• Home
  • Industry Blog
  • Quantum Computing and Bitcoin: The Migration Takes Shape

Quantum Computing and Bitcoin: The Migration Takes Shape

Picture2wolfgang.png
Wolfgang Amadeus VitaleCrypto Protocol Expert
31 Aug 20269 Min

Quantum computing's threat to Bitcoin's elliptic curve cryptography (ECC) is no longer a theoretical concern. The question of whether Bitcoin will need to migrate to post-quantum cryptography has been replaced by practical work of making that happen. 

The debate around what happens to the coins that cannot migrate to post-quantum addresses has produced three broad positions: freeze vulnerable coins and risk setting a confiscation precedent, leave them exposed and risk a supply shock, or find a middle ground through rate-limiting. The debate continues and we expect it to stay controversial, but the good news is that this is not stopping protocol development. 

Several developments in August advanced the technical infrastructure that will determine how this migration functionally works, for Bitcoin and the broader crypto ecosystem alike. Four stood out.

Can frozen Bitcoin be rescued after a quantum migration? 

One of the most consequential developments for the migration debate has been development on rescue protocols. These are mechanisms that allow holders of frozen coins to prove ownership and reclaim their funds without relying only on their private key, which could be compromised once a cryptographically relevant quantum computer (CRQC) exists. 

Two proposals advanced in August. Dropkick, published on August 1 by pseudonymous developer Conduition, is a new commit/reveal rescue protocol. Lifeboat, authored by Tadge Dryja, was updated and recently presented at the bitcoin++ conference. 

Both follow a similar two-step process: to recover vulnerable coins after they have been frozen, the holder first commits information proving ownership, then later reveals it to authorize a rescue spend. Crucially, this information cannot be derived in advance by a CRQC. The details differ, but the principle is the same. 

Why does this matter? BIP-361 proposes to eventually disable ECC-based spending. Coins that fail to migrate would become unspendable: either permanently burned, or temporarily frozen. Rescue protocols are the mechanism that makes "temporarily frozen" a credible outcome rather than a euphemism. 

These protocols are also more conservative than the alternative path previously envisioned for the final phase of BIP-361, which relied on post-quantum secure ZK-SNARKs. "More conservative" here means more likely to be safe and to function correctly, because the cryptographic assumptions are simpler. That is a meaningful reduction in risk for the frozen-coins path. 

The practical implication: even if Bitcoin is eventually forced to disable ECC while millions of BTC remain unmigrated, most of those coins will have a way out. Not all, because some address types cannot benefit from rescue protocols, and truly lost coins have no one to commit a proof. But for a growing share of unmigrated coins, frozen would no longer mean permanently lost.

Is Bitcoin's post-quantum cryptography upgrade settled? 

Some believe Bitcoin's post-quantum cryptography upgrade is technically understood and that what remains is the social and governance work of reaching consensus on a migration strategy. This is only partially true. 

BIP-360 proposes P2MR (pay-to-Merkle-root) as a new post-quantum transaction output type. But it is not the only option under discussion. Developers are actively evaluating alternatives, including P2TRv2, P2TRH, and P2QR. The technical question of which output types Bitcoin should adopt is not settled, and the choice is not merely an implementation detail.  

The output type affects how quickly holders are likely to migrate. We want to avoid a hurried migration triggered by panic once CRQC viability is undeniable. It also influences whether ECC must be disabled entirely, or whether it can be disabled selectively for certain address types. That affects whether disabling ECC is perceived as confiscation or as an expected protocol transition, a central tension in Bitcoin's quantum governance debate. 

The question of which post-quantum signature scheme to use is also progressing on parallel tracks. While the output type defines how bitcoins can be spent, the signature proves that the spender is authorized to do so. Blockstream Research published a report evaluating lattice-based signatures for Bitcoin, identifying Falcon-1024 as the strongest lattice-based option at this stage.  

This doesn’t change the fact that hash-based cryptography remains the leading candidate for post-quantum Bitcoin. Reflecting this, Jonas Nick and co-authors formalized the hash-based SHRINCS specification in a BIP draft, the first concrete post-quantum signature scheme designed specifically around Bitcoin's technical constraints.  

In conclusion, Bitcoin’s post-quantum upgrade remains technically unsettled, but progress is encouraging: developers are now comparing concrete output designs and signature schemes through public discussion and review across code repositories, the Bitcoin Development Mailing List and Delving Bitcoin. Anyone with institutional exposure to Bitcoin's long-term protocol trajectory should be following this work closely.

How is Ethereum building a quantum-resistant blockchain? 

Ethereum's quantum readiness plan takes a layered approach to replacing vulnerable cryptography. One component of that plan has changed in a meaningful way. 

Ethereum had originally adopted Poseidon as the hash function for the hash-based cryptography needed for quantum readiness. Poseidon was designed to be efficient inside SNARKs, the zero-knowledge proof systems that Ethereum's roadmap depends on. But it is a relatively new hash function, and it had not been subjected to the same depth of cryptanalytic scrutiny as established standards like SHA or BLAKE. 

That concern has now been resolved through an unexpected route. New SNARK designs have demonstrated that traditional, battle-tested hash functions can match Poseidon's performance inside a SNARK. As Justin Drake summarized: the key was not SNARK-friendly hashes, but hash-friendly SNARKs. 

Ethereum is now moving to SHA or BLAKE at the core of its post-quantum cryptography layer. This fortifies the roadmap by replacing a newer, less-tested component with an industry standard that has decades of cryptanalytic validation behind it.

What does Google's post-quantum cryptography deadline mean for crypto? 

Google Cloud published a detailed post-quantum cryptography roadmap in August, targeting completion by 2029. This deadline was first announced in March and is now matched by Cloudflare and Microsoft, but the new roadmap provides substantially more operational detail on how Google intends to reach it. 

The 2029 target is not driven by a prediction that CRQCs will exist by then. It reflects a policy decision to complete the migration far ahead of regulatory deadlines, which in most jurisdictions extend to 2035 under NIST guidance. 

I bring this up because there are still voices, including among crypto market participants, who argue that quantum computers capable of breaking ECC are decades away or may never arrive. That position is increasingly difficult to reconcile with the capital allocation decisions of the companies that build and operate the world's computing infrastructure.  

Google, Cloudflare, and Microsoft are not migrating because they enjoy spending engineering resources on speculative threats. They are migrating because their risk assessment tells them to. The crypto ecosystem would do well to benchmark its own readiness against that pace.

From "whether" to "how" 

These developments share a common thread: the transition from "whether" to "how." Rescue protocols are being designed and refined. Post-quantum output types are being debated in earnest. An initial post-quantum signature scheme for Bitcoin has been formally specified. Ethereum has hardened its roadmap by choosing battle-tested cryptographic primitives. The traditional tech sector is executing against fixed deadlines. 

The technical building blocks for quantum readiness are advancing on multiple fronts. What remains unresolved, and what will ultimately determine outcomes for holders, are the governance and consensus questions that no amount of engineering can shortcut.

Image is AI generated.

Related Articles

  • Quantum Research

    Bitcoin's Quantum Debate: What Happens to the Coins That Can't Migrate?

    Bitcoin's quantum debate has shifted from urgency to migration. Should vulnerable coins be frozen, left to quantum attackers, or rate-limited? BIP-361 and the three positions explained.

    13 Aug 202610 Min
  • Quantum Research

    Beyond Bitcoin: How Other Blockchains Are Preparing for Quantum Computing

    Ethereum, Solana, Ripple and Cardano have published quantum resistant cryptography plans. Why the migration paths diverge, and where Bitcoin stands.

    31 Jul 20267 Min
  • Quantum Research

    Migration Is the Hard Part

    A sufficiently powerful quantum computer running Shor's algorithm could derive private keys from exposed public keys, breaking the elliptic curve cryptography (ECC) that Bitcoin depends on for digital signatures. The preparation window is measured in years, not decades, and the clock is already running.

    16 Jul 20269 Min

Personal Support, Every Step

Our team of native experts are here to provide you with the tools, insights and support you need.

Opening hours

24/7 online

Monday to Friday: 7am to 7pm

contact@bitcoinsuisse.com

0800 800 008

Call us toll-free from Switzerland

+41 41 660 00 00

Call us from abroad