D-Wave CEO Alan Baratz warns that advanced quantum computing will eventually break Bitcoin's proof-of-work protocol, urging the industry to adopt quantum-resistant alternatives. While IBM's demonstration of trusted quantum advantage using 70 logical qubits shows rapid hardware progress, it remains below the estimated 500,000 physical qubits Google research indicates is needed to break Bitcoin's elliptic curve cryptography. Proposed defenses like BIP-361 face fierce community resistance over controversial clauses to freeze unmigrated coins, including Satoshi Nakamoto's 1.1 million BTC stash.
Google quantum threat research findings
- ▪Google Quantum AI's research suggests a live Bitcoin transaction could have its private key derived in approximately nine minutes under certain conditions.
- ▪A March 2026 Google Quantum AI whitepaper, co-authored with the Ethereum Foundation and Stanford University, analyzed quantum computing requirements to attack elliptic curve cryptography.
- ▪Google Quantum AI's superconducting architecture circuits implementing Shor's algorithm against secp256k1 require fewer than 500,000 physical qubits, representing a 20-fold reduction from prior estimates.
Bitcoin on-spend attack vulnerability
- ▪Fast-clock quantum architectures, such as superconducting and photonic systems, enable on-spend attacks to complete within Bitcoin's ten-minute block confirmation window.
- ▪An on-spend attack occurs when a quantum computer derives a private key during the brief window between transaction broadcast and confirmation, allowing a fraudulent transaction to front-run the sender.
Cryptocurrency quantum exposure assessment
- ▪Approximately 6.9 million bitcoin, representing roughly one-third of the circulating supply, sit in wallets where public keys have already been exposed.
- ▪Security engineer Conor Deegan flagged that protocols like Ethereum's KZG trusted setup, Zcash's Sapling, and Litecoin's MimbleWimble embed elliptic curve hardness into fixed public parameters.
- ▪Approximately 1.7 million bitcoin sit in early Pay-to-Public-Key addresses, which includes holdings widely attributed to Satoshi Nakamoto.
Post-quantum migration proposals
- ▪D-Wave CEO Alan Baratz introduced an experimental quantum proof-of-work protocol that is proposed to be 1,000 times more energy efficient than Bitcoin's model.
- ▪Bitcoin Improvement Proposal 361, proposed in April 2026, outlines a three-phase migration plan to phase out quantum-vulnerable addresses and freeze unmigrated coins.
- ▪Bitcoin Improvement Proposal 360, introduced in February 2026, proposes a Pay-to-Merkle-Root output type to keep public keys off-chain until spending.
- ▪Avihu Levy published Quantum Safe Bitcoin on April 9, 2026, utilizing hash-based proofs under Script constraints without requiring a soft fork.
- ▪Postquant Labs launched Quip Network on April 28, 2026, a Layer 2 wallet using Winternitz One-Time Signature cryptography to reduce the on-spend window.
Community governance debate
- ▪Community reaction to BIP-361's proposed coin freeze was highly critical, with some users calling the upgrade proposal highly authoritarian and confiscatory.
- ▪Capriole Investments founder Charles Edwards estimates a 30% fear discount on Bitcoin's price due to quantum concerns, which could vanish upon committing to a roadmap.
Quantum computing hardware timeline
- ▪IBM's Starling roadmap, released in June 2025, targets a large-scale fault-tolerant quantum computer by 2029.
- ▪D-Wave CEO Alan Baratz warned on July 28, 2026, that sufficiently advanced quantum computing will eventually break Bitcoin's proof-of-work protocol.
- ▪IBM demonstrated trusted quantum advantage using 70 logical qubits and a new error-correction method, executing 2,415 logical two-qubit operations.
Story comments
Loading comments…