Adam Back Urges Bitcoin to Prepare for Quantum Computing Threat
Bitcoin currently relies on ECDSA and Schnorr signatures to secure asset ownership. A sufficiently powerful quantum computer could eventually use Shor’s algorithm to derive private keys from exposed public keys. Although the threat remains confined to laboratory experiments, migrating the network’s wallets, software and users would take considerable time, making early development of quantum-resistant safeguards critical to asset security.
Speaking at Paris Blockchain Week on April 16, 2026, Blockstream CEO Adam Back advocated introducing an optional upgrade first and giving users 10 years to move funds to quantum-resistant addresses. He estimated that a real threat remains at least 20 years away. Blockstream’s research division proposed a hash-based signature scheme in December 2025. The migration could also clarify whether the roughly 500,000 to 1 million Bitcoin attributed to Satoshi Nakamoto can still be moved.
All Coverage
4 original reportsThe Backstory
The history behind this eventNew Proof Offers Bitcoin a Post-Quantum Recovery Path
Bitcoin relies on elliptic-curve cryptography to authenticate wallet transactions. A sufficiently powerful quantum computer could derive private keys from exposed public keys, allowing an attacker to forge signatures and seize funds. The risk is not immediate, but migration is complex because blockchains must distinguish legitimate owners from attackers after conventional signatures fail. Coinbase’s quantum advisory council said in June 2026 that about 7 million bitcoin could eventually be exposed if holders do not move assets to quantum-safe addresses.
On July 15, 2026, Project Eleven unveiled a post-quantum zero-knowledge proof developed with Jim Posen, lead maintainer of the open-source Binius proof system. The method uses BIP-32 wallet derivation to prove control of key material above an address without revealing it, potentially authorizing recovery into a quantum-safe wallet. On an M5 MacBook Air, the prototype generated a proof in 243 milliseconds using four cores and verified it in 40 milliseconds, with 2.1 GB of peak proving memory. It supports P2PKH, P2WPKH and P2SH-P2WPKH addresses, but remains unaudited and requires protocol-level integration.
Quantum Computing Threatens Bitcoin Security as Bit Digital Shifts to Ethereum
Bitcoin transactions use elliptic-curve digital signatures to secure assets. A quantum computer running Shor’s algorithm could potentially derive private keys from public keys, putting older wallets and transaction security at risk. Ethereum, by contrast, has planned a mechanism allowing accounts to adopt quantum-resistant signatures, bringing corporate crypto treasury strategies and onchain governance capabilities into focus.
Google Quantum AI and other institutions published research on March 30, 2026, estimating that fewer than 500,000 physical qubits could crack a key in about nine minutes. Citi warned on May 18 that the potential attack timeline had shortened. Bit Digital had already announced on July 7, 2025, that it would sell about 280 Bitcoin and, alongside a $172 million fundraising, increase its holdings to 100,603 Ethereum.
Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security
Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.
Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.
Bitcoin Faces Outsized Security Threat as Quantum Computing Breakthroughs Accelerate, Citi Says
Quantum computers capable of using Shor’s algorithm to break elliptic-curve cryptography could put Bitcoin holdings with exposed public keys at risk of theft. The threat could also extend to internet and financial infrastructure. Citi said Bitcoin’s conservative governance and the need for community consensus on upgrades could leave its migration to quantum-resistant technology trailing Ethereum’s.
Citi issued a digital-assets research report on May 18, 2026, warning that quantum computing breakthroughs are shortening the timeline for a practical attack. The report estimated that the public keys of about 6.5 million to 6.9 million Bitcoin, roughly one-third of the circulating supply, had already been exposed on-chain. Those holdings were worth about $450 billion at prices prevailing at the time.
Glassnode Says Nearly 10% of Bitcoin Supply Faces Structural Risk From Quantum Breakthrough
Bitcoin uses secp256k1 elliptic-curve signatures to secure control of assets. If a large, fault-tolerant quantum computer could use Shor's algorithm to derive private keys from exposed public keys, attackers might be able to forge transactions. Blockchain analytics firm Glassnode said early P2PK, legacy P2MS and modern P2TR outputs all directly expose public keys, potentially making long-dormant assets from the Satoshi era targets.
On May 20, 2026, Glassnode published an analysis classifying 1.92 million BTC, or 9.6% of the supply, as “structurally unsafe,” including P2PK, P2MS and P2TR outputs. The report recommended adopting BIP-360, proposed in December 2024, which uses P2MR to remove Taproot's vulnerable key path. However, the proposal has yet to incorporate post-quantum digital signatures.
Project Eleven Warns Bitcoin’s Quantum Migration May Already Be Too Late
Bitcoin uses elliptic-curve digital signatures to secure asset ownership, but a powerful quantum computer could potentially derive private keys from public keys and steal funds. Quantum-security firm Project Eleven says the risk extends beyond Bitcoin to the global financial infrastructure, making migration to post-quantum cryptography an urgent issue.
Project Eleven’s latest report warns that quantum computers could become capable of breaking current cryptography between 2030 and 2033, threatening more than $3 trillion in digital assets. It argues that upgrading the Bitcoin protocol, migrating users and addressing legacy addresses would be time-consuming and costly, and that it may already be too late to begin the transition.
Bitcoin Must Begin Post-Quantum Migration Early to Counter Quantum Threat
Bitcoin currently protects assets with ECDSA and Schnorr signatures. If a large-scale quantum computer could run Shor’s algorithm, it might be able to derive private keys from public keys that have already been exposed. Project Eleven estimates that about $2.3 trillion in assets is at risk, making a post-quantum migration critical to the security of the entire wallet, exchange and custody ecosystem.
Project Eleven CEO Alex Pruden told CoinDesk’s Consensus Miami on May 6, 2026, that Bitcoin developers should immediately move post-quantum signatures from research into production. The Taproot upgrade took about five years and migration was voluntary. A new approach would require participation from all holders, wallets, exchanges and institutions, while BIP-360 has already laid the groundwork for a quantum-resistant output type.
Michael Saylor Says Quantum Threat to Bitcoin Is at Least 10 Years Away
Quantum computers capable of breaking public-key cryptography could threaten Bitcoin signatures and asset ownership, making the technology a long-term market risk. Strategy, formerly MicroStrategy, co-founder and Executive Chairman Michael Saylor said banks, the internet and crypto assets all face the same pressure to upgrade, while Bitcoin could adopt quantum-resistant cryptography through updates to its nodes, wallets and protocol.
Saylor told Natalie Brunell’s “Coin Stories” on Feb. 23, 2026, that any quantum breakthrough posing a material threat was at least 10 years away. At a Mizuho event on April 8, he again said the risk was overstated and could be addressed through upgrades. He also said Bitcoin had likely bottomed at about $60,000 in early February; its price was around $71,200 when the report was published on April 9.
Nobel Physics Laureate Warns of Bitcoin Quantum Threat, Urges Swift Post-Quantum Planning
Bitcoin uses public- and private-key cryptography to verify asset ownership and transactions. If powerful quantum computers become capable of deriving private keys from public keys, assets held at some addresses could be stolen. John Martinis, a Nobel physics laureate and former head of quantum hardware at Google, said the risk now raises questions about Bitcoin’s long-term security and its capacity for decentralized governance.
Martinis recently warned that quantum computers could become capable of breaking Bitcoin’s public-key cryptography within the next 5 to 10 years, and that the community should not wait for an attack before responding. He called for early planning on post-quantum cryptography, software upgrades and asset-migration mechanisms. The reports did not provide an exact publication date, the value of assets at risk or the scale of quantum computer that could break Bitcoin in practice.
Samson Mow Warns Rushed Bitcoin Quantum Fix Could Create Security Risks
Bitcoin relies primarily on elliptic-curve digital signatures to protect assets. If a practical quantum computer emerges, it could theoretically break addresses whose public keys have been exposed. A transition to quantum resistance is therefore a long-term concern, but protocol changes would require compatibility across nodes, wallets and exchanges worldwide. A flawed upgrade could also directly jeopardize network security.
Jan3 founder Samson Mow opposed accelerating the deployment of a quantum-resistant fix in a recent report. He warned that new signatures could become significantly larger, increasing the burden on block space, bandwidth and verification while creating compatibility vulnerabilities. Mow argued that Bitcoin should not sacrifice its defenses against current attacks before the quantum threat becomes imminent. The report provided no specific launch date or figures for the potential increase.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →