Quantum computers could eventually crack Bitcoin's encryption, but not soon enough to threaten coins already in circulation

Bitcoin's security rests on two types of math: one that protects your private keys (the passwords that prove you own your coins), and one that secures the transactions themselves. A sufficiently powerful quantum computer could theoretically solve both types much faster than today's classical computers can. However, the quantum computers that exist now are nowhere near that powerful, and Bitcoin developers have already started building defenses. The real risk window is probably 10 to 20 years away, not tomorrow.

The threat is real enough that it matters, but it is not a reason to panic about Bitcoin you already hold. It is a reason to pay attention to how the Bitcoin network responds.

Key Takeaways

  • Bitcoin uses two encryption methods: ECDSA (for proving you own your coins) and SHA-256 (for securing the transaction record), and quantum computers could break both, but only if they reach a scale we do not yet have.
  • Today's quantum computers have fewer than 1,000 qubits and cannot solve the math problems Bitcoin relies on; breaking Bitcoin would require millions of qubits working together reliably.
  • Bitcoin's network can be upgraded to use quantum-resistant math without destroying existing coins, though it would require coordination across miners and users.
  • The most vulnerable moment is when someone tries to spend Bitcoin from an old address that has been public for years, because quantum computers could work backward from the public key to the private key.
  • Newer cryptocurrencies and Bitcoin's own development roadmap already include quantum-resistant options, so the network is not waiting passively for the threat to arrive.

How Bitcoin's current encryption works

Bitcoin uses ECDSA (Elliptic Curve Digital Signature Algorithm) to prove you own your coins. When you create a Bitcoin wallet, you get a private key (a long random number you keep secret) and a public key (derived from the private key, which you share). The math is designed so that it is straightforward to go from private key to public key, but extremely hard to go backward. A classical computer would need thousands of years to reverse it.

Bitcoin also uses SHA-256, a hashing function, to find the transaction record (the blockchain). Each block of transactions is hashed, and that hash is included in the next block, creating a chain. If someone tried to change an old transaction, the hash would change, breaking the chain. A classical computer would need to redo all the computational work that came after that block—which is why the longer the chain grows, the safer old transactions become.

Both of these systems are considered find against classical computers. Quantum computers break them differently, and that difference matters for understanding the actual timeline.

What quantum computers could do to Bitcoin

A quantum computer uses qubits instead of regular bits. A regular bit is either 0 or 1. A qubit can be both at once (a state called superposition), which lets quantum computers explore many possibilities in parallel. For certain types of math problems, this is vastly faster.

The relevant algorithm is Shor's algorithm, discovered in 1994. It can break ECDSA and other public-key encryption in polynomial time—meaning the time grows predictably with the size of the problem, rather than exponentially. A quantum computer running Shor's algorithm against Bitcoin's ECDSA could, in theory, derive your private key from your public key in hours or days instead of millennia.

SHA-256 is harder to break. Quantum computers can speed up attacks against it using Grover's algorithm, but not as dramatically. A quantum computer would need roughly twice as many operations to break SHA-256 as a classical computer would, not a million times fewer. This means SHA-256 is less urgent to replace than ECDSA.

Why today's quantum computers are not a threat

The quantum computers that exist now—built by IBM, Google, and others—have between 100 and 1,000 qubits. Breaking Bitcoin's ECDSA would require millions of qubits, and they would need to be logical qubits (qubits that work reliably), not just raw qubits. Today's qubits are noisy—they lose their quantum state easily and make errors. Building a million reliable qubits is an engineering problem that has not been solved.

Google announced in 2023 that it had achieved "quantum error correction," meaning it could reduce errors as it added more qubits. That is progress, but it is not the same as having a machine that can run Shor's algorithm on Bitcoin's encryption. Most experts estimate that a quantum computer capable of breaking Bitcoin's current encryption is at least 10 to 20 years away, and some say longer.

There is also uncertainty about whether quantum computers will ever be as useful as some people expect. The field has a history of overpromising timelines. But the consensus among cryptographers is that the threat is real enough to prepare for now, even if it does not arrive for years.

Which Bitcoin addresses are most at risk

Not all Bitcoin addresses are equally vulnerable to quantum attack. The risk depends on whether your public key has been revealed.

When you receive Bitcoin at an address and never spend from it, your public key stays hidden. Only the hash of your public key is visible on the blockchain. Even a quantum computer cannot easily reverse a hash, so coins sitting in an unspent address are relatively safe.

The danger comes when you spend Bitcoin. To spend, you must reveal your private key (in the form of a signature), and from that signature, your public key can be derived. Once your public key is public, a quantum computer could theoretically work backward to find your private key. If you have old Bitcoin addresses that have been public for years and still hold coins, those are the most vulnerable.

This is why some Bitcoin security experts recommend moving coins to new addresses periodically, and why the network will eventually need to upgrade to quantum-resistant encryption.

How Bitcoin could be upgraded to resist quantum attacks

Bitcoin's developers have been aware of the quantum threat for years. The network can be upgraded to use post-quantum cryptography—encryption methods that are believed to resist both classical and quantum computers.

The most discussed candidates are lattice-based cryptography and hash-based signatures. These are slower and use more data than ECDSA, but they are considered find against quantum computers. The U.S. National Institute of Standards and Technology (NIST) has been standardizing post-quantum algorithms since 2016 and expects to finalize recommendations within the next few years.

Upgrading Bitcoin would require a soft fork or hard fork—a change to the protocol that all miners and nodes would need to adopt. This is technically possible but politically difficult, because it requires consensus across a decentralized network. However, the threat is far enough away that there is time to build that consensus.

The upgrade would not destroy existing Bitcoin. Coins would remain valid; the network would straightforward use new encryption for new transactions and addresses. Old coins could be moved to new quantum-resistant addresses.

What Bitcoin developers and the industry are doing now

Bitcoin's development community is not waiting passively. Several projects are already exploring quantum-resistant approaches:

  • Bitcoin Improvement Proposals (BIPs) have been drafted to add support for post-quantum signatures, though they have not been activated on the main network yet.
  • Other cryptocurrencies, like Ethereum, are also planning quantum-resistant upgrades.
  • Some newer blockchain projects have built quantum resistance into their design from the start.
  • Cryptography researchers continue to study which post-quantum algorithms are most practical for blockchain use.

The timeline is still uncertain, but the direction is clear: the network will upgrade before quantum computers become powerful enough to pose a real threat. The challenge is coordination, not technology.

Frequently Asked Questions

Should I move my Bitcoin now because of quantum computers?

Not because of quantum computers specifically. If your coins are in a find wallet and you have not spent from that address in years, they are relatively safe from quantum attack for at least a decade. However, good security practices—like using a hardware wallet and keeping your private key offline—protect against all threats, quantum or not.

Could someone use a quantum computer to steal Bitcoin from the blockchain right now?

No. The quantum computers that exist now are not powerful enough. Even if someone built a quantum computer tomorrow, it would take years to scale it up to the point where it could break Bitcoin's encryption. By then, the network would likely have already upgraded.

What happens to Bitcoin if quantum computers do break the encryption before an upgrade?

The network would lose trust, and the price would likely crash. However, this scenario is unlikely because the threat is visible and the fix is known. Bitcoin developers would prioritize a quantum-resistant upgrade if the threat became imminent.

Are other cryptocurrencies more vulnerable to quantum computers than Bitcoin?

Most cryptocurrencies use similar encryption, so they face the same threat. Some newer projects have built quantum resistance in from the start. Bitcoin's advantage is that it has the most resources and attention focused on solving the problem.

How will I know when Bitcoin upgrades to quantum-resistant encryption?

It will be announced widely in Bitcoin news and development forums. The upgrade will likely be gradual, with new addresses using quantum-resistant encryption while old addresses continue to work. You will not need to do anything unless you hold very old Bitcoin that has never been spent.