Bitcoin’s quantum threat has suddenly acquired something crypto developers tend to notice: a deadline.
Washington is pouring up to $300 million into three quantum-computing companies just as Bitcoin and Ethereum engineers are planning how to replace the cryptography that protects billions of dollars in digital assets.
On Tuesday, the U.S. Commerce Department finalized CHIPS Act awards worth as much as $100 million each for Rigetti, D-Wave and Quantinuum. The government is also taking minority stakes in the companies, with the funding aimed at expanding quantum hardware, manufacturing and error-correction technology.
That matters because the machines themselves are still far from being capable of cracking Bitcoin or Ethereum. But the clock is being set around the same period that developers have started treating as the critical window for migration.
Ethereum has gone the most explicit route. Its protocol team has chosen December 2029 as an internal target for making the network’s base layer resistant to quantum attacks across execution, consensus and data.
In practice, that means Ethereum is planning on the assumption that a so-called Q-day could arrive as early as 2030, even though there is no certainty that a machine capable of attacking today’s cryptography will exist by then.
Bitcoin has no comparable network-wide deadline. Still, work around two proposals has accelerated this year: BIP-360, which introduces a post-quantum output type, and BIP-361, which outlines a phased transition away from ECDSA and Schnorr signatures.
The Bitcoin quantum threat is not simply about building a faster computer. It is also about giving an enormous global network enough time to replace the cryptographic machinery embedded throughout it.
Bitcoin’s quantum threat is becoming a migration problem
For Bitcoin, one of the thorniest issues is already sitting on the blockchain.
Millions of coins are held in addresses where public keys have been exposed. That includes an estimated 1 million BTC associated with Bitcoin creator Satoshi Nakamoto, making older holdings an obvious point of concern if sufficiently powerful quantum machines eventually become practical.
BIP-361 proposes restricting legacy signatures after a migration period. That could create an uncomfortable trade-off: protecting the network may eventually require limiting access to coins whose owners never move them to newer, quantum-resistant addresses.
Ethereum has a different headache. Its foundation already has a dedicated post-quantum team and a fixed target, but upgrading the underlying protocol is only part of the job.
Wallets, decentralized applications and users would also have to adopt new signature systems. A network can change its cryptography on paper much faster than millions of people and pieces of software can change their habits in the real world.
The hardware race explains why developers are planning before the danger becomes visible.
Google Quantum AI estimated earlier this year that breaking 256-bit elliptic-curve cryptography could require fewer than 1,200 error-corrected qubits. A qubit is the quantum equivalent of the basic information unit used in conventional computing, although the comparison between quantum machines and today’s cryptographic security is more complicated than a simple hardware score.
IBM, meanwhile, plans to deliver Starling in 2029, targeting a fault-tolerant system capable of running 100 million gates on 200 logical qubits. Quantinuum is also aiming for hundreds of logical qubits around the same period.
Those numbers cannot be directly lined up against Google’s estimate as though they were measuring the same thing. They do, however, illustrate why crypto developers are reluctant to wait for a cryptographically relevant machine to arrive before beginning the migration.
That is the real tension behind the Bitcoin quantum threat. The problem is not that a quantum computer is about to empty wallets tomorrow. It is that replacing cryptography across mature networks takes time, coordination and, eventually, user action.
Bitcoin’s approach is especially difficult because of the scale and history of its installed base. Ethereum’s challenge is less about dormant coins and more about coordinating a sprawling ecosystem of protocols, applications and wallets around new cryptographic assumptions.
The race, then, is happening on two different tracks. Quantum engineers are trying to make fault-tolerant machines practical, while crypto developers are trying to make sure their networks no longer depend on vulnerable cryptography before those machines get there.
The Bitcoin quantum threat may still belong to the future. The deadline for preparing for it does not.
