Overview

  • While quantum computers could theoretically compromise Bitcoin’s elliptic-curve cryptography, a suitable machine has yet to be developed.
  • Researchers at Google suggest that exploiting Bitcoin’s encryption might involve fewer than 500,000 qubits—significantly less than the previously mentioned “millions.”
  • BIP-360 and BIP-361 introduce new methods for quantum-resistant Bitcoin transactions and a gradual transition away from outdated signatures.
  • Ripple is working on a four-phase strategy to ensure the XRP Ledger is quantum-proof by 2028, while Ethereum aims for quantum resistance via its Strawmap initiative by 2030.
  • The main concern is the “harvest now, decrypt later” approach, where attackers gather encrypted data for future decryption using advanced quantum computers.

Quantum computing has the potential to dismantle Bitcoin’s elliptic-curve cryptography, although the requisite technology is not yet available. Here’s what cryptocurrency investors should be aware of regarding the looming quantum threat, the countermeasures in development, and the pertinent timelines.

Data accurate as of April 2026.

Understanding the Quantum Risk to Bitcoin

Bitcoin secures its transactions through the elliptic curve digital signature algorithm (ECDSA). When Bitcoin is sent, the user’s private key generates a digital signature, which the network verifies using the public key. This mechanism is effective because no conventional computer can feasibly reverse-engineer the private key from its corresponding public key.

However, quantum computers could alter this dynamic significantly. A competent quantum computer operating Shor’s algorithm could potentially derive a private key from a public key in mere minutes, enabling an attacker to fabricate transactions and misappropriate assets.

As of April 2026, no quantum computer has achieved this capability, but advancements are being made rapidly.

How Near Are Quantum Computers to Breaching Bitcoin?

In early 2026, Google released a whitepaper indicating that fewer than 500,000 physical qubits might be necessary to compromise Bitcoin’s elliptic-curve cryptography, a figure far lower than the “millions” frequently cited. Google’s team anticipates that such a machine could breach Bitcoin’s encryption in less than nine minutes.

During April 2026, researcher Giancarlo Lelli successfully cracked a 15-bit elliptic curve key using publicly available quantum technology, earning a 1 BTC reward from Project Eleven. Although Bitcoin employs 256-bit keys, this progress marks a remarkable 512-fold enhancement over what was achieved in September 2025.

Nobel Laureate Serge Haroche expressed concern in April 2026 that Bitcoin might become an early target for quantum-infused attacks. A panel of six cryptographers from Coinbase agreed that such a machine is inevitable and stressed the need for proactive migration.

Can Quantum Computers Compromise Bitcoin Mining?

No, not in practical terms. Research from April 2026 suggests that mounting an attack on SHA-256 mining would necessitate around 10²³ qubits and an energy output similar to that of a star. The genuine vulnerability lies in transaction signing (ECDSA), rather than in mining (SHA-256).

What Measures Are in Place to Safeguard Bitcoin?

BIP-360: Quantum-Resistant Transactions

BIP-360 introduces a new transaction type called Pay-to-Merkle-Root (P2MR), utilizing NIST-approved ML-DSA signatures. BTQ Technologies has successfully demonstrated BIP-360 transactions on a testnet.

BIP-361: Transition from Legacy Signatures

BIP-361, co-authored by Jameson Lopp and others, outlines a stepwise shift from outdated signatures:

  • Phase A (3 years): prohibits new funds to vulnerable addresses.
  • Phase B (5 years): abolishes ECDSA and Schnorr signatures completely.

Hashcash creator Adam Back advocates for the adoption of optional quantum-resistant features now, while others call for mandatory timelines for migration.

Google’s Warning on Taproot

In March 2026, researchers from Google discovered that the Taproot upgrade for Bitcoin may unintentionally make quantum attacks more feasible by broadening the exposure of public keys. Although it isn’t an immediate threat, it amplifies the urgency for the BIP-360 transition.

How Are Other Blockchains Responding?

Ethereum: Vitalik Buterin’s “Strawmap” (February 2026) aims for quantum resistance across various layers, including consensus, accounts, data availability, and zero-knowledge proofs. Forks for Glamsterdam and Hegotá are slated for 2026. Discover more about Ethereum’s plans for quantum resistance.

XRP Ledger: Ripple has devised a four-phase plan to enhance quantum resistance by 2028. ML-DSA signatures are already operational on the AlphaNet, and Ripple is collaborating with Project Eleven for validator assessments. Learn more about Ripple’s roadmap for a quantum-resistant XRP Ledger.

Hedera (HBAR): This blockchain already employs hash-based cryptography and has strategies aligned with NIST’s post-quantum cryptography (PQC) standards.

NIST’s Post-Quantum Standards

In August 2024, NIST finalized three PQC standards: ML-KEM (encryption), ML-DSA (signatures), and SLH-DSA (hash-based backup). It added HQC as a supplementary standard in March 2025. Google aims for complete migration to PQC by 2029.

What Should Cryptocurrency Investors Do Now?

  1. Stay calm — there are currently no quantum computers capable of breaching Bitcoin. The potential threat is estimated to arise in the next 5–10 years.
  2. Avoid reusing addresses — keeping public keys unexposed protects them from quantum threats.
  3. Keep an eye on BIP-360 and BIP-361 — required migration might necessitate action from all Bitcoin holders.
  4. Diversify your custody methods — hardware wallets will require firmware updates for post-quantum signatures.
  5. Adhere to NIST standards — blockchains that adopt PQC standards first will benefit from increased trust.

The ‘Harvest Now, Decrypt Later’ Concern

State-sponsored entities may already be gathering encrypted blockchain information to decrypt later with advanced quantum technology. Each exposed public key represents a possible future target. The urgency concerning BIP-360 and BIP-361 centers around safeguarding historical data from tomorrow’s technology.

Common Questions

Can quantum computers compromise Bitcoin right now?

No. The leading quantum computers in 2026 possess roughly 1,500 qubits. Breaching 256-bit ECDSA would need 500,000 or more. Such a machine is not currently available.

When will quantum computers be capable of breaking Bitcoin?

Experts from Google and Coinbase estimate a timeline of 5–10 years. The technology is “at least two significant engineering breakthroughs away,” but the migration itself is time-consuming, which is why preparations should commence now.

Is Bitcoin mining susceptible to quantum attacks?

Not really. Launching a SHA-256 attack would entail about 10²³ qubits and energy output comparable to that of a star—far beyond what current technology can achieve.

What is BIP-360?

A proposed soft fork that introduces quantum-resistant Pay-to-Merkle-Root (P2MR) transactions through NIST-approved post-quantum signatures.

What is BIP-361?

A gradual elimination of outdated signatures. After three years, new funds to vulnerable addresses would be banned. After five years, ECDSA and Schnorr signatures would be completely phased out.

Is Ethereum quantum-safe?

Not yet. Buterin’s “Strawmap” (February 2026) aims for quantum resilience by around 2030, targeting multiple layers including consensus, accounts, data availability, and zero-knowledge proofs.

Is XRP secure against quantum risks?

Ripple’s four-phase strategy aims for quantum resistance by 2028. ML-DSA signatures are already operating on the AlphaNet testnet.

Should I transfer my Bitcoin to a new address?

If you have reused addresses, your public key may be revealed. Transitioning to a new address conceals it—a best practice irrespective of quantum concerns.

What does ‘harvest now, decrypt later’ mean?

This strategy entails adversaries gathering encrypted data now to decrypt it later using future quantum capabilities. Each public key exposed today could become a target once sufficiently powerful quantum machines become a reality.

Share.