
Google Quantum AI puts a qubit-and-minutes estimate on breaking BTC/ETH signatures
The nearer-term risk is coordination: moving funds off exposed-key address types before quantum hardware reaches scale.
Google Quantum AI’s March estimate for breaking Bitcoin- and Ethereum-style signatures with Shor’s algorithm reframes the quantum threat as an engineering timeline, not a sci-fi unknown. Bitcoin and Ethereum both have post-quantum paths on paper, but the trader-relevant risk is whether users can coordinate a mass migration away from address types that have already exposed public keys.
Key Takeaways
- Google Quantum AI estimated in March that cracking Bitcoin/Ethereum-style elliptic curve signatures with Shor’s algorithm could take roughly 1,200–1,450 logical qubits, potentially fewer than 500,000 physical qubits and about 18–23 minutes on superconducting hardware.
- Bitcoin’s proposed mitigation path is BIP 360, which adds a new P2MR address type intended to let users opt into quantum-resistant signatures later without forcing a hard fork.
- Ethereum is pursuing a more explicit multi-year transition, with a staffed Post-Quantum Security team and Vitalik Buterin’s Lean Ethereum plan to swap validator signatures to hash-based ones and add quantum-resistant STARK proofs.
- As of September 2026, no top-20 cryptocurrency is fully quantum-safe, and coins sitting in older address types with already-exposed public keys are flagged as the clearest migration bottleneck.
Google’s ‘logical qubits + minutes’ estimate turns quantum risk into a timeline problem
The new ingredient in the quantum-risk debate is a concrete resource estimate that traders can actually reason about. Google Quantum AI put a number on what it would take to break the signature schemes used by Bitcoin and Ethereum once a public key is visible: about 1,200 to 1,450 logical qubits running Shor’s algorithm, with a translation on superconducting hardware of fewer than 500,000 physical qubits and an 18–23 minute runtime.
That “logical qubits plus minutes” framing matters because it turns the threat from a vague end-state into a capacity planning question. Logical qubits are the error-corrected units you build by combining many noisy physical qubits, so the physical-qubit requirement is the real hardware hurdle. The paper was co-signed by researchers from the Ethereum Foundation and Stanford, which is a signal that protocol-adjacent teams are treating the estimate as something worth operational planning.
The timing is still a wide band. The same source frames credible views ranging from “before 2030” to “2040,” and it explicitly notes that “Nobody knows when the afternoon arrives.” Current hardware cited in the piece remains far below the threshold, with Google’s Willow chip at 105 qubits and the biggest machines “anyone has today” around 2,000–2,500 qubits. A companion paper from Oratomic, co-authored by Caltech’s John Preskill, argues neutral-atom hardware could do the job with about 26,000 qubits, which is a very different scaling story if that hardware path holds up.
The real attack surface: exposed public keys, not the block hash chain
The mechanism traders need to picture is simple: Shor’s algorithm is the quantum tool that can derive a private key from a public key once the quantum computer is powerful enough. In Bitcoin and Ethereum, public keys are not always visible until an address spends. That means the risk concentrates around coins that have already revealed their public keys onchain, and around any workflow that repeatedly reuses or exposes keys.
This is also why “quantum breaks Bitcoin” is an imprecise headline. The hashing that chains blocks together is described as holding up “reasonably well” against known and expected quantum attacks, while transaction signatures do not. Hardware wallet firmware is also called out as a separate weak layer. In practice, the threat is not that a quantum machine rewrites history by snapping the hash chain. The nearer attack is key theft: once a public key is exposed, a sufficiently capable quantum attacker could race to derive the private key and spend the funds.
Post-quantum cryptography is not the missing ingredient. NIST finished standardizing its first post-quantum algorithms in 2024, including lattice-based ML-DSA and hash-based SLH-DSA, and Microsoft and IBM already sell post-quantum security features in cloud and security products. The catch is cost. Post-quantum signatures are described as “bigger and slower” than today’s elliptic curve signatures, and on a blockchain every node stores every signature indefinitely. That makes signature migration a permanent throughput and storage tax, at a time when the piece argues AI-driven demand has pushed storage prices “into the stratosphere.”
Bitcoin’s opt-in path: BIP 360 P2MR and the coordination constraint
Bitcoin’s cited path is BIP 360, which adds a new address type called P2MR. The design goal is coordination avoidance: pre-wire an address format so users can opt into quantum-resistant signatures later, without forcing the entire network through a backward-incompatible hard fork.
That choice reduces governance risk, but it increases adoption risk. An opt-in path only works if holders actually move funds into the new address type before quantum hardware makes exposed keys exploitable. The source’s investor takeaway is blunt on the constraint: “The thing to watch is not whether quantum-safe code gets written. It is how long it takes before people actually use it.” It also flags that Bitcoin “cannot make holders upgrade,” and that “millions of coins sit in old addresses with public keys already sitting in the open.”
Taproot, activated in November 2021, is described as quantum-safe in certain uses based on Blockstream researchers’ findings, which implies Bitcoin’s exposure is not uniform across all script and spend patterns. The limitation is scope. “Certain uses” is not a blanket migration plan, and it does not solve the coordination problem for legacy coins that never move until they do.
Altcoin and wallet ‘quantum-ready’ signals—and the cost problem of bigger signatures
Outside BTC and ETH, the most concrete signal in the packet is that post-quantum signing is already being exercised in production-like conditions. Algorand has performed real transactions signed with Falcon-1024, described as the first major smart contract chain where optional next-generation security keys “actually work.” That does not make Algorand “quantum safe” end-to-end, but it does demonstrate that the UX and verification path can be made real rather than theoretical.
Zcash is taking a different route, funding work to bring quantum-proof private transactions directly to hardware security chips. The piece says Zcash should be quantum-proof in 2027, citing founder Josh Swihart. If that target slips, the useful signal will still be whether the hardware-chip integration ships, because that is where key management and signing performance constraints tend to surface.
Wallet vendors are positioning for the same bottleneck: end-user migration capacity. Trezor Safe 7 advertises a “quantum-ready dual-chip setup” intended to run post-quantum firmware when major chains support it, and Ledger is retooling wallet chips to handle “fatter” post-quantum keys. That is not a protocol upgrade by itself, but it is a prerequisite for one. If wallets cannot store and sign with larger keys cheaply and reliably, opt-in address formats will sit unused.
My read: the market catalyst isn’t ‘quantum is coming’—it’s whether users actually migrate
The threshold that matters is not when NIST finishes standards or when a protocol team publishes a roadmap. Those are already in motion. The real test is whether quantum-safe options become the default path for new deposits and routine wallet behavior before quantum hardware closes the gap implied by Google’s “logical qubits plus minutes” estimate.
Bitcoin and Ethereum are signaling different coordination philosophies. Bitcoin is trying to avoid a hard-fork fight with an opt-in address path, while Ethereum is framing a multi-year swap of validator signatures and proof systems via its Post-Quantum Security team and the Lean Ethereum plan. If either chain fails here, it will not be because post-quantum signatures do not exist. It will be because the ecosystem could not absorb the cost and coordination of moving value away from exposed-key address types fast enough for the timeline to stop being theoretical.