A new and structurally significant variable has entered the Bitcoin valuation equation: quantum computing risk. Over the past 90 days, the theoretical threat that a sufficiently powerful quantum computer could derive private keys from exposed public keys has migrated from academic footnotes into ...
"Markets had begun pricing in the risk of a future Q Day breakthrough... Bitcoin's long-term tendency to gain purchasing power when measured in ounces of gold is no longer in play." — Willy Woo, on-chain analyst, February 2026
A new and structurally significant variable has entered the Bitcoin valuation equation: quantum computing risk. Over the past 90 days, the theoretical threat that a sufficiently powerful quantum computer could derive private keys from exposed public keys has migrated from academic footnotes into institutional risk disclosures, ETF filings, and portfolio rebalancing decisions. The result is a measurable "quantum discount" being applied to Bitcoin's store-of-value premium — one that is reshaping BTC's 12-year outperformance trend against gold.
Bitcoin, trading at approximately $68,880 as of February 17, 2026, has fallen roughly 45% from its $126,000 peak.[^1] While macroeconomic factors and leverage unwinding account for the bulk of the decline, a growing body of evidence suggests that quantum computing fears are becoming a distinct and persistent valuation headwind. Crypto investment products have posted four consecutive weeks of outflows totaling $3.8 billion, with total assets under management sliding to $133 billion — the weakest level since April 2025.[^2] The question is no longer whether quantum computing will affect crypto valuations, but how much of the discount is already priced in, and whether the industry's response is moving fast enough.
This report examines the technical reality of the quantum threat, maps the divergence between fear and physics, quantifies the economic impact on capital flows, and evaluates the migration pathways that Bitcoin and Ethereum are pursuing.
Bitcoin's security rests on elliptic-curve cryptography (ECDSA), which protects the link between public keys and private keys. A sufficiently powerful quantum computer running Shor's algorithm could theoretically reverse this relationship, deriving private keys from public keys and enabling unauthorized spending from affected addresses. This is the scenario referred to as "Q Day."
The timeline debate is fierce and unresolved. On one end, the Quantum Doomsday Clock — developed by cryptographer Rick Carback and entrepreneur Colton Dillion — predicts that Bitcoin's encryption could be broken by March 8, 2028, modeling exponential improvements in quantum hardware, error correction, and cryptographic attack efficiency.[^3] IonQ CEO Niccolo De Masi has aligned with similar timelines, suggesting cryptographically relevant quantum computers could appear by the end of this decade.
On the opposite end, CoinShares' February 2026 report — "Quantum Vulnerability in Bitcoin: A Manageable Risk" — argues that breaking Bitcoin's cryptography would require fault-tolerant quantum systems approximately 100,000 times more powerful than the largest machines operating today.[^4] Adam Back, co-founder of Blockstream and a cited figure in the original Bitcoin whitepaper, places the threat at 20-40 years out, if ever.[^5]
The current state of the art is Google's Willow processor, a 105-qubit superconducting chip that achieved a breakthrough in quantum error correction in late 2024 by demonstrating that larger arrays of physical qubits could reduce rather than compound errors — a first in quantum computing.[^6] Google has demonstrated "verifiable quantum advantage" with Willow, running algorithms 13,000 times faster than classical supercomputers. Yet the gap between 105 qubits and the millions of fault-tolerant logical qubits needed to crack ECDSA remains vast. Google's own roadmap places its large-scale milestone machine "somewhere around the end of the decade."
The physics, by most credible assessments, is not imminent. But markets do not price physics — they price probability-weighted risk over time horizons. And that is where the damage is being done now.
Not all Bitcoin is equally vulnerable. The quantum threat is specific to addresses where public keys are already exposed on-chain — meaning the cryptographic material needed to begin an attack is already public.
CoinShares' analysis provides the most granular breakdown available:
| Category | BTC at Risk | % of Supply | Concentration | |---|---|---|---| | P2PK addresses (early Bitcoin, pre-2012) | ~1.6 million BTC | ~8% | Distributed across 32,000+ UTXOs | | Concentrated high-value targets | ~10,200 BTC | ~0.05% | Large enough to cause market disruption | | Satoshi-era coins (estimated) | ~1.1 million BTC | ~5.5% | Presumed lost, public keys exposed |
On-chain analyst Willy Woo paints a broader picture, estimating that approximately 4 million BTC — roughly 25-30% of the total supply — reside in addresses with exposed public keys.[^7] This includes coins widely presumed to be lost (including Satoshi Nakamoto's estimated 1.1 million BTC), whose re-emergence via quantum-enabled theft would undermine a core pillar of Bitcoin's scarcity thesis.
The critical nuance: CoinShares argues that only ~10,200 BTC is concentrated enough for its theft to "cause appreciable market disruption," with the remaining 1.6 million spread across small UTXOs averaging ~50 BTC each — making mass extraction time-consuming and economically marginal even under optimistic quantum timelines.[^4]
Woo estimates a 25% probability that the network would agree to freeze vulnerable coins via hard fork — one of the most contentious governance questions Bitcoin has ever faced.[^7] Such a fork would effectively destroy the fungibility guarantee that underpins Bitcoin's monetary thesis.
The quantum discount is no longer theoretical. It is manifesting in three measurable ways:
1. The BTC/Gold Ratio Has Broken
Bitcoin's 12-year uptrend against gold — the metric that defined its "digital gold" narrative — has reversed. In 2026, BTC is down 6.5% year-to-date while gold has surged 55%. The BTC/gold ratio stood at 19.26 in January 2026, reflecting what Woo calls a "structural discount" on Bitcoin's valuation versus gold for the next 5-15 years.[^8]
2. Institutional Portfolio Rebalancing
Christopher Wood, Jefferies' global head of equity strategy, removed a 10% Bitcoin allocation from his model portfolio in January 2026, citing quantum concerns. He split the allocation into 5% physical gold and 5% gold-mining stocks.[^9] Multiple institutional allocators have signaled that they are unlikely to allocate more than 3% of portfolios to Bitcoin until quantum risks are better understood and mitigated.
3. ETF Filing Disclosures
BlackRock expanded its quantum risk disclosure in an amended S-1 filing for the iShares Bitcoin Trust (IBIT), its $64 billion spot Bitcoin ETF. The filing warns that "quantum breakthroughs might eventually undermine the cryptographic systems that secure Bitcoin wallets and transactions" and that "there is no guarantee that new quantum-proof architectures will be built and appropriate transitions will be implemented across the network at scale in a timely manner."[^10]
The cumulative effect: $3.8 billion in crypto investment product outflows over four consecutive weeks, with US-based products hemorrhaging $403 million in the most recent week alone. A notable geographic divergence has emerged, with Germany, Canada, and Switzerland collectively attracting $230 million in inflows — suggesting that European and Canadian institutional investors may be viewing the discount as an entry point.[^2]
The industry's technical response is underway — but the pace is a source of legitimate concern.
BIP-360, co-authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, proposes adding a new address type to Bitcoin capable of using post-quantum signatures. The proposal introduces a "quantum witness" mechanism — analogous to SegWit's witness discount — that would accommodate larger post-quantum signature algorithms like ML-DSA (Dilithium) and SLH-DSA (SPHINCS+), both standardized by NIST in 2024.[^11]
The debate is intensifying. Charles Edwards has called for a 2026 deployment and suggested penalizing coins that do not migrate by 2028. Adam Back and Samson Mow have pushed back, arguing the threat is not imminent and that rushed upgrades introduce their own risks.[^5]
Historical precedent is sobering: SegWit took approximately 8.5 years from conception to widespread adoption. Taproot took roughly 7.5 years. If BIP-360 follows a similar trajectory, Bitcoin may not have quantum-resistant addresses until the mid-2030s.[^12]
BTQ Technologies has launched the first quantum-safe Bitcoin testnet — "Bitcoin Quantum Core Release 0.2" — replacing ECDSA with NIST-approved ML-DSA. But this remains an experimental fork, not a mainnet upgrade.[^13]
The Ethereum Foundation elevated post-quantum security to a top strategic priority in January 2026, launching a dedicated PQ team led by Thomas Coratger.[^14] The roadmap targets a post-quantum-resistant consensus framework by approximately 2030.
Key initiatives include:
Ethereum's account abstraction architecture gives it a structural advantage — it can theoretically support quantum-resistant signatures at the wallet level without a full protocol overhaul. But "theoretically" is doing heavy lifting in that sentence.
Viewed through webthreepedia's economic value framework, the quantum threat amplifies an existing structural vulnerability. Blockchain networks already operate on approximately $86-113 billion in annualized funding, of which 85-90% comes from subsidy mechanisms — token inflation, venture capital, and issuance programs — rather than self-sustaining fee revenue.
A quantum-driven migration adds a new cost layer to this equation:
For a sector that generates only ~$13.7 billion in on-chain revenue annually, adding a multi-billion-dollar migration cost further strains the sustainability gap. The networks that manage this transition most efficiently will gain a durable competitive advantage. Those that delay may find the "quantum discount" becomes permanent.
The quantum threat to Bitcoin is real but not imminent. Cryptographically relevant quantum computers are likely a decade or more away, but markets are pricing the risk now. The BTC/gold ratio's 12-year uptrend has broken.
Only ~10,200 BTC faces concentrated, market-moving theft risk, though up to 4 million BTC has exposed public keys. The distinction between these numbers is critical for calibrating institutional risk models.
$3.8 billion in ETF outflows over four consecutive weeks reflects quantum-adjacent fear — alongside macro deleveraging — entering institutional allocation decisions. BlackRock, Jefferies, and Grayscale have all formally acknowledged the risk.
BIP-360 is Bitcoin's primary migration pathway, but historical upgrade timelines (7.5-8.5 years) suggest full quantum resistance may not arrive until the mid-2030s. Ethereum's PQ team has a 2030 target.
Post-quantum migration will be expensive. Larger signature sizes (33x ECDSA) strain block space economics, and ecosystem-wide coordination costs will add a new burden to networks that are already 85-90% subsidy-dependent.
The "quantum discount" may persist for 5-15 years, functioning as a structural drag on Bitcoin's valuation until the migration is complete and the threat timeline is better understood.
The quantum computing threat to cryptocurrency is the rare case where the market narrative may actually be underreacting to the long-term structural risk while overreacting to the near-term probability. The physics says Q Day is distant. The economics say the migration will be painful. And the governance says Bitcoin's decentralized upgrade process is structurally ill-suited to the urgency that a compressed timeline would demand.
What investors are pricing today is not the physics — it is the uncertainty. The absence of a clear, funded, timeline-bound migration plan from Bitcoin Core is itself a form of risk. Ethereum's more organized response, while still years from deployment, may earn it a relative premium in institutional portfolio construction.
The most consequential question is not when quantum computers will be powerful enough. It is whether Bitcoin's governance can move fast enough to close the window before institutions permanently reallocate to assets — like gold — that face no such existential cryptographic risk.
For a sector that has spent 15 years arguing it is the future of money, the inability to articulate a credible plan for the most predictable technological threat on the horizon is, itself, worth a discount.
[^1]: Bitcoin Stabilises at USD 68,880 — LatestLY, February 17, 2026
[^2]: Latest Crypto News of February 2026: $3.8B Floods Out of ETFs — Tribune India, February 2026
[^3]: Bitcoin Faces Quantum Threat: Doomsday Clock Sets 2028 Deadline — CoinCentral
[^4]: CoinShares Says Only 10,200 BTC Face Real Quantum Risk — The Block, February 2026
[^5]: Willy Woo Flags Q Day Risk, Devs See No Rush — Bitbo, February 2026
[^6]: Google Achieves First Verifiable Quantum Advantage: Willow Chip — Programming Helper, 2026
[^7]: Willy Woo Warns of Potential 4 Million BTC Market Dump — ForkLog, February 2026
[^10]: BlackRock Flags Quantum Risk in Bitcoin ETF Filing — Bitbo
[^11]: Bitcoiners To Quantum-Proof BTC: BIP-360, Hash-Based Signatures — CoinTelegraph, 2026
[^12]: Bitcoin and Quantum Computing: Current Status and Future Directions — Chaincode Labs
[^13]: BTQ Technologies Launches Bitcoin Quantum Testnet — PR Newswire, 2026
[^14]: Ethereum Foundation Makes Post-Quantum Security a Top Priority — CoinDesk, January 2026
[^15]: Post-Quantum Cryptography in 2026: 5 Predictions — QuantumXC