Tech

Can Quantum Computers Break Bitcoin?

By Eric Williamson
AI & Data: Who Really Holds the Power?

Can Quantum Computers Break Bitcoin?

Here's What the Evidence, the Roadmaps and the Experts Actually Say

A comprehensive briefing on Google Quantum AI's 2026 resource estimates, Bitcoin's BIP-360 defence, the hardware race, and the regulatory pressure now bearing down on the industry

Key Takeaways

 

1

Google Quantum AI's March 2026 whitepaper, co-authored with the Ethereum Foundation and Stanford University, cut the estimated physical qubit requirement for breaking Bitcoin's elliptic curve cryptography to under 500,000, roughly a twentyfold reduction on the prior best estimate of around 9 million.

2

The paper's headline attack designs need only 1,200 to 1,450 logical qubits, and it introduces a new, more alarming scenario: superconducting quantum computers could, in principle, intercept and forge a transaction within Bitcoin's ten-minute block window.

3

Justin Drake of the Ethereum Foundation, a late co-author on the paper, now estimates at least a 10 per cent probability of quantum key recovery by 2032. However, he stresses that quantum-assisted mining remains far off.

4

Roughly $452 billion in Bitcoin sits in wallets with exposed public keys, including an estimated $70 billion believed to belong to Satoshi Nakamoto and around $180 billion in other abandoned, publicly exposed coins.

5

Bitcoin Improvement Proposal 360, merged in February 2026, introduces the Pay-to-Merkle-Root (P2MR) address format, which hides public keys without yet adding a post-quantum signature scheme, deliberately deferring that harder problem.

6

IBM's Starling roadmap targets a fault-tolerant, roughly 200 logical qubit machine by 2029, a scale still well short of what Google's paper says is needed. Still, the gap between hardware and threshold is narrowing faster than expected.

7

Opinion within the industry is sharply divided: figures such as Blockstream's Adam Back and Strategy's Michael Saylor argue the threat remains one to several decades away, while others, including Ethereum's Vitalik Buterin, put meaningful odds on a break before 2030.

8

Regulators are moving regardless of the debate: NIST has set 2030 for deprecating classical algorithms, and 2035 for prohibiting them; the NSA's CNSA 2.0 framework mandates migration for national security systems by 2031; and France and the US Department of Commerce have both begun formal transitions.

 

Introduction

Bitcoin's security has rested for seventeen years on a single mathematical assumption: that solving the elliptic curve discrete logarithm problem is computationally infeasible. On 31 March 2026, that assumption came under its most serious scrutiny yet. Google Quantum AI, working with researchers from the Ethereum Foundation and Stanford University, published a 57-page whitepaper showing that the quantum resources required to break Bitcoin's cryptography are roughly twenty times smaller than the industry's previous best estimate.

The paper did not claim that Bitcoin can be broken today. Today's most advanced quantum processors remain three to four orders of magnitude too small and too error-prone. What the paper changed was the shape of the horizon: a threat once assumed to sit safely beyond mid-century now looks, to a meaningful number of credible researchers, plausibly reachable within the next decade. That shift has forced Bitcoin's developers, institutional holders and regulators to take a question they had long been able to defer and treat it as an active engineering problem.

This report sets out what Google's research actually found, how far current and planned quantum hardware sits from the threshold it identifies, how much Bitcoin value is genuinely exposed, what the Bitcoin and Ethereum communities are doing in response, and why serious, informed people continue to disagree sharply about the urgency of it all.

The Cryptography Behind Bitcoin, and Why Quantum Computers Threaten It

Every Bitcoin address is ultimately controlled by a private key, an enormous randomly generated number. Ownership is proven through the Elliptic Curve Digital Signature Algorithm (ECDSA), applied to a specific curve known as secp256k1. A user's public key is derived from their private key through a one-way mathematical operation: computing the public key from the private key is trivial, but reversing the process with classical computers is not, because it requires solving the elliptic curve discrete logarithm problem (ECDLP). With today's hardware, and even projected classical hardware for the foreseeable future, that reversal is considered practically impossible.

Quantum computers threaten this asymmetry because of Shor's algorithm, a technique published in 1997 by mathematician Peter Shor showing that a sufficiently large, fault-tolerant quantum computer could solve both integer factorisation and the discrete logarithm problem in polynomial time. Shor's algorithm is why quantum computing is treated as an existential risk to essentially all currently deployed public-key cryptography, not just Bitcoin's, including the RSA and ECC schemes that secure banking systems, government communications and the wider internet.

Crucially, the risk to a given Bitcoin address depends on whether its public key has ever been revealed on the blockchain. Bitcoin's earliest addresses used the pay-to-public-key (P2PK) format, which places the public key directly on-chain and permanently exposed. Modern wallets default to pay-to-public-key-hash (P2PKH) or newer formats, which store only a hash of the public key; the underlying public key is revealed only at the moment funds are spent. That distinction, hidden until spent versus permanently exposed, is the single most important factor in assessing which coins are actually at risk.

Google's March 2026 Paper: What It Actually Found

The paper, titled Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations, was led by Google Quantum AI researchers Ryan Babbush and Hartmut Neven, with Stanford cryptographer Dan Boneh and Ethereum Foundation researcher Justin Drake joining as co-authors. It presents two optimised quantum circuits for solving the 256-bit ECDLP on secp256k1, each trading off logical qubit count against gate count.

The first design minimises qubit count, requiring around 1,200 logical qubits and roughly 90 million Toffoli gates. The second minimises gate count, using around 1,450 logical qubits and roughly 70 million Toffoli gates. Once realistic quantum error correction overhead is applied, both translate to fewer than 500,000 physical qubits on a superconducting architecture, against a prior best estimate, from a 2023 paper by Craig Gidney and Martin Litinski using a photonic architecture, of roughly 9 million physical qubits. The paper notes that more aggressive, as yet unproven, connectivity assumptions could in principle push the physical qubit figure below 100,000.

Perhaps the paper's most striking technical contribution is its analysis of attack speed. The authors distinguish between “fast-clock” quantum architectures, such as superconducting, silicon and photonic qubits, and “slow-clock” architectures, such as neutral atoms and ion traps. Their modelling suggests that fast-clock superconducting systems could, in principle, execute an attack within Bitcoin's roughly ten-minute average block confirmation window, intercepting a broadcast transaction, deriving its private key from the exposed public key, and substituting a fraudulent transaction before the original is confirmed. This so-called “on-spend” attack is more alarming than the traditional, slower “at-rest” threat model that had dominated prior discussions, because it would expose not just old P2PK coins but any transaction the instant its public key is revealed.

Rather than publishing the circuits themselves, Google verified its claims using a zero-knowledge proof generated with the SP1 zero-knowledge virtual machine, which lets independent parties confirm the team holds circuits of the stated size capable of correct elliptic curve point addition across 9,000 random test inputs, without revealing the attack design itself. Google engaged the US government ahead of publication and has set an internal 2029 deadline for migrating its own authentication services to post-quantum standards.

On the mining side, separate analysis using Grover's algorithm, a different quantum technique that offers only a quadratic rather than exponential speed-up, suggests that quantum-assisted Bitcoin mining is not commercially viable in any near-term scenario, a point Drake has been explicit about even as he has raised his estimate of the signature-forgery risk.

The Hardware Gap: How Far Away Is 500,000 Qubits?

The gap between Google's threshold and deployed hardware remains very large, though it is narrowing on multiple fronts simultaneously. Today's most advanced superconducting processors, including Google's own Willow-generation chips and IBM's Heron-class processors, operate with roughly 105 to 156 physical qubits, several orders of magnitude below the estimated 500,000 physical qubits, and hundreds of times below even the 1,200 to 1,450 logical qubits, the paper identifies as sufficient.

IBM's public roadmap is the clearest signpost for how quickly that gap could close. The company's Starling system, targeted for 2029 and built at a dedicated data centre in Poughkeepsie, New York, aims to deliver around 200 logical qubits capable of roughly 100 million quantum operations, using quantum low-density parity-check (qLDPC) error correction codes rather than the more resource-hungry surface codes used historically. IBM has committed more than $10 billion to its quantum programme over five years and has already hit interim milestones: a 120-qubit Nighthawk processor and an experimental Loon chip in late 2025, and, in mid-2026, a demonstration IBM described as “trusted quantum advantage” using 70 logical qubits with a new error-correction method, though independent commentators and IBM itself stressed this remains well below what would threaten Bitcoin.

IBM's own security specialists have offered a working estimate: Jeff Crume has placed cryptographically relevant Q-Day somewhere between 2030 and 2035, a range broadly consistent with the gap between Starling's 200 logical qubits and Google's 1,200 to 1,450 logical qubit threshold. ARK Invest's March 2026 research report was more conservative still, characterising the industry as sitting at “Stage 0”, meaning quantum computers exist but have not yet demonstrated any commercially relevant computational advantage, and noting that even optimistic hardware trajectories do not reach 500,000 qubits before the early 2030s at the earliest.

How Much Bitcoin Is Actually Vulnerable

Estimates converge on a striking figure: approximately $452 billion in Bitcoin sits in wallets whose public keys have already been exposed on-chain, and would therefore be immediately at risk the moment a cryptographically relevant quantum computer existed. Justin Thaler, research partner at Andreessen Horowitz, has separately estimated that around $180 billion of that total sits in coins that appear abandoned, meaning nobody remains able to move them to a safer address even if the community wished them to.

Around $70 billion, using the Bitcoin price assumptions applied consistently throughout this analysis, is widely believed to belong to Satoshi Nakamoto's original mining rewards, most of which have never moved and were created using the exposed pay-to-public-key format. Because Satoshi's identity and keys have never resurfaced, these coins present a governance problem with no clean technical solution: nobody can migrate funds, and nobody can access them.

Address reuse compounds the exposure. Even holders using modern pay-to-public-key-hash addresses lose their protection the moment they reuse an address for a second outgoing transaction, since the public key is revealed the first time funds are spent and remains visible thereafter. Venture capitalist Nic Carter has summarised the shift in perception this way: he has described quantum computing as having moved from a remote theoretical possibility to merely an engineering challenge. That reframing, from a physics problem to an engineering and funding problem, is precisely what has driven the Bitcoin community's defensive response over the past year.

Bitcoin's Defence: BIP-360 and the Road to Quantum-Safe Addresses

Bitcoin Improvement Proposal 360 was merged into the reference implementation in February 2026. It introduces a new output type, Pay-to-Merkle-Root (P2MR), which keeps a spending public key hidden inside a Merkle commitment until the moment coins are spent, reducing the window during which an exposed key is sitting on-chain waiting to be attacked. Deliberately, BIP-360 does not itself introduce a post-quantum signature algorithm; that harder, more contentious change has been deferred to future proposals, allowing the address-format change to ship as a soft fork rather than requiring the far more difficult political and technical coordination of a hard fork.

The reason post-quantum signatures were deferred separately is largely one of storage economics. Justin Thaler has noted that post-quantum signature schemes can run 10 to 100 times larger than Bitcoin's current 64-byte ECDSA signatures. NIST-standardised lattice-based schemes such as ML-DSA produce signatures in the 2.4 to 4.6 kilobyte range, while the more conservative hash-based SLH-DSA scheme can run to tens of kilobytes; both would sharply increase transaction sizes, straining Bitcoin's already constrained block space and pushing up fees for ordinary users. Choosing between a smaller, newer lattice-based assumption and a larger, more conservatively studied hash-based one is itself an unresolved design debate within the Bitcoin developer community.

A separate and more difficult governance question concerns coins that can never be migrated, chiefly Satoshi's holdings and other abandoned P2PK balances. Draft proposals such as BIP-361 would freeze coins that remain in vulnerable, exposed-key addresses past a defined deadline, effectively removing them from circulation rather than leaving them as a permanent, unmovable honeypot for whoever builds a capable quantum computer first. That idea remains contentious precisely because it would mean deliberately altering balances that have not consented to any change, a step in tension with Bitcoin's foundational principle of immutability.

Ethereum's Parallel, More Structured Response

Ethereum faces a closely related but architecturally distinct problem: its consensus layer relies on BLS signatures over elliptic curve pairings to aggregate votes from hundreds of thousands of validators, which are similarly vulnerable to Shor's algorithm. In February 2026, Ethereum co-founder Vitalik Buterin published a roadmap, subsequently nicknamed the “Strawmap”, identifying four distinct areas of Ethereum's cryptography needing post-quantum upgrades and outlining a four-year plan of roughly seven hard forks, each addressing different components: validator signatures, in-protocol proofs, wallet security and the underlying hash function choices.

Buterin has been notably more numerically explicit about timing than most Bitcoin commentators. Citing the forecasting platform Metaculus, he has put the probability of a cryptographically relevant quantum computer arriving before 2030 at around 20 per cent, with the median community forecast closer to 2040. He has separately warned that elliptic curve cryptography could conceivably break before the 2028 US presidential election, urging Ethereum to complete its transition within roughly four years. The Ethereum Foundation has also stood up a dedicated post-quantum research team and, as a longer-term contingency, Buterin has previously sketched an emergency hard-fork mechanism that would let users prove ownership of a vulnerable address through a zero-knowledge STARK proof and move funds to a quantum-safe contract, framed explicitly as a last-resort recovery tool rather than a primary plan.

The comparison is instructive largely because of governance, not cryptography. Ethereum's smaller set of client teams and its established cadence of coordinated hard forks give it a structural advantage in shipping cryptographic change quickly. Bitcoin's more decentralised, consensus-driven governance model, prized precisely for making unilateral changes difficult, is the same feature that makes a rapid, coordinated cryptographic migration considerably harder to execute.

The Expert Divide: Urgency Against Scepticism

Few topics in cryptocurrency currently produce a wider spread of credible, informed opinion than the quantum timeline. The following table summarises where key voices in the debate currently stand.

Commentator

Affiliation

Broad view expressed

Justin Drake

Ethereum Foundation, paper co-author

At least 10 per cent chance of Q-Day by 2032; growing confidence after co-authoring the Google paper.

Adam Back

CEO, Blockstream

Cryptographically relevant threat remains 20 to 40 years away.

Michael Saylor

Executive Chairman, Strategy

Threat is a decade or more away and would hit banks and the internet before Bitcoin.

Vitalik Buterin

Co-founder, Ethereum

Citing Metaculus, roughly a 20 per cent chance of a break before 2030, median forecast nearer 2040.

Jeff Crume

IBM security expert

Places Q-Day, a cryptographically relevant quantum computer, between 2030 and 2035.

Christopher Tam

President, BTQ Technologies

Views the federal 2031 migration deadline as insufficiently urgent.

ARK Invest (March 2026 report)

Investment research

Assesses the industry as still at “Stage 0”: quantum computers exist but lack commercially relevant capability.

 

The scepticism is not fringe. Michael Saylor, executive chairman of Strategy and overseer of the largest corporate Bitcoin treasury, has repeatedly argued that concerns are overstated, at one point dismissing the narrative as mainly marketing from people who want to sell you the next quantum yo-yo token. His broader argument is threefold: that a genuinely capable quantum computer would compromise banks, governments and the internet before it meaningfully threatens Bitcoin specifically; that the cybersecurity community's rough consensus places any credible threat at least a decade away; and that Bitcoin's software, unlike legacy banking infrastructure, can be upgraded relatively quickly once a real threat materialises. Adam Back has taken a similarly measured position, arguing the cryptographically relevant threat sits twenty to forty years out and that Bitcoin retains ample time to integrate quantum-safe signatures without undue haste.

Against that, Justin Drake's public shift after co-authoring Google's paper is notable precisely because it came from inside the research rather than from commentary on it: his confidence in a 2032 Q-Day, in his own words, rose significantly once he had worked through the resource estimates directly. BTQ Technologies president Christopher Tam has gone further, criticising the US federal government's 2031 migration deadline for national security systems as insufficiently urgent given the pace of hardware progress. The honest summary is that the disagreement is not really about the mathematics, which is well understood, but about how quickly engineering, funding and error-correction breakthroughs will compound over the coming decade, a genuinely difficult forecasting problem on which serious people continue to differ.

Regulatory Pressure Is Building Regardless of the Debate

Governments have chosen not to wait for the industry to reach consensus. In August 2024, the US National Institute of Standards and Technology (NIST) finalised its first three post-quantum cryptography standards: ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) as the primary general-purpose post-quantum signature scheme, and SLH-DSA (FIPS 205), a more conservative hash-based signature standard intended as a structurally independent backup. A further code-based key-encapsulation standard and a compact Falcon-based signature standard, FIPS 206, remain in progress. NIST's published timeline calls for deprecating classical algorithms such as RSA and ECDSA by 2030 and prohibiting their use entirely by 2035.

The US National Security Agency's CNSA 2.0 framework sets a parallel, somewhat faster schedule specifically for National Security Systems, with phased implementation milestones beginning in 2030 and mandatory deployment across covered systems by the end of 2031. A June 2026 executive order added concrete civilian federal deadlines, including a Commerce Department migration pilot by 2027 and full key-establishment migration by 2030. The Department of Commerce separately committed $2 billion to quantum development in May 2026, underscoring that federal investment in the underlying hardware and the mandated defensive migration are, somewhat awkwardly, advancing in parallel.

Outside the United States, France began phasing out certification for non-quantum-safe encryption in June 2026 as part of its national cybersecurity policy, adding to the general international direction of travel. None of these mandates applies directly to Bitcoin's decentralised protocol, which no government can compel to upgrade. Still, they add sustained pressure on the exchanges, custodians and payment processors that sit around it, all of which do fall within regulatory reach and will need quantum-safe infrastructure regardless of what Bitcoin's own core protocol ultimately decides.

What Happens Next

BIP-360's P2MR implementation is undergoing community review and wallet-level testing through 2026 and into 2027, with the harder question of which post-quantum signature algorithm to standardise, and how to manage the resulting increase in transaction size, still unresolved. Both Google and IBM have flagged 2029 as a significant marker: Google's own internal migration deadline and IBM's targeted delivery of the Starling system, meaning the next three years should materially clarify whether the hardware trajectory is tracking toward Drake's more urgent timeline or Back and Saylor's more relaxed one.

In the meantime, the practical, uncontested advice from essentially every commentator across the spectrum is the same: holders should avoid address reuse, move long-held balances out of any address whose public key has ever been exposed, particularly early pay-to-public-key addresses, and follow BIP-360's rollout as wallet providers begin to support quantum-resistant output types. None of that requires taking a position on whether Q-Day arrives in 2032 or 2050; it simply removes exposure that costs nothing to eliminate today.

Frequently Asked Questions

Can quantum computers break Bitcoin today?

No. Today's leading superconducting quantum processors operate with roughly 105 to 156 physical qubits, several orders of magnitude below the scale Google's research identifies as necessary. Substantial advances in both qubit count and error correction are still required before such an attack becomes practically possible.

How many qubits are needed to break Bitcoin?

Google's March 2026 research estimates fewer than 500,000 physical qubits, translating to roughly 1,200 to 1,450 logical qubits once error correction is applied, around twenty times fewer than the approximately 9 million physical qubits estimated in prior research.

What is Q-Day in cryptocurrency?

Q-Day is the informal term for the hypothetical date on which a quantum computer becomes powerful and reliable enough to break the cryptographic algorithms, principally ECDSA, that currently secure Bitcoin and most other blockchain networks.

What is BIP-360?

Bitcoin Improvement Proposal 360 introduces the Pay-to-Merkle-Root (P2MR) output type, which keeps a spending public key hidden until coins are spent, reducing quantum attack exposure. It does not itself add a post-quantum signature algorithm; that is expected to follow through separate future proposals.

How much Bitcoin is currently at risk?

Approximately $452 billion sits in wallets with exposed public keys, including around $180 billion in apparently abandoned coins and an estimated $70 billion believed to belong to Satoshi Nakamoto's original holdings.

What is an on-spend quantum attack, and how is it different from an at-rest attack?

An at-rest attack targets old coins whose public key has been permanently exposed on-chain, giving an attacker unlimited time to work. An on-spend attack, the more alarming scenario raised in Google's paper, would intercept a transaction the moment it is broadcast and attempt to derive the private key and forge a competing transaction before the original confirms, a window of roughly ten minutes on Bitcoin.

When could quantum computers realistically threaten Bitcoin?

Expert estimates vary widely, from Justin Drake's at least 10 per cent probability of key recovery by 2032, through IBM's Jeff Crume placing Q-Day between 2030 and 2035, to Adam Back's and Michael Saylor's view that a genuine threat remains one to several decades away.

Is Ethereum more prepared than Bitcoin for the quantum threat?

Ethereum's Strawmap targets quantum-resistant protection through a structured four-year, roughly seven-fork upgrade plan, aided by a smaller set of coordinating client teams. Bitcoin's more decentralised governance model, which requires broad community consensus for protocol changes, is likely to make an equivalent transition slower, even though BIP-360 shows the process is now genuinely underway.

 What should individual Bitcoin holders do now?

Avoid reusing addresses, since a public key is exposed the first time an address spends funds, and consider moving long-dormant balances, especially those in early pay-to-public-key addresses, to fresh, unused addresses as a low-cost precaution. At the same time, the industry works through its longer-term migration.

References

1. Google Finds Quantum Computers Could Break Bitcoin Sooner Than Expected (Forbes, 31 March 2026) https://www.forbes.com/sites/digital-assets/2026/03/31/google-finds-quantum-computers-could-break-bitcoin-sooner-than-expected/

2. What Is Q-Day? The Quantum Threat to Bitcoin (Decrypt, 2026) https://decrypt.co/resources/what-q-day-quantum-threat-bitcoin-explained

3. Bitcoin Improvement Proposal 360 (The Quantum Space, 24 February 2026) https://thequantumspace.org/2026/02/24/bitcoins-first-quantum-step/

4. Will Quantum Computing Break Bitcoin's Cryptography? (FinTech Magazine, 2026) https://fintechmagazine.com/news/will-quantum-computing-break-bitcoins-cryptography

5. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations (Google Quantum AI whitepaper, 30 March 2026) https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf

6. Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography (ISC2 Community, March 2026) https://community.isc2.org/t5/Tech-Talk/Google-Quantum-AI-Achieves-10x-Reduction-in-Resources-to-Break/td-p/88924

7. Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography (PostQuantum.com, April 2026) https://postquantum.com/security-pqc/google-quantum-bitcoin-ecdlp/

8. Can Quantum Computers Break Bitcoin? 2026 Google Research (altFINS Knowledge Base) https://altfins.com/knowledge-base/can-quantum-computers-break-bitcoin/

9. 9 Minutes to Crack Bitcoin? The Technical Boundaries and Industry Misreading of Google's Quantum White Paper (Safeheron, April 2026) https://safeheron.com/blog/google-quantum-whitepaper/

10. Google Suggests Quantum Attacks on Cryptocurrency Encryption May Require Fewer Resources (The Quantum Insider, 31 March 2026) https://thequantuminsider.com/2026/03/31/google-suggests-quantum-attacks-on-cryptocurrency-encryption-may-require-fewer-resources/

11. Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline (The Quantum Insider, 31 March 2026) https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/

12. IBM's New Quantum Roadmap Brings the Bitcoin Threat Closer (Decrypt, 14 June 2025) https://decrypt.co/325183/ibm-quantum-roadmap-brings-blockchain-threat-closer

13. Bitcoin Quantum Threat Inches Closer as IBM Claims 'Trusted Quantum Advantage' (Decrypt, 2026) https://decrypt.co/374753/bitcoin-quantum-threat-ibm-claims-trusted-quantum-advantage

14. IBM Achieves Trusted Quantum Advantage with 70 Logical Qubits (GNCrypto News, 2026) https://www.gncrypto.news/news/ibm-trusted-quantum-advantage-70-logical-qubits/

15. IBM's Quantum Computing Push Shifts the Timeline for Bitcoin Risk (Crypto Valley Journal, 3 June 2026) https://cryptovalleyjournal.com/focus/background/ibm-quantum-computing-push-shifts-the-timeline-for-bitcoin-risk/

16. IBM's Vision for a Large-Scale Fault-Tolerant Quantum Computer by 2029 (Forbes (Moor Insights & Strategy), 10 June 2025) https://www.forbes.com/sites/moorinsights/2025/06/10/ibms-vision-for-a-large-scale-fault-tolerant-quantum-computer-by-2029/

17. Post-Quantum Migration Guide for Digital Asset Custody (Silence Laboratories) https://silencelaboratories.com/blog/post-quantum-migration-guide

18. NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration (Quantum Safe News Center) https://www.gopher.security/news/nist-post-quantum-cryptography-migration-roadmap

19. NIST Post-Quantum Cryptography Standards: Complete Guide to FIPS 203, 204, 205 (QRAMM) https://qramm.org/learn/nist-pqc-standards.html

20. Michael Saylor Explains Why Quantum Computing Is Not a Threat to Bitcoin (Cryptopolitan, 10 June 2025) https://www.cryptopolitan.com/web-stories/michael-saylor-explains-why-quantum-computing-is-not-a-threat-to-bitcoin/

21. Saylor Brushes Off Quantum Fears, Says Bitcoin Can Adapt (MEXC News, 2026) https://www.mexc.com/news/785155

22. Post-Quantum Cryptography on Ethereum (ethereum.org) https://ethereum.org/roadmap/security/quantum-resistance/

23. Vitalik Buterin Unveils 4-Year Roadmap to Make Ethereum Quantum-Resistant (Fibo Crypto, 27 February 2026) https://fibo-crypto.fr/en/blog/vitalik-buterin-ethereum-quantum-resistant-roadmap-2026/

24. Vitalik Buterin Maps Quantum Upgrade to Ethereum to Replace Core Cryptography (Decrypt, 26 February 2026) https://decrypt.co/359352/vitalik-buterin-maps-quantum-upgrade-ethereum

25. Why Vitalik Believes Quantum Computing Could Break Ethereum's Cryptography Sooner Than Expected (TradingView / Cointelegraph, December 2025) https://www.tradingview.com/news/cointelegraph:128a37bc4094b:0-why-vitalik-believes-quantum-computing-could-break-ethereum-s-cryptography-sooner-than-expected/