No top-20 cryptocurrency is fully quantum-safe yet, but Bitcoin and Ethereum are both building upgrade paths against machines that could one day break the encryption securing every wallet. Researchers say post-quantum signatures work — they are just bigger, slower and more expensive to run at network scale.
Bitcoin and Ethereum developers are racing to shield their networks from a threat that does not exist today but could arrive within a decade: a quantum computer powerful enough to derive a private key from the public key every wallet exposes when it spends. Google Quantum AI researchers estimated in March that such a machine would need about 1,200 to 1,450 logical qubits, translating to fewer than 500,000 physical qubits on superconducting hardware and a runtime of 18 to 23 minutes. Ethereum Foundation and Stanford researchers co-signed that paper.
No network is quantum-safe today
Google's Willow chip currently carries 105 qubits, and the largest machines anyone operates run roughly 2,000 to 2,500. A separate paper from Oratomic, co-authored by Caltech's John Preskill, argues neutral-atom hardware could reach the same threat level with about 26,000 qubits. Estimates for when a machine actually crosses that line split between before 2030 and as late as 2040, so developers are building for the earlier date.
Bitcoin and Ethereum take different paths
Bitcoin's answer is BIP 360, a new address type called P2MR that lets holders opt into quantum-resistant signatures without forcing a network-wide hard fork. Blockstream researchers also found that Taproot, live since November 2021, is quantum-safe in certain uses. Ethereum is moving faster: the Ethereum Foundation has staffed a dedicated Post-Quantum Security team, and co-founder Vitalik Buterin's Lean Ethereum plan maps a multiyear swap of validator signatures for hash-based ones plus quantum-resistant STARK proofs.
Beyond the top two, Algorand has already completed real transactions signed with the quantum-resistant Falcon-1024 algorithm, becoming the first major smart contract chain to make that option work. Zcash is funding a project to bring quantum-proof private transactions to hardware security chips, and founder Josh Swihart says the network should be quantum-proof in 2027. Hardware wallet makers are moving too: the Trezor Safe 7 markets a quantum-ready dual-chip setup, and Ledger is retooling its chips for the larger keys post-quantum signatures require.
The upgrades carry a real cost. The National Institute of Standards and Technology finished standardizing its first post-quantum algorithms — the lattice-based ML-DSA and hash-based SLH-DSA — in 2024. Microsoft and IBM already sell post-quantum security inside their cloud products today. But those signatures are bigger and slower than the elliptic curve signatures crypto runs on today, and every node has to store every signature forever, raising storage costs across the network.
O'Leary ties Bitcoin's $1 million case to the same risk
Investor Kevin O'Leary, speaking with The Rollup podcast at Avalanche Summit in New York, said Bitcoin can reach $1 million. According to Decrypt: "if it can resolve the doubt creeping in around quantum computing", a risk the industry has nicknamed "Q-Day." No quantum computer capable of that attack exists today, and estimates for when one might range from the early 2030s to never. O'Leary has said elsewhere that the uncertainty is why big funds cap Bitcoin exposure around 3% of a portfolio, treating it more like a sliver of gold than a core holding.
Millions of bitcoins sit in old addresses with their public keys already exposed, waiting for whichever machine arrives first. None of the fixes above are optional forever.
Sources: The Motley Fool, Decrypt
Trading involves risk.