possibility of chain splits producing competing versions of the same asset. The more likely path, and the one expected to take shape through 2026, is the formation of social consensus around a soft fork toward quantum resistance implementing BIP-360 or a similarly scoped proposal.

This outcome would matter well beyond the technical fix. It would demonstrate that Bitcoin can respond to an existential challenge in an orderly, deliberate way.

Three Questions for Institutional Decision-Makers

For institutional decision-makers, the technological threat translates into three concrete questions:

  • First, it is worth examining whether the current custody architecture creates unnecessary attack surface through outdated address formats or systematic address reuse.
  • Second, the competence of partners comes into focus: only custodians with genuine protocol-level expertise will be able to handle the complex migrations ahead smoothly.
  • Third, those who are not actively tracking the consensus signals around forward-looking proposals like BIP-360 should expect to be caught off guard by the technological reality of 2026.

Preparation, Not Panic

Quantum computing will not dominate digital asset markets in 2026, and short-term volatility driven by hardware roadmap updates is largely noise. But the technological reassessment is unavoidable.

The encouraging news is that the developer communities around Bitcoin and Ethereum know what is coming. Holdings already stored in modern address formats are protected for now. Institutions that start asking the right questions today will be well-positioned to manage the transition without operational disruption. But the window for orderly adaptation does not stay open forever. It is worth using while it still is.


Wolfgang Vitale is Crypto Protocol Expert at Bitcoin Suisse.