Quantum computers could crack Bitcoin's cryptographic defenses by 2028, exposing 35 percent of the circulating supply.
Quantum computers could crack Bitcoin's cryptographic defenses by 2028, exposing 35 percent of the circulating supply.

Fundstrat's Tom Lee warned quantum computers could break Bitcoin's defenses by 2028, exposing 35 percent of supply in legacy wallets.
Lee told CNBC that Bitcoin has not reached agreement on how to prevent a quantum attack, citing Google research that quantum machines could break current encryption standards by 2028. He said Ethereum and Solana face less exposure because of their faster upgrade cycles.
Galaxy Digital estimated in March that roughly seven million Bitcoin sit in addresses that have already exposed their public key on-chain, worth about $470 billion. Glassnode put the figure at 6.04 million, or 30.2 percent of supply. Google's April 2026 whitepaper put cracking Bitcoin's elliptic-curve cryptography at fewer than 500,000 qubits, while leading quantum machines today run on roughly 1,000 to 1,200 physical qubits.
The threat has triggered a race to harden the network. BIP-360, a draft proposal to add quantum-resistant address types, has merged into the Bitcoin Improvement Proposals repository. A companion proposal, BIP-361, would phase out spending from old, exposed address types — a move that could freeze coins held in dormant wallets, including those attributed to Satoshi Nakamoto.
Bitcoin traded at $64,005.38 as of Aug. 5, up 0.54 percent over 24 hours, with market cap at $1.28 trillion and 24-hour volume at $22.99 billion, according to CoinMarketCap data.
Adam Back, creator of Hashcash and a prominent Bitcoin cypherpunk, pushed back on Lee's framing, noting that Bitcoin does not use encryption to process transactions. Coin ownership is protected by digital signatures, specifically ECDSA, and seed phrases are secured by entropy levels a quantum computer cannot brute-force. The real vulnerability, Back said, applies only to addresses whose public keys have already been exposed on-chain.
IBM chief executive Arvind Krishna told CNBC's Mad Money that investors should "get rather paranoid" about the threat in three to four years, with quantum computing expected to have a measurable impact on IBM's top line by 2028 or 2029. Ethereum Foundation researcher Justin Drake estimates a 10 percent chance a quantum computer could pull a Bitcoin key from an exposed public key by 2032.
The binding constraint is coordination, not raw cryptography. Bitcoin holds the technical tools to adapt — post-quantum signature schemes standardized by NIST in August 2024, and soft-fork mechanisms that can add new address types without forcing a hard fork. But roughly one-third of all Bitcoin sits in wallets that would need to migrate, including lost coins and the approximately one million BTC attributed to Satoshi Nakamoto.
BIP-361's proposal to restrict and eventually sunset spending from old address types has drawn sharp criticism. Supporters argue freezing dormant coins beats letting a future quantum thief drain them and dump them on the market. Critics call it confiscation.
The quantum clock is ticking for Bitcoin's legacy supply, but the timeline remains contested. No cryptographically relevant quantum computer exists today, and most researchers place practical risk a decade or more away. The debate now centers on whether the network can coordinate a migration before hardware closes the gap.
This article is for informational purposes only and does not constitute investment advice.