21Relay
Advanced curriculum
Lesson 1220 minReviewed July 2026

Quantum Computing and Bitcoin

Understand the conditional quantum threat to Bitcoin signatures and hashes, the difference between present risk and future capability, and the coordination required for migration.

Learning outcomes

By the end of this lesson, you should be able to

  • Shor's and Grover's algorithms affect Bitcoin primitives differently.
  • No public quantum computer can currently recover Bitcoin keys at the required scale.
  • Exposed public keys are the main signature concern.
  • A migration would require consensus, wallet and operational coordination.
1

Quantum computers are not one universal shortcut

Quantum algorithms affect different cryptographic problems differently. A sufficiently capable fault-tolerant quantum computer running Shor's algorithm could threaten the elliptic-curve signatures Bitcoin currently uses.

Grover's algorithm would reduce the effective security margin of ideal hash searches roughly to a square-root level rather than simply making SHA-256 useless. Bitcoin's signatures and hash functions therefore require separate analysis.

2

The practical threat is conditional

Public quantum demonstrations are far from the scale and reliability required to recover Bitcoin private keys from public keys. Estimates change as hardware and error-correction research develops, so a responsible lesson avoids predicting a precise break date.

The threat is still worth planning for because protocol migration, wallet upgrades and moving old outputs could take years. Other digital infrastructure is preparing for the same class of risk through post-quantum standards.

3

Which coins could be exposed first

To attack a signature key, an adversary needs its public key. Some older output types expose public keys directly, and spending modern outputs reveals key material as part of transaction validation.

Hashing a public key before it is revealed may reduce one exposure window, but address reuse, mempool observation, Taproot output keys and already exposed keys make 'just use a new address' an incomplete network-wide solution.

4

Bitcoin can change, but migration is difficult

A quantum-resistant path would require reviewed cryptographic constructions, new address or script rules, wallet support, hardware support and broad coordination. Larger signatures and verification costs would affect block space and node resources.

Rules for old quantum-vulnerable outputs are especially difficult. Freezing, migrating or permitting recovery of them involves security, property and consensus trade-offs; no single proposal is currently the settled Bitcoin solution.

5

What users should do now

Use maintained wallet software, avoid unnecessary address reuse, protect seed material and follow credible Bitcoin development discussions. Do not move funds because of sensational claims or reveal recovery information to a supposed quantum-protection service.

If a migration is eventually adopted, verify instructions through multiple official project channels and test with small amounts. Quantum planning is a protocol-engineering problem, not a reason to abandon ordinary security today.

Visual recap

From research signal to safe migration

A credible response requires evidence, reviewed cryptography and coordinated deployment—not a rushed wallet service.

01

Assess capability

02

Review primitives

03

Design proposal

04

Test implementations

05

Coordinate activation

06

Migrate outputs

Key takeaways

  • Shor's and Grover's algorithms affect Bitcoin primitives differently.
  • No public quantum computer can currently recover Bitcoin keys at the required scale.
  • Exposed public keys are the main signature concern.
  • A migration would require consensus, wallet and operational coordination.
  • Post-quantum planning should not replace seed and device security today.

Lesson recap

Check what you learned

Reveal each model answer, then honestly mark whether you understood it or need another review.

1 of 3

Recall

Would a powerful quantum computer automatically let an attacker create bitcoin beyond the 21 million limit?

References

Further reading

Lesson progress

Loading progress...

Rate this lesson

Was this lesson helpful?

No name or financial information is collected.

Found inaccurate or outdated information? Report a correction