Blog/Explainer/Can a quantum computer break Bitcoin?
Explainer

Can a quantum computer break Bitcoin?

Quip Network
Quip Network
Postquant Labs
August 26, 2026·2 min read

Every few months a quantum computing headline sends this question around again, and the answers on offer run from "tomorrow, sell everything" to "never, ignore it." The accurate answer is more specific than either, and it turns on which part of Bitcoin you mean.

The short version

No quantum computer that exists today can break Bitcoin or Ethereum. The machine that could is being built in public, by teams at Google, IBM, IonQ and Quantinuum. What it threatens is narrower than most coverage suggests: it breaks the keys that prove ownership, and leaves the mining that secures the network intact.

What a quantum computer breaks in Bitcoin

And what it leaves untouched

Safe

Mining and hashes

SHA-256, proof of work

  • Grover's algorithm only halves hash security
  • SHA-256 stays near 128-bit
  • The network keeps mining
At risk

Signatures and keys

ECDSA, coin ownership

  • Shor's algorithm breaks elliptic-curve keys outright
  • Exposed public keys can have their funds taken
  • Millions of addresses already expose one

The exposure is the keys, not the mining. The machine that does it is gate-model, not an annealer.

What's actually at risk

Bitcoin and Ethereum rely on two different kinds of cryptography, and quantum computers affect them very differently.

Mining and hashes hold. Proof-of-work runs on SHA-256 hashing. The best known quantum attack, Grover's algorithm, only cuts hash security roughly in half, which still leaves it far beyond practical attack. Nobody's quantum computer is going to out-mine the network.

Signatures and keys are the real exposure. Ownership of coins is proven with elliptic curve signatures. Shor's algorithm, running on a large enough quantum computer, breaks elliptic curve cryptography outright. Once such a machine exists, any address whose public key is visible on-chain can have its private key derived and its funds taken. Millions of addresses, including Satoshi-era coins, already have exposed public keys.

What kind of machine, and when

Two kinds of quantum computer exist, and only one of them is a cryptographic threat.

Annealers, like D-Wave's machines, solve optimization problems. They are real, commercially available, and genuinely useful for logistics, scheduling, and finance. They cannot run Shor's algorithm. An annealer will never break a key.

Gate-model machines, the kind Google and IBM build, are the cryptographic threat. Today's largest are hundreds to a few thousand noisy qubits; breaking elliptic curve keys needs thousands of error-corrected logical qubits. Current estimates put that machine somewhere in the next five to fifteen years. NIST considered the threat real enough to finalize post-quantum cryptography standards in 2024 and direct US agencies to migrate.

The subtler problem is called "harvest now, decrypt later": an attacker records encrypted data or exposed keys today and waits for the machine. For long-lived assets, the threat date is earlier than the machine date.

Richard Carback, co-founder and CTO of Postquant Labs, on quantum attacks.Zcash Blockspäti · Berlin

What you can actually do

The defense is post-quantum signatures: schemes built on hash functions rather than elliptic curves, which survive both classical and quantum attack. NIST standardized them in FIPS 205. The migration challenge for crypto is that existing chains can't swap their signature scheme overnight.

That is the problem Quip Network works on: quantum-resistant accounts that wrap assets on Bitcoin, Solana, Ethereum, and other EVM chains you already use, so funds are protected by a post-quantum signature today without migrating to a new network. While funds are inside, even a quantum breakthrough against the underlying chain doesn't expose them.

If you want a running clock on the research milestones between here and the machine that matters, we maintain one at quantumdoomclock.com.

Share
Filed underExplainer
Newsletter

Don't miss an update

Get new posts and project updates delivered to your inbox. No spam, unsubscribe anytime.