How many qubits would it take to break Bitcoin's encryption?

Started by VB, Jul 19, 2026, 07:52 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: How many qubits would it take to break Bitcoin's encryption?   Views(Read 66 times)

VB

Genuine question, is there an actual number of qubits that would be needed to crack Bitcoin's cryptography?
The truth is usually more complicated than the headline

Beth

Estimates generally range from several thousand to a few hundred thousand physical qubits depending on the error correction approach used, current quantum computers sit around 1,000 to 1,500 physical qubits, so there's still a real gap. That required number has been shrinking over time though as error correction techniques improve, which is why the estimate isn't a fixed target

Panda54

The short answer is: we don't know precisely, but it's a lot more than current quantum computers have. Bitcoin uses ECDSA with secp256k1, which relies on the difficulty of solving the discrete logarithm problem. A sufficiently powerful quantum computer could run Shor's algorithm and crack that in polynomial time. Estimates vary wildly - some papers suggest 2,000-3,000 logical qubits would be enough, but that's before error correction. Physical qubits needed could be 100x or 1000x higher depending on error rates. Current state-of-the-art is maybe 1,000 noisy physical qubits, nowhere near stable enough. So we're probably decades away, if it's even feasible at that scale. :) The real question isn't "can it be done" but "can it be done before Bitcoin upgrades its crypto."
All original content unless stated

FrostDrifter

Last post is right about the range, but let's get specific. A 2017 paper by Roetteler and Svore estimated around 2,330 logical qubits and about 100 million physical operations to break a 256-bit elliptic curve key. More recent work suggests you'd need somewhere between 20,000 to 400,000 physical qubits when you factor in error correction overhead. The variance comes from assumptions about qubit quality and error rates. Current quantum processors from IBM and Google top out around 1,000-4,000 physical qubits, and they're extremely noisy. Error correction is the bottleneck - you might need 1,000 physical qubits to make one stable logical qubit. That's why the "hundreds of thousands" estimate keeps appearing. ;D The other thing people forget: even if you have the qubits, you need to run the algorithm before decoherence kills your computation. That's a whole other challenge.

Hydra47

Going to push back on the timeline a bit - everyone assumes quantum computers will scale linearly, but we've been stuck in the "few hundred qubits" range for years now. The engineering challenges are brutal. Cooling, isolation, error rates, connectivity between qubits - every improvement creates new problems. Some physicists argue we might hit fundamental limits before reaching the qubit counts needed for cryptanalysis. That said, I wouldn't bet my life savings on it. The risk is asymmetric: if quantum computers do scale, Bitcoin is toast unless it migrates to quantum-resistant signatures beforehand. The good news? We know what those look like. Lattice-based cryptography, hash-based signatures - NIST is already standardizing post-quantum algorithms. The transition would be messy but doable. :-\ The real question is political, not technical: can the community agree on a fork before crisis hits?

BetaMyles75

Tangent: the quantum threat to Bitcoin is overblown, but not for the reasons people think. Sure, a quantum computer could derive your public key from your address... except your public key isn't public until you spend from that address. If you use each address once (which you should), a quantum attacker would need to crack your key in the few seconds between broadcast and confirmation. That's a much harder problem than just "break ECDSA." They'd need a quantum computer with microsecond latency to the network, which is... unlikely. :( The real vulnerability is reused addresses - people who've spent from an address before have exposed their public key permanently. Those are quantum-vulnerable today, theoretically. So the practical advice: don't reuse addresses, and if you're paranoid, move old coins to new addresses. The quantum apocalypse can wait.

Inland Renegade

The estimates keep shifting because quantum computing is still experimental physics, not engineering. We don't have reliable models for how error correction scales at millions of qubits. Some researchers think topological qubits (Microsoft's approach) could dramatically reduce overhead, but that tech is years behind superconducting qubits. Others argue we'll need entirely new architectures. The uncertainty is frustrating. :o Here's what I tell people: if you're holding long-term, assume quantum computers will eventually be a threat and plan accordingly. That doesn't mean selling - it means using modern wallets with address rotation, maybe diversifying into projects actively working on quantum resistance. The Bitcoin community has been surprisingly slow on this front. We've had a decade to prepare and most devs still treat it as "not our problem." That's going to end badly.
Still figuring it all out

Andy99

Love the technical discussion, but can we talk about the incentive structure? If someone builds a quantum computer capable of breaking ECDSA, why would they announce it? They could quietly drain vulnerable wallets for years before anyone noticed. By the time the community reacts, the damage is done and Bitcoin's reputation is toast. That's the real risk - not the technology itself, but the economic incentives around disclosure. A rational actor with that capability would exploit it stealthily. >:( The only defense is assuming the threat exists even if we haven't seen it. Again: address rotation, post-quantum migration, and maybe keeping some coins in quantum-resistant alts as insurance. The optimist in me thinks the crypto community would rally and fork quickly if this became real. The pessimist remembers how long it took to get SegWit approved.

CosmicRay91

Numbers game: let's say you need 300,000 physical qubits with current error rates. IBM's roadmap targets 100,000 qubits by 2033, but that's aspirational. Google, Rigetti, and others are on similar timelines. Even if they hit those targets, you need error rates low enough to run Shor's algorithm for hours without decoherence. That's the real bottleneck - coherence time. Current qubits stay coherent for milliseconds. You'd need orders of magnitude improvement. Some papers suggest you could break ECDSA with fewer qubits if you have enough time and can run the algorithm iteratively, but that requires memory qubits that can store state for extended periods. We don't have that yet. 8) The timeline is probably 15-30 years for a credible threat, assuming steady progress. But "steady progress" in quantum computing has been a joke for two decades. Could be tomorrow, could be never.

Ruby92

Hot take: the quantum threat is a feature, not a bug. It forces the crypto ecosystem to evolve. Bitcoin maximalists hate this conversation, but every encryption scheme in history has eventually been broken. DES, MD5, SHA-1 - they all fell. ECDSA will too, quantum or not. The question is whether we adapt in time. The cool thing about Bitcoin is that it has a built-in governance mechanism: soft forks and hard forks. If quantum computers become a real threat, the network can migrate to post-quantum signatures. It'll be contentious, sure, but it'll happen. The real risk is complacency. ::) We've gotten lazy assuming "it can't be broken." That's not how security works. You assume it will be broken and design accordingly. Bitcoin was designed in 2008 with 2008 threats in mind. We're in 2026 now. Time to update the threat model.
Not financial advice. Not medical advice. Just vibes.

NightHarbour30

Meta-point: the quantum discussion reveals something interesting about Bitcoin's security model. It's not actually "unbreakable" - it's "unbreakable with current technology and economic incentives." That's always been the case. The difference with quantum is that it's a foreseeable, binary threat. Either someone builds a large-scale quantum computer or they don't. There's no gradual improvement in attack methods like classical computing. When the threshold is crossed, it's game over for ECDSA. That's why the timeline matters more than the exact qubit count. If we have 20 years, we're fine. If we have 5, we're in trouble. :-\ The uncertainty is the problem. Nobody knows when the threshold will be crossed because quantum computing progress is lumpy and unpredictable. Best case: we get clear warning signs (qubit counts scaling, coherence times improving) and can migrate proactively. Worst case: someone announces a breakthrough and we have months to react. I know which scenario keeps me up at night.

CodyRhodes29

The last post about public key exposure is crucial and often overlooked. Your Bitcoin address is a hash of your public key, not the key itself. Hash functions (SHA-256 and RIPEMD-160) are quantum-resistant in practice - Grover's algorithm only gives a quadratic speedup, which you counter by doubling key sizes. The vulnerability is only the signature, which requires the public key. So yes, unused addresses are safe-ish. But here's the rub: if you've ever spent from an address, your public key is on-chain forever. Anyone with a quantum computer could retroactively derive your private key and steal those coins. That's billions in "vulnerable" Bitcoin right now, sitting in addresses that have been used before. :'( The only fix is moving to new addresses with quantum-resistant signatures before the threat materializes. Problem is, nobody knows when that is. Could be 2040, could be never, could be last Tuesday.

ProperJobs89

Can we talk about the difference between logical and physical qubits? This is where the estimates get muddy. A logical qubit is an error-corrected, stable qubit - what you actually need for computation. A physical qubit is the raw hardware, which is noisy and error-prone. Depending on error rates, you might need 100 to 10,000 physical qubits per logical qubit. So when someone says "2,000 qubits can break Bitcoin," they mean 2,000 logical qubits, which could be 200 million physical qubits. That's why the range is so wide. Current machines have maybe 1,000-4,000 physical qubits with error rates that make them useless for Shor's algorithm. We're probably 3-4 orders of magnitude away. ;D The other factor: not all qubits are equal. Superconducting, trapped ion, photonic, topological - each has different error profiles and scaling characteristics. Nobody knows which will win.

Related Topics (1)

Save money on everyday spending Free cashback on thousands of retailers
View offer