Could Quantum Computers Break Bitcoin? An Honest Explainer
A large enough quantum computer could in theory forge Bitcoin signatures, but none can today. See what is at risk, what is not, and what could be done.
By Christopher Cannucciari · Published

Key takeaways
- No quantum computer that exists today can break Bitcoin. The concern is about a possible future machine far larger and more reliable than current ones.
- The exposed part, in theory, is the signature scheme that proves you may spend a coin. Hashing, which secures mining and shields public keys in many addresses, is much less affected.
- Coins in addresses whose public key is already visible on the blockchain are the most exposed, which is one more reason to avoid address reuse.
- Experts disagree widely about when, or whether, a large enough quantum computer will exist. This article gives no dates and makes no forecasts.
- A fix is possible in principle, but moving a decentralized network to new cryptography is a hard coordination problem.
Could a quantum computer break Bitcoin?
In theory, a large enough quantum computer could forge Bitcoin signatures and so take coins that belong to someone else, but no machine that exists today comes close to doing this. The risk is real as a research question and unresolved as a practical one.
A quantum computer is a different kind of machine, built to solve certain problems that ordinary computers find impractical. It does not speed up everything. For a few specific mathematical problems, though, known quantum algorithms offer enormous speedups, and some of those problems are the ones that protect Bitcoin’s signatures. The word “theory” matters: running those algorithms against real-world keys would take a machine with many reliable components working together, and today’s machines are far from that.
Plenty of serious people are watching the field, including cryptographers and Bitcoin developers. Their views on how worried to be differ, and the sections below separate what is established from what is disputed. To follow the technical terms, How Does Bitcoin Work? explains keys, signatures and hashing in plain language.
Which parts of Bitcoin are exposed, and which are not?
The signature scheme is the part that is exposed in theory, while the hashing is much less so. Bitcoin relies on two kinds of cryptography, and quantum computing affects them very differently.
Signatures. When you spend bitcoin, you prove you hold the private key by making a digital signature. Bitcoin’s signatures are based on elliptic-curve cryptography. A sufficiently powerful quantum computer running a known algorithm, called Shor’s algorithm, could in principle work out a private key from its matching public key. That would let an attacker sign transactions as the owner. This is the main theoretical concern.
Hashing. Mining and address creation use hash functions such as SHA-256. Quantum computers also offer a speedup against hash searching, using a different algorithm, but it is much smaller. It would weaken hash security by far less than the break threatened for signatures, and it can be offset by using longer outputs. For that reason, the mining side and the hashing inside addresses are not thought to be the weak point.
Inside a Bitcoin Mining Operation explains how hashing is used in mining.
Why do exposed public keys matter?
Exposed public keys matter because the signature attack starts from a public key, so coins whose public key is already visible are the easiest targets. A public key is the number your wallet derives from your private key. Most addresses do not contain it directly. Instead, many address types contain a hash of the public key, and the public key itself is not revealed until you spend from that address.
Once you spend, the public key appears on the blockchain, where everyone can see it. If you reuse that address and leave more bitcoin in it, the leftover coins sit behind a key that is now public. A quantum attacker would only need to derive the private key from the public one. Some very early coins sit in an older output type that places the public key directly on the blockchain from the start. The newer Taproot address type also publishes a key in the output.
This is also why address reuse is a bad habit for privacy reasons already, as What Is a Bitcoin Address? explains. A fresh address for each payment keeps keys hidden until the moment of spending, and that leaves a smaller window of exposure.
When could this happen? Experts disagree
Nobody knows when a quantum computer capable of breaking Bitcoin’s signatures might exist, and expert opinion on timing differs widely. Some researchers consider it a distant prospect or doubt it will ever be practical. Others take it seriously enough to prepare now, because upgrades to widely used systems take many years, and because data encrypted today could be targeted later.
The reasons for the disagreement are technical. Quantum computers are easily disturbed by their surroundings, which causes errors, and correcting those errors takes very large numbers of components working together. How quickly engineers overcome that, and whether they can build machines of the needed size at all, is uncertain, so every timeline is a guess and some are more confident than the evidence supports.
For that reason, this article gives no dates. Be careful with anyone who does: a headline claiming that Bitcoin is about to be broken is as unfounded as an assurance that the issue will never matter. The sensible position is to take the question seriously without panic, and to watch for credible updates from cryptographers and from standards bodies. For example, the US standards body NIST has published standards for some quantum-resistant algorithms, which shows that the wider tech world is working on the same problem.
What would a quantum-resistant Bitcoin involve?
A quantum-resistant Bitcoin would need new kinds of signatures that quantum computers cannot break, plus a way for people to move their coins to addresses that use them. Cryptographers have designed such signature schemes, and they exist as research and in standards. The hard part is not inventing them but deploying them on a network that has no owner.
Bitcoin has no central operator who can push an update. A new signature type would likely be added as an optional upgrade, which node operators, miners and wallet makers would each have to adopt. Then every holder would need to move their coins to the new type, using a transaction that costs a fee and takes space in blocks. Some new schemes also produce larger signatures, which affects how many transactions fit in a block, so there are trade-offs to weigh.
The thornier question concerns coins that never move. Some are in wallets whose owners are gone or whose keys are lost, and those cannot be migrated. What the community should do about them, if anything, is a hard debate, and there is no agreed answer. The same difficulty of agreeing on changes is discussed in How Many Bitcoin Are Left to Mine? in the context of the supply cap.
What can you do as an individual?
As an individual, you can avoid address reuse and stay informed, and there is little else you need to do today. Practical steps:
- Use a fresh address for each payment. Most wallets do this automatically, and it keeps your public key hidden until you spend.
- Do not leave a balance in an address you have already spent from. If you spend from an address, move the remainder to a new one, which most wallets handle for you.
- Keep your own keys backed up and secure, because ordinary theft and loss are far more likely threats than quantum attacks. The Power of Self-Custody covers backups and safe storage.
- Follow reliable sources. If a real migration path appears, wallet software is likely to guide users through it.
Do not rush into unfamiliar products or “quantum-proof” offers, which are a common hook for scams. A calm approach is justified, and for personal financial decisions a qualified professional can advise on your circumstances. If you are still building the basics, the Start Here path lists the core articles in order.
Where to go next
- What Is a Bitcoin Address?: address types, reuse and why fresh addresses help.
- How Does Bitcoin Work?: keys, signatures and hashing in plain language.
- The Power of Self-Custody: safe storage and backups for your own keys.
- Is Bitcoin Safe? The Real Risks and Common Scams: the risks that matter most today.
Frequently asked questions
Can quantum computers break Bitcoin today?
No. No quantum computer that exists today can break the cryptography Bitcoin uses. The concern is about a possible future machine that is far larger and more reliable than anything built so far.
Which part of Bitcoin is vulnerable to quantum computers?
In theory the digital signature scheme is the exposed part. It is based on elliptic curves, and a large quantum computer running a known algorithm could work out a private key from a public key. The hashing used in mining and addresses is much less affected.
When will quantum computers be a threat to Bitcoin?
Nobody knows. Experts disagree widely, with some expecting a threat within a modest time frame and others doubting a machine of the needed size will ever be built. Treat any specific date you read with caution.
Can Bitcoin be upgraded to resist quantum attacks?
Yes in principle. Bitcoin could add new kinds of signatures designed to resist quantum computers, and people would move their coins to new address types. The hard part is agreement and coordination across a decentralized network, not the existence of the cryptography.
What can I do to protect my bitcoin from quantum computers?
Avoid reusing addresses, since an address you have already spent from has revealed its public key. Use a fresh address for each payment, and follow developments from reliable technical sources. No other action is needed today.



