Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Bitcoin

New Proof Offers Bitcoin a Post-Quantum Recovery Path

1 reports · First detected 2026-07-30 · Last active 2026-07-30

Bitcoin relies on elliptic-curve cryptography to authenticate wallet transactions. A sufficiently powerful quantum computer could derive private keys from exposed public keys, allowing an attacker to forge signatures and seize funds. The risk is not immediate, but migration is complex because blockchains must distinguish legitimate owners from attackers after conventional signatures fail. Coinbase’s quantum advisory council said in June 2026 that about 7 million bitcoin could eventually be exposed if holders do not move assets to quantum-safe addresses.

On July 15, 2026, Project Eleven unveiled a post-quantum zero-knowledge proof developed with Jim Posen, lead maintainer of the open-source Binius proof system. The method uses BIP-32 wallet derivation to prove control of key material above an address without revealing it, potentially authorizing recovery into a quantum-safe wallet. On an M5 MacBook Air, the prototype generated a proof in 243 milliseconds using four cores and verified it in 40 milliseconds, with 2.1 GB of peak proving memory. It supports P2PKH, P2WPKH and P2SH-P2WPKH addresses, but remains unaudited and requires protocol-level integration.

All Coverage

1 original reports

The Backstory

The history behind this event
Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security2026-05-30 · 1 reports · similarity 0.83

Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.

Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.

Project Eleven Warns Bitcoin’s Quantum Migration May Already Be Too Late2026-05-10 · 1 reports · similarity 0.81

Bitcoin uses elliptic-curve digital signatures to secure asset ownership, but a powerful quantum computer could potentially derive private keys from public keys and steal funds. Quantum-security firm Project Eleven says the risk extends beyond Bitcoin to the global financial infrastructure, making migration to post-quantum cryptography an urgent issue.

Project Eleven’s latest report warns that quantum computers could become capable of breaking current cryptography between 2030 and 2033, threatening more than $3 trillion in digital assets. It argues that upgrading the Bitcoin protocol, migrating users and addressing legacy addresses would be time-consuming and costly, and that it may already be too late to begin the transition.

Bitcoin’s BIP-360 Proposal Formally Sets Out Quantum-Resistance Roadmap2026-05-04 · 3 reports · similarity 0.84

Bitcoin, with a market capitalization of about $1.3 trillion, relies on elliptic-curve cryptography to secure transactions. If large-scale quantum computers become viable, exposed public keys could potentially be used to derive private keys. Bitcoin developers have therefore proposed BIP-360, adding a quantum-resistant migration to the network’s long-term technical roadmap to reduce the potential risk to existing assets.

Proposed in 2025, BIP-360 introduces Pay-to-Merkle-Root (P2MR), which removes Taproot’s public-key spending path and instead locks scripts with a Merkle root, allowing keys to remain hidden until funds are spent. The proposal remains a draft, with no mainnet activation date, and does not yet introduce a complete post-quantum signature scheme. It nevertheless establishes a foundation for future upgrades.

Google Research Finds Quantum Threat to Bitcoin Lower Than Expected2026-04-18 · 14 reports · similarity 0.81

Bitcoin and Ethereum rely on elliptic-curve cryptography to safeguard assets. A quantum computer capable of deriving a private key from a public key could potentially steal funds. Bitcoin activated Taproot on November 14, 2021, and because some transactions expose public keys in advance, the potential window for attack has widened.

The latest research from Google Quantum AI estimates that about 500,000 error-corrected physical qubits could be enough to crack a key within Bitcoin’s roughly nine-minute transaction confirmation window, far below previous estimates of several million qubits. No funds have been reported stolen through such an attack, but the researchers are urging the community to begin planning a migration to post-quantum cryptography.

Adam Back Urges Bitcoin to Prepare for Quantum Computing Threat2026-04-17 · 4 reports · similarity 0.83

Bitcoin currently relies on ECDSA and Schnorr signatures to secure asset ownership. A sufficiently powerful quantum computer could eventually use Shor’s algorithm to derive private keys from exposed public keys. Although the threat remains confined to laboratory experiments, migrating the network’s wallets, software and users would take considerable time, making early development of quantum-resistant safeguards critical to asset security.

Speaking at Paris Blockchain Week on April 16, 2026, Blockstream CEO Adam Back advocated introducing an optional upgrade first and giving users 10 years to move funds to quantum-resistant addresses. He estimated that a real threat remains at least 20 years away. Blockstream’s research division proposed a hash-based signature scheme in December 2025. The migration could also clarify whether the roughly 500,000 to 1 million Bitcoin attributed to Satoshi Nakamoto can still be moved.

StarkWare Researcher Proposes Quantum-Safe Bitcoin Without a Soft Fork2026-04-10 · 4 reports · similarity 0.85

Bitcoin transactions rely on elliptic-curve digital signatures. A sufficiently powerful quantum computer running Shor’s algorithm could derive private keys from exposed public keys and steal assets. Replacing the signature mechanism would require network-wide consensus and asset migration, drawing attention to StarkWare’s upgrade-free approach as a fallback until longer-term changes such as BIP-360 are completed.

On April 9, 2026, StarkWare Chief Product Officer and BIP-360 co-author Avihu Levy published the QSB paper and open-source code. The system uses Bitcoin’s existing Script constraints and hash-based proofs to create quantum-resistant transactions without a soft fork or miner activation. Each transaction requires substantial offline GPU computation at an estimated cost of $75–$200, and the tool is currently intended for emergency recovery.

Quantum Attack on Bitcoin Mining Would Require Star-Scale Energy, Study Says2026-04-08 · 1 reports · similarity 0.84

Bitcoin uses a proof-of-work mechanism, and an attacker controlling more than 50% of the network’s computing power could theoretically reorganize its transaction history. An academic research team found that while quantum computing could accelerate calculations, a 51% attack on Bitcoin mining would still face physical constraints including hardware scale, cooling and energy supply, limiting the near-term threat.

As of July 20, 2026, the latest research estimates that a quantum computer powerful enough to overwhelm the entire Bitcoin network could require energy on the scale of a star, putting such a system beyond what existing institutions could deploy with funding alone. A more practical risk is the compromise of older wallets whose public keys remain exposed. Bitcoin developers have begun exploring quantum-resistant signatures and network upgrades.

Nobel Physics Laureate Warns of Bitcoin Quantum Threat, Urges Swift Post-Quantum Planning2026-04-07 · 1 reports · similarity 0.82

Bitcoin uses public- and private-key cryptography to verify asset ownership and transactions. If powerful quantum computers become capable of deriving private keys from public keys, assets held at some addresses could be stolen. John Martinis, a Nobel physics laureate and former head of quantum hardware at Google, said the risk now raises questions about Bitcoin’s long-term security and its capacity for decentralized governance.

Martinis recently warned that quantum computers could become capable of breaking Bitcoin’s public-key cryptography within the next 5 to 10 years, and that the community should not wait for an attack before responding. He called for early planning on post-quantum cryptography, software upgrades and asset-migration mechanisms. The reports did not provide an exact publication date, the value of assets at risk or the scale of quantum computer that could break Bitcoin in practice.

Bitcoin’s Quantum-Proof Upgrade Faces Governance Challenge2026-03-26 · 1 reports · similarity 0.82

Quantum computers could threaten Bitcoin private keys and onchain assets if they become capable of breaking today’s elliptic-curve cryptography. BOLT Technologies founder Yoon Auh said adopting post-quantum cryptography would require more than a protocol overhaul. Large numbers of wallets, exchanges and holders worldwide would also need to migrate in coordination, testing the efficiency of decentralized governance.

The latest report focuses on whether Bitcoin governance can move quickly enough to address quantum risks, comparing the upgrade capacity of decentralized networks such as Ethereum with that of centralized systems. It gives no value for the assets at risk, potential date of a quantum attack or upgrade timetable. However, it stresses that assets held at legacy addresses could remain exposed if some wallets fail to migrate, even after the core protocol is updated.

ARK Invest White Paper Examines Bitcoin’s Quantum-Attack Resilience2026-03-13 · 4 reports · similarity 0.82

Bitcoin relies on elliptic-curve digital signatures to secure asset ownership, but powerful quantum computers could eventually derive private keys from public keys that have already been exposed. ARK Invest and Bitcoin financial services provider Unchained therefore studied advances in quantum technology and potential paths for Bitcoin to adopt quantum-resistant cryptography, an issue with implications for long-term asset security and consensus on network upgrades.

On March 11, 2026, ARK Invest and Unchained published the “Bitcoin and Quantum Computing” white paper, estimating that 34.6%, or about 6.9 million BTC, is theoretically at risk. That includes about 1.7 million BTC believed to be lost and roughly 5.2 million BTC that could be moved to more secure addresses. The report said the threat would emerge in stages and was not urgent in the near term, leaving the community time to deploy quantum-resistant solutions.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)