Can quantum computers crack Bitcoin?
No. No quantum computer can crack Bitcoin today, and nothing close to the needed machine exists as of 2026. The real long-term risk is to Bitcoin's signatures, called ECDSA: Shor's algorithm could work out their secret keys. But that needs thousands of error-corrected logical qubits running over a hundred billion steps, and today's hardware has shown one good logical qubit. The risk is still taken seriously. About a quarter of all BTC sits in addresses whose public keys are already exposed, and in February 2026 developers merged a draft quantum-safe plan called BIP-360.
Yes — the discrete-logarithm version of Shor's algorithm breaks secp256k1 in principle (1994) The same 1994 paper that broke RSA in theory also gave a polynomial-time quantum method for discrete logarithms. Polynomial time means the work grows gently as keys get longer, not explosively. That covers the elliptic-curve problem behind Bitcoin's ECDSA signatures. Given a public key, an ideal quantum computer could work out the private key. For ordinary computers, this is completely out of reach at 256 bits.
Costed on paper: about 2,330 logical qubits and about 1.3 x 10^11 Toffoli gates for a 256-bit curve key This is the standard cost estimate for elliptic-curve keys. It comes from a simulated build of the full point-addition circuit. One notable result: 256-bit ECC falls to a smaller quantum computer than RSA-2048 does, even though the two give similar security against ordinary computers. So elliptic-curve keys, Bitcoin's included, are earlier in the firing line than RSA.
Grover speeds up SHA-256 mining and hash attacks only quadratically (to the square root) — no break in the hash itself Bitcoin's proof-of-work and address hashing rest on SHA-256 and RIPEMD-160. Shor's algorithm does not touch these. Grover's algorithm gives at most a quadratic speedup. It cannot be split across machines efficiently, and each quantum hash check is far slower than an ASIC's. Mining and hashed addresses are not seriously threatened. The signatures are the target.
No — no quantum computer has ever worked out any real-world private key Independent 2026 studies of the quantum threat to Bitcoin and Ethereum find no near-term capability. Take the most-discussed scenario: a public key shows up in the mempool, and an attacker races to work out the private key before the transaction confirms. That would need more than an error-corrected machine. It would need one that runs the full Shor circuit in minutes, far beyond every published roadmap.
No quantum capability today — but ~25% of BTC sits in quantum-exposed addresses (per Deloitte) A Deloitte analysis found about a quarter of circulating bitcoin sits in P2PK outputs or reused P2PKH addresses, where the public key is already public. These coins are safe today. They would be the first targets if a code-breaking quantum machine ever existed. And dormant coins cannot be protected unless their owners move them.
A migration path exists on paper: BIP-360, merged as a draft in February 2026 BIP-360 was first called Pay-to-Quantum-Resistant-Hash and is now written up as Pay-to-Merkle-Root. It never shows a classical public key on-chain. It was merged into the BIP repository as a draft in February 2026 and has run on a testnet. Several things are still unresolved: switching it on for the main network, the trade-offs of larger signatures, and above all moving millions of existing UTXOs (unspent coins), dormant ones included. A plan is not a deployment.
What exactly would a quantum computer attack in Bitcoin?
"Cracking Bitcoin" mixes up two very different targets. It helps to know two tools first.
A hash is a fingerprint for data. SHA-256 turns any input into a fixed 256-bit fingerprint. It is easy to make, but you cannot run it backward. Bitcoin uses SHA-256 for mining, the guessing race that adds new blocks. It also uses hashes to build addresses.
A digital signature proves you own your coins. You hold a private key, which is a secret number. From it comes a public key that anyone can see. Think of a wax seal. Anyone can check the seal, but only you own the stamp. Bitcoin's signatures are called ECDSA. They use an elliptic curve named secp256k1.
Target one is SHA-256. Grover's algorithm gives only a quadratic speedup there, which means the work shrinks to its square root. Each quantum step is also much slower than one hash on an ASIC, a chip built only for mining. And the speedup mostly vanishes when you split the work across machines. So mining is not the story.
Target two is the signatures, and this risk is built into the math. Shor's algorithm solves the problem behind them, called the discrete logarithm, in polynomial time. That means the work grows gently as keys get longer, not explosively. A big enough error-corrected machine could work out a private key from a public key. In seal terms, it could rebuild your stamp from the print. Unlike a real seal, the attack needs nothing but the public key and a lot of math.
The catch is the word public. A modern address is a hash of the public key, so the key stays hidden until you spend. But old pay-to-public-key outputs show the key on-chain forever. Most coins from Satoshi's early years are like this. So are addresses that people reused. That is how roughly a quarter of all BTC ends up in the future firing line.
There is also a timing attack. Every spend shows the public key in the mempool, the waiting room for unconfirmed transactions. An attacker would have a few minutes to work out the key and send a rival transaction. That needs more than a big quantum computer. It needs an unrealistically fast one.
How big is the gap between today's hardware and a key-stealing machine?
The benchmark estimate (Roetteler et al., 2017) puts one 256-bit curve key at about 2,330 logical qubits and about 126 billion Toffoli gates. A Toffoli gate is one basic step of quantum arithmetic.
A logical qubit is the expensive kind. It is built from hundreds to thousands of physical qubits, the real hardware parts. They keep checking each other for errors, and a computer fixes the errors they find. Think of a group project where everyone double-checks everyone else. Unlike a group project, the qubits cannot just copy each other's answers. They compare shared patterns instead, without reading the stored value.
Work the numbers. Say each logical qubit takes 1,000 physical ones. Then 2,330 × 1,000 ≈ 2.3 million physical qubits. So the attack lands in the millions of qubits. That is the same league as the RSA-2048 estimates.
Now compare today. The best result shown by 2026 is a single logical qubit that beats its best physical part, on a chip of about 105 physical qubits. No quantum computer has ever worked out a private key of any real-world size. The gap is about three orders of magnitude (1,000 times) in qubit count. It is many more in long, error-corrected runs. For the mempool race, add more orders of magnitude in speed.
See what actually exists on the QPU index, and compare machines side by side.
What would have to change — and what is Bitcoin doing about it?
Three things would turn this from theory into danger:
- Error-corrected machines growing from one logical qubit to thousands.
- Error rates and error-correction costs improving enough to make that affordable.
- Cost estimates falling further, the way RSA estimates have. They dropped 20 times between 2019 and 2025 from better algorithms alone.
So watch logical-qubit counts and error-corrected gate speeds, not raw qubit numbers.
Bitcoin's response has started, but it is early. BIP-360 defines a new address type that never shows a classical public key. It hooks into post-quantum signatures, meaning ones built to resist quantum attacks. NIST standardised these in August 2024 (ML-DSA and SLH-DSA). BIP-360 was merged as a draft in February 2026.
The hard part is not the math. It is moving the coins. Coins only become safe when their owners move them to new addresses. Millions of BTC sit in old, exposed addresses, and their owners may be gone. It is like changing every lock in a city when some houses are empty and nobody has the keys. So what happens to those coins? Leave them to be taken, or freeze them? That is a live argument, not a settled plan.
Practical advice today is the same as it has been since 2010: never reuse addresses. Then your public key shows only in the short window when you spend.
Classifications follow the QPU137 editorial policy: every applied label carries a date, source, scale, and hardware, or it does not render. Found an error? Report it.