• Home
  • Industry Blog
  • Three Scenarios for Bitcoin's Post-Quantum Transition

Three Scenarios for Bitcoin's Post-Quantum Transition

Picture2wolfgang.png
Wolfgang Amadeus VitaleCrypto Protocol Expert
17 Sep 20269 Min

The quantum computing threat to Bitcoin's elliptic curve cryptography (ECC) is established, and the timeline for cryptographically relevant quantum computers (CRQCs) continues to point at the early 2030s. The migration to post-quantum cryptography is underway; output types and signature schemes are under active comparison, and rescue protocols are advancing alongside them. What happens to coins that cannot migrate remains contested. 

Each of these is a component of the transition. None of them says how the components resolve together. Outcomes for holders depend on whether the coordination timeline can advance faster than the threat timeline is compressing. That gap is where Bitcoin's quantum computing risk actually sits. 

Two of the possible answers on consensus are already well documented: some vulnerable coins will remain unmigrated whatever else happens, and consensus could fracture into a contested fork. The three scenarios below depend on timing rather than on what the network decides. 

In the first, the migration finishes with margin to spare. In the second, the market reprices quantum risk long before any capable machine exists. In the third, capability arrives without being announced, and the migration proceeds against a threat estimate that is wrong. Each asks something different of holders, and each has a signal that it is the pressure now in the lead.

What does an orderly post-quantum migration look like?

This is the scenario Bitcoin developers are actively working toward, and it remains my base case. It depends on a sequence of steps, and the first of them has not been completed yet. 

First, the network has to agree on a post-quantum output type. BIP-360 proposed P2MR, but it is no longer the only candidate: P2TRv2, P2TRH and P2QR are all under evaluation, and the choice has consequences for migration costs and whether users’ quantum protection depends on the network disabling ECC in time. 

A soft fork then deploys that output type. A second fork might be needed after it to enable signing with a post-quantum scheme, though bundling both into a single soft fork is at least as likely. Hash-based cryptography remains the leading candidate, and the front-runner is SHRINCS, recently formalized in a BIP draft as the first hash-based post-quantum signature designed around Bitcoin's constraints. Only then does the migration itself begin, holder by holder, across every wallet, exchange and custodian in the network. 

No step in that sequence has a fixed duration. Consensus is the hardest to forecast, and holder migration takes the longest once it begins. That is why the signal worth watching is whether the technical discussion narrows or widens. The strongest indicator would be convergence on a concrete upgrade proposal: which output types and signature schemes to deploy, and how they fit into a migration plan. 

This path asks the least of holders. Follow the upgrade as it happens and migrate once the path opens, and in the meantime basic good practice on address reuse remains advisable.

Can markets price in quantum risk before a CRQC exists? 

Bitcoin's price currently shows no visible reaction to quantum computing news. Announcements of quantum hardware progress do not move it, and neither does progress by Bitcoin developers on the migration. The market does not show signs of adjusting its assessment of either the risk or the response. 

That indifference sits on top of a real exposure. Roughly 7 million BTC sit in addresses whose public keys are already visible on chain, and a CRQC could derive the private keys for any of them. The danger is not only the theft. As covered in the debate on unmigratable coins, even a small fraction of that supply moving within a few blocks would be enough to collapse confidence in the network. That cost reaches holders who migrated on time and never lost a coin, and it does not require anything close to the full 7 million moving.  

Three developments could force the market to react. The first is a hardware result that removes reasonable doubt: sustained error correction across operations involving Toffoli gates, measured end to end on a full computation. That is the threshold I watch, and nothing published so far has crossed it. 

The second is another compression of the requirement itself. Breaking RSA went from an estimated 20 million physical qubits in 2021 to roughly one million four years later, and the logical qubit requirement for Shor's algorithm fell from several thousand to around one thousand earlier this year. A further drop of that magnitude moves the threat estimate without any new machine being built. 

The third is institutional, and it is the one least discussed. Jefferies cited quantum computing among its reasons for eliminating its Bitcoin position. If that reasoning spreads through allocation committees, repricing could arrive through mandates well before any single technical milestone forces the issue. 

Not everyone agrees most of the potential repricing lies ahead. In one of our podcasts, Charles Edwards argued that part of it has already happened, pointing to Bitcoin's underperformance against gold through 2025 as evidence that institutional allocators are discounting the risk in function of “Q-day” proximity.  

I do not see it in the data, but I don’t rule out a relatively stable quantum-risk discount factor that may remain until post-quantum readiness is established. Reaction is easier to read. The first time a quantum headline moves the price in either direction, it may signal that quantum risk is becoming a recurring source of volatility rather than a background concern.

What if quantum capability arrives without being announced? 

Both scenarios above assume that progress remains visible. That assumption has weakened over the past year. 

When Google Quantum AI published its optimization of Shor's algorithm against secp256k1, the curve underpinning Bitcoin's signatures, it withheld the key implementation step behind a zero-knowledge proof: enough to demonstrate the result, not enough to reproduce it. The aim was to give defenders enough information to plan their migration without giving attackers the implementation. 

An independent researcher reconstructed the withheld step within months, so the practical effect was delay rather than prevention. Still, this is concrete evidence that quantum cryptanalysis is becoming a disclosure dilemma, as practical attacks become increasingly plausible. 

Consider the incentives. The entities with the resources to reach a CRQC first include national programs whose entire purpose is to hold capabilities that adversaries do not know about. While publication is how academic and commercial labs claim credit, it is not how intelligence services operate. 

In this scenario, the migration clock keeps running against a threat estimate drawn from public information that no longer describes the real state of the art. I have written before that by the time a quantum computer visibly proves it can break today's cryptography, the chance to migrate in an orderly way has already passed. Here, that outcome is structural rather than merely likely. 

This calls for preparation that does not depend on attempts to accurately estimate a timeline based only on public information. Beyond keeping public keys unexposed and avoiding reuse, that means not concentrating large holdings in a single exposed address, since any attacker with a CRQC would work down from the largest targets first.

Which scenario should holders prepare for? 

These are not mutually exclusive and ranking them is a matter of judgment rather than calculation. Orderly migration remains the most likely, and the work done this year supports it. Repricing could arrive soonest, because it requires no machine to exist and no protocol decision to be made. Stealth capability is the one that defeats a wait-and-see posture, because in that scenario the signal to act never arrives in time to act on. 

The preparation is common to all three, which is the useful conclusion. Keep public keys unexposed, avoid reuse, avoid concentration, and work with a custodian that is reading the consensus signals as they form rather than waiting to be told what was decided.

Image is AI generated.

Related Articles

  • Quantum Research

    Quantum Computing and Bitcoin: The Migration Takes Shape

    Rescue protocols, post-quantum cryptography output types, Ethereum's hash pivot, and Google's 2029 deadline. How Bitcoin's quantum migration is taking shape in August 2026.

    31 Aug 20269 Min
  • Quantum Research

    Bitcoin's Quantum Debate: What Happens to the Coins That Can't Migrate?

    Bitcoin's quantum debate has shifted from urgency to migration. Should vulnerable coins be frozen, left to quantum attackers, or rate-limited? BIP-361 and the three positions explained.

    13 Aug 202610 Min
  • Quantum Research

    Beyond Bitcoin: How Other Blockchains Are Preparing for Quantum Computing

    Ethereum, Solana, Ripple and Cardano have published quantum resistant cryptography plans. Why the migration paths diverge, and where Bitcoin stands.

    31 Jul 20267 Min

Personal Support, Every Step

Our team of native experts are here to provide you with the tools, insights and support you need.

Opening hours

24/7 online

Monday to Friday: 7am to 7pm

contact@bitcoinsuisse.com

0800 800 008

Call us toll-free from Switzerland

+41 41 660 00 00

Call us from abroad