In brief

  • A quantum computer could someday derive private keys from exposed public keys and drain Bitcoin wallets—the hypothetical "Q-Day"—though no such machine exists and timelines vary widely.
  • Fixes fall into three buckets, all in the news this week: quantum-safe transactions under current rules, protocol upgrades like a soft fork, and custody-layer defenses.
  • Nothing shipped this week makes Bitcoin quantum-safe on its own; the field is driving down defense costs while measuring how fast the threat is closing.

Every few months, a fresh headline warns that quantum computers could one day crack Bitcoin. This week brought three at once—a cost breakthrough, a new privacy design, and a custody playbook—which makes it a good moment to separate the real threat from the noise.

First, the problem—and it’s a very real one. Bitcoin secures wallets using elliptic-curve cryptography, the math that links a private key to a public one. A sufficiently powerful quantum computer running Shor's algorithm could, in theory, derive a private key from an exposed public key, forge a signature and drain the wallet.

Myriad: How high will Bitcoin go? Click to make your prediction.
Myriad: How high will Bitcoin go? Click to make your prediction.

The industry calls the hypothetical arrival of such a machine "Q-Day." No such computer exists today, and estimates for when one might range widely—but the timelines keep compressing, which is why preparation has accelerated.

The fixes fall into three buckets, and this week produced news on each.

The first is making quantum-resistant transactions work under Bitcoin's current rules. StarkWare, which mined the first quantum-safe Bitcoin transaction on mainnet last month, said an open competition—with AI models topping the leaderboards—cut the estimated cost of building one from about $320 to roughly $67 in a single week.

That's only a workaround, by the company’s own admission. The transactions are nonstandard and only protect coins whose public key hasn't already been exposed. StarkWare still considers a soft fork the better long-term answer.

BitcoinBTC · USD
$84,458+4.08%
Sep 20Sep 22Sep 24Sep 25Sep 27
$87.2k$85.1k$83.0k$80.9k
24h HighHigh$85,089
24h LowLow$83,835
VolVol$882.0M
→
Buy Bitcoin with USDT
Powered by Jupiter
Price data by CoinGeckoCoinGeckoMore Bitcoin news and projections →

The second is the protocol-upgrade path—changing Bitcoin itself to adopt post-quantum signatures. That's the durable fix, but Bitcoin's decentralized governance means such upgrades take years to design, test and deploy, and the community has only recently begun engaging with it in earnest.

The third is defense at the custody layer. This week, Coinbase's head of cryptography laid out how the exchange, which safeguards roughly $250 billion in assets, is building post-quantum custody designed to adapt to whatever signature scheme Bitcoin eventually adopts—including a hardware fallback if the chosen standard proves incompatible with the key-splitting techniques custodians rely on today.

A related thread runs alongside all this: privacy. The same cryptographic machinery being marshaled against quantum threats overlaps with efforts to make Bitcoin more private, and researchers this week published a separate "Zcash-style" design for shielded Bitcoin transfers.

The bottom line is that Q-Day remains hypothetical and likely years away, and nothing shipped this week makes Bitcoin quantum-safe on its own. What the week showed is a field moving from theory to logistics—driving down what defense costs while measuring how fast the threat is closing.

Whatever the real gap is between those two numbers is how much time the crypto industry has to prepare.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.