Bitcoin and Quantum Computing

The emergence of cryptographically-relevant quantum computers (CRQC) poses an existential threat to Bitcoin, requiring a complex transition to post-quantum cryptography to ensure long-term security.
Bitcoin’s signatures are broken if a cryptographically-relevant quantum computer (CRQC) were to appear tomorrow. Bitcoin requires changes both to its code and to everyone’s wallets (at least a soft fork and many users moving coins to different types of addresses) to be secure in the presence of a CRQC.
The remaining uncertainty is in two main areas: timeline and how to address this. I will frame these two issues in the following way:
- What is the likelihood of a CRQC appearing, and on what timeframe?
- What are the best paths for Bitcoin successfully upgrading so that it would not be broken in the presence of a CRQC, and at what cost to Bitcoin?
A CRQC is an existential threat to Bitcoin. Your measurement of this threat should literally be: (A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will NOT successfully upgrade by that time.
Google recently introduced a timeline for moving to PQC by 2029. The last soft fork in Bitcoin (Taproot) took nearly 4 years from proposal to activation. If there’s a 10% chance of a CRQC by 2030 and a 50% chance Bitcoin fails to upgrade in time, there is a 5% risk of total failure.
How to think about this as an investor
This probability of Bitcoin no longer working is a floor for how much you should value Bitcoin at $0. This should additively combine with all the other types of uncertainty you have about Bitcoin’s continued successful operation: keys might get stolen, Ethereum might overtake Bitcoin, or cryptoeconomic security might break down.
Moving forward
The clearest way to eliminate this existential threat is to make B zero and upgrade Bitcoin to post-quantum cryptography as soon as safely possible. However, challenges remain:
- Which specific signature scheme(s) should we use? Most PQ schemes produce larger signatures or require longer verification times.
- How to handle old UTXOs? Choosing badly might violate Bitcoin’s core principles of self-sovereignty.
- Wallet adoption: An entire ecosystem of wallets and exchanges must upgrade their systems.
I think the risk is high enough to warrant prioritizing designing, implementing, and evaluating post-quantum signature schemes and consensus upgrades in Bitcoin now. Calling everything FUD is lazy and unhelpful; on a long enough timeframe, the appearance of a CRQC becomes a question of when, not if.
Source: Hacker News















