Quantum apocalypse for Bitcoin: a real threat or a delayed scenario?

The debate over whether quantum computing will spell the end for bitcoin has been raging in the industry for years. At the heart of these concerns is Shor's algorithm, which radically changes the rules of the game: what is considered computationally impossible today becomes routine, measured in minutes, given sufficient quantum power. This concerns recovering a private key from a public one — a fundamental vulnerability of elliptic curve cryptography.
The essence of the threat and the current state of affairs
Theoretically, Shor's algorithm solves the discrete logarithm problem in polynomial time. This puts ECDSA and Schnorr signatures used in bitcoin at risk, since both schemes rely on the secp256k1 curve. However, in practice, no existing device has come close to the required parameters. Modern processors have about 1,100–1,200 "noisy" physical qubits without full error correction, whereas a real attack requires millions of stable logical qubits. The first to fall within the blast radius will be addresses whose public keys have already been exposed on the blockchain.
The cost of the issue: how many qubits are actually needed
Estimates of the attack's cost vary by orders of magnitude. Conservative forecasts suggest the need for ~2,330 logical qubits, which, accounting for error correction, is equivalent to 1–13 million physical qubits. Researchers at the University of Sussex cite a figure of 13 million qubits to break the encryption within a day. Earlier calculations for RSA-2048 required ~317 million physical qubits. However, a breakthrough study by Google Quantum AI, published in March 2026, significantly revised these estimates downward: fewer than 500,000 physical qubits (about 1,200 logical) and roughly 70 million computational steps are enough to crack a private key in less than 9 minutes. This is a twenty-fold improvement over 2019 projections.
The real risk picture
By 2029, IBM plans to build a fault-tolerant system with 200 logical qubits, while IonQ aims for 2 million physical qubits by 2030. If these plans come to fruition, we could see a machine capable of striking the network as early as the second half of the 2030s. However, authoritative experts such as Adam Back believe the real threat is pushed back 20–40 years. A survey of 26 experts at the Institute for Global Risk estimates the probability of a cryptographically significant quantum computer emerging within 10 years at 28–49%, and within 15 years at 51–70%.
The key vulnerability factor is not the size of the balance, but digital hygiene. The risk is concentrated in P2PK addresses from the Satoshi era, Taproot architecture, and wallets with address reuse. According to Glassnode estimates, keys for 6.04 million BTC (30.2% of the total supply, or ~$469 billion) have been exposed on the blockchain. Of these, 1.92 million BTC represent a structural P2PK vulnerability, while 4.12 million BTC are operational (reuse). In contrast, P2PKH, P2SH, and SegWit outputs remain protected until the first outgoing transaction, as they are hidden behind a hash.
The HNDL strategy and market risks
The most dangerous strategy is "harvest now, decrypt later" (HNDL). Attackers do not need to wait for a quantum computer to emerge: they can already store all exposed public keys to decrypt them later. A study by the U.S. Federal Reserve explicitly points to bitcoin as an example of the limitations of post-quantum migration: new algorithms will not hide already published data or automatically transfer funds from old outputs.
Conclusions for holders and investors
For holders, this is not a reason for panic, but a signal to conduct an audit. It is necessary to check whether funds are held in P2PK outputs or reused addresses, and whether long-term savings are stored in wallets with an exposed public key. Lost and "dormant" wallets from the early years have no one to migrate them — they will become the first targets.
For the investor, narrative risk is also critical: the price may react long before technical implementation. A single high-profile publication about reduced qubit requirements is enough for the market to start pricing in risks. Two horizons are at play here: technological (10+ years) and narrative (any upcoming quarter). Regulators, including the NSA and NCSC, are already preparing the transition to post-quantum cryptography, and bitcoin will have to coordinate migration through consensus — a process that proceeds significantly slower than the updating of commercial vendors' roadmaps.
My view: The quantum threat is not a question of "if," but a question of "when." However, the real catalyst for the market will not be the hack itself, but the moment when investors believe in its inevitability. Until then, bitcoin will continue to operate on the classical paradigm, and proper key auditing and avoiding address reuse remain the only sensible defense.