Quantum apocalypse for bitcoin: a real threat or a delayed scenario?

The question of whether a quantum computer will become the "killer" of bitcoin has long stirred the minds of crypto enthusiasts. At the center of these concerns is Shor's algorithm, which fundamentally changes the approach to breaking cryptography. It transforms the task of recovering a private key from a public one from practically unsolvable to theoretically solvable within minutes, but only with the appropriate hardware.
Let's figure out how real this threat is today, which assets are exactly in the danger zone, and why the market might start panicking long before the first quantum hack becomes a reality.
Short answer: there is a theoretical risk, but not a practical one yet
Shor's algorithm is indeed capable of solving the elliptic curve discrete logarithm problem in polynomial time. This puts the security of ECDSA and Schnorr signatures, which use the secp256k1 curve, at risk. However, none of the existing devices have come close to the required power. Modern processors have about 1100–1200 physical qubits without error correction, while millions are needed for an attack on bitcoin. Key point: addresses whose public keys are already exposed in the blockchain are primarily at risk.
Why this is so
Bitcoin's security rests on the impossibility of computing a private key from a public one. The best classical algorithms require on the order of 2¹²⁸ operations—this is beyond the capabilities of any modern system. Shor's algorithm does not just speed up brute force; it changes the complexity class of the problem itself. But the cost is in qubits. Estimates vary by orders of magnitude: from 2330 stable logical qubits (equivalent to 1–13 million physical ones) to more modest forecasts. A Google Quantum AI study published in March 2026 lowered this estimate to less than 500,000 physical qubits, which would allow cracking a key in 9 minutes. This is a twenty-fold reduction in requirements compared to 2019 forecasts.
IBM and IonQ's plans to build fault-tolerant systems by 2029–2030 look encouraging, but even if implemented, a truly dangerous quantum computer might only appear in the second half of the 2030s. Meanwhile, a survey of 26 experts from the Institute for Global Risk puts the probability of a cryptographically significant device emerging within 15 years at 51–70%.
The key vulnerability factor is not the balance size, but the owner's digital hygiene. At increased risk are P2PK addresses from the Satoshi era, the Taproot architecture, and wallets with address reuse. According to Glassnode estimates, keys for 6.04 million BTC (30.2% of the total supply) have been exposed in the blockchain. The structural vulnerability of P2PK affects 1.92 million BTC, and the operational one another 4.12 million BTC.
From this follows the main practical risk—the HNDL strategy ("harvest now, decrypt later"). An attacker does not need a quantum computer today. It is enough to save all exposed public keys and wait for the arrival of a CRQC. A US Federal Reserve study directly points to bitcoin as an example of the limitations of post-quantum migration: new algorithms will not be able to hide already published data.
What this means for the investor
For holders, this is a reason for an audit, not for panic. Check whether funds are on P2PK outputs or reused addresses. For an investor, another risk matters too: the price may react before the technology does. A single high-profile publication about reduced qubit requirements is enough for the market to start pricing in risks long before a real attack. Regulators, including the NSA and NCSC, are already preparing the transition to post-quantum cryptography, and bitcoin will have to coordinate migration through consensus, which is always slower than updating commercial vendors' roadmaps.
My analysis: The market often overestimates technological threats and underestimates narrative ones. Even if decades remain before a real hack, the publication of any significant progress in this area could trigger short-term volatility. A sensible investor should consider both scenarios: the technological and the informational.