TECH
Quantum computing is an inevitable threat to bitcoin?
There is a question that has accompanied Bitcoin almost since quantum computing began to advance: what would happen if a sufficiently powerful machine managed to break the cryptography protecting digital currencies? This hypothesis has already raised alarms among researchers, investors, and developers. Now, two studies viewed side-by-side suggest a much more complex—and potentially reassuring—scenario, although the debate is far from over.
The quantum threat to Bitcoin is primarily linked to the elliptic curve cryptography used in its digital signatures. In theory, a sufficiently advanced quantum machine could use Shor's algorithm to solve the mathematical problem protecting certain keys.
Quantum computers and cryptography...A great amount of digital ink has been spilled on the topic of how quantum computers pose an existential threat to currently used asymmetric cryptography. We will therefore not discuss this in detail, but only explain the aspects that are relevant for the analysis in this article.
In asymmetric cryptography, a private-public key pair is generated in such a manner that the two keys have a mathematical relation between them. As the name suggests, the private key is kept as secret, while the public key is made publicly available. This allows individuals to produce a digital signature (using their private key) that can be verified by anyone who has the corresponding public key. This scheme is very common in the financial industry to prove authenticity and integrity of transactions.
The security of asymmetric cryptography is based on a mathematical principle called a “one-way function”. This principle dictates that the public key can be easily derived from the private key but not the other way around. All known (classical) algorithms to derive the private key from the public key require an astronomical amount of time to perform such a computation and are therefore not practical. However, in 1994, the mathematician Peter Shor published a quantum algorithm that can break the security assumption of the most common algorithms of asymmetric cryptography. This means that anyone with a sufficiently large quantum computer could use this algorithm to derive a private key from its corresponding public key, and thus, falsify any digital signature.
Bitcoin 101...To understand the impact of quantum computers on Bitcoin, we will start with a brief summary about how Bitcoin transactions work. Bitcoin is a decentralized system for transferring value. Unlike the banking system where it is the responsibility of a bank to provide customers with a bank account, a Bitcoin user is responsible for generating his own (random) address. By means of a simple procedure, the user's computer calculates a random Bitcoin address (related to the public key) as well as a secret (private key) that is required in order to perform transactions from this address.
Moving Bitcoins from one address to another is called a transaction. Such a transaction is similar to sending money from one bank account to another. In Bitcoin, the sender must authorize their transaction by providing a digital signature that proves they own the address where the funds are stored. Remember: someone with an operational quantum computer who has your public key could falsify this signature, and therefore potentially spend anyone’s Bitcoins!
In the Bitcoin network, the decision of which transactions are accepted into the network is ultimately left to the so called miners. Miners compete in a race to process the next batch of transactions, also called a block. Whoever wins the race, is allowed to construct the next block, awarding them new coins as they do so. Bitcoin blocks are linked to each other in a sequential manner. Together, they form a chain of blocks, also called the “blockchain”.
The victorious miner who creates a new block, is free to include whichever transaction they wish. Other miners express their agreement by building on top of blocks they agree with. In case of a disagreement, they will build on the most recently accepted block. In other words, if a rogue miner attempts to construct an invalid block, honest miners will ignore the invalid block and build on top of the most recent valid block instead.
Under certain circumstances, this would allow a private key to be derived from public information, thereby compromising funds.
A new chapter in this story has emerged with a study by researchers from Chinese universities. They calculated the resources required to solve the so-called discrete logarithm problem on 256-bit elliptic curves.
The result is striking: approximately 835 logical qubits would be required.
This estimate represents a reduction compared to previous calculations, which pointed to 1,098 or 1,175 qubits in certain configurations. For the secp256k1 curve used by Bitcoin, the researchers also arrived at a figure of 835 logical qubits, while estimating a cost of approximately 230.88 million Toffoli gates.
At first glance, reducing the resources needed for an attack seems like terrible news.
But there is another figure that completely changes the interpretation.
A potential physical barrier stands in the way of quantum computers... Physicist Tim Palmer, from the University of Oxford, is working on a formulation called Rational Quantum Mechanics. Among the implications discussed in this work is a hypothesis that is particularly relevant to large-scale quantum computing.
Investor Fred Krueger publicly linked this research to the new cryptography calculations and highlighted a potential limitation of approximately 400 coherently entangled qubits. It is precisely the difference between the two numbers that has sparked interest.
If breaking a 256-bit cryptographic curve requires around 835 logical qubits, yet there exists a fundamental physical barrier near 400 coherently entangled qubits, a quantum computer capable of executing such an attack could face an obstacle far deeper than merely scaling up its technological capacity.
In other words, it would not simply be a matter of waiting for better computers.
Physics itself could impose a limit.
This interpretation, however, hinges on important conditions. Palmer’s hypothesis does not definitively establish that no quantum system can surpass this threshold, nor does it prove in isolation that Bitcoin is permanently secure.
For now, it remains a theoretical possibility contrasted against another estimate.
Logical qubits are not the same as the qubits advertised by companies...There is yet another essential detail to understanding why these numbers can be misleading.
The 835 qubits mentioned in the study are logical qubits, not merely physical qubits.
Real-world quantum computers suffer from noise and errors. Constructing a single reliable logical qubit—protected by error-correction systems—may require many physical qubits.
This means that a machine capable of carrying out a cryptographically relevant attack would need to be far more sophisticated than a computer simply advertised as having 835 qubits.
The researchers themselves acknowledge that quantum algorithms relevant to cryptography continue to face limitations regarding hardware, error correction, and the need to maintain sufficiently low error rates.
Consequently, the scenario of a quantum computer stealing bitcoins does not appear imminent.
However, this does not mean developers are ignoring the issue.
The technical community has been exploring ways to make the protocol more resilient should cryptographically relevant computers actually emerge.
One such initiative is BIP-360, a proposal introducing a new type of output called Pay-to-Merkle-Root, or P2MR. Its goal is to reduce exposure to certain long-term quantum attacks by removing a vulnerable spending path associated with elliptic curve cryptography.
The proposal itself makes it clear that this alone would not resolve all possible attacks.
More comprehensive protection might eventually require the introduction of post-quantum signature schemes. The idea is to allow Bitcoin to evolve gradually as the actual threat level becomes clearer.
This precaution is important because there are still many unknowns.
By March 2026, a Google Quantum AI study had already reignited the discussion by indicating that the resources required to attack the encryption used by Bitcoin could be significantly lower than previous estimates suggested. Even so, there is currently no quantum machine capable of executing such an attack under real-world conditions.
The threat has not vanished, but the story has become more complex...It would be premature to declare Bitcoin definitively secure against quantum computers.
These new studies do not settle the debate; in fact, they add another layer of uncertainty.
On one hand, researchers continue to find ways to reduce the theoretical resources needed to break cryptographic systems. On the other, there are hypotheses suggesting that fundamental physical limitations could prevent quantum computers from reaching the necessary scale.
While this contest plays out in laboratories, Bitcoin developers are working on alternatives to avoid relying on a single bet regarding the future.
Perhaps this is the most important conclusion.
Bitcoin’s security in the face of quantum computing depends on more than just determining whether a machine capable of cracking its encryption might one day exist. There is also a race to modify defenses before such a machine appears.
And, following these new calculations, a threat that once seemed to hinge solely on time and technological progress has raised a far more intriguing question: what if there is a barrier that even quantum computers cannot cross?
mundophone
No comments:
Post a Comment