Why Quantum Is Likely To Break Bitcoin Before The Encrypted Web
Dr. Kris Naudts, Zeynep Koruturk (Founding & Managing Partners) & Donald Harmitt (Associate) at Firgun Ventures.
The most disruptive thing a quantum computer might one day do is also its best known: break the mathematics that secures almost all digital value. For three decades that prospect sat on a distant horizon, until in late March 2026 it moved. Google Quantum AI, with researchers at Stanford and the Ethereum Foundation, published a paper that announced no machine but recalibrated the target, cutting the estimated cost of breaking the encryption approach (elliptic-curve cryptography (ECC)) behind Bitcoin by roughly 20 times.
More striking still was the worked example, which modelled the theft of a Bitcoin holding whose public key is already visible and found the active phase could run in about nine minutes, inside the Bitcoin network’s ten-minute block time. That window is important because the key must fall before the next block is mined. The figure reframed a long debate, pointing somewhere unintuitive: the protocols that look safest classically are often the first to fall to a quantum one, and Bitcoin is likely to break before the encrypted web traffic most assume is the target.
Why The Vulnerability Lives In The Signature
Asymmetric cryptography, an encryption method that uses two different keys (public and private key), rests on a pair of mathematically related keys. The private key stays secret while the public one is shared freely, letting anyone verify a signature without seeing the secret behind it. Recovering the private key from the public one is, classically, hopeless. In 1994 the mathematician Peter Shor showed that a large enough quantum computer could dissolve that guarantee, deriving the private key from the public one and forging any signature built on it.
Bitcoin’s exposure sits squarely in that signing step, since transactions are authorised using the cryptographic algorithm, Elliptic Curve Digital Signature Algorithm (ECDSA), on the 256-bit curve secp256k1, to prove that the person moving the coins is authorised to do so, and once a transaction is broadcast the public key becomes visible on the blockchain, which means that address is more exposed to a future quantum attack. Project Eleven, a group tracking the threat, estimates that roughly 6.9 million Bitcoin, close to a third of supply, sit in addresses with exposed keys, including some 1.7 million coins in ancient addresses thought to be Satoshi Nakamoto’s, the pseudonymous person who developed Bitcoin.
The Inversion That Classical Intuition Gets Wrong
Today’s digital security relies heavily on two forms of public key cryptography. RSA, one of the older and best known systems, is difficult to break because it depends on the challenge of splitting a very large number into its prime factors. Elliptic curve cryptography relies on a different mathematical problem that is even harder for classical computers to attack efficiently. That is why a 256 bit elliptic curve key can offer similar protection to a much larger 3,072 bit RSA key, and why elliptic curve cryptography now protects much of the modern internet, including Bitcoin and secure web traffic.
Shor’s algorithm, the best known quantum threat to public key cryptography, does not attack these systems in the same way a classical computer would. Instead, it looks for hidden patterns in the maths behind both RSA and elliptic curve cryptography. Once that happens, the advantage of elliptic curve cryptography begins to look like a weakness. Its smaller keys, which make it efficient and attractive today, could make it cheaper to break on a sufficiently powerful quantum computer. In other words, the very feature that made elliptic curve cryptography the modern standard may also make it one of the first major security systems forced to migrate. To Shor’s algorithm the size of the lock is all that matters, and a smaller lock opens faster.
Harvest Now, Decrypt Later And The Race To Migrate
The same ordering shapes the defence, and in an uncomfortable direction. The harvest now, decrypt later (HDNL) threat, recording encrypted traffic today to decrypt once mature-enough hardware arrives, reaches elliptic-curve-protected data first: messaging apps, modern web sessions and every protocol that left RSA because the curve looked stronger. Such a machine will not be announced when it arrives, and several state programmes, China’s among them, are investing heavily and quietly.
The institutional response has quickened on more than one front. National Institutes of Standards and Technology (NIST) finalised its first post-quantum standards in 2024, and national guidance from the UK’s National Cyber Security Centre to the US National Security Agency now points to quantum-safe systems before 2035. In Bitcoin the urgency is newly visible. The BIP-360 proposal, merged in February 2026, added the network’s first quantum-resistant address type, and a companion in April set out a phased plan to migrate and freeze the millions of exposed coins. Days after the paper, Coinbase chief executive Brian Armstrong said he would lead an industry coalition, Bitcoin’s transition to quantum-resistant cryptography following research highlighting potential vulnerabilities. Ethereum is further ahead than many blockchains on post-quantum preparation. Justin Drake, an Ethereum Foundation researcher and coauthor of the Google Quantum AI whitepaper is involved in the debate, and the Ethereum Foundation has formed a dedicated post-quantum security team. Ethereum has also published a structured roadmap to replace or mitigate quantum vulnerable primitives, including ECDSA account signatures and BLS consensus signatures, with core post quantum infrastructure targeted around 2029, although this remains a planning target rather than a guaranteed retirement date. For a network whose founding promise is ownership without conditions, freezing dormant coins could pose an interesting rupture.
RSA’s Falling Cost And What The Inversion Means For Capital
The thesis carries a caveat which assumes the cost of attacking RSA does not fall faster than that of attacking the elliptic curve. That has held for six years, yet RSA estimates are dropping quickly. In February 2026 the Sydney startup Iceberg Quantum claimed RSA-2048 could be factored with fewer than 100,000 physical qubits, an order of magnitude below the prior best, by replacing the error-correcting codes behind most estimates. Today, the claim rests on simulation rather than demonstration, and so far the largest number ever factored by Shor’s algorithm on real hardware is 21.
Strip away the detail and a clean signal remains. The cryptographic asset class that looks safest, with its smaller keys and harder problem, is structurally the most exposed to quantum attack, and the timeline to fix it is tighter than conventional risk models assume. These kinds of reversals, where the market’s sense of what is safe turns out to be backwards, are often where the biggest opportunities appear. As post quantum standards move from policy papers into procurement decisions, security budgets, and infrastructure upgrades, the winners is likely to be those that help institutions move valuable digital assets onto quantum resistant foundations before the risk becomes impossible to ignore.
Insights

