Google's quantum research division estimated in March 2026 that breaking Bitcoin's elliptic-curve cryptography requires fewer than 500,000 physical qubits — a twentyfold reduction from the 2019 estimate of approximately 9 million. The hardware gap between current machines and that threshold stand...
"There's no notification explaining the breach technique when an adversary compromises your cryptographic key." — Christopher Smith, CEO, Quantus Network
Google's quantum research division estimated in March 2026 that breaking Bitcoin's elliptic-curve cryptography requires fewer than 500,000 physical qubits — a twentyfold reduction from the 2019 estimate of approximately 9 million. The hardware gap between current machines and that threshold stands at roughly 400–500x, down from 9,000x seven years ago. Google has set an internal deadline of 2029 to complete its own post-quantum cryptography migration. NIST has targeted 2030 for deprecating current encryption standards.
The blockchain industry's response is fragmented. Bitcoin merged BIP-360 — its first quantum-resistant address type — on February 11, 2026. A companion proposal, BIP-361, published April 14, would freeze coins that fail to migrate to quantum-safe addresses by a network-defined deadline. Ethereum's Vitalik Buterin introduced a "Ship of Theseus" strategy in February 2026 targeting four vulnerable cryptographic primitives, with a 2029 completion target. Algorand claims a 2027 timeline. Solana's early tests show quantum-safe signatures are 20–40x larger and reduce network throughput by approximately 90%.
Between 6.5 and 6.9 million BTC — roughly one-third of total supply — sit in addresses where public keys are already exposed, according to Project Eleven. At current prices, that exposure exceeds $400 billion. The Federal Reserve published a September 2025 paper warning that "harvest now, decrypt later" attacks represent an active, ongoing threat to blockchain networks, and that no existing method can retroactively safeguard data already stored on public ledgers.
Google researcher Craig Gidney published a paper in March 2026 demonstrating that breaking RSA-2048 could require fewer than one million qubits — down from the 20 million estimated in his own 2019 work. A separate April 2026 Google whitepaper placed the threshold for cracking Bitcoin's ECDSA signatures at fewer than 500,000 physical qubits, or approximately 1,200 to 2,330 stable logical qubits.
Current quantum hardware operates at roughly 100 logical qubits, built on 1,000 to 1,200 noisy physical qubits. Google's Willow chip, announced December 2024, carries 105 qubits and was the first to demonstrate exponential error reduction as qubit count scales — the inverse of the historical pattern. IBM has deployed 433-qubit Condor processors. Atom Computing has launched 1,225-qubit neutral-atom machines.
The hardware gap is still measured in orders of magnitude. But the trajectory has shifted. Justin Drake, an Ethereum Foundation researcher, estimates a 10% probability that a quantum computer could recover a Bitcoin private key from an exposed public key by 2032. Google has internally set 2029 as its migration deadline. Adam Back, Blockstream CEO and inventor of Hashcash, remains skeptical, arguing the timeline is 20–40 years.
The disagreement itself is informative. When credible researchers' estimates span from 2029 to 2065, the risk distribution is wide enough to warrant protocol-level response.
BIP-360, published and merged into Bitcoin's official repository on February 11, 2026, introduces Pay-to-Merkle-Root (P2MR) — the network's first quantum-resistant address type. It uses ML-DSA signatures (formerly CRYSTALS-Dilithium), one of three algorithms standardized by NIST in 2024 under FIPS 204. Structurally, P2MR resembles Taproot (P2TR) with one critical removal: the key-path spend, which would expose a public key to quantum attack.
BIP-361, formally titled "Post Quantum Migration and Legacy Signature Sunset," followed on April 14, 2026. Its mechanism is straightforward: set a network-wide deadline by which holders of vulnerable coins must migrate to quantum-resistant addresses. After that deadline, the network stops honoring spends from legacy signature types. Coins that remain in vulnerable addresses would be permanently frozen.
The proposal's scope is not trivial. Project Eleven estimates that 6.5 to 6.9 million BTC sit in addresses where public keys are already exposed — through past transaction signatures, ancient Pay-to-Public-Key (P2PK) outputs, or certain Taproot spends. That figure includes an estimated 1.7 million coins in addresses widely attributed to Satoshi Nakamoto. At $65,000 per BTC, the exposed value exceeds $420 billion.
BIP-361 raises a governance question with no precedent in Bitcoin's history: whether the network should forcibly disable spending from addresses whose owners may be dead, lost, or simply inactive. The Satoshi coins alone represent approximately $110 billion. Freezing them would constitute the largest involuntary asset lockout in financial history.
A full Bitcoin migration is estimated to take 5–7 years, according to industry timelines cited by KuCoin research. SHA-256 mining remains quantum-safe — breaking it would require an impractical 10²³ qubits — so the consensus mechanism itself is not at risk.
The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026. The following month, Vitalik Buterin published a roadmap identifying four cryptographic primitives requiring replacement: BLS signatures (used in proof-of-stake consensus), KZG commitments (used in data availability), ECDSA signatures (used in transaction authorization), and Groth16 proofs (used in zero-knowledge applications).
Buterin's strategy — which he termed "Ship of Theseus" — proposes replacing each component incrementally across three to four years of scheduled hard forks, bundling security upgrades with performance improvements to reduce migration friction. The target completion date is 2029, aligned with Google's own internal deadline.
A "frame transaction" proposal is scheduled for the Hegemony upgrade in late 2026, marking the first protocol-level quantum preparation step.
Ethereum's approach differs from Bitcoin's in one important respect: it requires coordinated foundation leadership and scheduled forks, whereas Bitcoin's BIP process depends on decentralized developer consensus. This gives Ethereum more execution speed but concentrates upgrade risk in a smaller decision-making body.
Algorand is the furthest along. The network executed its first post-quantum cryptography (PQC)-secured transaction in 2025 and unveiled a roadmap in June 2026 targeting broad quantum resistance by 2027. FALCON-based accounts are available on an opt-in basis. However, every Algorand account still signs transactions with Ed25519 by default — the quantum-vulnerable standard. The headline resistance protects historical state, not current balances, unless users actively migrate.
Solana faces a structural disadvantage. Unlike Bitcoin and Ethereum, which derive addresses from hashed public keys, Solana exposes public keys directly. Alex Pruden, CEO of Project Eleven and former Army Green Beret turned crypto executive (Coinbase, a16z), stated in a CoinDesk interview: "In Solana, 100% of the network is vulnerable. A quantum computer could pick any wallet and immediately start trying to recover the private key." Early PQC testnet results show quantum-safe signatures are 20–40x larger than current signatures, reducing network throughput by approximately 90%. For a network that markets sub-second finality, the tradeoff is existential. An alternative approach using "Winternitz Vaults" is under exploration but remains pre-production.
Cardano has published post-quantum research but has no live protocol-wide PQC signature implementation. No binding timeline has been announced.
The Federal Reserve Board published a paper in September 2025 — "Harvest Now Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks" — authored by Jillian Mascelli and Megan Rodden (FEDS 2025-093). The paper's central finding: adversaries can collect encrypted blockchain data today and decrypt it once quantum capability arrives. Because blockchain ledgers are public and immutable, every transaction ever broadcast is permanently available for collection.
The HNDL risk applies differently to blockchains than to traditional encrypted communications. In a TLS session, captured ciphertext becomes readable. On a blockchain, captured public keys become spendable. The attacker does not merely read your data — they move your money.
Citi published a January 2026 report framing post-quantum security as a "trillion-dollar" issue across financial infrastructure. Sean Cheetham, a security analyst at Blockchain Capital, has suggested that rational adversaries would prioritize exchange operational wallets over dormant holdings like Satoshi's — the return on effort is higher when the target wallet actively receives deposits.
The exposure is not evenly distributed across the Bitcoin network:
| Address Type | Vulnerability | Estimated BTC Exposed | |---|---|---| | P2PK (Pay-to-Public-Key) | Direct public key exposure | ~1.7M BTC | | Reused P2PKH addresses | Public key revealed in prior spends | ~3.5–4M BTC | | Certain Taproot (P2TR) spends | Key-path spend reveals public key | Varies | | Total | | ~6.5–6.9M BTC |
At $65,000 per BTC, total exposure ranges from $422 billion to $448 billion. This represents approximately one-third of Bitcoin's circulating supply.
Ethereum's exposure is structurally different but potentially broader. Every Ethereum externally owned account (EOA) exposes its public key after the first outbound transaction. Michael Coates, CISO of the Solana Foundation, declined to estimate a specific timeline but noted the industry's pattern of "perpetually projecting Q-day as five years distant for over a decade."
The distinction matters for economic analysis. Bitcoin's vulnerability is concentrated in dormant or legacy wallets. Ethereum's and Solana's vulnerability spans active wallets. A quantum attacker targeting Ethereum or Solana could theoretically compromise recently active accounts, not just archaeological holdings.
Three timelines are now converging:
Hardware capability: Google's 2029 internal migration deadline implies the company believes cryptographically relevant quantum computers could arrive by the early 2030s. Justin Drake's 10% probability by 2032 aligns with this.
Standards deprecation: NIST plans to deprecate current encryption standards by 2030. The U.S. government's Quantum Computing Cybersecurity Preparedness Act (signed December 2022) requires federal agencies to begin transition planning.
Protocol migration: Bitcoin's BIP-360/361 has no activation date. Ethereum targets 2029. Algorand targets 2027. Solana is in early testing with severe performance constraints.
The gap between standards deprecation (2030) and protocol readiness (2027–2032+) creates a window of elevated risk. For protocols that cannot complete migration before quantum hardware reaches the required threshold, the race becomes adversarial.
Roy Blackstone, CEO of hardware wallet maker NGRAVE, noted that earlier risk assessments failed to anticipate the convergence of AI and quantum computing advances. The March 2026 Google paper used AI-assisted optimization to achieve its twentyfold resource reduction — suggesting future improvements may also arrive faster than linear extrapolation would predict.
The quantum threat to blockchain cryptography is no longer a theoretical exercise scheduled for "someday." Google's 2029 internal migration deadline, NIST's 2030 deprecation target, and the Federal Reserve's formal acknowledgment of HNDL risks establish an institutional consensus that the window is narrowing. The question is no longer whether blockchain protocols need to migrate — it is whether they can do so before the hardware catches up.
Bitcoin's BIP-360/361 framework provides a technical path but introduces an unprecedented governance dilemma around $110 billion in likely-inaccessible coins. Ethereum's coordinated approach offers faster execution at the cost of centralized decision-making. Solana's architectural exposure and severe performance tradeoffs suggest it faces the most difficult migration of any major chain.
The economic value at risk — over $400 billion in Bitcoin alone, plus uncalculated exposure across Ethereum, Solana, and other networks — makes this a balance-sheet issue, not merely a research curiosity. Protocols that complete migration first gain a measurable security premium. Those that lag assume a tail risk that grows less tail-like with each hardware generation.