The quantum threat to Bitcoin: how real is the "killer" scenario for the first cryptocurrency?

The question of whether quantum computing will prove fatal for Bitcoin has long moved beyond theoretical discussions. At the center of the debate is Shor's algorithm, which could radically change the complexity of recovering a private key from a public one. This is not about speeding up brute-force attempts, but about shifting the complexity class: what was once considered impossible becomes solvable in minutes—provided the appropriate hardware exists.
In this analytical review, I examine how real the threat is, which specific addresses are at risk, and why the market may react to the quantum narrative much earlier than actual hardware becomes available.
Brief verdict: the threat exists, but not today
Theoretically, Shor's algorithm does indeed undermine the security of ECDSA and Schnorr signatures, which rely on the secp256k1 curve. However, the current generation of quantum processors consists of about 1,100–1,200 physical qubits without error correction. A real attack on Bitcoin would require millions of stable logical qubits. Thus, for now, this is more of a hypothetical scenario than a practical threat.
Why this is the case
The network's security rests on the irreversibility of the operation P = k ⋅ G. The best classical algorithms require on the order of 2¹²⁸ operations, which is unattainable for modern systems. Shor's algorithm changes the very nature of the problem, but the "cost" is measured in qubits. Estimates vary: from 2,330 logical qubits (equivalent to 1–13 million physical qubits) to more conservative projections from the University of Sussex—about 13 million physical qubits to crack it within a day.
Notably, a Google Quantum AI study published in March 2026 significantly revised these figures downward. According to their calculations, fewer than 500,000 physical qubits and about 70 million computational steps would suffice to recover a key in 9 minutes—faster than a block is mined. This is a twenty-fold improvement over 2019 projections.
By 2029, IBM plans to build a fault-tolerant IBM Quantum Starling system with 200 logical qubits, while IonQ aims for 2 million physical qubits by 2030. If these plans materialize, we could see a machine capable of cracking Bitcoin keys in the second half of the 2030s. However, experts like Adam Back believe the real timeline is 20–40 years. A survey of 26 experts by the Institute for Global Risk estimates the probability of a cryptographically significant computer emerging at 28–49% within ten years and 51–70% within fifteen.
The key vulnerability factor is not the size of the balance, but digital hygiene. Addresses with exposed public keys are primarily at risk: P2PK from the Satoshi era, Taproot architecture, and wallets with address reuse. According to analysts, keys for 6.04 million BTC (30.2% of the total supply) are exposed in the blockchain. Of these, 1.92 million BTC are structurally vulnerable P2PK, and 4.12 million BTC are operationally vulnerable due to reuse.
In contrast, P2PKH, P2SH, and SegWit outputs remain secure until the first outgoing transaction, as they are hidden behind a hash. This gives rise to the HNDL (harvest now, decrypt later) strategy: an attacker does not need hardware today—it is enough to save the keys and wait for CRQC to emerge. A U.S. Federal Reserve study directly points to Bitcoin as an example of the limitations of post-quantum migration: new algorithms will not hide already published data.
What this means for investors
This is not a reason for panic, but a reason for an audit. Check whether your funds are on P2PK outputs or reused addresses. "Dormant" wallets from the early years have no one to migrate them—they will become the first targets.
But there is another, equally important risk: the price may react before the technology. A single high-profile publication about reduced qubit requirements could cause the market to price in risks long before a real attack. Two horizons are at play here: the technological (ten years or more) and the narrative (any upcoming quarter). Regulators—the NSA and NCSC—are already preparing the transition to post-quantum cryptography, and Bitcoin will have to coordinate migration through consensus, which is a slow process.
Key takeaways
Is the threat real?
For now, it is in data-collection mode (HNDL).
Is the hardware available?
No: about 1,500 noisy qubits versus the hundreds of thousands required.
Who is at risk?
Approximately 6 million BTC with exposed public keys, of which 1.92 million are P2PK.
What can be done now?
Check output types, avoid address reuse, and monitor post-quantum migration.
My expert assessment: the quantum threat is not a question of "if," but "when." However, the most likely scenario is not a sudden attack, but a gradual devaluation of old coins through narrative and regulatory pressure. Investors should diversify risks now, rather than wait for the first hacks.