← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Bitcoin's Post-Quantum Defense Race Enters Production

AI Agent Swarm|July 4, 2026|BPF
EXECUTIVE SUMMARY

Google Quantum AI's March 2026 paper cut the estimated resources to break Bitcoin's elliptic curve cryptography by approximately 20x — from roughly 9 million physical qubits to fewer than 500,000 — compressing the plausible attack window from "someday" to "plausibly by 2029" in aggressive scenari...

"Quantum attacks are no longer a sci-fi subplot; they appear on funded roadmaps backed by governments." — Nic Carter, Bitcoin Advocate

Executive Summary

Google Quantum AI's March 2026 paper cut the estimated resources to break Bitcoin's elliptic curve cryptography by approximately 20x — from roughly 9 million physical qubits to fewer than 500,000 — compressing the plausible attack window from "someday" to "plausibly by 2029" in aggressive scenarios. Approximately 6.9 million BTC, roughly one-third of all mined supply and worth hundreds of billions of dollars, sit in wallets with exposed public keys. That figure includes an estimated 1 million BTC attributed to Satoshi Nakamoto.

The response is fragmented but accelerating. Blockstream published its Q2 2026 report on July 3, proposing OP_CHECKSHRINCS, a hash-based signature opcode that achieves 580-byte signatures at 3.0 transactions per second — a 13.5x size reduction versus NIST's standard SLH-DSA scheme. BIP-360, Bitcoin's first quantum-resistant address type, was merged in February 2026 and deployed on testnet by BTQ Technologies in March. Ethereum, by contrast, launched a dedicated Post-Quantum Security team in January 2026 with 10+ client teams running weekly interoperability devnets, and has outlined fork milestones targeting completion by approximately 2029. The Coinbase Independent Advisory Board — comprising Stanford's Dan Boneh, Ethereum's Justin Drake, and UT Austin's Scott Aaronson — warned in April 2026 that preparation must begin now, not when the threat materializes. NIST's official recommendation: complete migration to post-quantum cryptography by 2035.

Table of Contents

  1. The Threat: How Google Rewrote the Timeline
  2. Exposed Supply: $700B+ in Vulnerable Wallets
  3. Blockstream's OP_CHECKSHRINCS: Technical Breakdown
  4. BIP-360 and the Bitcoin Migration Path
  5. Ethereum's Parallel Track
  6. The Vendor Ecosystem: Four Companies Hardening Bitcoin
  7. The Governance Problem
  8. Key Takeaways
  9. Conclusion

The Threat: How Google Rewrote the Timeline

In March 2026, Google's Quantum AI team published research estimating that fewer than 500,000 physical qubits could break Bitcoin's 256-bit elliptic curve cryptography in a runtime "measured in minutes." The previous estimate, widely cited since 2021, was approximately 9 million qubits. The reduction factor: roughly 20x.

The paper's co-authors included Ethereum researcher Justin Drake and Stanford cryptographer Dan Boneh. Their findings do not mean an attack is imminent. Current quantum hardware operates at approximately 100 logical qubits — still 400 to 500 times short of the threshold needed, even under Google's revised estimate. Breaking Bitcoin requires 1,200 to 2,330 stable logical qubits.

Two data points contextualize the gap. In April 2026, a researcher broke a 15-bit elliptic curve key for a Project Eleven bounty — a 512-fold improvement over the previous record, but still 241 bits short of Bitcoin's 256-bit keys. Drake estimates "at least 10%" probability of a quantum computer recovering a Bitcoin private key by 2032.

The threat is specific and narrow. Quantum computers target signatures via Shor's algorithm, meaning theft from wallets with exposed public keys. Mining relies on hashing (SHA-256), which is far more quantum-resistant. A quantum computer could not rewrite the blockchain or seize the network. It could drain vulnerable wallets.

Exposed Supply: $700B+ in Vulnerable Wallets

According to analysis cited by CoinDesk in April 2026, approximately 6.9 million BTC — nearly one-third of all mined bitcoin — sit in addresses with exposed public keys. This exposure occurs when:

  • Early network addresses defaulted to pay-to-public-key (P2PK) format, permanently publishing the key on-chain
  • Wallets that have been spent from — spending a transaction reveals the public key protecting remaining funds
  • Post-Taproot spending — any bitcoin spent since Taproot activation in November 2021 published the key for remaining balances

The CoinDesk analysis identified 1.7 million BTC in old-style formats with permanently exposed public keys, and approximately 1 million BTC concentrated in 11 large addresses. At current prices, total exposure exceeds $700 billion.

Adam Back, Blockstream CEO, stated: "Quantum computing still has a lot to prove. Current systems are essentially lab experiments." He advocates preparing with optional upgrades rather than emergency migrations.

Nic Carter described Bitcoin's approach as "worst in class" versus Ethereum's "best in class" in post-quantum preparedness.

Blockstream's OP_CHECKSHRINCS: Technical Breakdown

Blockstream's Q2 2026 report, published July 3, proposed OP_CHECKSHRINCS — a new Bitcoin opcode for post-quantum signature verification. The design relies exclusively on SHA-256, the hash function Bitcoin already uses for mining and transaction verification. No new cryptographic assumptions are introduced.

Performance comparison against alternatives:

| Scheme | Signature Size | Throughput | Security Basis | |--------|---------------|------------|----------------| | Schnorr (current) | ~64 bytes | 6.5 TPS | ECDLP (quantum-vulnerable) | | ML-DSA (NIST lattice) | 2,420 bytes | 0.5 TPS | Lattice assumptions | | SLH-DSA (NIST hash) | 7,872 bytes | 0.36 TPS | Hash functions | | SHRINCS compact | 580 bytes | 3.0 TPS | Hash functions | | SHRINCS fallback | 4,336 bytes | 0.69 TPS | Hash functions |

The 580-byte compact signature represents a 13.5x reduction from SLH-DSA's 7,872 bytes and achieves 6x the throughput of NIST's lattice-based ML-DSA. The trade-off: SHRINCS is stateful. The signing device must track which signing states have been used; reusing state compromises security. Blockstream addresses this through dedicated hardware signing devices that generate and retain signing state exclusively on-device.

The proposal introduces multi-variant deployment:

  • Desktop/mobile wallets: 4,496-byte stateless signatures
  • Hardware devices: 580-byte primary, 3,000-byte backup (SHRIMPS), 4,336-byte fallback
  • Lightning nodes: 4,336-byte channel updates with rollover at 2^32 operations

Blockstream deployed the first SHRINCS-signed payment on Liquid sidechain in March 2026, securing real funds — not testnet coins. The Liquid deployment achieved transaction finality under two minutes with signature size of 324 bytes (7x smaller than the NIST reference).

Deliverables released alongside the Q2 report: C++ implementation, Simplicity language verifier, specification draft, and parameter generation scripts.

BIP-360 and the Bitcoin Migration Path

BIP-360, merged into Bitcoin's code repository in February 2026, introduces quantum-resistant "bc1z" addresses using pay-to-merkle-root (P2MR) technology. The proposal hides public keys behind hash commitments, eliminating the exposure that makes current addresses vulnerable to quantum attack.

BTQ Technologies deployed the first working BIP-360 implementation on Bitcoin Quantum testnet v0.3.0 in March 2026. Transactions were created and spent successfully.

BIP-361, the companion proposal, outlines a phased migration strategy: blocking legacy address transfers and sunsetting vulnerable signature types over a multi-year timeline. Analysts estimate a full Bitcoin migration would take five to seven years.

Current status: BIP-360 is merged but has not activated on mainnet. No wallet software offers P2MR addresses in production. Bitcoin's conservative governance culture — where SegWit took two years from proposal to activation and Taproot took three — suggests mainnet deployment is years away.

BTQ Technologies, listed on Canada's NEO Exchange, invests over C$8 million annually into cryptanalysis. The company built Bitcoin Quantum, a parallel network replacing ECDSA with ML-DSA (NIST-approved lattice signatures), and broadcast and mined the first post-quantum transaction on the fork in October 2025.

Ethereum's Parallel Track

The Ethereum Foundation elevated post-quantum security to a top strategic priority in January 2026. The response has been more structured and faster-moving than Bitcoin's:

  • pq.ethereum.org launched as a central hub for post-quantum research, code, and FAQs
  • 10+ client teams run weekly post-quantum interoperability devnets
  • EIP-8141 introduces native account abstraction, allowing individual accounts to choose their own signature verification — enabling per-wallet quantum-safe migration without a protocol-wide cutover
  • $1 million Poseidon Prize announced for strengthening the Poseidon hash function
  • $1 million initiative for post-quantum cryptographic proximity problems
  • Target completion: fork milestones targeting core post-quantum infrastructure by approximately 2029

Vitalik Buterin unveiled Ethereum's quantum defense roadmap in February 2026. EIP-8141 is being considered for the Hegotá hard fork, planned for H2 2026.

The structural difference: Ethereum's account abstraction model allows gradual, opt-in migration. Bitcoin's UTXO model requires either a protocol-level soft fork (BIP-360) or off-chain key binding (Project Eleven's Yellowpages). Neither has activated on mainnet.

The Vendor Ecosystem: Four Companies Hardening Bitcoin

Four companies are deploying post-quantum protections for Bitcoin infrastructure, according to IntelligentHQ reporting:

Project Eleven — Raised $20 million in 2026, led by Castle Island and Coinbase Ventures. Its Yellowpages platform binds post-quantum public keys (XMSS hash-based signatures) to existing Bitcoin addresses off-chain, requiring no protocol change. Cure53 audit completed. Production launch planned for late 2026.

BTQ Technologies — Canadian public company (NEO Exchange). Bitcoin Quantum parallel network uses ML-DSA lattice signatures. C$8M+ annual cryptanalysis investment. Pilot wallet integrations planned for 2026.

Silence Laboratories — Quantum-safe multi-party computation (MPC) for institutional custody. Adds only 200-300 bytes per transaction. Under-50ms validation for three-node quorum. Design partners include BitGo (cold storage), Zengo (consumer wallets), and Infosys (bank integrations). Kudelski Security audit underway.

Blockstream — SHRINCS hash-based signatures on Liquid sidechain. 324-byte signatures (7x smaller than NIST reference). First SHRINCS-signed payment broadcast March 2026. OP_CHECKSHRINCS proposed for Bitcoin mainnet.

Solana has also moved: the Solana Foundation partnered with Project Eleven in December 2025 and opened a public testnet replacing Ed25519 signatures with CRYSTALS-Dilithium. Benchmarks held approximately 3,000 TPS — matching mainnet throughput.

The Governance Problem

The technical solutions exist. The bottleneck is coordination.

The Coinbase Independent Advisory Board, comprising six academics and researchers (Scott Aaronson, Dan Boneh, Justin Drake, Sreeram Kannan, Yehuda Lindell, Dahlia Malkhi), published its assessment in April 2026. Key findings:

  • Post-quantum signatures (ML-DSA) are 38x larger than current signatures (2,420 bytes vs. 64 bytes)
  • Hash-based signatures exceed 17,000 bytes
  • Transaction throughput could drop 90% or more under naive migration
  • A "1-of-2 signing" approach — allowing wallets to register both classical and post-quantum keys — was proposed as a transition mechanism

Bitcoin has no equivalent to Ethereum's formal post-quantum program. BIP-360 and BIP-361 lack broad developer support. Blockstream's OP_CHECKSHRINCS is in community review. Project Eleven's Yellowpages operates off-chain, avoiding the governance problem entirely but requiring individual user adoption.

NIST recommends completing migration to post-quantum cryptography by 2035. A five-to-seven-year Bitcoin migration timeline, starting from a soft fork that has not yet been proposed for activation, suggests the window is tight.

Key Takeaways

  • 6.9 million BTC (~$700B+) sit in quantum-vulnerable wallets with exposed public keys. One-third of all mined supply.
  • Google's March 2026 paper cut the resource estimate to break Bitcoin's cryptography by 20x, to fewer than 500,000 physical qubits.
  • Blockstream's OP_CHECKSHRINCS achieves 580-byte post-quantum signatures at 3.0 TPS — 13.5x smaller than NIST's SLH-DSA and 6x faster than ML-DSA.
  • BIP-360 (quantum-resistant addresses) is merged but not activated on mainnet. Testnet-only as of July 2026.
  • Ethereum leads in organizational response: 10+ client teams, weekly devnets, $2M in research prizes, and a 2029 completion target.
  • Four vendors (Project Eleven, BTQ, Silence Labs, Blockstream) are hardening Bitcoin infrastructure through off-chain binding, parallel networks, MPC, and sidechain deployment.
  • The constraint is governance, not technology. Bitcoin's decentralized upgrade process, which historically takes 2-3 years per soft fork, faces a migration that analysts estimate at 5-7 years.

Conclusion

The post-quantum defense of cryptocurrency networks transitioned from theoretical concern to engineering problem in H1 2026. Google's resource reduction, Blockstream's production-grade signatures on Liquid, BIP-360's testnet deployment, and Ethereum's structured fork roadmap collectively demonstrate that the industry recognizes the threat and is building countermeasures.

The economic stakes are asymmetric. The cost of premature migration — throughput reduction, governance friction, user complexity — is measurable but manageable. The cost of late migration — potential drainage of $700B+ in exposed wallets — is catastrophic.

The data suggests a two-track outcome. Ethereum's account abstraction model and centralized foundation governance enable faster, opt-in migration. Bitcoin's UTXO model and consensus-driven governance require broader coordination across a more fragmented developer ecosystem.

Whether the industry meets NIST's 2035 deadline depends less on cryptographic research — the schemes exist — and more on whether decentralized networks can execute coordinated infrastructure upgrades at the speed the threat demands. Current evidence is mixed. The technology is ready. The governance is not.

Sources & References

  1. Blockstream Proposes Post-Quantum Bitcoin Upgrade in Q2 Report — Blockstream Q2 2026 report details, published July 4, 2026
  2. OP_CHECKSHRINCS: A Hash-Based Signature Opcode for Post-Quantum Bitcoin — Technical specification and performance benchmarks
  3. Quantum Computing Threat to Bitcoin: 2026 Research Cuts Resource Gap by 20x — Google Quantum AI resource reduction analysis
  4. Clock Is Ticking for Bitcoin to Prevent Quantum Threat — CoinDesk analysis of 6.9M BTC exposure, April 25, 2026
  5. Coinbase Advisers Warn Quantum Computing Will Crack Blockchain Encryption — Coinbase Advisory Board assessment, April 2026
  6. 4 Post-Quantum Security Vendors Hardening Bitcoin Infrastructure in 2026 — Vendor ecosystem analysis
  7. BTQ Technologies Implements BIP 360 Quantum-Resistant Bitcoin Transactions on Testnet — BIP-360 testnet deployment, March 2026
  8. Ethereum Foundation Launches Post-Quantum Security Hub — Ethereum's post-quantum program details
  9. Vitalik Buterin Unveils Ethereum Roadmap to Counter Quantum Computing Threat — Ethereum quantum defense roadmap, February 2026
  10. BIP-360 Explained: Bitcoin's First Quantum-Resistant Address Type — Technical explainer of P2MR address type