|

Can quantum computers crack Bitcoin—should you be worried?

It’s one of the industry’s most reliable headlines: Whenever Google or IBM unveils a new quantum chip, the warning “Quantum computers threaten Bitcoin” follows. The price flinches, and the forums are abuzz. In 2026, however, this debate has taken on a new level of seriousness—not because the end of the world is drawing nearer, but because a distant “someday” has turned into a concrete engineering project. It’s time for a sober assessment.

In Short:

No quantum computer today can crack Bitcoin—not even close. The threat is real, but it is neither imminent nor specific to Bitcoin: The same cryptographic foundation also secures online banking, government agencies, and half of all internet traffic. It’s digital signatures that are at risk, not mining. And unlike in banking, Bitcoin is working publicly on a solution—the first quantum-secure addresses were already incorporated into the protocol in 2026.

What exactly is a quantum computer—in three sentences?

A quantum computer performs calculations using so-called qubits instead of classical bits. This allows it to solve certain, very specific types of problems much faster than any computer available today—but for almost everything else, it is no faster. So it’s important to note: A quantum computer is a highly specialized tool, not a “super-PC” that can simply do everything better. One of these specific problems relates to the mathematics on which Bitcoin signatures are based.

Where exactly would Bitcoin be vulnerable—and where not?

It’s worth making a clear distinction here, because most headlines confuse two things:

  • Signatures (the relevant vulnerability): Your Bitcoin is secured by a key pair. A sufficiently powerful quantum computer could theoretically derive the private key from a publicly visible public key. This would primarily affect older address types where the public key is openly visible on the blockchain—including, presumably, coins mined early on during Satoshi’s time.
  • Mining (practically unvulnerable): The mining of new blocks relies on a different type of cryptography (SHA-256) that is largely resistant to quantum attacks. According to estimates from 2026, an attack on the mining process would require an astronomical number of qubits and an enormous amount of energy—nearly equivalent to the power of a star. A quantum computer could therefore not “take over” or rewrite the blockchain.

How real is the danger, really?

This is the most honest—and at the same time, the most uncomfortable—part. For a long time, the threat was considered to be “decades away.” By 2026, this consensus had shifted. New research—including work by Google—significantly lowered the estimated number of qubits required, in some cases by a factor of twenty compared to earlier assumptions. This brings the timeline closer. Nevertheless, the gap between what today’s quantum computers are capable of (a few hundred to just over a thousand qubits, prone to errors) and what a real attack would require (hundreds of thousands of stable qubits) remains enormous—orders of magnitude, not percentages.

Experts are genuinely divided on the timing. Many specialists expect a quantum computer capable of cryptographic applications to emerge in the 2030s. Some believe it could happen as early as 2030. While respected skeptics don’t see a real threat for another 20 to 40 years. We’re deliberately not giving you a specific year—anyone who does is passing off speculation as fact. The honest reality is a range, not a single date.

A Shift in Perspective: It’s Not Just About Bitcoin

That’s the point the headlines almost always fail to mention. The same cryptographic foundation that protects Bitcoin signatures also secures your online banking, encrypted websites (the padlock icon in the browser), government IT systems, industrial facilities, and messaging apps. A quantum computer capable of cracking Bitcoin would first and foremost pose a problem for all of those other systems—for the entire digital financial and communications system at once.

Added to this is a threat that is already underway: “Harvest now, decrypt later.” Attackers—often state-sponsored—are already collecting encrypted data today in order to decrypt it as soon as the technology is ready. This affects banking data, health records, and diplomatic communications. In this context, Bitcoin is the most transparent “patient”—because the blockchain is public—but by no means the “sickest.” To put it bluntly: With traditional banking, you can only hope that your bank makes the switch in time. With Bitcoin, you can watch the migration unfold in public.

What is Bitcoin doing about it?

More than most people realize—and by 2026, it had moved from theory to code. The standards for quantum-secure cryptography already exist: The U.S. National Institute of Standards and Technology (NIST) finalized the first three in 2024, and the entire industry—from Google to banks—is gradually migrating to them. For Bitcoin itself, an initial proposal—BIP-360—was added to the official repository in early 2026, introducing a quantum-secure address type. A follow-up proposal (BIP-361) outlines a phased migration away from the vulnerable legacy addresses.

The real challenge here isn’t the math, but the logistics. Migrating millions of existing addresses to the new system in an orderly fashion, without causing chaos and without anyone losing their coins. That is precisely why there is heated debate—for example, about whether old addresses should eventually be “decommissioned.” The fact that this debate is taking place openly and early on is not a weakness, but rather the advantage of a transparent system. We explain how such changes to Bitcoin actually take place in our post on the current development debates.

What can you do on your own?

Not much, but not nothing—and without the hassle. The key factor isn’t a specific type of address, but your behavior: As long as the public key associated with an address isn’t visible, it offers no vulnerability to a quantum attacker.

Three simple habits:

  • Never reuse addresses. That’s the most important point. With common address types (legacy addresses starting with “1…,” SegWit addresses starting with “bc1q…”), your public key remains hidden as long as you’re only receiving funds. It only becomes visible when you send funds. Anyone who continues to use the same address after that exposes the rest of the key—so use a new address for every transaction you receive. Modern wallets do this automatically.
  • SegWit is a solid default choice—with one caveat. Addresses that begin with “bc1q…” (SegWit) keep the key hidden behind a hash until a transaction is made. Important to know: When you send funds from such an address, the remaining balance should be transferred to a new address. This happens automatically and within the same transaction—the wallet sends the remainder back as “change” to a new address of its own, so you only pay the network fee once and nothing is left in the now-disclosed address.
  • Understand Taproot, but put it in the right context. The most modern type (“bc1p…,” Taproot) is great for privacy and fees—but it isn’t automatically better when it comes to quantum security alone: It includes the key in the address, making it visible from the start. No cause for concern today, but it also offers no quantum security advantage over SegWit.

Don´t panic

And most importantly: don’t panic. Hastily reallocating large holdings “just to be safe” is counterproductive—because moving coins exposes the public key and incurs fees, even though there is no real danger at this time. The actual transition to quantum-secure methods will happen in an orderly manner via wallet updates (keyword: BIP-360) when the time comes. What you should do until then: Keep an eye on the state of development—if there’s a truly fundamental shift in quantum hardware or Bitcoin migration, that’s the moment to act, not the next sensational headline.

Three questions to verify a story

To help you make sense of the next “quantum headline” on your own, here’s a simple guide. Ask yourself three questions whenever you see a news story:

  1. Logical or physical qubits? Headlines often cite huge numbers of qubits, but they’re referring to error-prone physical qubits. What counts are stable logical qubits—an attack would need hundreds of thousands of them. If the number isn’t specified, caution is advised.
  2. A lab record or ready for deployment? A chip milestone in the lab is not the same as a computer that can withstand a real-world attack for days or weeks. Question: Was something actually demonstrated, or was it just announced?
  3. Peer-reviewed or press release? Does the statement come from a peer-reviewed publication or from the marketing department of a company that sells quantum products? The latter is not proof—it’s merely a point of interest.

Frequently Asked Questions

Can a quantum computer steal Bitcoin today?

No. No existing quantum computer even comes close to the performance required for this. There is a shortage of stable qubits by orders of magnitude. The threat is real, but it lies in the future; based on current knowledge. It will not materialize until the 2030s at the earliest, and possibly much later. No one can credibly give a specific date.

Which type of address offers the best protection against quantum attacks?

It’s less about the type and more about your behavior. With hash-based addresses (legacy “1…” and SegWit “bc1q…”), your public key remains hidden as long as you’re only receiving funds and don’t reuse the address. Taproot (“bc1p…”) is great for privacy and fees, but it exposes the key earlier when the quantum criterion is met. The best rule of thumb: Use SegWit and only use each address once for sending. When you make a payment, the wallet automatically sends the remaining amount as “change” to a new address of its own. All within the same transaction, so you only pay the network fee once, not twice. Modern wallets handle this in the background. The desktop wallets Sparrow and Wasabi from our wallet comparison make this particularly transparent. Clearly displaying each address and its use.

Why isn’t mining under threat, but the signatures are?

Because they are both based on different mathematical principles. Signatures use a method that a quantum algorithm (Shor’s algorithm) can theoretically crack efficiently. Mining is based on hash functions (SHA-256), against which quantum computers have only a slight advantage. An attack would be absurdly costly in terms of both energy and technical effort.

Is Bitcoin less secure against quantum computers than the banking sector?

It’s actually the other way around. While Bitcoin’s blockchain is public—which exposes some addresses—countermeasures are being developed transparently and early on (see BIP-360). The traditional financial system faces the same fundamental problem but is working on it less visibly. Ultimately, both are affected, because it’s the same cryptography.

Conclusion

The quantum threat is real, but it’s a marathon, not a sprint. Bitcoin is running it openly and with a solid plan. The apocalypse that the headlines proclaim every few months isn’t happening. Instead, a multi-year technical overhaul is underway, and you can watch it unfold. If you use modern addresses and stay informed, you’ve done your part. The rest is handled by a protocol that has already survived many other headlines declaring it dead—as our crash story shows.

This article provides an overview of the current state of technical development and does not constitute investment or security advice. The field of quantum technology is evolving rapidly; the information provided reflects the state of research at the time. As of July 2026.

Similar Posts