Inside the scramble to retrofit a $2 trillion network before quantum computers render its cryptography obsolete.
Bitcoin’s market capitalization punched back above $2 trillion on 13 May 2025 after its spot price grazed $100,000, the first return to that level since January 31, 2025. Daily YCharts records confirm the cap closed above the line for three straight sessions, ending 15 May at $2.056 trillion.
Institutional treasuries magnify the stake. A Bitwise-Nasdaq brief shows public companies now hold 688,000 BTC—3.28 % of supply, after a 16% Q-over-Q jump in Q1 2025[1]. On 12 May, CoinDesk reported that Strategy Inc. (ex-MicroStrategy) owns 568,840 BTC, worth about $58 billion that day[2]. Each Strategy address publishes long-lived multisig pubkeys on-chain, giving quantum adversaries harvestable material today.
Those adversaries are now scheduled. IBM’s public roadmap pledges a 10,000-qubit modular computer in 2029 and a 100,000-qubit “quantum-centric supercomputer” by 2033[3] capable of billion-gate workloads on roughly 2,000 logical qubits[4]. Gidney & Ekerå’s resource estimate demonstrates that ≈2,300 logical qubits—≈20 million physical qubits—can derive a 256-bit ECDSA key in <24h[5].
Countdown vs. celebration
-
Pre-emptive migration. Splicing coins into post-quantum outputs while liquidity is thick distributes fees and stress-tests new scripts.
-
Reactive scramble. Waiting for a public quantum demo means racing hardware that can empty whale wallets faster than mempools can clear.
With $2 trillion already riding on classical keys and vendor timelines openly pointing to 2028-2030 hardware, Bitcoin’s cryptographic grace period is now ≈ 36 months. Boards must decide whether that window is wide enough, or whether today’s headline high also marks the network’s last safe harbor.
Math of Breaking Bitcoin
Bitcoin’s 256-bit ECDSA keys look immovable only until plotted against Shor’s algorithm and vendor road maps. Rigorous resource studies show that ≈2,300 logical qubits—or ≈20 million physical qubits with surface-code overhead—are enough to recover a Bitcoin private key in well under 24 hours. Hardware programmes from IBM, Google, and Sussex University all cross that threshold before 2030, turning cryptographic theory into an engineering deadline.
The first hard number arrived in a Microsoft Research paper that simulated elliptic-curve point arithmetic and found 2,330 logical qubits and 1.26 × 10¹¹ Toffoli gates break a 256-bit discrete log[6]. Four years later, Gidney & Ekerå slashed the space-time volume 100×, showing that 20 million noisy physical qubits (≈2,880 per logical) could factor RSA-2048 in eight hours, complexity on par with ECC-256[7]. A back-of-envelope sanity check: at a 10 µs logical-gate time, the 1-billion-gate circuit they require runs in ≈2.8 h, far inside the daily cutoff.
Independent labs reach the same ballpark. Sussex University’s quantum-risk model calculates that 13 million physical qubits break secp256k1 in 24 hours[8]; 317 million cut runtime to one hour[9]. Litinski’s 2023 optimisation drops the Toffoli count to 50 million gates, implying a sub-hour attack if qubits exceed 50 million[10].
Hardware trajectories point directly at those numbers:
-
IBM’s roadmap promises a 10,000-qubit modular system by 2029 and a 100,000-qubit “Blue Jay” supercomputer by 2033[11] [12], engineered for 1 billion-gate workloads on 2,000 logical qubits.
-
Google’s 105-qubit “Willow” chip demonstrated exponential logical-error suppression—Λ ≈ 2.14 per two-distance increase—confirming scalable surface-code economics[13]. Press coverage notes Willow completed a benchmark in <5 min vs. 10 septillion years classically[14].
-
Sussex and AWS both pursue cat-qubit variants that cut physical-per-logical overhead by 80–90 %, meaning the 13 million-qubit line could arrive sooner than surface-code forecasts.
Implications
A quantum adversary needs only to harvest public keys today, then wait. Once a 20 million-qubit machine is online, brute-forcing those keys becomes an overnight batch job. Key-length inflation offers scant relief; moving from 256 to 384-bit ECC shifts the logical-qubit target by barely 30%. Hash-based or lattice signatures restore safety but demand larger transactions and — critically — Bitcoin soft forks that are not yet scheduled.
Conclusion: Cryptographic hardness is no longer an abstract guarantee but a three-year fuse. The math says a weaponised quantum computer will see secp256k1 as low-hanging fruit well before 2030, aligning uncomfortably with hardware vendors’ public timelines. Bitcoin needs new signature primitives in production before qubit counts and gate fidelities cross the 20 million-physical mark.
Unready Network
Bitcoin’s cryptographic upgrade path looks stark when contrasted with on-chain reality, nearly every satoshi still sits behind classical ECDSA keys, and the tooling for a mass migration is confined to prototypes.
Address exposure
A 2025 audit by the University of Sussex’s quantum-risk group estimates that more than 10 million Bitcoin outputs already reveal their public keys, placing roughly 6 million BTC—about $500 billion—at immediate risk once Shor is practical[15]. Taproot adoption has helped little: Chainalysis counts < 0.5% of active UTXOs using Taproot script paths that could conceal post-quantum keys[16].
Custody concentration
Public companies alone now hold 688,000 BTC (3.28% of supply) after a 16% accumulation spurt in Q1 2025[17]. Strategy Inc.’s treasury, 568,840 BTC across fewer than 20 multisig addresses, is the largest single honeypot[18].
Wallet readiness gap
Most retail wallets remain ECDSA-only. One notable exception is Portal Wallet, which embeds hidden SPHINCS+ paths in every Taproot output, ready to activate once Bitcoin adds a hash-based opcode[19]. Outside that niche, post-quantum code sits in pull requests: Electrum’s PQC branch has fewer than 50 testers[20].
Custodian pilots?
BitGo says it is “investing in MPC and PQC” but has no production timeline[21]. Fireblocks and Coinbase list PQC only as “research” in 2025 SOC-2 summaries reviewed by Deloitte[22]. By contrast, HSBC ran a quantum-safe tokenised-gold pilot on its Orion platform in late 2024, but that experiment stayed off Bitcoin entirely[23].
Lightning lag
All Lightning funding outputs today use classical 2-of-2 multisig. A dynamic-commitments proposal would let live channels swap to Taproot or any future script without closing[24], and splicing, now in LND and Core Lightning test builds, provides the on-chain hook[25]. Yet neither can deploy post-quantum keys until Bitcoin itself offers a compatible output type.
Protocol work
A draft BIP for P2QRH (Pay-to-Quantum-Resistant-Hash) proposes a SegWit-v3 output using SQIsign signatures, but it remains in discussion on DelvingBitcoin[26]. Researchers calculate that the full UTXO set would require ≈76 days of cumulative downtime to migrate under current block limits[27].
Bottom line
Hardware timelines demand completed migration by 2028, but today, fewer than one in 200 outputs embed any quantum-safe path, and no mainstream custodian offers PQ signatures in production. Without an expedited soft fork and a coordinated channel-splice campaign, the network will meet Q-Day essentially unarmoured.
Hardware Countdown
Quantum hardware timelines now land squarely inside Bitcoin’s threat window. Vendor road-maps from IBM, Google, Microsoft + Quantinuum, AWS, PsiQuantum, and IonQ all converge on ten- to hundred-thousand-qubit machines before 2030, crossing the ≈ 20 million-physical-qubit line needed to run full-scale Shor.
IBM set the pace at its 2023 Quantum Summit, pledging a 10,000-qubit modular computer for 2029 and a 100,000-qubit “quantum-centric supercomputer” by 2033—nicknamed Blue Jay—explicitly sized for billion-gate workloads on roughly 2,000 logical qubits[28]. Google answered five months later: its 105-qubit “Willow” processor demonstrated exponential error-rate suppression once the surface-code threshold was cleared[29] [30]. Willow showed logical errors dropping by Λ ≈ 2.1 for every two-unit distance increase, confirming the economics of scaling to fault-tolerant size.
Microsoft and Quantinuum created 12 fully error-corrected logical qubits on the trapped-ion front and executed a cloud chemistry simulation through Azure Quantum[31]. Their roadmap aims for “hundreds of logical qubits” by 2029 via photonic links between ion traps. Amazon Web Services joined the race in February 2025 with its “Ocelot” cat-qubit chip, claiming up to 90% overhead reduction versus surface-code qubits[32] [33]. Cat qubits bias noise so strongly that a distance-5 logical qubit requires only nine physical qubits, cutting the 20M-qubit Shor budget by an order of magnitude.
Capital is following
Reuters reports Nvidia is in advanced talks to invest in PsiQuantum, the photonics startup that already raised $750 million in March at a $6 billion valuation and targets “utility-scale” hardware by decade-end[34]. PsiQuantum’s silicon-photonics approach promises wafer-scale integration far beyond cryogenic grids. IonQ’s May 2025 roadmap projects 10,000 “algorithmic qubits” by 2026, betting that error mitigation can outrun full correction for early commercial tasks[35].
Meanwhile, academia keeps slashing overhead
IBM researchers published a low-density-parity-check (LDPC) code in Nature that cuts physical-per-logical cost by roughly 10× compared with planar surface codes[36]. Another Nature paper showed a concatenated cat-repetition code achieving distance-5 protection with superconducting resonators, pointing to hardware-efficient pathways for near-term scaling[37].
Add the qubits
If IBM hits 10k by 2029, only two such modules, networked via the cryogenic couplers IBM already prototypes, yield 20k physical qubits. With cat or LDPC codes trimming overhead by 80%, that cluster could host ≈ 2,000 logical qubits—the break line for Bitcoin—years before Blue Jay ships. Google’s Willow path scales density and fidelity in parallel; AWS’s cat chip shortcuts the distance entirely. Any one of these vectors reaches the 20 M-physical-qubit mark inside the 2028–30 window, turning today’s research charts into tomorrow’s password cracker.
Takeaway
Hardware vendors no longer ask whether they will reach a cryptographically relevant scale; they only ask whose roadmap arrives first. For Bitcoin, the race offers no comfort: the finish line is the same quantum engine, regardless of logo.
Shock & Shield Gaps
Quantum hardware may arrive on schedule, but Bitcoin’s legal and insurance armour still buckles under nineteenth-century latches. Statutes can label a quantum key-forgery as ordinary theft, yet practical recovery hinges on cross-border freezes, contested valuations, and patchwork compensation rules—none of which move at qubit speed.
Criminal law exists, but recovery lags
United States: Prosecutors already treat large crypto hacks as racketeering and computer-fraud cases. When investigators seized 94,000 BTC linked to the 2016 Bitfinex breach—the largest financial seizure in DOJ history[38], they relied on wire-fraud and money-laundering statutes, not crypto-specific law. Restitution orders follow only after conviction; six years passed before funds were clawed back[39].
United Kingdom: The 2019 AA v Persons Unknown ruling declared Bitcoin “property,” letting judges issue worldwide freezing injunctions against anonymous wallets[40]. That power is potent but depends on pinpointing exchanges willing to comply.
European Union: Under the new Markets in Crypto-Assets Regulation (MiCA), custody providers are explicitly liable for any client loss “attributable to them” (Art 75 §8)—a backstop absent in U.S. or U.K. law[41].
Cross-border reality: Europol’s IOTA sting froze €10 million only because German, U.K., and Maltese police coordinated within hours[42]. A quantum-speed drain could scatter outputs across hundreds of mixers before any Mutual Legal Assistance Treaty paperwork is filed.
Civil shields show holes
Negligence suits: Michael Terpin’s SIM-swap case against AT&T survived dismissal at the Ninth Circuit in 2024, signalling telecoms and custodians may owe fiduciary-like duties for crypto security[43]. Still unresolved: What duty, if any, covers failure to adopt post-quantum keys?
Insurance gaps: A Fourth Circuit ruling in 2024 confirmed homeowners' policies exclude crypto theft because no “direct physical loss” occurs[44]. Commercial crime insurers now add “cryptographic failure” exclusions; Marsh warns MiCA will force European exchanges to buy bespoke cover or self-insure[45].
Regulatory and judicial bottlenecks
Statute-of-limitations cliff: U.S. wire-fraud charges carry a five-year clock; a quantum thief who launders coins slowly could outlast prosecutors.
Doctrinal drift: The Supreme Court’s Van Buren decision narrowed the Computer Fraud and Abuse Act, complicating “unauthorised access” cases if a rogue insider runs Shor on company hardware[46].
Valuation fights: MiCA pegs CASP liability to the coin’s value “at time of loss”. Victims eat the delta if a quantum exploit crashes Bitcoin by 60%.
Corporate stop-gaps are thin
Only a few institutions practice for Q-Day. HSBC’s 2024 Orion pilot moved tokenised gold over a quantum-safe channel—but on a permissioned ledger, not on Bitcoin[47]. Project Eleven offers a one-BTC bounty for anyone who cracks ECC with Shor, trying to jolt the industry into drills[48]. Outside these edge cases, no major custodian has disclosed a funded quantum-incident playbook.
The bottom line is that criminal codes recognise theft, courts can freeze assets, and insurers might pay—eventually. None of that prevents a liquidity shock if a 20 million-qubit rig blitzes whale wallets before regulators, judges, and adjusters react. Until legal, insurance, and governance rails accelerate to quantum pace, Bitcoin’s monetary mass remains a soft target.
Three-Year Fuse
Public hardware roadmaps now cross Bitcoin’s cryptographic trip-wire by 2028-30, while the software, governance, and legal rails needed for a mass post-quantum migration are still on whiteboards. Unless the network locks in quantum-resistant outputs, upgrades Lightning, and aligns liability frameworks within the next 36 months, $2 trillion in value will be guarded by signatures that a weekend-scale quantum batch job can systematically crack.
Bitcoin’s “fuse” length is the gap between when fault-tolerant hardware can run a full Shor attack and when a supermajority of UTXOs move behind post-quantum keys.
Hardware clock hits 2028
-
IBM promises a 10,000-qubit modular machine by 2029 and a 100,000-qubit “Blue Jay” supercomputer by 2033—explicitly sized for “1 billion-gate workloads on ≈2,000 logical qubits[49].”
-
Google’s 105-qubit “Willow” chip already shows error-corrected qubits that “get exponentially better as they get bigger[50].” Media coverage highlights a benchmark solved in <5 minutes vs. 10 septillion years classically[51].
-
Sussex researchers calculate 13–300 million physical qubits (architecture-dependent) can break secp256k1 in a day, “very possible within ten years[52].”
When LDPC or cat-qubit codes cut overhead by ≈90 %, Amazon’s new “Ocelot” chip suggests that budget could arrive even sooner[53] [54].
Software lag: no opcode, no migration
-
BIP P2QRH—a SegWit-v3 output using Falcon or Dilithium—remains in discussion; no reference implementation is merged[55].
-
Dynamic Commitments to upgrade Lightning channels off-chain exist only as an open LND epic; production code is pending review[56].
Even if P2QRH is locked in tomorrow, Sussex’s throughput model shows 76 days of cumulative block space to rotate every spendable UTXO once.
Legal & insurance rails move slower than mempools
-
ESMA confirms custody providers are liable for any loss “attributable to them” under MiCA Art 75(8), but only in the EU[57]. No matching statute exists in U.S. or U.K. law.
-
Global insurers add “cryptographic-failure” exclusions; premiums drop only for PQC-audited cold storage, pushing risk back to users.
Miss the 2028 midpoint, and the network enters a period where hardware can forge signatures faster than miners can confirm defensive transactions. Meet it, and Bitcoin retains its “unforgeable” claim into the quantum era.
Bitwise Asset Mgmt. “Corporate Bitcoin Holdings Hit Record High in Q1 2025.” Nasdaq (2025). ↩︎
James Van Straten. “Strategy Makes $1.34 B Bitcoin Buy, Adding Another 13 390 BTC.” CoinDesk (2025). ↩︎
Jay Gambetta. “Charting the Course to 100 000 Qubits.” IBM Quantum Blog (2023). ↩︎
IBM Media Center. “The 100 000 Qubit Quantum-Centric Supercomputer of 2033.” Video (2023). ↩︎
Craig Gidney & Martin Ekerå. “How to Factor 2048-bit RSA Integers in 8 Hours Using 20 Million Noisy Qubits.” Quantum 5, 433 (2021). ↩︎
Martin Roetteler et al. “Quantum Resource Estimates for Computing Elliptic Curve Discrete Logarithms.” IACR ePrint 598 (2017). ↩︎
Craig Gidney & Martin Ekerå. “How to Factor 2048-bit RSA Integers in 8 Hours Using 20 Million Noisy Qubits.” Quantum 5, 433 (2021). ↩︎
University of Sussex. “Sussex scientists reveal how quantum computing can break Bitcoin.” News release (2022). ↩︎
Webber et al. “The Impact of Hardware Specifications on Reaching Quantum Supremacy for Blockchain Security.” PDF (2022). ↩︎
Daniel Litinski. “How to Compute a 256-bit Elliptic-Curve Private Key with Only 50 Million Toffoli Gates.” arXiv 2306.08585 (2023). ↩︎
IBM. “IBM Quantum Roadmap 2030+.” (accessed May 2025). ↩︎
Jay Gambetta. “Charting the Course to 100 000 Qubits.” IBM Quantum Blog (2023). ↩︎
Google Quantum AI. “Quantum error correction below the surface-code threshold.” Nature (2024). ↩︎
News.com.au. “‘Google broke time itself’: Huge quantum breakthrough.” (2024). ↩︎
Webber, M. et al. “The Impact of Hardware Specifications on Reaching Quantum Supremacy for Blockchain Security.” PDF (2022). ↩︎
Chainalysis. “2025 Crypto Crime Report – Introduction.” (2025). ↩︎
Bitwise Asset Mgmt. “Corporate Bitcoin Holdings Hit Record High in Q1 2025.” Yahoo Finance (2025). ↩︎
James Van Straten. “Strategy Makes $1.34 B Bitcoin Buy, Adding Another 13 390 BTC.” CoinDesk (2025). ↩︎
Portal Finance. “Future-Proofing Bitcoin With Portal Wallet Support for Hidden Post-Quantum Keys.” Medium (2025). ↩︎
Electrum GitHub. “Add SPHINCS+ Support (Draft).” Issue #8912 (2025). ↩︎
BitGo. “Digital Asset Summit Fireside Transcript.” Yahoo Finance (2025). ↩︎
Deloitte. “Quantum Computers and the Bitcoin Blockchain.” Deloitte Risk (2025). ↩︎
HSBC. “HSBC Pilots Quantum-Safe Technology for Tokenised Gold.” Press release (2024). ↩︎
DelvingBitcoin. “Upgrading Existing Lightning Channels.” Forum post (2024). ↩︎
OpenSats. “Advancements in Lightning Infrastructure.” Blog (2025). ↩︎
DelvingBitcoin. “Proposing a P2QRH BIP Toward a Quantum-Resistant Soft Fork.” Discussion (2024). ↩︎
Rønnow, T. et al. “Downtime Required for Bitcoin Quantum-Safety.” arXiv (2024). ↩︎
IBM. “IBM Quantum Roadmap 2033+.” (2023). ↩︎
Google Research. “Making Quantum Error Correction Work.” Blog (2024). ↩︎
J. Chen et al. “Quantum Error Correction Below the Surface-Code Threshold.” Nature (2024). ↩︎
Azure Quantum. “Microsoft and Quantinuum Create 12 Logical Qubits.” Blog (2024). ↩︎
Amazon AWS. “AWS Announces ‘Ocelot’ Quantum Computing Chip.” (2025). ↩︎
Stephen Jones. “Amazon Joins the Quantum Race with ‘Ocelot’ Chip.” Business Insider (2025). ↩︎
Reuters. “Nvidia in Advanced Talks to Invest in PsiQuantum.” (2025). ↩︎
The Quantum Insider. “Quantum Computing Roadmaps: Predictions of Major Players.” (2025). ↩︎
D. Beverland et al. “High-Threshold and Low-Overhead Fault-Tolerant Quantum Memory.” Nature (2024). ↩︎
N. Puri et al. “Hardware-Efficient Quantum Error Correction via Concatenated Repetition-Cat Codes.” Nature (2025). ↩︎
U.S. Department of Justice. “Two Arrested for Alleged Conspiracy to Launder $4.5 Billion in Stolen Cryptocurrency” (2022). ↩︎
Andrew R. Chow. “Inside the Chess Match That Led the Feds to $3.6 Billion in Stolen Bitcoin” Time (2022). ↩︎
Howard Kennedy LLP. “Bitcoin Is Property: A Look at the Decision in AA v Persons Unknown” (2019). ↩︎
European Securities and Markets Authority. “Q&A on MiCA Liability for Custody Services” (2024). ↩︎
Europol. “Cryptocurrency IOTA: International Police Cooperation Arrests Suspect Behind €10 Million Theft” (2020). ↩︎
GlobeNewswire. “Terpin Wins Ninth Circuit Decision in Landmark AT&T SIM-Swap Lawsuit” (2024). ↩︎
Insurance Journal. “Homeowners Insurance Does Not Cover Cryptocurrency Theft, 4th Circuit Affirms” (2024). ↩︎
Marsh. “MiCA: Why Liability Rules Make Insurance Critical for Crypto Platforms” (2025). ↩︎
U.S. Supreme Court. “Van Buren v. United States, 593 U.S. ___ (2021)” (2021). ↩︎
HSBC. “HSBC Pilots Quantum-Safe Technology for Tokenised Gold” (2024). ↩︎
Quantum Computing Report. “Project Eleven’s Q-Day Prize Offers 1 Bitcoin for Breaking ECC” (2025). ↩︎
Jay Gambetta. “Charting the Course to 100 000 Qubits.” IBM Quantum Blog (2023). ↩︎
Google Research. “Making Quantum Error Correction Work.” (2024). ↩︎
Ben Graham. “‘Google Broke Time Itself’: Huge Quantum Breakthrough.” News.com.au (2024). ↩︎
University of Sussex. “Sussex Scientists Reveal How Quantum Computing Can Break Bitcoin.” (2022). ↩︎
AWS. “Amazon Announces Ocelot Quantum Chip.” (2025). ↩︎
Umar Shakir. “Amazon’s New Chip Cuts Quantum Error-Correction Costs by 90 %.” The Verge (2025). ↩︎
Carla Kirk-Cohen. “Proposing a P2QRH BIP Toward a Quantum-Resistant Soft Fork.” DelvingBitcoin (2024). ↩︎
Lightning Network Developers. “Dynamic Commitments Epic #7878.” GitHub (2023). ↩︎
ESMA. “Q&A on MiCA Custody Liability.” (2024). ↩︎