A new white paper from ARK Invest and Unchained has quantified what much of the Bitcoin community has treated as a distant hypothetical: the quantum computing threat. The report, published March 12, maps a five-stage risk framework and concludes that 34.6% of all Bitcoin supply — roughly 6.9 mill...
"Bitcoin isn't just one piece of software. There's an entire ecosystem of wallets, hardware devices, and exchanges, and migrating all of that will take time." — Ethan Heilman, Cryptographer and BIP-360 Co-Author
A new white paper from ARK Invest and Unchained has quantified what much of the Bitcoin community has treated as a distant hypothetical: the quantum computing threat. The report, published March 12, maps a five-stage risk framework and concludes that 34.6% of all Bitcoin supply — roughly 6.9 million BTC worth over $500 billion — sits in address types theoretically vulnerable to future quantum attacks. The threat is real, but not imminent. Current quantum systems operate at approximately 100 logical qubits; breaking Bitcoin's elliptic curve cryptography would require at least 2,330 error-corrected logical qubits and billions of quantum gate operations.
The report arrives amid a growing policy and technical debate. BIP-360, the first Bitcoin Improvement Proposal to formally address quantum resistance, has been merged into the official Bitcoin repository. Project Eleven's Q-Day Prize — offering 1 BTC to anyone who can crack elliptic curve cryptography using Shor's algorithm before April 5, 2026 — has turned theoretical risk into a live, measurable bounty. Meanwhile, NIST has finalized three post-quantum cryptography standards, and IBM demonstrated Shor's algorithm on real quantum hardware in September 2025, cracking a six-bit elliptic curve key for the first time.
The question is no longer whether Bitcoin must upgrade. It is when — and whether the community can coordinate a migration across wallets, exchanges, hardware devices, and node operators before the window closes.
Authored by Dhruv Bansal (Unchained CSO), Tom Honzik (Unchained Director of Custody Research), and David Puell (ARK Invest), the white paper rejects the binary "Q-Day" narrative — the idea that quantum computing will suddenly render Bitcoin worthless overnight. Instead, it introduces a graduated five-stage framework:
| Stage | Description | Threat to Bitcoin | |-------|-------------|-------------------| | Stage 0 | Quantum computers exist but lack commercial utility. This is roughly where we are today. | None | | Stage 1 | Quantum machines achieve commercial value for specific tasks (drug discovery, logistics optimization) but have no cryptographic capability. | None | | Stage 2 | Quantum computing becomes powerful enough to crack weak or outdated cryptographic systems (e.g., small RSA keys). | Minimal — Bitcoin's keys remain safe | | Stage 3 | Quantum computers can theoretically break elliptic curve cryptography (ECC), the algorithm protecting Bitcoin private keys. | First real risk to Bitcoin | | Stage 4 | A quantum machine can break a private key faster than Bitcoin's 10-minute block time. | Existential threat to Bitcoin as a monetary system |
The researchers' balanced scenario — aligned with mainstream institutional forecasts — projects that quantum computers will reach Stage 3 in 10 to 20 years. The authors emphasize: "Quantum development will be a gradual technological progression — not a sudden 'Q-day' event."
Critically, any quantum machine capable of breaking Bitcoin's encryption would first compromise TLS, banking infrastructure, and military communications — meaning the broader internet would face existential challenges before Bitcoin specifically becomes a target.
Not all Bitcoin is created equal in quantum risk terms. The vulnerability depends entirely on whether an address's public key has been exposed on-chain.
The ARK-Unchained breakdown:
Within that vulnerable pool:
Deloitte's independent analysis broadly confirms these figures, estimating 4.5 million BTC (25% of supply) face quantum exposure, valued at approximately $550 billion.
A notable complication: Bitcoin analyst Willy Woo has flagged that Taproot — Bitcoin's most recent major upgrade — is actually more quantum-vulnerable than older SegWit and Legacy formats, because Taproot's key-path spending exposes a form of the public key. Taproot adoption has already declined from 42% of transactions in 2024 to roughly 20% today, a trend Woo attributes partly to growing quantum awareness.
BIP-360, co-authored by cryptographer Ethan Heilman, represents Bitcoin's first formal step toward post-quantum security. The proposal introduces Pay-to-Merkle-Root (P2MR), a new script type that:
BIP-360 has been merged into Bitcoin's official repository as of early 2026 — a significant milestone, though merging a BIP is not the same as activating it on mainnet. Implementation would require coordination across the entire ecosystem: hardware wallets, node operators, exchanges, and custody providers.
The proposal is deliberately conservative. It establishes the framework for quantum resistance without mandating a specific post-quantum algorithm, acknowledging that the cryptographic landscape is still evolving.
The Bitcoin community is deeply divided on how fast to move. The debate has crystallized around two camps:
The urgency camp:
The patience camp:
The tension reflects a genuine engineering dilemma. Moving too slowly risks catastrophic loss if quantum computing advances faster than expected. Moving too fast risks a contentious, rushed fork that could fragment the network or introduce new attack vectors through hasty cryptographic choices.
Project Eleven, a quantum computing research firm, has launched the Q-Day Prize: 1 BTC to the first team that can break an elliptic curve cryptographic key using Shor's algorithm on a real quantum computer before April 5, 2026.
The challenge directly targets ECDSA — the signature scheme protecting Bitcoin wallets — and seeks to convert theoretical risk into empirical measurement. No team has come close to claiming the prize, but the initiative has catalyzed research activity and media attention.
The quantum hardware landscape is advancing rapidly. In the past 18 months:
To crack a Bitcoin key (256-bit ECC), a quantum computer would need approximately 4 million physical qubits — a factor of roughly 38,000x beyond today's most advanced hardware. The gap remains enormous, but the trajectory is accelerating.
The U.S. National Institute of Standards and Technology finalized three post-quantum cryptography standards in August 2024, providing the algorithmic foundation for a future Bitcoin migration:
For Bitcoin specifically, the ARK-Unchained paper references ML-DSA and SLH-DSA as the most viable replacements. Hash-based signatures (SLH-DSA) are attractive because their security assumptions are simpler and better understood, but they produce larger signatures that could impact block space efficiency. Lattice-based signatures (ML-DSA) offer better performance but rely on newer mathematical hardness assumptions.
A fourth standard, FN-DSA (FIPS 206), is expected in draft form in 2026 and may be particularly relevant for blockchain applications due to its compact signature size.
The migration will not be a single software update. It requires consensus on algorithm selection, backward-compatible transaction formats, wallet software updates, hardware wallet firmware changes, exchange infrastructure upgrades, and a community-wide migration window — a coordination challenge that Heilman estimates will take 5 to 10 years of discussion alone.
The ARK-Unchained white paper has done the Bitcoin community a service by replacing vague anxiety with a structured, data-driven risk assessment. The five-stage framework makes clear that "Q-Day" is not a single event but a gradual technological progression with visible milestones along the way.
But the report also underscores an uncomfortable truth: Bitcoin's decentralized governance model — its greatest strength — is also its greatest vulnerability in the face of a coordinated upgrade requirement. Unlike centralized systems that can mandate a migration timeline, Bitcoin must achieve rough consensus across millions of participants, thousands of node operators, and hundreds of wallet and exchange providers.
The economic stakes are staggering. Over $500 billion in Bitcoin sits in quantum-vulnerable addresses today. The cryptographic tools for defense exist. The engineering pathway (BIP-360) has been formalized. What remains is the hardest part of any open-source infrastructure project: coordination under uncertainty, where the cost of moving too slowly is catastrophic loss and the cost of moving too fast is network fragmentation.
The quantum clock is ticking — slowly, but visibly. The question for Bitcoin holders is whether slow and visible is fast enough.