Key Highlights:
- Recent quantum-computing advances do not yet demonstrate a clear, linear path to a cryptographically relevant quantum computer (CRQC).
- Neutral-atom devices are among the more promising developments, but it remains too early to know whether any current technology can reach the required scale and stability.
- Bitcoin developers should continue pursuing post-quantum cryptographic upgrades despite the absence of an imminent quantum attack.
Why Recent Quantum Advances Have Not Changed Bitcoin’s Risk Profile
Recent developments in quantum computing have generated significant attention, but they do not yet establish a practical path toward a cryptographically relevant quantum computer (CRQC). Many newly published results are advances in pure mathematics rather than demonstrations of usable quantum hardware. A recent Google paper, for example, reported a result significant enough that the company chose to redact its theoretical quantum circuit rather than risk its use against important cryptographic systems. However, the existence of that circuit does not mean a machine capable of running it currently exists.
Quantum hardware still lacks the stability and scale required for such systems. Until the technology experiences what the source describes as its “Falcon 9 moment,” there is no device that comes close to implementing the redacted circuit. The argument is that concealing a circuit designed for a machine that may never exist creates the appearance of major progress without changing the immediate technological reality.
Hardware progress also needs to be evaluated carefully. New results and technical developments appear every year, but they may involve different quantum-computing approaches, or represent a restart after an earlier candidate technology reached a dead end. Rather than forming a linear progression toward a working CRQC, these efforts may amount to a breadth-first search across an extremely large possibility space. Researchers are attempting to identify a viable route and advance along it without encountering another fundamental obstacle.
The Uncertain Path Toward a Cryptographically Relevant Quantum Computer
The future of quantum computing remains unclear. There are promising technological developments, particularly in neutral-atom devices, but it is too early to determine whether any currently known approach can ultimately produce a CRQC. A stronger basis for confidence would require repeated iterations of the same candidate technology, with each generation producing more capable machines and meaningful computational results that cannot also be achieved by a precocious child.
There are at least two broad explanations for the repeated failure to develop a CRQC over several decades. Quantum computing may simply be an exceptionally difficult scientific and engineering problem that researchers will eventually solve through continued ingenuity. Alternatively, a CRQC may be impossible or permanently beyond practical reach.
Why the Theory Remains Unresolved
A CRQC would need to represent, within its quantum superposition, a field of possibilities comparable to the complexity of the cryptographic problem it is intended to solve. To break the 128-bit security of the elliptic-curve discrete logarithm problem on Bitcoin’s secp256k1 curve, the relevant quantum superposition would need to represent all possible values of a 128-bit number.
In classical computing, representing all those values would require vastly more storage than humanity has ever produced. The source also raises two unresolved possibilities: the quantum superposition may have even a slight degree of granularity rather than being perfectly continuous across every possible value, or the energy required to maintain a superposition may scale with the complexity of the field being represented. Either condition could prevent a quantum computer from ever becoming cryptographically relevant. Current understanding of quantum physics does not rule out either possibility.
Bitcoin’s Cryptographic Development Must Continue
Uncertainty about the feasibility or timing of a quantum attack does not justify stopping Bitcoin’s work on new cryptographic algorithms. A quantum attack on Bitcoin’s cryptography is not imminent by any means, but other vulnerabilities could emerge through unrelated research. Certain elliptic curves have already been found to have weaknesses, and secp256k1 could potentially face a similar discovery.
Bitcoin’s resilience has historically improved as attacks expose weaknesses and prompt defensive development. That process is expected to continue as concerns about quantum computing evolve. Work on P2MR, P2TRv2, SHRINCS, SPHINCS, IBC, ML-DSA, and other post-quantum signature schemes could strengthen Bitcoin against future threats, regardless of whether researchers eventually build an operational CRQC.
Why This Matters
The debate over quantum computing and Bitcoin is not limited to whether a quantum attack is close. It also concerns how Bitcoin should prepare for uncertain technological risks while preserving the network’s long-term security. Current research has not shown a practical CRQC, and the route from experimental quantum systems to cryptographically meaningful hardware remains unproven. Nevertheless, continued development of post-quantum signatures gives Bitcoin a way to improve its resilience before a specific threat becomes urgent.
This analysis appears in the latest print edition of Bitcoin Magazine, The Quantum Issue. The online post, The Quantum Issue: Quantum Isn’t Coming For Your Bitcoin, was written by Brandon Black and presents an early look at ideas explored throughout the full issue.
Frequently Asked Questions
Is a quantum attack on Bitcoin imminent?
No. The source states that a quantum attack on Bitcoin’s cryptography is not imminent. Current quantum hardware does not have the stability or scale needed to run the theoretical circuits associated with such an attack.
Which quantum-computing technology appears most promising?
Neutral-atom devices are identified as a particularly promising area. However, it remains too early to determine whether neutral-atom technology or any other current approach can eventually produce a CRQC.
Why should Bitcoin pursue post-quantum cryptography now?
Bitcoin should continue developing post-quantum signature schemes because vulnerabilities may be discovered through means unrelated to quantum computing. Projects and proposals including P2MR, P2TRv2, SHRINCS, SPHINCS, IBC, and ML-DSA could improve Bitcoin’s resilience against future attacks.




