Google Quantum AI research shows that the quantum resources required to crack Bitcoin signature cryptography are 20 times less than previously estimated.
About one-third of all bitcoins in circulation are stored in public keys. In the public address. Bitcoin mining itself remains mathematically immune to quantum computers. Trump signed two executive orders in June making quantum computing a national priority. Moody\'s has warned digital asset companies that they need to prove their ability to resist quantum by 2030.
Two executive orders signed by President Trump on June 22 have moved quantum threats to Bitcoin from research laboratories to conference rooms of exchanges, custodians and stablecoin issuers. Two days later, Moody\'s Ratings issued an industry comment warning of the significant impact of quantum computing on the credit of digital assets and setting a rough 2030 deadline for the industry\'s ability to protect its underlying cryptography. The pressure stems from a white paper released by Google\'s Quantum AI team at the end of March, which showed that the quantum resources needed to crack Bitcoin signature cryptography were 20 times less than previously estimated.
What changes lies in mathematics itself, not machines
To understand why rating agencies started setting cryptography deadlines, it\'s important to first understand what Google actually proves. Ownership of Bitcoin relies on the secp256k1 elliptic curve. Anyone who knows the wallet\'s public key can theoretically derive the private key by solving the discrete logarithm problem, a calculation that takes longer for a classical computer than the age of the universe. A quantum computer running Shore\'s algorithm completely changes this equation, and the unresolved question has always been how big such a machine needs to be.
The Google team answered this question with extraordinary precision. The researchers designed two quantum circuits that implement Shore\'s algorithm for specific curves of Bitcoin. One circuit uses approximately 1200 logic qubits and 90 million Toffoli gates, and the other uses approximately 1450 logic qubits and 70 million Toffoli gates. On superconducting architectures, any circuit can solve the problem in minutes rather than days.
The disclosure method itself is almost as eye-catching as the numbers. The team did not publish the details of the circuit, but instead released a zero-knowledge proof-based cryptographic verification, built using SP1zkVM and Groth 16SNARK, allowing anyone to verify its claims without having to access attack details. Google said it had communicated with the U.S. government before release, and this step is usually only used for serious vulnerability research.
Nine-minute versus ten-minute block
The paper describes two different attack scenarios, the second of which is more disturbing to ordinary users. The first scenario is for \"static\" coins. Any address whose public key is already present on the blockchain-whether through the old \"pay-to-public key\" format or through address reuse-can be attacked at any time. The ledger is publicly and permanently archived, so attackers do not need to access it in real time. This is the \"store first, decrypt later\" logic: Intelligence agencies and well-funded groups can copy data on the chain now and wait until the hardware matures before running attacks.
The second scenario is for \"in-transit\" transactions. Modern Bitcoin addresses hash the public key and are not disclosed until spent by the owner. At that moment, the public key is broadcast to the transaction memory pool and the timing begins. Bitcoin blocks are confirmed every ten minutes on average. Google-optimized circuitry calculates the private key in approximately nine minutes. An attacker residing in the transaction memory pool could extract the key before confirmation and sign a competing transaction with a higher fee, thereby beating the legitimate owner. The paper estimates that the success rate of this rush is 41%.
How many bitcoins are actually exposed
Research by Galaxy Digital and independent analysts shows that the number of vulnerable bitcoins ranges from 6.9 million to 7 million, accounting for 34% to 35% of the circulating supply, and is worth as much as US$470 billion at current valuations.
Types of Bitcoin exposed:
Traditional P2PK addresses (2009-2012)-approximately 1.72 million BTC-Reason for risk: public keys are posted directly on the ledger
Satoshi Nakamoto\'s dormant wallet-about 1.1 million BTC-Risk reason: All are in traditional P2PK format, and modern addresses that are reused by
have never been moved-about 4.1 million BTC-Risk reason: Public key exposure after the first external expenditure
The total exposure-approximately 6.9 million to 7 million BTC (approximately 35%)-has a risk exposure of up to US$470 billion
Nakamoto\'s coins pose a problem that no protocol upgrade can solve. Its owners have remained silent since 2011, and dormant funds cannot migrate into a quantum secure format on their own. The community will eventually face a choice: either watch the coins empty by anyone who builds the hardware first, or freeze them through consensus rules-but that would break Bitcoin\'s core promise that \"no one can confiscate your property.\"
Why mining survives while signatures face invalidation
An important nuance in the paper is often ignored by the title. Bitcoin\'s proof-of-work mechanism relies on the SHA-256 hash function rather than elliptic curves, and quantum computers can only obtain a secondary acceleration of the hash function through Grover\'s algorithm. In fact, a quantum machine is more like a slightly more efficient mining machine than a weapon capable of rewriting the chain. The threat focuses entirely on ownership, on signatures proving who controls which coins.
The rebuttal focuses on the reality of the hardware. Willow, Google\'s most advanced processor, runs 105 physical qubits. Expanding to 500,000 error-correcting qubits requires breakthroughs in cryogenics, materials science and chip manufacturing, which may take a decade or more. Skeptics like Blockstream\'s Adam Back believe the danger period is 20 to 40 years away. The paper itself is a resource estimate, not a time projection, and there is no single machine with 1% of the required capacity.
Institutional funding moves ahead of paper release
The realignment starts weeks before Google releases. In mid-January, Christopher Wood, Jefferies \'head of global equity strategy, emptied his high-profile GREED & FEAR model portfolio of all 10% bitcoin allocations and allocated them instead to 5% physical gold and 5% gold mining stocks. Wood cited a study by Chaincode Labs that estimated that 20 to 50 percent of the circulating supply could be vulnerable to quantum key extraction attacks, calling the threat \"existential\" for Bitcoin\'s argument as a store of value for long-term pension portfolios.
Moody\'s went further in its June 24 comments, viewing quantum readiness as a credit issue rather than a technological singularity. The agency pointed out that a fix for Bitcoin already exists on paper, a quantum-signature-resistant scheme, but uses consensus, soft forks, and coordinated wallet migration across a decentralized network that has no central authority to enforce deadlines. An executive order from Trump calls for the development of a quantum computer powerful enough to usher in the era of quantum-enabled discovery and the submission of system specifications within 90 days. Moody\'s warned that a high-profile quantum breach in a traditional wallet could trigger a chain of panic selling across the asset class because blockchain theft cannot be rolled back, has no insurance, and has no legal recourse. Citi analysts added that generative AI is accelerating quantum error correction research, further compressing the defense window.
The response at the protocol level is faster than Bitcoin\'s reputation for deadlock. BIP-360 introduced a quantum-resistant address type and was merged into the Bitcoin codebase on February 11. Its supporting proposal, BIP-361, goes a step further and outlines a plan to phase out traditional signatures and ultimately freeze coins that have never been migrated-a mechanism that directly addresses the problems of Satoshi Nakamoto\'s era. In its second quarter report released on July 3, Blockstream highlighted OP_CHECKSHRINGS, a hash-based signature opcode that was first proposed in May and built on a scheme already running on the Liquid sidechain. Google has promised to complete its own post-quantum migration internally in 2029. The hardware is still hundreds of times smaller: In April, a researcher received a bounty of 1 Bitcoin from security company Project Eleven for cracking a 15-bit elliptic curve key on public quantum hardware, a record-breaking achievement that still falls far short of Bitcoin\'s 256-bit key. The competition between both sides is real. The question is who reaches the finish line first.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC