Loading market data...

Quantum Risk to Bitcoin Could Trigger Panic Before Any Hack, Experts Warn

Quantum Risk to Bitcoin Could Trigger Panic Before Any Hack, Experts Warn

Two researchers are warning that the crypto industry is treating the quantum computing threat too casually. Stefano Gogioso and Daniela Herrmann argue that the real danger isn't just a future hack — it's the psychological panic that could hit long before any actual quantum theft. The key question, they say, is the probability and cost of a quantum attack, not the specific year.

The probability that matters

Gogioso argues that even a 2% probability of a quantum tail event by 2030 could lead to trillions in losses, potentially wiping out most of crypto value. The cost of preparing quantum-resistant cryptography is trivial compared to that potential loss. But the industry isn't moving fast enough.

Timeline keeps shrinking

Herrmann notes that estimates for practical quantum computing have rapidly shrunk: from 30 years in 2024, to 15-20 years in 2025, to 3-5 years in 2026, and as low as 1-2 years by October 2026. Google has set an internal 2029 target to move its own products onto quantum-resistant encryption. In May 2025, Google researcher Craig Gidney showed that breaking RSA-2048 might need fewer than 1 million qubits, down from his 2019 estimate of about 20 million. In March 2026, Google Quantum AI, the Ethereum Foundation, and Stanford estimated that breaking Bitcoin's elliptic-curve cryptography (secp256k1) could take fewer than 500,000 physical qubits, roughly 20 times lower than the previous best estimate. Gidney does not expect another tenfold drop without new assumptions; further reductions shift the burden to unsolved engineering problems.

The nine-minute window

The attack mechanism is precise: when a Bitcoin is spent, the public key is briefly exposed. A quantum computer could derive the private key in about nine minutes, within Bitcoin's average block time of 10 minutes. That means an attacker could steal funds before the network even confirms the transaction.

The real weakness is psychological

Gogioso emphasizes the real weakness is psychological: if one Satoshi-era coin is moved with a message like 'you've been quantum punked', panic could cause a market collapse regardless of actual protection. Herrmann draws a parallel to tulip mania: belief can hold until the instant it breaks, and institutional asset managers would flee at the first sign of a quantum theft. The industry has yet to adopt quantum-resistant cryptography at scale. The question is whether it will act before a single Satoshi-era coin moves with a message.