Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home » Focus » Background » Quantum computers put Bitcoin’s cryptography under pressure
    Falling qubit estimates bring the quantum computer threat to Bitcoin closer and spark a debate over freezing Satoshi's coins.

    Quantum computers put Bitcoin’s cryptography under pressure

    By Editorial Office CVJ.CH on 20. July 2026 Background

    In July 2026, Binance founder Changpeng Zhao proposed freezing Satoshi Nakamoto's roughly 1.1 million BTC. His coins would stay frozen unless they move to quantum-safe addresses within 6 to 12 months. The trigger is the prospect that quantum computers could break the cryptography behind Bitcoin transactions.

    The threat targets a technical detail. Bitcoin secures its transactions with the ECDSA signature scheme on the secp256k1 curve. A sufficiently powerful quantum computer could use Shor's algorithm to derive the private key once the public key is exposed. Mining via SHA-256, however, stays out of reach, because Grover's algorithm delivers only a quadratic speedup. During 2026, the debate escalated quickly. First, the migration proposal BIP-360 entered Bitcoin's official developer repository in February. Later, the more contested BIP-361 followed with a freeze mechanism. At the same time, Google Quantum AI revised the required qubit count sharply downward. Moreover, roughly a third of the circulating supply sits with a visible public key. Available quantum computers, by contrast, reach only around 2,000 to 2,500 physical qubits.

    Subscribe to our newsletter

    The best articles of the week, directly delivered into your mailbox.

    Shor versus Grover: why only the signatures are vulnerable

    Bitcoin uses two cryptographic building blocks with very different risk profiles. The transaction signatures run through ECDSA on the secp256k1 curve, while mining and address hashing rely on SHA-256. On a powerful quantum computer, Shor's algorithm delivers an exponential speedup. As a result, the matching private key can be derived from a public key. This attack hits ECDSA directly.

    Mining tells a different story. Here Grover's algorithm applies, and it speeds up SHA-256 only quadratically. The effective security therefore drops from 2^256 to roughly 2^128 operations. That figure stays practically out of reach. SHA-256 thus counts as far more robust against quantum attacks than ECDSA. Ultimately, the difference between the two algorithms decides the entire risk profile. An exponential speedup turns an unsolvable problem into a matter of minutes.

    Quantum mining also makes no economic sense. Estimates put the stock needed for profitable mining at around 10^23 qubits. In addition, the energy costs would exceed those of a large national power grid. The proof-of-work mechanism thus stays beyond the reach of realistic quantum hardware over the long term. Consequently, the danger concentrates on the moment when a public key becomes visible on-chain.

    Which Bitcoin holdings already lie exposed

    A public key becomes visible in three places. First, in the P2PK outputs from 2009 and 2010, which include the coins attributed to Satoshi Nakamoto. Second, in every address that has sent at least one transaction, because the signature exposes the key. Third, in every Taproot keypath spend through the P2TR output type.

    How much Bitcoin this exposes depends heavily on the methodology. One frequently cited estimate puts the amount at around 6.9 million BTC, or roughly a third of the supply. Other counts in early March 2026 likewise reached more than 34 percent of the circulating amount. An older Deloitte analysis from 2023, by contrast, arrived at around 4 million BTC. That count still left out the Taproot keypath spends. Furthermore, the BIP-360 context separates roughly 1.72 million BTC as highly vulnerable. Another 4.49 million BTC count as vulnerable but migratable.

    The range shows how differently the sources count. As an order of magnitude, however, roughly a third of the supply remains. Part of that falls to a single holder. Estimates value the holdings attributed to Satoshi Nakamoto at around 1.1 million BTC. For institutional holders, a once abstract question thus shifts into concrete custody planning.

    Ray Dalio’s Bridgewater Associates Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Falling qubit estimates bring the quantum computer threat to Bitcoin closer and spark a debate over freezing Satoshi's coins. Background

    Quantum computers put Bitcoin’s cryptography under pressure

    US spot XRP ETF outflows hit USD 7.18 million, ending a two-month inflow streak, while Bitcoin and Ethereum ETFs returned to net inflows. Financial Products

    XRP ETFs record first outflows in two months

    Digital finance transparency relies on Proof of Reserves, Merkle trees, MPC custody and 24/7 monitoring to verify solvency and user assets. Basics

    Transparency as the foundation of security in digital finance

    Ray Dalio’s Bridgewater Associates Minds

    Star investor Ray Dalio considers Bitcoin inferior to gold

    Falling qubit estimates bring the quantum computer threat to Bitcoin closer and spark a debate over freezing Satoshi's coins. Background

    Quantum computers put Bitcoin’s cryptography under pressure

    How close a Bitcoin-breaking quantum computer really is

    The time horizons have shifted less through hardware than through mathematics. Google Quantum AI in 2026 put the requirement for breaking Bitcoin's ECDSA at under 500,000 physical qubits. Its runtime falls in the range of minutes. The whitepaper came from Craig Gidney and Ryan Babbush. Justin Drake of the Ethereum Foundation and Stanford cryptographer Dan Boneh also contributed. By comparison, Litinski's 2023 figure came in far higher, at around 9 million qubits, roughly twenty times more.

    Real hardware, however, remains far from that scale. The largest publicly known quantum computers currently reach around 2,000 to 2,500 physical qubits. Moreover, error correction today demands between 1,000 and 10,000 physical qubits per logical qubit. A large gap thus still separates ambition from reality.

    IBM's roadmap, however, shows how fast the field moves. The Loon processor (2025) leads into Kookaburra (2026), the first fault-tolerant module. Cockatoo (2027) and finally Starling (2028/29) with 200 logical qubits follow. At the same time, the roadmap shifts from surface codes to quantum LDPC codes. That change should cut the qubit overhead by up to 90 percent. Regulation is also responding already. In August 2024, NIST finalized the first post-quantum standards FIPS 203, 204 and 205. In March 2025, the agency added the backup KEM HQC.

    BIP-360 and BIP-361: a fight over Bitcoin's answer

    Bitcoin now has two competing response paths. BIP-360 comes from Hunter Beast, Ethan Heilman and Isabel Foxen Duke. Bitcoin's official proposal repository accepted it in February 2026. The proposal introduces a new output type, Pay-to-Quantum-Resistant-Hash, with the address prefix "bc1r". It works like Taproot but removes the quantum-vulnerable keypath spend. Among the signature schemes under discussion is the NIST standard ML-DSA. Later, in March 2026, BTQ Technologies delivered the first working BIP-360 implementation on a testnet.

    The second path goes considerably further. In April 2026, Jameson Lopp, the security chief at Casa, and five other developers published BIP-361. The proposal outlines a phased transition that ends with the network freezing coins that have not migrated. This compulsion is contested. In mid-April, Bitcoin Core developer Adam Back positioned himself against a forced freeze and instead favors optional upgrades.

    In early July, the debate reached its provisional peak. Changpeng Zhao proposed freezing Satoshi's roughly 1.1 million BTC if they stay untouched once quantum computers pose a real threat. First, a window of 6 to 12 months would give holders time to migrate. Critics nevertheless see high political hurdles. Michael Terpin points out that the SegWit upgrade alone took years to reach consensus. Moreover, such a deep intervention touches Bitcoin's core promise of immutability. For the first time, the network thus faces a serious question. The issue is whether it may disable coins that belong to others to protect them from a future attacker.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    Editorial Office CVJ.CH
    • Website
    • Twitter
    • LinkedIn

    Since 2018, the editorial team at Crypto Valley Journal has been reporting from Zug - the heart of Switzerland’s Crypto Valley - on Bitcoin, cryptocurrency, blockchain, and regulatory developments in digital assets. Behind the publication’s collective editorial voice is a team of writers with backgrounds in financial markets, law, and technology.

    Related Articles

    Wall Street Blockchain

    Bitcoin Seeks Support as Wall Street Builds on Blockchain

    Strategy CEO Phong Le confirms the company stays a Bitcoin buyer and sees debt risks only if Bitcoin falls below USD 10,000.

    Strategy CEO: Debt risk sits below a Bitcoin price of USD 10,000

    JPMorgan ranks Strategy's sales below the bigger Bitcoin risk and names tokenization beyond public chains as the real threat.

    JPMorgan sees biggest Bitcoin risk beyond Strategy

    Wall Street Blockchain
    20. July 2026

    Bitcoin Seeks Support as Wall Street Builds on Blockchain

    Falling qubit estimates bring the quantum computer threat to Bitcoin closer and spark a debate over freezing Satoshi's coins.
    20. July 2026

    Quantum computers put Bitcoin’s cryptography under pressure

    CVJ weekly review
    18. July 2026

    Weekly review: Strategy CEO sees Bitcoin risk at $10,000

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search

    Type above and press Enter to search. Press Esc to cancel.