Google Research Finds Quantum Threat to Bitcoin Lower Than Expected
Bitcoin and Ethereum rely on elliptic-curve cryptography to safeguard assets. A quantum computer capable of deriving a private key from a public key could potentially steal funds. Bitcoin activated Taproot on November 14, 2021, and because some transactions expose public keys in advance, the potential window for attack has widened.
The latest research from Google Quantum AI estimates that about 500,000 error-corrected physical qubits could be enough to crack a key within Bitcoin’s roughly nine-minute transaction confirmation window, far below previous estimates of several million qubits. No funds have been reported stolen through such an attack, but the researchers are urging the community to begin planning a migration to post-quantum cryptography.
All Coverage
14 original reportsThe Backstory
The history behind this eventQuantum Computing Threatens $440 Billion in Bitcoin, Including Satoshi's Million-Coin Stash
Bitcoin transactions rely on elliptic-curve digital signatures. A sufficiently powerful quantum computer could use Shor's algorithm to derive a private key from a public key, leaving older addresses whose keys have already been exposed at greatest risk. A February 2026 estimate put nearly 7 million BTC at risk, including about 1 million attributed to Satoshi Nakamoto, with a combined value of about $440 billion. The issue has implications for holders' property rights and consensus across the network.
On June 13, 2026, an independent quantum computing advisory board convened by Coinbase said quantum computers could not yet break Bitcoin but urged immediate planning for quantum-resistant signatures. It estimated that about 6.7 million BTC was at risk but did not endorse freezing or restricting older coins. A May 6 report from Project Eleven set 2033 as its baseline year for Q-Day, with 2030 as the earliest scenario.
Quantum Computing Threatens Bitcoin Security as Bit Digital Shifts to Ethereum
Bitcoin transactions use elliptic-curve digital signatures to secure assets. A quantum computer running Shor’s algorithm could potentially derive private keys from public keys, putting older wallets and transaction security at risk. Ethereum, by contrast, has planned a mechanism allowing accounts to adopt quantum-resistant signatures, bringing corporate crypto treasury strategies and onchain governance capabilities into focus.
Google Quantum AI and other institutions published research on March 30, 2026, estimating that fewer than 500,000 physical qubits could crack a key in about nine minutes. Citi warned on May 18 that the potential attack timeline had shortened. Bit Digital had already announced on July 7, 2025, that it would sell about 280 Bitcoin and, alongside a $172 million fundraising, increase its holdings to 100,603 Ethereum.
Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security
Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.
Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.
Project Eleven Awards 1 BTC Bounty After Researcher Cracks 15-Bit ECC Key With Quantum Computer
Blockchains including Bitcoin and Ethereum use elliptic-curve cryptography (ECC) to verify control of assets. A sufficiently powerful quantum computer could use Shor’s algorithm to derive a private key from a public key. Nonprofit Project Eleven created the Q-Day Prize to track that risk through real-world testing and encourage the industry’s transition to post-quantum cryptography (PQC). The latest result, however, remains far below the 256-bit security scale used by Bitcoin.
Project Eleven announced on April 24, 2026, that it had awarded the 1 BTC Q-Day Prize to Giancarlo Lelli. Using a variant of Shor’s algorithm on a publicly accessible quantum computer, Lelli derived a 15-bit ECC private key from its public key. The search space of 32,767 possibilities was 512 times larger than the 6-bit record set in September 2025, establishing a new high for a public demonstration at the time.
Wall Street Broker Bernstein Warns of Quantum Threat to Bitcoin but Says Risk Is Manageable
Bitcoin uses elliptic-curve digital signatures to prove asset ownership. If a large-scale quantum computer could use Shor's algorithm to derive private keys, older addresses whose public keys have been exposed could be vulnerable to theft. Wall Street research and brokerage firm Bernstein said the risk is concentrated in Satoshi-era wallets holding about 1.7 million BTC, rather than posing an immediate threat to mining or the entire network.
Bernstein said on April 8, 2026, that Google had cut its estimate of the number of qubits needed to break the cryptography by about 20-fold to fewer than 500,000, but Bitcoin still had three to five years to upgrade. On April 13, the firm said BTC's nearly 50% retreat from its October 2025 peak of $126,198 had already priced in most of the quantum risk. The real challenge, it said, lies in securing community consensus and migrating wallets.
Michael Saylor Says Quantum Threat to Bitcoin Is at Least 10 Years Away
Quantum computers capable of breaking public-key cryptography could threaten Bitcoin signatures and asset ownership, making the technology a long-term market risk. Strategy, formerly MicroStrategy, co-founder and Executive Chairman Michael Saylor said banks, the internet and crypto assets all face the same pressure to upgrade, while Bitcoin could adopt quantum-resistant cryptography through updates to its nodes, wallets and protocol.
Saylor told Natalie Brunell’s “Coin Stories” on Feb. 23, 2026, that any quantum breakthrough posing a material threat was at least 10 years away. At a Mizuho event on April 8, he again said the risk was overstated and could be addressed through upgrades. He also said Bitcoin had likely bottomed at about $60,000 in early February; its price was around $71,200 when the report was published on April 9.
Quantum Attack on Bitcoin Mining Would Require Star-Scale Energy, Study Says
Bitcoin uses a proof-of-work mechanism, and an attacker controlling more than 50% of the network’s computing power could theoretically reorganize its transaction history. An academic research team found that while quantum computing could accelerate calculations, a 51% attack on Bitcoin mining would still face physical constraints including hardware scale, cooling and energy supply, limiting the near-term threat.
As of July 20, 2026, the latest research estimates that a quantum computer powerful enough to overwhelm the entire Bitcoin network could require energy on the scale of a star, putting such a system beyond what existing institutions could deploy with funding alone. A more practical risk is the compromise of older wallets whose public keys remain exposed. Bitcoin developers have begun exploring quantum-resistant signatures and network upgrades.
Nobel Physics Laureate Warns of Bitcoin Quantum Threat, Urges Swift Post-Quantum Planning
Bitcoin uses public- and private-key cryptography to verify asset ownership and transactions. If powerful quantum computers become capable of deriving private keys from public keys, assets held at some addresses could be stolen. John Martinis, a Nobel physics laureate and former head of quantum hardware at Google, said the risk now raises questions about Bitcoin’s long-term security and its capacity for decentralized governance.
Martinis recently warned that quantum computers could become capable of breaking Bitcoin’s public-key cryptography within the next 5 to 10 years, and that the community should not wait for an attack before responding. He called for early planning on post-quantum cryptography, software upgrades and asset-migration mechanisms. The reports did not provide an exact publication date, the value of assets at risk or the scale of quantum computer that could break Bitcoin in practice.
Galaxy Digital Says Bitcoin Faces a Real Quantum Threat, but Not Yet an Existential Crisis
Quantum computers could theoretically derive private keys from public keys exposed on-chain, allowing attackers to forge signatures and steal assets. Cybersecurity organization Project Eleven estimates that about 7 million Bitcoin may face long-term exposure, worth roughly $470 billion at recent prices. Most wallets whose public keys have not been revealed are currently unaffected, however, meaning the risk does not extend across the entire network.
Galaxy Digital research head Alex Thorn said on March 19, 2026, that the quantum threat was real but did not yet pose an existential crisis for Bitcoin. Research analyst Will Owens added on March 20 that related proposals had increased markedly since late 2025. Developers are advancing quantum-resistant addresses, BIP 360 and phased upgrade plans, while investors should currently view the issue as a long-term technical challenge.
ARK Invest White Paper Examines Bitcoin’s Quantum-Attack Resilience
Bitcoin relies on elliptic-curve digital signatures to secure asset ownership, but powerful quantum computers could eventually derive private keys from public keys that have already been exposed. ARK Invest and Bitcoin financial services provider Unchained therefore studied advances in quantum technology and potential paths for Bitcoin to adopt quantum-resistant cryptography, an issue with implications for long-term asset security and consensus on network upgrades.
On March 11, 2026, ARK Invest and Unchained published the “Bitcoin and Quantum Computing” white paper, estimating that 34.6%, or about 6.9 million BTC, is theoretically at risk. That includes about 1.7 million BTC believed to be lost and roughly 5.2 million BTC that could be moved to more secure addresses. The report said the threat would emerge in stages and was not urgent in the near term, leaving the community time to deploy quantum-resistant solutions.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.