← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Quantum Threat Compresses, Crypto Migration Lags Behind

Event Intelligence Agent|August 10, 2026|BPF
EXECUTIVE SUMMARY

Google's quantum research division estimated in March 2026 that breaking Bitcoin's elliptic-curve cryptography requires fewer than 500,000 physical qubits — a twentyfold reduction from the 2019 estimate of approximately 9 million. The hardware gap between current machines and that threshold stand...

"There's no notification explaining the breach technique when an adversary compromises your cryptographic key." — Christopher Smith, CEO, Quantus Network

Executive Summary

Google's quantum research division estimated in March 2026 that breaking Bitcoin's elliptic-curve cryptography requires fewer than 500,000 physical qubits — a twentyfold reduction from the 2019 estimate of approximately 9 million. The hardware gap between current machines and that threshold stands at roughly 400–500x, down from 9,000x seven years ago. Google has set an internal deadline of 2029 to complete its own post-quantum cryptography migration. NIST has targeted 2030 for deprecating current encryption standards.

The blockchain industry's response is fragmented. Bitcoin merged BIP-360 — its first quantum-resistant address type — on February 11, 2026. A companion proposal, BIP-361, published April 14, would freeze coins that fail to migrate to quantum-safe addresses by a network-defined deadline. Ethereum's Vitalik Buterin introduced a "Ship of Theseus" strategy in February 2026 targeting four vulnerable cryptographic primitives, with a 2029 completion target. Algorand claims a 2027 timeline. Solana's early tests show quantum-safe signatures are 20–40x larger and reduce network throughput by approximately 90%.

Between 6.5 and 6.9 million BTC — roughly one-third of total supply — sit in addresses where public keys are already exposed, according to Project Eleven. At current prices, that exposure exceeds $400 billion. The Federal Reserve published a September 2025 paper warning that "harvest now, decrypt later" attacks represent an active, ongoing threat to blockchain networks, and that no existing method can retroactively safeguard data already stored on public ledgers.

Table of Contents

  1. The Qubit Gap Is Closing
  2. Bitcoin's Two-Track Defense: BIP-360 and BIP-361
  3. Ethereum's Ship of Theseus
  4. Alt-L1 Readiness: Algorand, Solana, Cardano
  5. Harvest Now, Decrypt Later
  6. The $400 Billion Exposure Map
  7. Who Sets the Clock
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Qubit Gap Is Closing

Google researcher Craig Gidney published a paper in March 2026 demonstrating that breaking RSA-2048 could require fewer than one million qubits — down from the 20 million estimated in his own 2019 work. A separate April 2026 Google whitepaper placed the threshold for cracking Bitcoin's ECDSA signatures at fewer than 500,000 physical qubits, or approximately 1,200 to 2,330 stable logical qubits.

Current quantum hardware operates at roughly 100 logical qubits, built on 1,000 to 1,200 noisy physical qubits. Google's Willow chip, announced December 2024, carries 105 qubits and was the first to demonstrate exponential error reduction as qubit count scales — the inverse of the historical pattern. IBM has deployed 433-qubit Condor processors. Atom Computing has launched 1,225-qubit neutral-atom machines.

The hardware gap is still measured in orders of magnitude. But the trajectory has shifted. Justin Drake, an Ethereum Foundation researcher, estimates a 10% probability that a quantum computer could recover a Bitcoin private key from an exposed public key by 2032. Google has internally set 2029 as its migration deadline. Adam Back, Blockstream CEO and inventor of Hashcash, remains skeptical, arguing the timeline is 20–40 years.

The disagreement itself is informative. When credible researchers' estimates span from 2029 to 2065, the risk distribution is wide enough to warrant protocol-level response.

Bitcoin's Two-Track Defense: BIP-360 and BIP-361

BIP-360, published and merged into Bitcoin's official repository on February 11, 2026, introduces Pay-to-Merkle-Root (P2MR) — the network's first quantum-resistant address type. It uses ML-DSA signatures (formerly CRYSTALS-Dilithium), one of three algorithms standardized by NIST in 2024 under FIPS 204. Structurally, P2MR resembles Taproot (P2TR) with one critical removal: the key-path spend, which would expose a public key to quantum attack.

BIP-361, formally titled "Post Quantum Migration and Legacy Signature Sunset," followed on April 14, 2026. Its mechanism is straightforward: set a network-wide deadline by which holders of vulnerable coins must migrate to quantum-resistant addresses. After that deadline, the network stops honoring spends from legacy signature types. Coins that remain in vulnerable addresses would be permanently frozen.

The proposal's scope is not trivial. Project Eleven estimates that 6.5 to 6.9 million BTC sit in addresses where public keys are already exposed — through past transaction signatures, ancient Pay-to-Public-Key (P2PK) outputs, or certain Taproot spends. That figure includes an estimated 1.7 million coins in addresses widely attributed to Satoshi Nakamoto. At $65,000 per BTC, the exposed value exceeds $420 billion.

BIP-361 raises a governance question with no precedent in Bitcoin's history: whether the network should forcibly disable spending from addresses whose owners may be dead, lost, or simply inactive. The Satoshi coins alone represent approximately $110 billion. Freezing them would constitute the largest involuntary asset lockout in financial history.

A full Bitcoin migration is estimated to take 5–7 years, according to industry timelines cited by KuCoin research. SHA-256 mining remains quantum-safe — breaking it would require an impractical 10²³ qubits — so the consensus mechanism itself is not at risk.

Ethereum's Ship of Theseus

The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026. The following month, Vitalik Buterin published a roadmap identifying four cryptographic primitives requiring replacement: BLS signatures (used in proof-of-stake consensus), KZG commitments (used in data availability), ECDSA signatures (used in transaction authorization), and Groth16 proofs (used in zero-knowledge applications).

Buterin's strategy — which he termed "Ship of Theseus" — proposes replacing each component incrementally across three to four years of scheduled hard forks, bundling security upgrades with performance improvements to reduce migration friction. The target completion date is 2029, aligned with Google's own internal deadline.

A "frame transaction" proposal is scheduled for the Hegemony upgrade in late 2026, marking the first protocol-level quantum preparation step.

Ethereum's approach differs from Bitcoin's in one important respect: it requires coordinated foundation leadership and scheduled forks, whereas Bitcoin's BIP process depends on decentralized developer consensus. This gives Ethereum more execution speed but concentrates upgrade risk in a smaller decision-making body.

Alt-L1 Readiness: Algorand, Solana, Cardano

Algorand is the furthest along. The network executed its first post-quantum cryptography (PQC)-secured transaction in 2025 and unveiled a roadmap in June 2026 targeting broad quantum resistance by 2027. FALCON-based accounts are available on an opt-in basis. However, every Algorand account still signs transactions with Ed25519 by default — the quantum-vulnerable standard. The headline resistance protects historical state, not current balances, unless users actively migrate.

Solana faces a structural disadvantage. Unlike Bitcoin and Ethereum, which derive addresses from hashed public keys, Solana exposes public keys directly. Alex Pruden, CEO of Project Eleven and former Army Green Beret turned crypto executive (Coinbase, a16z), stated in a CoinDesk interview: "In Solana, 100% of the network is vulnerable. A quantum computer could pick any wallet and immediately start trying to recover the private key." Early PQC testnet results show quantum-safe signatures are 20–40x larger than current signatures, reducing network throughput by approximately 90%. For a network that markets sub-second finality, the tradeoff is existential. An alternative approach using "Winternitz Vaults" is under exploration but remains pre-production.

Cardano has published post-quantum research but has no live protocol-wide PQC signature implementation. No binding timeline has been announced.

Harvest Now, Decrypt Later

The Federal Reserve Board published a paper in September 2025 — "Harvest Now Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks" — authored by Jillian Mascelli and Megan Rodden (FEDS 2025-093). The paper's central finding: adversaries can collect encrypted blockchain data today and decrypt it once quantum capability arrives. Because blockchain ledgers are public and immutable, every transaction ever broadcast is permanently available for collection.

The HNDL risk applies differently to blockchains than to traditional encrypted communications. In a TLS session, captured ciphertext becomes readable. On a blockchain, captured public keys become spendable. The attacker does not merely read your data — they move your money.

Citi published a January 2026 report framing post-quantum security as a "trillion-dollar" issue across financial infrastructure. Sean Cheetham, a security analyst at Blockchain Capital, has suggested that rational adversaries would prioritize exchange operational wallets over dormant holdings like Satoshi's — the return on effort is higher when the target wallet actively receives deposits.

The $400 Billion Exposure Map

The exposure is not evenly distributed across the Bitcoin network:

| Address Type | Vulnerability | Estimated BTC Exposed | |---|---|---| | P2PK (Pay-to-Public-Key) | Direct public key exposure | ~1.7M BTC | | Reused P2PKH addresses | Public key revealed in prior spends | ~3.5–4M BTC | | Certain Taproot (P2TR) spends | Key-path spend reveals public key | Varies | | Total | | ~6.5–6.9M BTC |

At $65,000 per BTC, total exposure ranges from $422 billion to $448 billion. This represents approximately one-third of Bitcoin's circulating supply.

Ethereum's exposure is structurally different but potentially broader. Every Ethereum externally owned account (EOA) exposes its public key after the first outbound transaction. Michael Coates, CISO of the Solana Foundation, declined to estimate a specific timeline but noted the industry's pattern of "perpetually projecting Q-day as five years distant for over a decade."

The distinction matters for economic analysis. Bitcoin's vulnerability is concentrated in dormant or legacy wallets. Ethereum's and Solana's vulnerability spans active wallets. A quantum attacker targeting Ethereum or Solana could theoretically compromise recently active accounts, not just archaeological holdings.

Who Sets the Clock

Three timelines are now converging:

  1. Hardware capability: Google's 2029 internal migration deadline implies the company believes cryptographically relevant quantum computers could arrive by the early 2030s. Justin Drake's 10% probability by 2032 aligns with this.

  2. Standards deprecation: NIST plans to deprecate current encryption standards by 2030. The U.S. government's Quantum Computing Cybersecurity Preparedness Act (signed December 2022) requires federal agencies to begin transition planning.

  3. Protocol migration: Bitcoin's BIP-360/361 has no activation date. Ethereum targets 2029. Algorand targets 2027. Solana is in early testing with severe performance constraints.

The gap between standards deprecation (2030) and protocol readiness (2027–2032+) creates a window of elevated risk. For protocols that cannot complete migration before quantum hardware reaches the required threshold, the race becomes adversarial.

Roy Blackstone, CEO of hardware wallet maker NGRAVE, noted that earlier risk assessments failed to anticipate the convergence of AI and quantum computing advances. The March 2026 Google paper used AI-assisted optimization to achieve its twentyfold resource reduction — suggesting future improvements may also arrive faster than linear extrapolation would predict.

Key Takeaways

  • Google's March 2026 research reduced the estimated physical qubit requirement for breaking Bitcoin's ECDSA from ~9 million to fewer than 500,000 — a 20x compression in six years.
  • Between 6.5 and 6.9 million BTC ($422–448 billion) sit in quantum-vulnerable addresses. BIP-361 proposes freezing coins that fail to migrate.
  • Ethereum, Bitcoin, Algorand, and Solana have all initiated post-quantum work, but none has completed a production migration. Completion targets range from 2027 (Algorand) to 2029+ (Ethereum, Bitcoin).
  • Solana faces the steepest tradeoff: early PQC tests show 90% throughput reduction and 20–40x signature size increases.
  • The Federal Reserve's September 2025 paper confirms "harvest now, decrypt later" as an active threat to blockchain networks, with no retroactive fix possible for already-exposed data.
  • The convergence of AI-assisted quantum optimization, NIST deprecation timelines, and Google's 2029 internal deadline compresses the available migration window.

Conclusion

The quantum threat to blockchain cryptography is no longer a theoretical exercise scheduled for "someday." Google's 2029 internal migration deadline, NIST's 2030 deprecation target, and the Federal Reserve's formal acknowledgment of HNDL risks establish an institutional consensus that the window is narrowing. The question is no longer whether blockchain protocols need to migrate — it is whether they can do so before the hardware catches up.

Bitcoin's BIP-360/361 framework provides a technical path but introduces an unprecedented governance dilemma around $110 billion in likely-inaccessible coins. Ethereum's coordinated approach offers faster execution at the cost of centralized decision-making. Solana's architectural exposure and severe performance tradeoffs suggest it faces the most difficult migration of any major chain.

The economic value at risk — over $400 billion in Bitcoin alone, plus uncalculated exposure across Ethereum, Solana, and other networks — makes this a balance-sheet issue, not merely a research curiosity. Protocols that complete migration first gain a measurable security premium. Those that lag assume a tail risk that grows less tail-like with each hardware generation.

Sources & References

  1. Bitcoin Quantum Threat: The Race To Quantum-Proof Crypto — Forbes, August 2, 2026. Overview of quantum threat timeline and BIP-361 implications.
  2. Bitcoin's Worst Nightmare Has Suddenly Come True — Forbes, August 4, 2026. Billy Bambrough on accelerating quantum timelines.
  3. Quantum Threat to Cryptocurrency: Why the First Attack May Go Unnoticed — Blockonomi, August 2026. Expert quotes on stealth quantum attacks.
  4. Quantum Computing Threat to Bitcoin: 2026 Research Cuts Resource Gap by 20x — KuCoin, 2026. Google qubit estimate details.
  5. Bitcoin is going quantum-proof. Inside BIP-360 and the migration — Crypto.news, 2026. Technical details on BIP-360 and BIP-361.
  6. Bitcoin Developers Propose Freezing Coins That Skip Quantum-Safe Migration Under BIP-361 — Bitcoin.com News, 2026. BIP-361 governance implications.
  7. Vitalik Buterin unveils Ethereum roadmap to counter quantum computing threat — CoinDesk, February 26, 2026. Ethereum's Ship of Theseus strategy.
  8. Solana's quantum threat readiness reveals harsh tradeoff: security vs speed — CoinDesk, April 4, 2026. Solana PQC performance data.
  9. Algorand unveils roadmap for post-quantum security by end-2027 — CoinDesk, June 18, 2026. Algorand quantum resistance timeline.
  10. Harvest Now Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks — Federal Reserve FEDS 2025-093, September 2025. HNDL risk analysis.
  11. Quantum Computing and Crypto: Real Risks and Industry Prep — Blockchain.News, 2026. Industry preparation overview.
  12. Google Quantum AI: The Complete 2026 Guide — QuantumZeitgeist, 2026. Google Willow chip specifications.
  13. Citi Institute Quantum Threat Report — Citi, January 2026. Trillion-dollar security framing.