Concerns surrounding the potential of quantum computers to "kill" Bitcoin have been circulating within the cryptocurrency community for some time. Central to these worries is Shor's algorithm, which transforms the task of reconstructing a private key from a public one from "impossible" to "solvable in minutes," given the right hardware.
The latest installment of the "Quantum & After" series explores how Shor's algorithm functions, which addresses are at risk, and why the market could react long before an actual attack occurs.
Brief Overview
The theoretical threat is genuine. Shor's algorithm can solve the discrete logarithm problem on elliptic curves in polynomial time. This theoretically enables the recovery of private keys, thereby compromising the security of ECDSA and Schnorr signatures, both of which utilize the secp256k1 curve. However, no existing devices are capable of launching such an attack. Current top processors have about 1100–1200 physical qubits without error correction, while millions are required for a successful breach. The first addresses at risk are those whose public keys have already been revealed on the blockchain.
Why Is This the Case?
The security of Bitcoin relies on the practical impossibility of calculating the private key k from the public key P = k ⋅ G. The best classical algorithms necessitate approximately 2¹²⁸ operations, which exceed the capabilities of current computational systems. Shor's algorithm fundamentally alters the complexity class of the task itself rather than merely speeding up brute-force attempts.
A key consideration is the "cost" of the issue, measured in qubits. Researchers' estimates vary widely depending on architecture, error rates, and correction methods. Conservative predictions suggest that around 2330 stable logical qubits are necessary, which, with error correction, translates to 1–13 million physical qubits. Experts from the University of Sussex estimate that to crack the encryption of the first cryptocurrency network in one day, a quantum computer with approximately 13 million physical qubits would be required. In 2022, physicists calculated that hacking RSA-2048 within one hour would necessitate about 317 million physical qubits.
A study by Google Quantum AI, published in March 2026, significantly reduced this estimate, indicating that less than 500,000 physical qubits (around 1200 logical) and approximately 70 million computational steps would suffice. Under these conditions, a private key could be compromised in a maximum of 9 minutes — quicker than a new block can be mined. This represents a twentyfold decrease in requirements compared to the 20 million qubits predicted in 2019.
By 2029, IBM aims to develop a fault-tolerant quantum supercomputer named IBM Quantum Starling, featuring 200 logical qubits. The leading company targeting the creation of a device with 2 million physical qubits by 2030 is the American firm IonQ.
If these plans materialize at least partially, a quantum computer capable of recovering Bitcoin's private keys could emerge in the latter half of the 2030s. However, Blockstream's Adam Back believes such systems will not be available for another 20–40 years. According to a survey of 26 experts from the Global Risk Institute, the likelihood of a cryptographically significant quantum computer appearing within the next decade was estimated at 28–49%, increasing to 51–70% within 15 years.
The vulnerability of Bitcoin assets is determined not by the size of the balance but by the owner's digital hygiene. The main threat factor is the exposed public key. Addresses from the P2PK era of Satoshi, the Taproot architecture, and any wallets compromised by address reuse are at heightened risk.
In contrast, P2PKH, P2SH, and SegWit outputs remain secure until the first outgoing transaction since they are hidden behind a cryptographic hash. Analysts from Glassnode have calculated that revealed keys in the blockchain correspond to 6.04 million BTC (30.2% of the total supply, or approximately $469 billion). Notably, the structural vulnerability (P2PK) affects 1.92 million BTC, while operational vulnerability (address reuse) impacts 4.12 million BTC.
This leads to a significant practical risk known as the HNDL strategy. An attacker does not require a quantum computer today; they merely need to retain all exposed public keys and wait for a cryptographically threatening quantum computer (CRQC) to become available. A study by the U.S. Federal Reserve cites Bitcoin as an example of the limitations of post-quantum migration: new algorithms can secure future transactions, but they cannot conceal already published data or automatically transfer funds from old outputs.
What Does This Mean?
For holders, this is a call not for panic but for an audit: to check whether funds reside on P2PK outputs or reused addresses, and to ensure that long-term holdings are not kept in wallets with exposed public keys. Keys that remain under control can be transferred, while lost and "dormant" wallets from earlier years will have no one to migrate them — these will become the primary targets.
For investors, another risk is also relevant: prices may react before the technology does. A single high-profile report about reduced qubit requirements could lead the market to start pricing in risks long before an actual attack occurs. Therefore, two timelines are at play: the technological (over ten years) and the narrative (any upcoming quarter). An additional factor is regulatory: NSA and NCSC are already preparing for the transition to post-quantum cryptography. Bitcoin will eventually need to align its migration through consensus, a process that is progressing more slowly than the updates to commercial vendors' roadmaps.
Q-check ForkLog: Quantum Threat to Bitcoin
Is the threat real?Currently, it is in data collection mode (HNDL).
Is there hardware?No: about 1500 noisy qubits against the hundreds of thousands required.
Who is at risk?Approximately 6 million BTC with exposed public keys, of which 1.92 million are P2PK.
What can be done now?Check output types, avoid address reuse, and monitor developments in post-quantum migration.
Roadmap or press release?Currently, there are roadmaps and experimental systems.
What’s Next?
To assess the real potential of qubits, one must look "under the hood." In the next issue, we will examine how quantum computers differ from classical ones, what is truly behind the term "quantum supremacy," and why the number of qubits is not the main issue, with error correction remaining the primary challenge.
Read previous issues:
- Can you profit from quantum technologies?
- How blockchains are preparing for the "quantum" era.
- Is it possible to hack the quantum internet?
