πŸ’° Read News and Earn $USDT Β· Cryptews β€” Read to Earn Platform Get Started

Cryptopolitan Report: Nearly Half Of Our Readers Think Quantum Breaks Bitcoin By 2035

1 hour ago 324

We asked our newsletter readers whether quantum computing would be able to break Bitcoin by 2035. Last week, on July 28, an AI model that has not been publicly released found a flaw in a post-quantum signature scheme that two years of human review had missed. No quantum computer was involved here. This report goes through what Bitcoin actually relies on, the actual threat to BTC and why what happened last week adds a whole new dimension alongside the quantum timeline.Β 

Where Our Readers Landed

Add those who responded β€œyes, they probably will” to the β€œbefore 2030” cohort and what you get is 47% of readers see the potential of a quantum break on Bitcoin within the next nine years. To this day, the largest elliptic-curve key broken on real quantum hardware is 15 bits, which happened in April this year by a researcher claiming Project Eleven’s Q-Day Prize. For context, Bitcoin’s keys are 256 bits and getting from one to the one within the span of nine years is going to require an extraordinary run of engineering innovation. Roughly third of this audience is currently seeing this as a real possibility.Β 

What is Actually At Risk For BTC

Before we go on to discussing in depth what the poll reveals, it’s important to clarify that Bitcoin does not encrypt anything. There is no secret message being scrambled and every transaction on the network has always been public since inception. What Bitcoin does is sign and hash. Two different jobs, two different pieces of maths, two very different quantum timelines.Β 

The signing part is the exposed part and where there is a vulnerability. When you spend Bitcoin, your wallet produces a signature proving you own the coins and this is done on an elliptic curve cryptography called secp256k1. Bitcoin has used two signing methods over the years, ECDSA from the start and Schnorr since 2021. The security in both methods rests on one assumption, which is that deriving a private key from a public key is impossible.Β 

This is where Shor’s algorithm comes into the picture and targets that assumption. Given a large enough quantum computer, it can work backwards from a public key to the private key that generated it. In March this year, Google researchers published estimates putting the requirement at less than 1,200 logical qubits and under 500,000 physical qubits. A later paper from Caltech and Oratomic brought that as low as 10,000 qubits using a neutral-atom architecture. Nobody has built anything close. But those numbers used to run into the millions, and the direction of travel is the reason Bitcoin developers stopped treating this as a problem for the 2040s.Β 

The hashing side is in far better shape. Bitcoin uses SHA-256 for mining, for address generation, and for linking blocks together. The best quantum attack against it is Grover’s algorithm, which offers only a quadratic speedup. In practice that reduces 256-bit security to something like 128-bit, which remains well beyond reach for any machine anyone has sketched on paper. Mining is not the weak point here, and neither is the chain structure.

So the accurate framing is narrower than β€œquantum breaks Bitcoin.” What is at risk are coins whose public keys are already sitting on the chain in plain view. That happens when an address has been spent from before, or when funds sit in older address formats that expose the key by default. The current estimate is somewhere between 6.5 and 6.9 million BTC, roughly a quarter to a third of total supply, and that figure includes around 1.7 million coins in early addresses widely believed to belong to Satoshi.Β 

Coins held in modern addresses that have never been spent from do not expose a public key at all. For those, a quantum attacker would only get a window during the few minutes a transaction sits in the mempool waiting to confirm. Still a problem worth solving. A much smaller one than the headline number suggests.

Bitcoin’s Answer To The Quantum Problem

On February 11, 2026, BIP-360 was merged into the official Bitcoin BIP repository, the network’s first formal quantum-resistance proposal to get that far. It introduces a new output type called Pay-to-Merkle-Root, or P2MR, authored by Hunter Beast, Ethan Heilman and Isabel Foxen Duke.

P2MR is essentially Taproot with the key-path spend removed. Taproot commits to both an internal public key and a Merkle root of scripts, which means the key is always derivable from what sits on the chain. P2MR commits only to the Merkle root. No public key appears until you actually spend, and even then only the leaf you used. It closes the long-exposure hole.

A companion proposal, BIP-361, arrived on April 14 with a three-phase plan to sunset ECDSA and Schnorr spends entirely. That is the one causing arguments, because phase three effectively freezes coins that never migrate.

Here is the part worth sitting with. Heilman’s own estimate is seven years from the moment consensus forms to full quantum resilience, and he calls that optimistic. Two and a half years for review and testing. Half a year to activate. Then five more years before roughly 90% of wallets, custodians, Lightning nodes and treasury software have actually upgraded. Notably, BIP-360 does not include post-quantum signatures at all. Those were stripped out in July 2025 and deferred to a future proposal. The scheme Bitcoin eventually adopts will most likely be ML-DSA or SLH-DSA, the algorithms NIST has already finalised.

Which brings us to last week.

A Post-Quantum Scheme Failed and No Quantum Computer Was Involved

On July 28, Anthropic’s Frontier Red Team published a finding from Claude Mythos Preview, a model that is not publicly available. Working semi-autonomously in an agentic setup, it found a previously unknown attack against HAWK, one of nine finalists in NIST’s additional post-quantum signature competition and the only lattice-based scheme to advance to round three in May.

The attack exploited a symmetry in HAWK’s lattice structure that nobody had used before. For the HAWK-256 parameter set, it dropped the estimated work for key recovery from about 2^64 operations to roughly 2^38. In plain terms, that is the gap between β€œno attacker on earth is doing this” and β€œa well-funded team could plausibly try.”

Now the details that make this uncomfortable. HAWK had already survived two rounds of expert human review across two years. The model found the flaw in about 60 hours, at a cost of roughly $100,000 in API spend. The researcher supervising the project had a theoretical computer science background and was not a lattice cryptography specialist.

Sophie Schmieg, a post-quantum cryptographer at Google, summed it up in five words: β€œBasically with this paper, HAWK is dead.” The HAWK team withdrew the scheme from NIST consideration the following day, noting that the obvious fixes, doubling parameters or moving to higher-rank modules, would leave it uncompetitive against the alternatives.

No quantum computer was involved at any point. The thing that broke was post-quantum cryptography, and a classical AI model broke it over a long weekend.

What The Poll Actually RevealedΒ 

Every option in our poll asked the same underlying question: when does the quantum hardware arrive. Readers split reasonably on that, and 47% landing inside nine years is a defensible read given how the qubit estimates have moved this year.

But the HAWK result suggests the hardware timeline may not be the binding constraint. The 33% who voted β€œnot that soon” or β€œonly after 2050” were making a bet about quantum engineering, and they might well be right about it. That bet does not protect them from a classical attack on the replacement algorithm.

The 20% who said β€œno idea” deserve some credit here. In an audience that follows this closely, one in five declining to guess is not apathy. It reads more like an accurate assessment of how many unknowns are stacked on top of each other: hardware progress, algorithm selection, consensus timelines, and now AI-assisted cryptanalysis moving faster than the review process built to catch it.Β 

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Read Entire Article
πŸ’¬ Comments
Loading…

Log in to leave a comment.