Shelf 1 · Computing Foundations · 4 / 45
Can Quantum Computers Break Bitcoin? Qubits, Error Correction, and Cryptographic Migration
A primary-source guide to qubits, Shor and Grover, error correction, Bitcoin signatures and SHA-256, public-key exposure, and draft BIP 360.
Check this article’s sources (13)Article brief
A quantum computer is not a universal machine that reveals every answer at once. Yet its advantage on particular algorithms is reason enough to start planning Bitcoin’s cryptographic migration now.
A useful mental model
Think of a specialist laboratory rather than a super-factory: classical computers prepare a suitable problem, a fragile quantum device performs one narrow stage, and the classical side checks the result.
Where the analogy stops
The analogy describes only the division of labor. Useful capability depends on logical qubits, error correction, gate fidelity, and circuit depth, and published experiments and resource estimates are not demonstrations of a practical Bitcoin attack.
Article structure
You will separate Shor from Grover, signatures from hashes, and research results from unactivated proposals, without inventing a date to fear.
Open the glossaryArticle contents13 chaptersJump to a chapter
1The 30-second answer: what is possible, and what is not yet
| Question | What the evidence supports today |
|---|---|
| Is a quantum computer a better CPU or GPU? | No. It can give particular algorithms an advantage, and it works alongside classical systems |
| Which part of Bitcoin is the main concern? | Recovering a private key from a signature public key that has been exposed |
| Does mining break overnight? | Grover’s square-root advantage is not the same thing as acquiring hash rate on Bitcoin’s scale |
| Can any public machine do the attack today? | There is no public demonstration. The published requirements are resource estimates that depend on assumptions |
| Is the remedy settled? | NIST standards and Bitcoin drafts exist, but none of them is an activated Bitcoin migration |
The answer is neither “harmless” nor “Bitcoin breaks tomorrow.” Cryptographic migration needs long preparation, and no evidence-based countdown to a practical attack exists.
2A quantum computer is not just a faster CPU
A classical computer executes instructions over bits that are either 0 or 1. A quantum computer applies gates to qubit states, uses interference to amplify the outcomes it wants, and finally measures a single classical result. It cannot read off every branch of some imagined infinite parallel computation: the algorithm has to arrange the interference so that useful information survives the measurement.
Browsers, databases, operating systems, and branch-heavy business logic do not all get faster by being “quantized.” State preparation, error correction, measurement, and checking the result stay classical work. Even a useful quantum system is better understood as a co-processor for narrow subroutines than as a replacement for CPUs and GPUs.
3Qubits, superposition, interference, and measurement
Before measurement, a qubit can carry amplitudes associated with 0 and with 1; measurement returns one classical result. The algorithm’s job is to strengthen the amplitudes that correspond to answers and cancel the rest. “Trying both at once” on its own gives you no way to read out every candidate answer.
Quantum states are fragile. Gates, waiting, and readout all introduce error. A raw qubit count therefore does not measure useful capability by itself: connectivity, gate fidelity, measurement, error correction, and circuit depth have to be read together.
4From physical qubits to logical qubits
A physical qubit is a piece of hardware. A logical qubit combines many physical qubits with repeated measurements to detect and correct errors, giving algorithms a more stable unit to work with. What a cryptographic discussion needs is enough logical qubits, and logical gates reliable enough, to run a long circuit, not simply a large raw device count.
A 2024 Nature paper led by Google Quantum AI demonstrated below-threshold surface-code behavior: larger codes reduced logical error. That is important progress, but it was not a demonstration of large-scale cryptographic key recovery. Experiments, resource estimates, corporate roadmaps, and systems capable of an attack are different stages of evidence.
5Shor and Grover: two effects that should not be merged
Given a large enough fault-tolerant quantum computer, Shor’s algorithm solves integer factoring and discrete logarithms in polynomial time. For Bitcoin’s secp256k1 public-key signatures, that opens a path from an exposed public key to its private key. It applies both to ECDSA and to the BIP 340 Schnorr signature used by Taproot.
Grover’s algorithm gives a square-root speed-up for unstructured search in an idealized query model. It applies to searching SHA-256, but real proof of work also involves reversible circuits, error correction, clock rate, parallelism, power, and competition with classical ASICs. “A 256-bit search becomes 128-bit in the query model” is not the same claim as “a quantum miner instantly gains majority hash power.”
6Separate Bitcoin’s two cryptographic surfaces
| Surface | Current role | Quantum question |
|---|---|---|
| secp256k1 signatures | ECDSA and BIP 340 Schnorr authorize spending | Shor key recovery from a public key |
| SHA-256-family hashes | Proof of work in the block header, identifiers, and commitments | Grover square-root search, in the idealized model |
If a private key is recovered, an attacker can produce a signature that ordinary node validation accepts. An advantage in hash search, by contrast, runs into network competition and difficulty adjustment. Collapsing the two into “cryptography breaks” hides both the priority and the remedy.
7When does a Bitcoin public key become exposed?
| Output or information | How the public key becomes exposed |
|---|---|
| P2PK / P2MS | A public key sits in the output from the moment it is created |
| P2TR | BIP 341 puts an x-only tweaked public key in the output from the moment it is created |
| P2PKH / P2WPKH | Normally only a public-key hash appears. Spending exposes the key briefly; reusing that exposed key for the remaining outputs can expose it for a long time |
| P2SH / P2WSH | A script can stay behind a hash; the script and branch revealed at spending decide whether keys are exposed, and for how long |
| xpub / descriptor | Disclosure off-chain can still reveal child public keys that others can derive |
“Never spent means safe” is therefore not a general rule. Both the output type and off-chain wallet information matter. Keys hidden behind a hash also appear in the mempool, in the normal case, once the output is spent.
8Long- and short-exposure attacks
A long-exposure attack targets a public key that has been visible for a long time, with no need to race a confirmation. P2PK, P2TR, address reuse, and leaked extended public keys can all create that condition.
A short-exposure attack tries to recover the key in the window after an ordinary spend reveals it in the mempool and before the transaction confirms, then to publish a conflicting spend. It needs a faster machine, and no amount of wallet hygiene removes it. Keeping the two models apart is what stops us from mistaking hash-based key hiding for a complete post-quantum signature scheme.
9Can AI or quantum computers break “Satoshi’s wallet”?
The short answer is that no evidence shows current AI, or any publicly demonstrated quantum computer, can spend the coins attributed to Satoshi Nakamoto. That is not a reason to say it is mathematically impossible forever. Nor is there one confirmed “Satoshi wallet.” The widely cited figure of roughly 1.1 million BTC is an analytical estimate that clusters many early coinbase outputs under a miner labeled Patoshi. Neither the identification of Patoshi as Satoshi nor a complete set of Satoshi-controlled keys has been proved cryptographically.
| Method | What the evidence supports today |
|---|---|
| Classical computing assisted by AI | No published algorithmic shortcut makes practical recovery of a secp256k1 private key from a public key possible. AI can still sharpen phishing, malware, the discovery of weak randomness, implementation exploits, and side-channel attacks |
| Publicly demonstrated quantum computers | No public demonstration has recovered a Bitcoin-sized 256-bit secp256k1 key |
| A future fault-tolerant quantum computer of sufficient size | In principle, Shor’s algorithm opens a path from an exposed public key to its private key |
| Bitcoin migration | Proposals exist, but BIPs 360 and 361 remain Draft and no post-quantum signature migration is activated |
AI and quantum computation have to be kept apart. AI can improve the search for, and the automation of, known techniques, but AI itself supplies no new complexity-theoretic shortcut for the elliptic-curve discrete-logarithm problem. The nearer-term risk is more likely to fall on people, wallet software, randomness, implementations, or key storage than on the underlying mathematics. That is a different statement from the sweeping claim that AI can therefore break cryptography.
Early mining rewards used P2PK, which places the public key directly in the output. Draft BIP 360 lists P2PK as vulnerable to long-exposure attacks and gives coins attributed to Satoshi as an example. An attacker would not have to race a new mempool transaction, because the public key has been visible on-chain for years already. Whether any particular early output really belonged to Satoshi is a separate question of attribution.
This is not necessarily a “wallet hack” in the ordinary sense of breaking into a wallet file. If a sufficiently capable quantum computer derived the private key from the exposed public key, it could produce a signature that the protocol treats as valid. Ordinary nodes could not tell that signature apart from one made by the original owner: the attack reconstructs a key that satisfies the UTXO’s spending condition.
A peer-reviewed paper published in PRX Quantum on 21 August 2026 gives two logical-circuit resource estimates for secp256k1 key recovery: at most 1,200 logical qubits and 90 million Toffoli gates, or at most 1,450 logical qubits and 70 million Toffoli gates. The paper separately converts those logical resources into physical-qubit counts and runtimes, under assumptions about physical error rates, connectivity, clock speed, and other engineering details. Neither layer is evidence that such a machine exists today, and neither is a forecast of when one will be built. A logical circuit, error-corrected hardware, and an operational attack capability are different stages of evidence.
Draft BIP 360 would help future outputs avoid long-lived public-key exposure, but it does not automatically protect existing P2PK coins, and it does not solve short exposure in the mempool. BIP 361 discusses migration and a sunset for legacy ECDSA and Schnorr signatures, but its status is Draft, its type is Informational, and it still depends on a post-quantum signature BIP that is marked TBD.
The defensible answer is therefore this: there is no evidence the coins can be broken today, but exposed P2PK outputs attributed to Satoshi cannot be guaranteed safe forever. It is also a question of Bitcoin governance, namely whether dormant vulnerable coins should be migrated, frozen, or left spendable by whoever can eventually reconstruct their keys.
10NIST post-quantum standards are not adopted Bitcoin rules
In 2024 NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). ML-KEM is a key-encapsulation mechanism for establishing a shared secret, so it is not a direct candidate for signing Bitcoin transactions. ML-DSA and SLH-DSA are digital-signature standards.
A standard existing does not make it part of Bitcoin consensus. Signature and public-key sizes, validation cost, block weight, hardware wallets, backups, addresses, migration of existing UTXOs, compatibility, and activation all have to be evaluated and agreed on. “Post-quantum” means designed around assumptions that known quantum algorithms do not break; it does not mean secure forever.
11What draft BIP 360 proposes, and what it does not
As of 24 August 2026, BIP 360 remains Draft. Pay-to-Merkle-Root (P2MR) would add a new output type by soft fork. It keeps a Taproot-like script tree but removes the quantum-vulnerable key-path spend, with the aim of keeping a long-lived public key out of the output.
P2MR is not itself a post-quantum signature, and it does not solve the short-exposure problem in the mempool. BIP 360 notes explicitly that post-quantum signatures may be required later. BIP 361 is also a Draft, discussing migration and the sunset of legacy signatures; neither proposal has a settled activation date or an adopted signature scheme.
12Migration is an implementation problem and a consensus problem
Even if new signatures can be implemented, Bitcoin has to decide who moves and when, how long old outputs stay valid, and how owners are reached. Coins with lost keys, no owner, or long exposure pose a governance problem: leave them spendable by a future attacker, or disable legacy spending and freeze coins that may still have legitimate owners.
Waiting lengthens the exposure; forcing migration too early can strand wallets, custodians, and users. What is needed is not one date to fear but monitoring of the research, crypto-agility, tests, staged wallet support, and transparent activation. This site does not forecast the year of a practical attack.
13Editorial perspective: quantum as a narrow collaborator, not a replacement
This section is our interpretation, not a reported fact. If practical QPUs do arrive, we expect them to behave less like universal replacements for CPUs, GPUs, and storage and more like co-processors: a classical system prepares a problem that suits them, the QPU runs a narrow algorithm, and the classical side verifies the result.
For Bitcoin, predicting a “quantum completion year” matters less than building a cryptographic migration that can be inspected across drafts, implementations, wallets, and consensus before the pressure arrives. That is a scenario inferred from current error-correction research and from the structure of migration; it is not a forecast that any BIP will activate, or that a QPU will arrive on a particular date.
Primary sources
- Peter Shor — Algorithms for Quantum Computation (original paper)
- Lov Grover — A Fast Quantum Mechanical Algorithm for Database Search (original paper)
- PRX Quantum 7, 031001 — Securing elliptic curve cryptocurrencies against quantum vulnerabilities (21 August 2026)
- Nature — Quantum error correction below the surface-code threshold
- NIST — FIPS 203 ML-KEM (Final)
- NIST — FIPS 204 ML-DSA (Final)
- NIST — FIPS 205 SLH-DSA (Final)
- BIP 340 — secp256k1 Schnorr Signatures
- BIP 341 — Taproot
- BIP 360 — Pay-to-Merkle-Root (Draft)
- BIP 361 — Post Quantum Migration and Legacy Signature Sunset (Draft)
- Sergio Demian Lerner — Early-block ExtraNonce and unspent-output analysis (2013)
- Sergio Demian Lerner — Patoshi-pattern reanalysis (2019)
Read next
The Future of Computing and Intelligence: 2031, 2036, and an Agentic Society13 min readRelated topics
Go deeper
Citation
- Title
- Can Quantum Computers Break Bitcoin? Qubits, Error Correction, and Cryptographic Migration
- Source
- Bitcoin Library (bitcoin.ne.jp)
- Canonical URL
- https://bitcoin.ne.jp/en/learn/quantum-computing
- Author
- KK siiiiiixth
- Topic
- quantum-computing
- Published
- Updated
- Last verified
- Editorial policy
- https://bitcoin.ne.jp/en/editorial-policy
- About
- https://bitcoin.ne.jp/en/about
- License
- Content reuse terms
Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.
Revision history
- Added a careful treatment of the plural, heuristically attributed outputs behind “Satoshi’s wallet”; separated AI-assisted classical attacks from cryptanalytic shortcuts; explained early P2PK long exposure and the conditions for future Shor key recovery; and kept draft BIPs 360 and 361 within their unactivated scope. Updated the elliptic-curve key-recovery resource estimate to the peer-reviewed PRX Quantum paper published on 21 August 2026.