No quantum computer can break Bitcoin, Ethereum, or another major blockchain’s core cryptography today, but researchers see a credible future risk. Most expert estimates place the earliest realistic breach eight to 18 years away. Because cryptographic migrations take years, NIST already advises organizations to begin moving toward quantum-resistant systems before a cryptographically relevant quantum computer appears.
The threat focuses mainly on digital signatures rather than blockchain hashing. Shor’s algorithm could eventually attack the elliptic curve systems that prove ownership of crypto wallets. Meanwhile, Grover’s algorithm offers only a square-root speedup against hash functions. That leaves 256-bit hashes with roughly 128-bit effective security, which remains beyond practical attack levels.
Bitcoin mining relies on SHA-256 hashing, so Grover’s algorithm would not give attackers an easy route to break the network. The more serious risk concerns wallet signatures. Bitcoin and Ethereum use ECDSA, while Solana uses EdDSA. Shor’s algorithm could theoretically solve the mathematical problems behind those schemes and allow attackers to forge transactions.
That distinction separates confidentiality from authenticity. A quantum attacker would not decrypt coins stored on-chain. Instead, the attacker could forge a valid signature after obtaining an exposed public key.
A cryptographically relevant quantum computer, or CRQC, would need enough stable logical qubits to run Shor’s algorithm against real ECC keys within a useful period. No such machine exists. Google researchers recently cut their estimate for breaking 256-bit elliptic curve cryptography to about 1,200 logical qubits. Today’s processors still contain noisy physical qubits, while error correction remains the central bottleneck.
Citi Institute places the chance of a CRQC at roughly 19% to 34% by 2034, rising to 60% to 82% by 2044. If migration takes years, how long can networks safely wait?
The security framework often called Mosca’s theorem compares three factors. These include how long data must remain secure, how long migration takes, and when a CRQC may arrive. For crypto, that framework matters most for long-term holdings. Cold storage, inheritance plans, treasury reserves, and dormant wallets may remain exposed for many years before owners move them.
Read More: Sui Prepares Quantum-Safe Accounts Without New Wallet Addresses
NIST has already finalized its main post-quantum cryptography standards. It also expects to deprecate quantum-vulnerable algorithms by 2035, while high-risk systems may need earlier transitions.
Google has set an internal migration target near 2029. Ethereum’s roadmap also targets full post-quantum protection around 2029, according to the material reviewed. At the same time, the wider crypto ecosystem faces a larger coordination task. Exchanges, wallet providers, custodians, and blockchains must test and deploy new cryptography before a CRQC makes legacy signatures unsafe.
Quantum computers do not threaten major blockchains today, but future systems could target wallet signatures rather than mining hashes. With NIST standards finalized and migration taking years, crypto networks, exchanges, custodians, and wallet providers face pressure to adopt post-quantum protections before cryptographically relevant hardware arrives.