Two research papers published on March 30–31, 2026, cut the estimated qubit threshold for breaking blockchain cryptography by a factor of 20. Google Quantum AI calculated that a superconducting machine with fewer than 500,000 physical qubits could derive a Bitcoin private key from its public key ...
"The prudent approach is to prepare Bitcoin and give people the option to migrate their keys to a quantum-ready format, with roughly a decade to do so." — Adam Back, CEO, Blockstream
Two research papers published on March 30–31, 2026, cut the estimated qubit threshold for breaking blockchain cryptography by a factor of 20. Google Quantum AI calculated that a superconducting machine with fewer than 500,000 physical qubits could derive a Bitcoin private key from its public key in approximately nine minutes. Separately, an Oratomic/Caltech team estimated that a neutral-atom system with roughly 26,000 physical qubits could achieve the same break in about ten days using high-rate quantum LDPC codes. Google's current Willow chip has 105 qubits.
The gap between 105 and 500,000 qubits remains large. No machine capable of executing the attack exists today. But the papers compressed the theoretical timeline enough to trigger the most concentrated burst of post-quantum development activity in Bitcoin and Ethereum history: BIP-360 merged into Bitcoin's official proposal repository, a StarkWare researcher published a no-fork quantum-safe transaction scheme, Lightning Labs' CTO shipped a working wallet-rescue prototype, and Vitalik Buterin formalized a four-year quantum-resistance roadmap for Ethereum. Wall Street broker Bernstein issued a note on April 8 characterizing the threat as "real but manageable," estimating a three-to-five-year migration window.
At current prices, approximately 6.5 million BTC — roughly $718 billion — sits in address types directly vulnerable to quantum key extraction, according to Project Eleven. That figure includes an estimated 1 million BTC attributed to Satoshi Nakamoto, held in early Pay-to-Public-Key (P2PK) addresses where public keys are permanently exposed on-chain.
Prior to March 2026, widely cited estimates placed the qubit requirement for breaking 256-bit elliptic curve cryptography (ECC-256) — the standard securing Bitcoin and Ethereum transaction signatures — at several million physical qubits. Two papers, released within 24 hours of each other, substantially lowered that number.
Google Quantum AI (March 31, 2026): Researchers demonstrated that an optimized version of Shor's algorithm running on a fast superconducting quantum computer would require fewer than 1,200 logical qubits and fewer than 500,000 physical qubits to solve the elliptic curve discrete logarithm problem for ECC-256. Execution time: approximately nine minutes. This sits within Bitcoin's average 10-minute block confirmation window, enabling what the paper describes as "on-spend" attacks — intercepting transactions in the mempool and deriving private keys before confirmation.
Oratomic/Caltech (March 30, 2026): A separate team proposed that a neutral-atom quantum computer leveraging high-rate quantum LDPC error-correcting codes could crack ECC-256 with approximately 26,000 physical qubits at the cost of a longer 10-day execution window. The paper's title: "Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits." The Oratomic result relies on qLDPC codes not yet demonstrated at scale, and several co-authors hold equity in Oratomic, warranting appropriate skepticism.
Context: Google's Willow chip, the most advanced publicly disclosed quantum processor, operates with 105 physical qubits. Google's stated roadmap targets a "useful, error-corrected quantum computer" by 2029, implying a scaling trajectory from hundreds to potentially one million physical qubits over four years. Google has set a 2029 internal deadline to migrate its own authentication services to post-quantum cryptography.
PC Gamer reported that Google estimates a 10% probability of "Q-Day" — the date a quantum computer can break widely used public-key cryptography — by 2032.
Not all Bitcoin addresses carry equal quantum risk. The vulnerability depends on whether a public key has been exposed on-chain.
High risk — Pay-to-Public-Key (P2PK): These legacy addresses, common in Bitcoin's early years (2009–2012), store the full public key directly on the blockchain. A quantum attacker needs only to read the chain and run Shor's algorithm. No transaction from the victim is required.
Medium risk — Address reuse: Any address that has sent a transaction has its public key exposed in that transaction's scriptSig. Users who reuse addresses after spending from them have their public keys permanently visible.
Lower risk — Unspent P2PKH/P2SH/P2WPKH: Addresses that have only received funds do not expose their public key on-chain. The public key is only revealed when the owner spends, creating a narrow attack window during transaction broadcast.
According to data cited by Project Eleven, approximately 6.51 million BTC — worth over $718 billion — is held in addresses vulnerable to "long-range" quantum attacks, representing nearly a third of the total current Bitcoin supply. CoinDesk reported in February 2026 that roughly 7 million BTC, including approximately 1 million attributed to Satoshi Nakamoto, could be exposed, valued at approximately $440 billion at prices at the time of reporting.
The March papers triggered three distinct development tracks within Bitcoin, each with different tradeoffs.
BIP-360, merged into Bitcoin's official improvement proposal repository in February 2026, introduces a new output type called Pay-to-Merkle-Root. It removes the public key from on-chain storage entirely, replacing it with a hash commitment. The proposal envisions quantum-resistant signature schemes (such as SPHINCS+) as drop-in replacements.
The governance obstacle is significant. Bitcoin's last major soft fork, Taproot, took approximately seven and a half years from concept to deployment. Bernstein's April 8 note described the quantum threat as a "manageable upgrade cycle," but acknowledged the consensus timeline risk.
On April 9, StarkWare Chief Product Officer Avihu Levy published QSB, a scheme that achieves quantum-safe Bitcoin transactions within existing consensus rules. QSB builds security on the pre-image resistance of RIPEMD-160, which quantum computers can only attack via Grover's algorithm (quadratic speedup, not a total break). The sender iterates over transaction parameters until the hash produces a valid DER-encoded ECDSA signature — no protocol change required.
Cost: $75–$200 per transaction in GPU compute. Levy described the scheme as a "last resort measure." It is incompatible with the Lightning Network and impractical for everyday use, but potentially viable for securing high-value holdings.
On April 8, Olaoluwa Osuntokun, CTO of Lightning Labs, posted a working prototype to the Bitcoin developer mailing list. The tool addresses a specific flaw in emergency quantum-defense plans: an upgrade that disables ECDSA signatures to block quantum attackers would also lock legitimate users out of their own funds.
Osuntokun's prototype lets users prove wallet ownership using their seed phrase without revealing it, through a zero-knowledge proof mechanism. Performance on a consumer MacBook: 55 seconds to generate the proof, under 2 seconds to verify, producing a 1.7 MB proof file. The system remains unoptimized with no formal deployment proposal.
Vitalik Buterin published a post-quantum resistance roadmap on February 26, 2026, following an Ethereum Foundation workshop in January. The plan identifies four components vulnerable to quantum attacks:
The proposed fix centers on EIP-8141, which would make Ethereum wallets flexible enough to support hash-based signatures. The technical challenge: ECDSA verification costs approximately 3,000 gas, while quantum-resistant signature verification may require up to 200,000 gas. The roadmap relies on recursive STARK aggregation to compress multiple signatures into a single proof.
Implementation timeline: approximately seven forks over four years, with Glamsterdam and Hegotá confirmed for 2026. A dedicated Post-Quantum Security team, established in January 2026, oversees the migration. Full activation is targeted before 2030.
An estimated 1 million BTC attributed to Satoshi Nakamoto — worth approximately $76 billion at current prices — sits in P2PK addresses with permanently exposed public keys. Satoshi has not moved a single coin in over 15 years. No protocol upgrade can force migration of an inactive wallet.
The Bitcoin community faces what Fortune described in April 2026 as "the unthinkable" — three options, none clean:
This is a social consensus problem, not a technical one. BeInCrypto characterized it as "Bitcoin's hardest social consensus test."
NIST: Released final post-quantum cryptography standards in 2024 (FIPS 203, 204, 205), covering ML-KEM, ML-DSA, and SLH-DSA. Under NIST IR 8547, all quantum-vulnerable algorithms will be deprecated by 2035, with high-risk systems transitioning earlier.
Blockstream: A 20-person research team has been testing post-quantum signatures (SPHINCS+) on the Liquid Network. CEO Adam Back stated on April 8 that the threat timeline is "decades away" but urged the industry to begin migration now.
Bernstein: Issued an April 8 client note stating the quantum threat is "real but manageable," framing it as an upgrade cycle rather than an existential crisis. The firm noted that Bitcoin mining (SHA-256 hashing) remains secure even against advanced quantum scenarios; the vulnerability is isolated to public-key signature schemes.
Google: Has set a 2029 internal deadline to migrate its own authentication services to post-quantum cryptography, signaling institutional urgency independent of the crypto sector.
The quantum threat to blockchain cryptography has transitioned from a theoretical concern to an active engineering problem. The qubit gap remains large — 105 today versus 500,000 needed — but the 20x reduction in estimated requirements, combined with Google's 2029 migration deadline for its own systems, has compressed planning timelines across the industry.
The economic exposure is concentrated but substantial: $718 billion in vulnerable Bitcoin, with $76 billion effectively un-migrateable without resolving the Satoshi wallet question. Ethereum's structured roadmap offers a clearer migration path than Bitcoin's governance-constrained process, where the last major soft fork took seven years.
The data does not support panic. It does support urgency. The difference between the two is measured in the engineering capacity and social consensus mechanisms these networks deploy over the next three to five years.