A threat that does not yet exist is already moving markets. In February 2026, Bitcoin is down 45% from its December 2025 peak of $126,000, with quantum computing concerns entering institutional risk models for the first time as a material valuation variable. Analyst Willy Woo has documented the b...
"The valuation trend broke down once quantum came into awareness." — Willy Woo, on-chain analyst, February 2026
A threat that does not yet exist is already moving markets. In February 2026, Bitcoin is down 45% from its December 2025 peak of $126,000, with quantum computing concerns entering institutional risk models for the first time as a material valuation variable. Analyst Willy Woo has documented the breaking of Bitcoin's 12-year outperformance trend against gold — a structural shift he attributes directly to the emergence of quantum risk in institutional consciousness. Jefferies' Global Head of Equity Strategy Christopher Wood has removed a longstanding 10% Bitcoin allocation from his model portfolio, rotating into gold and mining stocks. Kevin O'Leary has publicly stated that institutions will cap Bitcoin exposure at 3% of portfolios until developers resolve the quantum vulnerability.
The irony is sharp: the machines that could threaten Bitcoin's cryptography don't exist yet. Current quantum computers operate at roughly 1,500 physical qubits; breaking Bitcoin's elliptic curve cryptography would require approximately 2 million. But markets price risk on probability distributions, not certainties — and the probability distribution has shifted. This report examines the technical reality, the institutional response, and the protocol-level countermeasures now racing to close a gap that, for the first time, is measurably affecting crypto's largest asset class.
The distance between today's quantum hardware and the capability to break Bitcoin is vast — but it is shrinking on a defined roadmap.
Google's Willow chip, announced in December 2024, operates at 105 superconducting qubits with a breakthrough in quantum error correction: each scaling step (from 3×3 to 5×5 to 7×7 qubit grids) cut the error rate in half, achieving the first demonstration of below-threshold error correction.[^1] IBM's roadmap targets a 4,158-qubit system by late 2026, interconnecting three Kookaburra processors at 1,386 qubits each.[^2]
These are milestones, not threats. According to a widely cited 2017 Microsoft Research paper, breaking Bitcoin's 256-bit elliptic curve digital signature algorithm (ECDSA) would require a fault-tolerant quantum computer with approximately 2,330 logical qubits.[^3] Given current error rates, roughly 1,000 physical qubits are required to produce a single logical qubit. That places the requirement at approximately 2.3 million physical qubits — over 1,500 times what currently exists.
The consensus timeline among quantum researchers places "Q-Day" — the point at which cryptographically relevant quantum computers emerge — between 2030 and 2040. Grayscale, in its 2026 Digital Asset Outlook, called quantum risk a "red herring" for the coming year, stating that "research and preparedness will continue on post-quantum cryptography, but this issue is unlikely to affect valuations in the next year."[^4]
Yet valuations are already affected. The question is no longer whether quantum computing will break cryptography — it is when, and whether crypto protocols can migrate their security foundations before that day arrives.
The market is not waiting for Q-Day. It is pricing the possibility.
Bitcoin's year-to-date performance in 2026 is down 6.5%, while gold has surged 55%.[^5] Willy Woo's analysis identifies quantum awareness as the inflection point: Bitcoin's 12-year trend of outperforming gold on a risk-adjusted basis has broken for the first time. His thesis centers not on the immediate cryptographic vulnerability, but on the potential reactivation of an estimated 4 million "lost" BTC. If quantum breakthroughs rendered those coins accessible, the effective supply increase could be catastrophic. Woo estimates a 75% probability that a protocol hard fork to freeze lost coins would fail to achieve consensus.[^6]
The institutional response is quantifiable. Crypto investment products have seen four consecutive weeks of outflows totaling $3.74 billion, with total assets under management falling to $133 billion — the weakest level since April 2025.[^7] US-listed products bore the brunt with $403 million in weekly outflows, while European venues in Germany, Canada, and Switzerland absorbed $230 million in inflows, suggesting a geographic divergence in risk appetite.[^8]
Key institutional moves:
The mechanism is clear: pension funds and endowments with multi-decade horizons cannot ignore low-probability, high-impact tail risks. Even a 5% probability of quantum disruption within 10 years compresses the risk-adjusted return enough to cap allocations below traditional alternatives like gold.
Not all Bitcoin is equally exposed. CoinShares' February 2026 report narrows the genuine vulnerability to a specific subset of addresses.[^10]
The primary risk resides in legacy Pay-to-Public-Key (P2PK) addresses, where public keys are permanently visible on-chain. CoinShares estimates approximately 1.6 million BTC — roughly 8% of total supply — sits in these older address types. However, the firm's analysis goes further: only about 10,200 BTC is concentrated in UTXOs large enough that their theft could cause "appreciable market disruption." The remaining 1.6 million BTC is distributed across more than 32,000 UTXOs averaging approximately 50 BTC each — far less attractive targets given the computational cost of quantum attacks.
Modern Pay-to-Public-Key-Hash (P2PKH) and Pay-to-Taproot (P2TR) addresses do not expose public keys until a transaction is broadcast. This means an attacker would need to crack the key within the brief window between broadcast and confirmation — a constraint that dramatically narrows the attack surface, even for future quantum computers.
The real systemic risk is not theft of individual wallets but the potential unlocking of Satoshi Nakamoto's estimated 1.1 million BTC, held in early P2PK addresses. At current prices, this represents over $75 billion in latent supply — a sum large enough to trigger a confidence crisis regardless of whether the coins are actually moved.
The developer community is no longer treating quantum resistance as a theoretical exercise.
Bitcoin: BIP-360 (Pay-to-Merkle-Root)
On February 11, 2026, BIP-360 was merged into the official Bitcoin Improvement Proposal repository — a significant procedural milestone, though not an endorsement of activation.[^12] BIP-360 introduces Pay-to-Merkle-Root (P2MR), a new output type that operates similarly to Pay-to-Taproot (P2TR) but with the quantum-vulnerable keypath spend removed. By committing only to the script path, P2MR eliminates the exposure of public keys during normal spending operations.
BIP-360 is designed as a foundation layer. The proposal's authors identify NIST-standardized algorithms — ML-DSA (Dilithium) and SLH-DSA (SPHINCS+) — as candidates for follow-on soft forks that would introduce post-quantum signature schemes into Bitcoin's consensus rules.[^12]
The challenge is governance. Bitcoin's upgrade process is deliberately conservative, requiring broad community consensus. The last major upgrade, Taproot, took over three years from proposal to activation. A quantum-resistance upgrade would likely face similar timelines — a pace that some institutional observers consider dangerously slow.
Ethereum: The Walkaway Test
Vitalik Buterin has been more aggressive. In January 2026, he articulated the "walkaway test" — seven protocol requirements, including century-scale quantum resistance, that Ethereum must meet before the protocol can ossify.[^13] The Ethereum Foundation has elevated post-quantum security to a top strategic priority, forming a dedicated Post-Quantum team and launching biweekly developer sessions on post-quantum transactions. Two $1 million prizes have been announced for advances in post-quantum cryptography applicable to Ethereum.[^14]
Buterin's timeline is notably more urgent than Bitcoin's: he has warned that cryptography securing both networks could be vulnerable to breakthroughs as early as 2028.[^14]
A parallel market is forming around quantum resistance as a narrative and a product category.
Quantum-resistant tokens have reached a combined market capitalization of $9.37 billion in early 2026, led by projects including Zcash (which integrated post-quantum cryptography in its Sapling upgrade), Starknet (built on STARK proofs, which are inherently quantum-resistant), and the Quantum Resistant Ledger (QRL), purpose-built using hash-based signatures.[^15]
BTQ Technologies announced the first demonstration of a quantum-resistant Bitcoin implementation using NIST-standardized ML-DSA signatures, with enterprise pilots planned for Q1 2026 and mainnet deployment targeted for Q2 2026.[^16] NIST's three finalized post-quantum cryptography standards — ML-KEM, ML-DSA, and SLH-DSA — published in August 2024, provide the algorithmic foundation that blockchain developers are now integrating.[^17]
The market opportunity is real, but the economic sustainability question persists: quantum-resistant chains must generate sufficient fee revenue to justify their security overhead. Post-quantum signatures are significantly larger than ECDSA signatures — SPHINCS+ signatures, for example, are approximately 8 KB versus 72 bytes for ECDSA — creating direct tension between security and scalability.
The quantum transition will not be free. Migrating Bitcoin's UTXO set to post-quantum-safe formats would require every holder to execute at least one on-chain transaction, generating a one-time surge in block demand and fees. For Ethereum, the EVM's account model simplifies migration but introduces new gas costs for the larger signature verification computations.
From an economic value distribution perspective, the transition creates new revenue streams for validators (who will process migration transactions), new infrastructure demand for wallet providers (who must implement new signing schemes), and new consulting revenue for cryptographic auditors. It also creates a ticking clock: addresses that fail to migrate before Q-Day become permanently vulnerable, creating a two-tier security model within the same network.
The fundamental question echoes the core finding of our foundational economic value analysis: blockchain ecosystems remain roughly 85-90% subsidy-driven. Adding a multi-year cryptographic migration on top of an already subsidy-dependent infrastructure layer raises questions about who bears the cost. If the transition is not subsidized through foundation grants or protocol-level fee adjustments, the burden falls on individual users — many of whom hold small balances that may not justify the transaction cost of migration.
The quantum threat is not imminent but is already priced. Bitcoin is down 45% from its $126K peak, with quantum concerns contributing to a structural break in its 12-year outperformance trend against gold.
Only 10,200 BTC faces concentrated quantum risk according to CoinShares' granular UTXO analysis, though 1.6 million BTC in legacy P2PK addresses remains theoretically vulnerable.
Institutional allocation ceilings are hardening. Kevin O'Leary's 3% cap and Jefferies' portfolio rotation represent a measurable reduction in the addressable institutional market for Bitcoin.
BIP-360 and Ethereum's Post-Quantum team represent the first concrete protocol responses, but Bitcoin's governance model may be too slow for institutional comfort.
The quantum-resistant token market has reached $9.37 billion, but these projects must demonstrate economic sustainability — not just cryptographic resilience.
The migration cost problem is unsolved. Moving billions of UTXOs to post-quantum formats creates fee pressure, infrastructure demand, and a potential two-tier security model within networks.
The quantum threat to cryptocurrency is a paradox: it is simultaneously years away and already here. The machines that could break Bitcoin's cryptography do not exist and may not for a decade. But the institutional capital that determines Bitcoin's price trajectory operates on multi-decade risk models — and those models have been updated.
What we are witnessing is not a technical crisis but a pricing adjustment. Markets are applying a "quantum discount" to digital assets that lack a credible migration path, while rewarding gold — which is immune to cryptographic attack — with a historic premium. The $3.74 billion in ETF outflows, the broken gold correlation, and the 3% allocation ceiling are all symptoms of the same underlying cause: the market has decided that quantum risk is no longer zero, and crypto's governance structures have not yet demonstrated they can respond at institutional speed.
The protocols that move fastest — not in theoretical research, but in deployable, activated post-quantum security — will recapture the institutional confidence now flowing to traditional safe havens. The protocols that rely on the argument that "Q-Day is a decade away" may find that markets have already priced that decade's worth of uncertainty today.
[^1]: Google Research Blog, "Meet Willow, our state-of-the-art quantum chip," December 2024. https://blog.google/technology/research/google-willow-quantum-chip/ [^2]: Programming Helper Tech, "Quantum Computing Breakthrough 2026: IBM's 433-Qubit Condor, Google's 1000-Qubit Willow, and the $17.3B Race," February 2026. https://www.programming-helper.com/tech/quantum-computing-breakthrough-2026-ibm-google-qubit-race [^3]: BeInCrypto, "How Quantum Computing May Be Impacting Bitcoin's Valuation," February 2026. https://beincrypto.com/quantum-computing-bitcoin-gold-valuation-risk/ [^4]: Grayscale Research, "2026 Digital Asset Outlook: Dawn of the Institutional Era." https://research.grayscale.com/reports/2026-digital-asset-outlook-dawn-of-the-institutional-era [^5]: MarketScreener, "Crypto winter 2026: institutional risk-off and quantum threat," February 2026. https://www.marketscreener.com/news/crypto-winter-2026-institutional-risk-off-and-quantum-threat-ce7e5dd8d88af726 [^6]: U.Today, "Bitcoin's 'Quantum Discount': Why Willy Woo Says BTC Is Breaking 12-Year Trend Against Gold," February 2026. https://u.today/bitcoins-quantum-discount-why-willy-woo-says-btc-is-breaking-12-year-trend-against-gold [^7]: The Block, "Global crypto ETP outflows extend to fourth week as $3.7 billion exits in past month: CoinShares," February 2026. https://www.theblock.co/post/390001/global-crypto-etp-outflows-extend-to-fourth-week-as-3-7-billion-exits-in-past-month-coinshares [^8]: CoinDesk, "Bitcoin ETF outflows deepen as ether and XRP funds quietly attract inflows," February 2026. https://www.coindesk.com/markets/2026/02/04/bitcoin-etf-outflows-deepen-as-ether-and-xrp-funds-quietly-attract-inflows [^9]: CryptoBriefing, "Shark Tank's Kevin O'Leary says institutions will limit Bitcoin exposure to 3% until quantum threat is resolved," February 2026. https://cryptobriefing.com/quantum-risks-in-bitcoin-exposure/ [^10]: The Block, "CoinShares says only 10,200 BTC face real quantum risk big enough to move markets," February 2026. https://www.theblock.co/post/388969/coinshares-says-only-10200-btc-face-real-quantum-risk-pushing-back-on-overblown-estimates [^11]: Arkham Intelligence, "Bitcoin ETFs Approach Five Straight Weeks Of Outflows," February 2026. https://info.arkm.com/research/bitcoin-etfs-approach-five-straight-weeks-of-outflows [^12]: Bitcoin Magazine, "Bitcoin Advances Toward Quantum Resistance with BIP 360 and New P2MR Output," February 2026. https://bitcoinmagazine.com/news/bitcoin-advances-toward-quantum-resistance [^13]: CoinDesk, "Vitalik Buterin lays out 'walkaway test' for a quantum safe ether," January 2026. https://www.coindesk.com/tech/2026/01/12/vitalik-buterin-lays-out-walkaway-test-for-a-quantum-safe-ethereum [^14]: Yahoo Finance, "Ethereum Prioritizes Quantum Security as Vitalik Warns of Breakable Cryptography by 2028," 2026. https://finance.yahoo.com/news/ethereum-prioritizes-quantum-security-vitalik-085316076.html [^15]: BeInCrypto, "Why Quantum-Resistant Tokens Just Skyrocketed Past $9 Billion," 2026. https://beincrypto.com/quantum-resistant-tokens-market-2026/ [^16]: PRNewswire, "BTQ Technologies Demonstrates Quantum-Safe Bitcoin Using NIST Standardized Post-Quantum Cryptography," 2025. https://www.prnewswire.com/news-releases/btq-technologies-demonstrates-quantum-safe-bitcoin-using-nist-standardized-post-quantum-cryptography-protecting-2-trillion-market-at-risk-302585981.html [^17]: NIST, "NIST Releases First 3 Finalized Post-Quantum Encryption Standards," August 2024. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards