Here’s our Chinscratcher answer to the question “Are quantum computers a threat to Bitcoin in the short term?”
The One-Sentence Answer
No quantum computer on Earth can steal your Bitcoin today — but patient adversaries may already be collecting the data they’ll need to try in the future, and the window between “not yet” and “soon” is narrowing faster than most people expected.
Part 1: Why You Don’t Need to Panic Right Now
Think of Bitcoin’s security like a combination lock — an extremely sophisticated mathematical one. To crack it, a quantum computer would need to be roughly 125 times more powerful than the most advanced machine that exists today.
That gap isn’t just big. It’s a gap in kind, not just size — like the difference between a bicycle and a spacecraft. Today’s quantum computers are essentially scientific curiosities. They work for fractions of a second before their calculations dissolve into noise. They have no error correction — the quantum equivalent of a calculator that randomly changes its own numbers mid-calculation. The machines that could threaten Bitcoin would need to sustain perfect calculations, at enormous scale, for minutes at a time. Nobody has demonstrated anything close to that.
The most respected independent survey of quantum experts — drawing on 26 specialists worldwide — puts the probability of a Bitcoin-threatening machine existing within the next five years at very low. Most serious researchers, including Bitcoin’s own cypherpunk elders, agree: this is not a 2026 or 2027 problem.
Adam Back — one of Bitcoin’s founding technical figures, CEO of Blockstream, and a man who has tracked cryptographic threats for 25 years — put it plainly in April 2026:
“The current hardware…generally doesn’t have any error correction.” The machines today are “essentially lab experiments.”
His estimate for when a real threat could emerge: 20 to 40 years. Not imminent. Not next year.
Part 2: The Part That IS Already Happening (And This Is the Bit Worth Worrying About)
Here’s the thing. You don’t need a quantum computer today to start executing a quantum attack on Bitcoin. You just need a hard drive.
There is a strategy used by nation-state intelligence agencies — formally documented and publicly acknowledged by the NSA and GCHQ — called “Harvest Now, Decrypt Later.” The idea is simple:
Copy the encrypted data today. Decrypt it once the machine that can do so exists.
For most types of encrypted data — your email, your bank login — this strategy has a practical problem: by the time a quantum computer exists, the data will be years old and mostly useless. Who cares about your 2026 emails in 2040?
Bitcoin is different. Critically different.
The Bitcoin blockchain is a permanent, public, freely downloadable record of every transaction ever made, going back to 2009. Every public key ever exposed on the blockchain is sitting there right now — available to anyone with a hard drive. And roughly 35% of all Bitcoin ever mined sits in addresses where the public key has been exposed.
What does “exposed public key” mean? When you receive Bitcoin, the network sees your public key. Your private key — the one that proves ownership — is mathematically derived from the public key in a way that’s currently impossible to reverse. But with a powerful enough quantum computer, that reversal becomes possible. And the data needed to attempt that reversal — your public key — is already on the blockchain, permanently, for anyone to collect right now.
The Federal Reserve published a formal paper on this in October 2025, using Bitcoin as its primary case study. The finding: data on the Bitcoin blockchain from 2009 onward is already subject to the harvest-now-decrypt-later threat. The harvesting phase doesn’t require any quantum technology at all. It just requires copying a file that is freely available to anyone on Earth.
The lock on your house isn’t being picked today. But someone may already have photographed it — and they’re building the key.
Part 3: Why the Experts Are Arguing About the Timeline
So if it’s not a crisis today, why are serious people worried? Because the speed of progress has surprised almost everyone — including the experts.
Here is what changed just in the first half of 2026:
- March 30: Google published a paper showing that breaking Bitcoin’s encryption would require 20 times fewer quantum resources than they estimated just seven years ago. The math is moving in the wrong direction — for Bitcoin holders.
- June 2: Microsoft announced a new quantum chip (Majorana 2) that is 1,000 times more reliable than its predecessor. Microsoft’s own internal target for a powerful enough machine: 2029. That’s three years from now.
- June 22: President Trump signed an executive order formally directing the US government to build a fault-tolerant quantum computer by 2028. This is a funded government commitment, not a think-tank estimate. The US government has access to classified intelligence about what China and other adversaries are building. They evidently find the 2028 timeline credible enough to mobilise billions of dollars around it.
The independent expert survey that tracks this most rigorously (the Global Risk Institute, running since 2019) now puts the probability of a Bitcoin-threatening quantum computer existing within 10 years at between 28% and 49%. That was up from 19–34% just one year ago — the biggest single-year jump in the survey’s history.
In plain terms: a year ago, experts thought there was roughly a 1-in-5 chance of a major quantum breakthrough within a decade. Today they think it’s closer to a 1-in-3 to 1-in-2 chance.
That is not “panic” territory. But it is no longer “don’t worry about it” territory either.
Part 4: What the Experts Actually Disagree About
This is a genuine disagreement between serious, qualified people — not a fringe debate.
| Position | Who Holds It | What They’re Saying |
|---|---|---|
| “20–40 years, not urgent” | Adam Back (Blockstream) | Hardware is primitive; error correction unsolved; decades to go |
| “Could happen by 2028–2030, prepare now” | Vitalik Buterin (Ethereum), Dr. Michele Mosca (GRI) | Tail risk is real; 20–50% probability in 10 years; don’t wait |
| “2028 is a serious target” | US Government (Trump EO) | Formally funded; classified intelligence informs this view |
| “2029 is our target” | Microsoft (Majorana 2 team) | Timeline halved; topological architecture is the path |
They are not disagreeing about whether quantum computers will eventually be powerful enough. Everyone agrees they will. They are disagreeing about when — and therefore how urgently the Bitcoin community needs to act.
Part 5: What Should a Regular Bitcoin Holder Actually Do?
Right now: nothing urgent. No quantum computer can touch your Bitcoin today. If your coins are in a hardware wallet, a reputable exchange, or a modern address format, you are not at risk from a quantum attack in 2026.
In the medium term: pay attention to two things.
- Where your Bitcoin lives. The most vulnerable coins are in old-style addresses that have been used to send Bitcoin — because sending reveals your public key. If you have Bitcoin sitting in an address that has never sent a transaction, your public key has never been exposed, and you are significantly less vulnerable. If you have coins in a “reused” address — one that has sent and received multiple times — those public keys are already on the blockchain permanently.
- Whether Bitcoin upgrades. The fix is being built. A proposal called BIP 360 would make Bitcoin’s address format quantum-resistant. It’s already running on a test network. Three US government cryptography standards for the post-quantum era were finalized in 2024. The upgrade path exists. The question is whether the Bitcoin community activates it fast enough.
The honest bottom line: You don’t need to sell your Bitcoin because of quantum computing. You don’t need to move it today. But you should understand that roughly a third of all Bitcoin — possibly including yours, depending on your address history — is sitting in a position where a future quantum computer could theoretically threaten it. The preparation is happening. Whether it happens fast enough is the question that keeps the cryptographers up at night.


