8 ms·
Bitcoin and quantum computing
- EthanHeilman 6mo ago"A CRQC is an existential threat to Bitcoin (you might believe this is very low-likehood). Your measurement of this threat should literally be: (A) How likely you think it is a CRQC appears by a given time, multiplied by (B) How likely it is you think Bitcoin will not successfully upgrade by that time." It would interesting to survey people about their answers. My off the cuff answer is: 2030: A=0.05, B=0.01 2035: A=0.50, B=0.001 2045: A=~1.0, B=~0.0 I reserve the right to change my mind on these answers at any point. This is not a serious prediction.
- sayYayToLife 6mo agoKarl Popper calls this a psychological probability(% chance I go to the gym today). This is different from objective probability (% chance a dice lands on 5).
- EthanHeilman 6mo agoIn this case, it seems like we are rolling dice but no one is quiet sure if the dice are fair, how many sides it has and what numbers are written on the dice. The only thing I am confident in is if it the bigger the fire, the faster the work. I want the Bitcoin community to start the work as early as possible so that it doesn't have to rush because rushing increases the chance of mistakes. Start early, don't rush.
- hackernudes 6mo agoCRQC = cryptographically relevant quantum computer
- flatline 6mo agoI'm skeptical that B is fully possible. You can create a PQ fork of bitcoin but you cannot automatically bring vulnerable wallets along - and there are a lot of vulnerable wallets, especially from the early days. There's a catastrophe ahead for bitcoin with an apparent probability of 1.0. That's hard to account for in this scheme.
- sankao 6mo agoI would argue that the hackers will do the jobs of transferring funds from insecure wallets to secure ones very efficiently.
- netheril96 6mo agoIt would still tank the price. Right now many Bitcoins are lost because no one holds the keys any more. When they can hack it, suddenly the sell pressure significantly goes up.
- deleted 6mo ago[deleted]
- mono442 6mo agoa hard fork could burn bitcoins which are vulnerable
- tomtomtom777 6mo ago2045 A=~1.0 seems way off. CRQC is still a theoretical construct with hurdles to overcome. Yes, there is a significant risk that it will exist somewhere in the next decades, but there is also still a significant chance that it will be shown to be practically impossible.
- EthanHeilman 6mo agoThat is not what I am hearing from people working on CRQC. A prediction of a CRQC with 10% by 2030 was made by own of the top experts in this field. 2045 used to be the pessimistic outlook by experts with a bunch of experts predicting earlier. Recent work has shown that CRQC is actual 20 times easier to built that previously thought, accelerating all timelines. We are seeing significant progress in two different types of quantum computers, neutral atom and superconducting qubit. No one really knows when it will happen, but the chance that it is practically impossible is held only by a small number of experts. Given what we have seen in 2026 has significantly shifted expectations.
- hatthew 6mo ago"Accelerated timeline" and "impossible" are not mutually exclusive. We may just reach the point where we conclude it's impossible sooner. Not commenting on specific numbers/estimates.
- functional_dev 6mo agoDo you have a link to the paper showing the 20x improvement?
- littlecranky67 6mo agoYou should also consider that a CRQC needs not only to exist, but be used in a certain way. I can hardly see the first thing Google or IBM do upon their breakthrough, is stealing bitcoins. There is a reputation to have. And it is also unlikely some hacker can build a superior quantum computer in their backyard before some trillion dollar companies with a research budget can.
- tromp 6mo agoGood article with some questionable remarks like > Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin? > A: If you truly believe this, you really should value Bitcoin at 0 – it has many unnecessary components with a lot of overhead, like proof-of-work and digital signatures. Proof of work is still necessary for two reasons: 1) to fairly distribute all coins (it's not sufficient though, e.g. Bitcoin's halvings still concentrate wealth on early miners/adopters) 2) to provide objective proof for the true transaction history, anchored in energy expenditure. A related article on Bitcoin Core resistance to upgrading: https://murmurationstwo.substack.com/p/bitcoin-developers-are-mostly-not https://murmurationstwo.substack.com/p/bitcoin-developers-ar...
- lxgr 6mo agoI guess the argument goes more like: If nobody were to attempt to steal anything, you don’t need security for your ledger anyway.
- EthanHeilman 6mo ago> 2) to provide objective proof for the true transaction history, anchored in energy expenditure. Why do you need this if you are willing to trust other people not to steal coins or lie? > 1) to fairly distribute all coins Same question as above. If you don't care about perfidy, simply use the honor system for coin distribution. If you do care about perfidy, then you should probably care about people breaking the law to steal your coins.
- jaspanglia 6mo agoI think we still have a 3-4 years of escape window to reach the necessary qubit range of breaking the encryption. But China is unstoppable and advancing rapidly, So crypto community needs to upgrade to Post-Quantum Cryptography before the threshold breaks.
- xoa 6mo ago>Q: Stealing is illegal, so why would anyone use a CRQC to steal Bitcoin? I've had this thought for awhile actually: how would reproducing some random number be legally "stealing" under any legal system in the world? Putting aside that cryptocurrencies have always been about "code decides" etc, that they're outside of the legal system entirely, but I'm struggling to see where there's any actual property interest here. Randomly generated numbers are not protected by IP in any way. There's no computer fraud act angle or the like here, nobody would be having so much as the slightest interaction with anyone else's private system. They'd merely be taking publicly available unprotected numbers and doing some math on them with their own quantum computer. Somebody else who has something related to those numbers is never deprived of them or interacted with in the slightest. There is nothing resembling "hacking", no flaws in the software exploited, all just math there from the start. I can understand how suddenly a lot of proponents might wish to cling to and push the idea that it's "illegal" or "stealing", but doesn't appear to be any meat on dem bones. Maybe they hope to generate support to get laws passed banning it, though hard to see that working out either. As a practical matter seems like they're just going to have to agree on a transition to new version using PQE algorithms and try to convert over before it's too late?
- QuantumNomad_ 6mo agoCryptocurrency gains are taxable in many (most?) countries. Clearly the governments see cryptocurrency as something more than just random numbers without meaning. Likewise, when government agencies shut down dark net markets (DNMs), they will seize the cryptocurrency funds that the DNM had (from market fees etc., or even funds that belonged to customers and were in escrow etc. by the DNM) if they can (i.e. if they get access to the private keys of DNM owned wallets either by technical means or by convincing the operators of the DNM to hand over the keys). Again because the governments view cryptocurrencies as something more than just random numbers without meaning. Speaking of seized funds. Let’s say that a government agency had seized a significant amount of bitcoin from a DNM and was transferring those funds to wallets under government agency control. Along comes some guy with a quantum computer and takes those funds for himself. Is the government agency just going to throw its hands in the air and say “oh well, he guessed the random number, nothing more we can do!” No, I think not.
- schoen 6mo agoAs was alluded to in the comments, my colleagues at Blockstream Research are doing some work on this with mechanisms called SHRINCS and SHRIMPS. Of course, inventing and demonstrating a quantum-resistant signature mechanism isn't the same thing as deploying it in consensus or upgrading everyone's UTXOs to it, and it's fair to say that there are many steps in between!
- nehan 6mo agoThis work is important, and I'm looking forward to forming an opinion on it. Maybe a future post! For those who are interested, this is what I'm aware of: - Tim Ruffing proved that Taproot's commitment scheme was quantum-resilient: https://eprint.iacr.org/2025/1307 https://eprint.iacr.org/2025/1307 - Jonas Nick and Mikhail Kudinov have proposed SHRINCS: https://delvingbitcoin.org/t/shrincs-324-byte-stateful-post-quantum-signatures-with-static-backups/2158 https://delvingbitcoin.org/t/shrincs-324-byte-stateful-post-... and SHRIMPS: https://x.com/n1ckler/status/2038695067754328095 https://x.com/n1ckler/status/2038695067754328095.
- nehan 6mo agoAlso, LetsEncrypt is very cool! Thanks for working on it.
- tempera 6mo ago[dead]
- mmastrac 6mo agoThe mostly likely quantum attack on Bitcoin will be a catastrophic transfer of large wallets to burn addresses along with a massive short position. No need to worry about washing stolen coins when you can just enjoy your "well timed" legal short position's windfall.
- Jerrrrrrrry 6mo agoInteresting, considering the extra liability / (stability) volatility that bitcoin options provide when making ROI and hashrate calculations, this can be a triple threat. Like publicly destroying ivory /poppy stockpiles while simultaneously holding puts/futures on correlating pharmaceutical financial instruments.
- nehan 6mo agotwo things: 1) Short markets in Bitcoin don't have unlimited depth, and the centralized ones are KYC'd so there's some risk there 2) What if it doesn't tank the price? One thing people have suggested is just burning all the vulnerable coins[1]; it reduces supply so maybe the price will... go up? The point is there's uncertainty. [1] https://x.com/lostbutlucky/status/2040878873731080681 https://x.com/lostbutlucky/status/2040878873731080681
- dodobirdlord 6mo agoWhat risk are you envisioning in #1?
- nehan 6mo agoSorry I wasn't clear there. Because most of the short-depth is controlled by centralized exchanges, there's a risk you won't be able to actualize your short (withdraw, either in crypto or to a bank account), even if it's successful -- they could just block you from withdrawing and/or report you for fraud.
- tshaddox 6mo agoI’m pretty sure the hope isn’t that burning some coins tanks the price. The point is that publicly demonstrating that you can crack wallet keys is what tanks the price.
- adhoc32 6mo ago[dead]
- burakhopsule 6mo ago[flagged]
- glerk 6mo agoOne thing that is not addressed: say this quantum attack happens tomorrow and everyone agrees it was an attack, what would prevent the community (miners, node operators, and users) to hard fork the chain at a snapshot before the attack, patch the protocol, and call that Bitcoin? There would be loss of value of course, but it is not unrecoverable. It’s worth remembering that Ethereum forked for much less (not even a bug in the protocol, but a bug in a private application running on the protocol) and nobody seems too upset about it a decade later.
- Retr0id 6mo agoA hard fork implies a difference in consensus rules, and what do you propose that difference be? Existing wallets need to actively commit to some PQ signature mechanism, prior to Q-day.
- glerk 6mo agoEven if Q-day means there is a way to deterministically retrieve any private key from a public key (is that what it means? or is the blast radius of q-day contained? This is a bit above my level of cryptography), I’m sure we could come up with something to minimize the damage. In the worst case, it might involve a claim process with an authority or consensus mechanism to prove who the rightful owner of the funds is and revert the unauthorized transactions on the new chain. Yes, this is not ideal! But if the wallet conversion requires active participation, preemptive measures are also not ideal.
- Retr0id 6mo ago> Q-day means there is a way to deterministically retrieve any private key from a public key That's exactly what it means. (Note also that under ECDSA you can retrieve a public key from a valid signature). How do you prove anything, after the key material is compromised?
- glerk 6mo ago> How do you prove anything, after the key material is compromised? It’s a blockchain, so the simplest would be chain of custody until the chain points undeniably at you. This is not a pure cryptographic device, some social intervention might be needed here.
- memnips 6mo agoSomewhat ironic question, but as ETFs holdings of BTC continue to grow, is there a possibility that the custodians of those ETFs start to have a backup plan for ETF holders or create an alliance to push a fork forward? The management fee those companies generate is non-trivial, so they're incentivized to stay ahead of this. Now, of course, the irony here would be traditional finance infrastructure winning out over decentralized, which could definitely deal a psychological blow to BTC's perceived value... but it's something I've been thinking about lately as this existential threat rises on the horizon.
- pants2 6mo agoMicrostrategy is already pushing/funding quantum resilience for Bitcoin, so yes!
- wmf 6mo agoYes, if you read the fine print on the ETFs they tell you what they will do in case of a fork. Usually their custodian picks the "winning" chain at their discretion. There's a similar (although reversed) situation with stablecoins.
- dodobirdlord 6mo agoIn the absolute disaster scenario where the ecosystem is taken by surprise by an adversary with a CRQC, regulated custodians could form a consortium to reconstitute a new quantum-resistant version of bitcoin, pooling their ownership ledgers from before the disaster to reinitialize the blockchain and consigning to oblivion all coins not held in custody.
- avazhi 6mo agoWhich would ofc be hilarious given BTC’s raison d’être.
- fluxusars 6mo agoThe thing that supposedly sets Bitcoin apart from other cryptocurrencies is that it's deflationary and 'immutable', in that Satoshi is gone forever and any deviation of Bitcoin from his golden idea will result in undermining its essence. If Bitcoin can get quantum-attacked then, from a technical point of view, nothing will be lost. The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back the chain to before the attack, and all is well. Then they'll change the cryptography. But at that point, is it still Bitcoin? Because you've undermined the immutability. If the core devs can just say "this core property of Bitcoin is now something completely different", who's to say that they won't change their minds about the deflationary nature in the future? All credibility will be lost. Now, if you accept that, is perhaps all credibility lost already? ...
- schlauerfox 6mo agoThis was already pretty well hashed out (heh) during the 'core'/'cash' issue when there was an attempt to fork in an expanded the block size. Both chains still exist. Bitcoin operation is entirely up to the miners to determine the heaviest chain, and that's like two entities (the number of entities required is called the Nakamoto coefficient). It's not magic, but there is a huge cult built up around it by scammers, rubes, opportunists and speculators.
- wmf 6mo agoMiners enforce the consensus rules but they can't change them. If miners try to change the rules, exchanges have no obligation to follow.
- tomtomtom777 6mo ago> The Bitcoin core devs can issue a word-of-god statement stating that they'll roll back the chain to before the attack, and all is well. Then they'll change the cryptography. That doesn't work, because once the signature scheme has been broken, nobody can prove that their coins are theirs. No roll back or word-of-god would help. The only way to make bitcoin quantum-safe, is to introduce a quantum safe signature scheme, to encourage everyone to move their coins and to somehow accept that those who don't are not longer in control of their coins.
- EGreg 6mo agoApparently bitcoin foundation is already working on SHRINCS and SHRIMPS. But whether they will forcibly revoke keys of satoshi and all early bitcoin whales or not is another question!
- j2kun 6mo ago> I personally care more about using Bitcoin than its price I suspect that the author is in a pretty drastic minority here.
- kreetx 6mo agoYup. I quite literally don't know anyone who is using Bitcoin directly to pay for everyday expenses, nor even for larger purchases. It always includes using an off-ramp and going through fiat.
- janalsncm 6mo agoIt probably isn’t helpful that Bitcoin can only handle 7 TPS, so there is a scenario where even if you wanted to get out of BTC you couldn’t.
- arijun 6mo agoI assume that the solution to this would be a modification of the cryptographic basis of Bitcoin. Is there any way at all to do that without leaving behind people who aren't available at the time of transfer? Like if Satoshi was in a coma and not dead, is there any way at all to harden Bitcoin against attacks that would leave his wallet accessible to him?
- thyrsus 6mo agoAre there currently circulating cryptocurrencies that use quantum resistant cryptography?
- hgujral 6mo agoThe world digital economy is worth more than 20T and we're concerned about an asset <2T!? If quantum breaks the highest form of encryption we have today, we have bigger problems at hand.
- Retr0id 6mo agoQuantum computing does not break all cryptography.
- superpositions 6mo agoI think a lot of the confusion in these threads comes from treating quantum risk as a single binary event. A centralized system can often rotate credentials, patch infra, and recover operationally. A decentralized system with exposed legacy keys and social coordination constraints is a very different problem.
- dodobirdlord 6mo agoThe signature scheme used by bitcoin is far from the best encryption we have today, and more resistant to being updated than most more important things. So it’s an interesting novelty.
- tw600040 6mo agoNaive question may be. But if quantum can break bitcoin, won't it also be able to break other encryptions that literally everyone else uses as well? So, it's not that bitcoin is particularly vulnerable right any more than banks and Gmails?
- weakened_malloc 6mo agoYes and no. I'm no expert, but there's two things that don't make it nearly as dangerous as it is for BTC. The first is the fact that many things are centralized. Things like Signal already have quantum-resistant encryption, and if they don't, they're able to implement it relatively quickly because it's centralized. BTC is not centralized and needs to jump through a bunch of hoops to get anything done. The second is that because those things are centralized or close to, you can roll back changes with ease. For instance, if you hack a bank and steal a bunch of money from an account you're far more likely to be able to freeze those funds and get other banks to help stop everything before they're gone forever. You can't do that with BTC.
- nickvec 6mo agoFrom the article: Q: A CRQC also breaks banking, military communications, and most of the internet today! If one appears, isn’t Bitcoin the least of our problems? A: True! Banking software, military communications, and the internet also need to be upgraded. I have high confidence they will be, successfully (I’d put my B_{HTTPS} at close to 1). Unfortunately, I have less confidence that Bitcoin will upgrade successfully since upgrading a decentralized system of honey-badger-like participants is much more challenging and people like the questioner seem to think this is a valid argument that we shouldn’t even worry about it? If you disagree and think there will be a CRQC and the rest of the internet won’t upgrade successfully, maybe you should consider shorting the stock market and buying gold. But not Bitcoin, because if we do nothing that won’t work anymore. Not investment advice.
- burnerRhodov2 6mo agoThis is one of the most lazy writings i've ever heard... CRQC is not non-zero across all timeslines, it is inevitable. With the inevitability, the satoshi wallets can never be secured.
- mono442 6mo agotbh I've heard the same about the nuclear fusion for many years now
- burnerRhodov2 6mo agoWe created fusion in 1952.
- netheril96 6mo agoETH is not afraid of doing hard forks, so I'm expecting that they will lead in adopting post quantum cryptography. And then BTC ecosystem participants can learn from ETH.
- dnautics 6mo agoeven if btc does a hard fork, you'll need to "reshim" the encryption on each wallet. and you can only do (n) tx per block. and only 1 blocks per unit time. this limits the speed of bitcoin moving to PQC, it must take at leaat ~3 years iirc
- pruz 6mo ago[dead]
- junofan 6mo agoIs this an LLM comment. Why is the A*B framing so useful? It’s just two factors… Why would ppl underestimate B? There’s money at stake.
- TrackerFF 6mo agoIn practice, wouldn't it only be the dead wallets that would be affected? Granted, it is not a small number - IIRC, around 20% of all mined bitcoin are stored on these so-called dead wallets. With current prices that's a quarter trillion dollar worth BTC.
- aaroninsf 6mo agoI love the spell of cope in the morning.
- superpositions 6mo agoI think the tricky part is ownership after the break. If signatures are no longer trustworthy, rolling back doesn't really tell you who the coins belong to. It just rewinds you to a state where the same problem still exists. So this seems more like a migration problem than a governance problem.