BTC—ETH—SOL—XRP—BNB—ADA—DOGE—TRX—LINK—AVAX—DOT—LTC—
Live

Can quantum computers break Bitcoin? What the research shows

A quantum computer could in theory pull a Bitcoin private key from its public key, but the hardware is nowhere close. Breaking one key in a day would take an estimated 13 million qubits. The best public chip has 105. Here is the real risk and the real timeline.

By Zain

Published · 7 min read

No. Not today, and not for years. A quantum computer could in theory pull a Bitcoin private key out of its matching public key, but the machine that could do it does not exist yet. The best public chip has 105 qubits. An attack would need millions.

That gap is the whole story. This guide walks through what quantum computers could attack, how far the hardware really is, which coins are most at risk, and what Bitcoin can do about it. The science is public and the numbers are specific, so you can judge the threat for yourself.

How Bitcoin uses cryptography

Bitcoin leans on two kinds of math. One signs transactions. The other secures mining and links the blocks together.

Every payment is signed with a method called ECDSA, run over a curve named secp256k1. Your private key makes the signature. Your public key lets the network check it. The key is 256 bits long, a number 78 digits across. Guessing it with normal computers is not possible before the sun burns out.

Mining uses a different tool, a hash function called SHA-256. It turns any data into a fixed string that cannot be reversed. Miners race to find an input whose hash lands below a target, the work described in what Bitcoin miners actually do.

These two pieces matter in different ways to a quantum attacker. One is exposed. One is mostly safe.

What a quantum computer could actually attack

Here is the part that worries people. A big enough quantum computer running Shor's algorithm could take a public key and work backward to the private key. That breaks the signature system. Someone who did it could move coins from any address whose public key they can see.

Mining is a softer target. The best known quantum trick against a hash function, Grover's algorithm, only speeds up the search by a square root. The practical effect is small. It would cut SHA-256's strength roughly in half, and half of 256-bit security is still far out of reach. So mining stays safe long after signatures would fall.

One detail protects most users. A modern Bitcoin address is not your public key. It is a hash of your public key. The key only becomes visible when you spend from that address. Leave coins in a fresh address you have never spent from, and a quantum attacker sees a hash, not a key. That buys time.

How far away the hardware is

Now the numbers that matter. Breaking a 256-bit elliptic curve key is thought to need around 2,000 logical qubits. Logical qubits are the clean, error-corrected kind, and each one takes many physical qubits to build. CoinShares, an asset manager that studies this, put the full job at about 13 million physical qubits to crack a key inside a day. That is roughly one hundred thousand times more than the largest machine running now.

Google's Willow chip is that largest machine, unveiled on December 9, 2024, with 105 qubits. Read that again. 105, against a need for millions. IBM, Google and others publish roadmaps that stretch into the 2030s, and most researchers place a useful code-breaking machine in that decade or later, if it arrives at all.

No one has built anything within a factor of thousands of what an attack would take. Progress is real. Willow showed error rates falling as the chip grew, a long-sought milestone. But falling error rates on 105 qubits and a working attack on 256-bit keys are different worlds.

Why exposed keys matter even now

A quantum machine does not have to exist today to matter. Public keys that are visible now can be copied and stored now, then attacked on the day a capable computer finally arrives. Cryptographers call this harvest now, decrypt later. For Bitcoin the problem is narrow but real, because it only touches keys that are already on show.

This is the strongest reason not to reuse an address. Spend from one, and its public key is public from then on. Send your change to a new address each time, as most modern wallets do by default, and each batch of coins stays behind a hash until you move it. The habit costs nothing. It also shrinks what a future machine could ever reach.

Which coins are most exposed

Focus on the coins, not the qubits. The real worry is how much old Bitcoin already shows its public key in the open.

Two kinds of coins are exposed. The first is early pay-to-public-key, or P2PK, outputs from Bitcoin's first years, when an address was literally the public key. The second is any address that has been reused, because spending from it once reveals the key. CoinShares estimates about 1.6 million BTC, near 8 percent of all coins ever mined, sit with public keys on display. Project Eleven, a quantum research firm, uses a wider count and puts more than 6.2 million BTC at risk. The two groups measure different things, so the figures differ. Both point at the same soft spot.

Among those early coins are the roughly 1.1 million widely tied to Bitcoin's pseudonymous creator, Satoshi Nakamoto, which have never moved. A quantum attacker with a working machine would likely aim at exposed, high-value, long-dormant coins first. Nobody can spend them to safety, because nobody holds the keys. That is the real shape of the risk. Not every wallet at once. The oldest, most visible coins.

What is being done about it

The defense is already partly built. In August 2024, the US National Institute of Standards and Technology, known as NIST, published its first finished post-quantum encryption standards, FIPS 203, 204 and 205. Two of them cover digital signatures, the exact job Bitcoin needs protected.

"We encourage system administrators to start integrating them into their systems immediately, because full integration will take time," said Dustin Moody, a mathematician at NIST. His team added a blunt line for anyone waiting. There is no need to wait for future standards.

Bitcoin cannot just flip a switch. Adding quantum-safe signatures would need a coordinated change to the protocol, agreed by the people who run and build it, and a way for holders to move coins into new, safe address types. Developers have floated proposals to do exactly that, including plans to give owners a long window to migrate before any old, exposed coins are locked away. None has been adopted yet. The debate is live.

In the meantime, researchers are measuring the threat out loud. In April 2025, a firm called Project Eleven launched the Q-Day Prize, one bitcoin to the first team that could break an elliptic curve key with Shor's algorithm on real hardware. The test keys ran from 1 to 25 bits. Real Bitcoin keys are 256 bits. The contest, which ran to April 5, 2026, was built to track how fast that gap is closing, and the honest read so far is that it is closing slowly.

What to watch

Treat the quantum question as a slow weather front, not a storm at the door. Three things are worth tracking.

Watch the logical qubit count, not the raw one. A headline about a 1,000-qubit or 10,000-qubit chip means little if those are noisy physical qubits. The figure that matters is error-corrected logical qubits, and 2,000 of those is the real finish line.

Keep an eye on Bitcoin's own upgrade talk. If developers agree on a post-quantum signature plan, that is the signal the people closest to the code think the clock is worth beating. Moving coins out of old, exposed addresses would become the practical step for holders.

And keep the fear in proportion. A working code-breaking quantum computer would upend far more than Bitcoin. Bank transfers, secure web traffic and government records all lean on the same kind of math. If that day comes, a stolen dormant wallet may be the least of the world's problems. For a wider look at what could actually end the network, see whether Bitcoin can go to zero.

Frequently asked

Can a quantum computer steal my Bitcoin today?

No. The machine that could do it does not exist. Breaking a Bitcoin key is thought to need about 2,000 error-corrected qubits, which by one estimate means millions of physical qubits. Google's Willow chip, the largest public machine, has 105. Coins in a fresh address you have never spent from are safer still, because that address hides your public key.

Which Bitcoin is most at risk from quantum computers?

Coins whose public key is already visible. That means early pay-to-public-key outputs and any address reused after spending. CoinShares estimates about 1.6 million BTC sit this way, while Project Eleven puts the wider figure above 6.2 million. Coins held in unused modern addresses stay protected until the moment they are spent.

Does quantum computing threaten Bitcoin mining too?

Much less than it threatens signatures. Mining uses SHA-256 hashing, and the best known quantum method, Grover's algorithm, only cuts its strength by about half. Half of 256-bit security is still far beyond reach. Signatures, protected by elliptic curve keys, are the weaker point, which is why upgrade talk focuses there.

Sources, and what is behind them

  1. NIST Releases First 3 Finalized Post-Quantum Encryption Standards, National Institute of Standards and Technology (NIST) (August 13, 2024)Press report
  2. Meet Willow, our state-of-the-art quantum chip, Google (December 9, 2024)Vendor announcement
  3. Quantum computing research firm Project Eleven is offering 1 BTC to anyone who can break Bitcoin's cryptography, The Block (April 16, 2025)Press report
  4. Quantum Contest Offers 1 Bitcoin for Cracking Encryption With Shor's Algorithm, The Quantum Insider (April 18, 2025)Press report
  5. Quantum Vulnerability in Bitcoin: A Manageable Risk, CoinSharesOther