Quantum Isn't Coming for Your Bitcoin, and the Math Backs That Up
Bitcoin Magazine's Brandon Black argues a viable quantum computer might never get built at all. Looking at the actual physics and error-correction overhead, the panic looks overstated, though the industry's upgrade timeline is a genuine weak spot.
I've been reading quantum panic for the better part of a decade. Every few months, someone posts a qubit count chart, draws an exponential curve through it, and declares Bitcoin dead by 2030. So when Brandon Black's piece in Bitcoin Magazine landed in my feed arguing that a viable quantum computer might never get built at all, I paid attention.
It's a contrarian take, and admittedly one that runs against the hype cycle. But the details hold up better than the fear does.
The Engineering Wall
Here's the mechanics most coverage skips. Breaking Bitcoin's elliptic curve signatures, secp256k1, requires Shor's algorithm, and Shor's needs thousands of error-corrected logical qubits. Those logical qubits get built from physical ones, and the overhead is brutal. Depending on error rates, you might need a thousand physical qubits to produce one reliable logical qubit.
Google's Willow chip, the December 2024 headline-maker, has 105 qubits. IBM's roadmap points to 100,000 by 2033. Researchers at Google estimated in 2024 that factoring RSA-2048 would take roughly 20 million physical qubits running for eight hours. That's the ballpark we're actually talking about.
And the wiring problem is real. Every qubit needs control lines running into a dilution refrigerator held at about 15 millikelvin, colder than deep space. A million-qubit machine means a million wires into a very cold box. Nobody has shown how to do that at scale, and that's before we get to decoherence.
Granted, error rates keep improving. Gate fidelities keep climbing. But cryptography is moving too. NIST finalized its post-quantum standards, ML-KEM and ML-DSA, back in August 2024. Bitcoin's mining is essentially safe regardless, since Grover's algorithm only offers a quadratic speedup against SHA-256, which isn't nearly enough to matter.
What This Means for the Market
The actual exposure is narrower than the headlines suggest. Roughly 1.7 million BTC sit in pay-to-public-key outputs from Bitcoin's early days, plus coins sitting on reused addresses. Those public keys are already exposed, so they're the vulnerable class. Satoshi's roughly 1.1 million coins are somewhere in that pile.
But that's a story about a machine that doesn't exist. Quantum computing stocks like IonQ and Rigetti have traded on the narrative for years, and the harvest-now-decrypt-later thesis makes sense for long-lived government secrets. It makes less sense for Bitcoin, where a stolen coin has to move on-chain in front of the entire world.
To be fair, the market isn't dumb here. Quantum names get bid up on breakthroughs and sold off on delays, and the same reflex shows up around Bitcoin every time a new paper drops. The narrative moves faster than the physics, always has.
My Honest Read
I'm not entirely convinced by either extreme. The skeptics who say quantum can't scale have a track record of being wrong about computing generally. The proponents who say Bitcoin dies in five years have a track record of selling something.
The question worth asking: if a credible threat showed up tomorrow, could Bitcoin upgrade in time? History suggests otherwise. Taproot took years of argument. A post-quantum signature migration would be harder, because it touches every wallet, every hardware device, and every custodian on earth.
So don't sell. But do watch error-corrected logical qubit counts, not raw qubit marketing numbers. That's the metric that matters, and it's the one I'll be tracking.
Related Articles
Explore More
Key Terms Explained
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
A price decline of 10% or more from a recent high, but less than the 20% that defines a bear market.
Using computational power to validate transactions and create new blocks on proof-of-work blockchains.
Transactions and data recorded directly on the blockchain.