Quantum Won't Kill Bitcoin. We Might.
Quantum Won’t Kill Bitcoin. We Might.***
In early September 2026, just under 4,000 BTC walked out of Blockstream’s Liquid Network. The federation wallet went from 4,200 coins to 207. Whoever did it left a message on-chain claiming to be white hats and promising to return the money once Blockstream patches the bug.
It wasn’t quantum computing. It wasn’t AI. It was a bug in Elements, the Bitcoin-derived codebase that Liquid itself is built on.
A month before that, roughly 2,000 BTC left people’s hardware wallets. Coinkite, the company behind the Coldcard hardware wallet, shipped a firmware change in March 2021 that quietly routed seed generation to a weak software random number generator instead of the hardware one built into the chip. The code was public the whole time. Anyone could read it and rebuild the firmware to check it matched. And someone did look: Bitcoin developer James O’Beirne says he audited the firmware in May 2025, traced the randomness to the library at fault, and told the Coldcard team to pull it out. He says the answer he got was that if something were wrong, they’d already know. Fourteen months later, on July 30, an attacker emptied 1,196 addresses of 1,082 BTC in 41 minutes, from a laptop, without touching a single device.
Since then, every podcast has discovered that of course you roll your own dice, of course you’re in multisig, and here’s a sponsor who can help. I’ve been in this since 2017, and nothing I read or listened to back then said any of that. Before hardware wallets, your keys came out of Bitcoin Core, or software built on it, and you wrote them down. Then the devices arrived and the whole chorus was “not your keys, not your cheese”: buy the box, let it make the seed, sleep well. Dice rolls did protect everyone who used them, and that deserves saying. But rewriting the standard after the loss isn’t advice. It’s cope with a referral link.
What the Coldcard attack did involve is worth sitting with. Coinkite said afterward that AI review had failed to catch the flaw and warned every firm using AI to review security-critical code: go test that assumption. Days later a volunteer group calling itself the Bitcoin Red Team pointed AI models at 390 Bitcoin projects and filed nearly 5,000 findings in about 28 hours, 85 of them critical.
So, the AI story in Bitcoin right now isn’t hackers with robots. It’s that a fundamental randomness failure sat in public code for five years, got flagged by a human, and still wasn’t fixed. Now the machines are finding these things faster than maintainers can patch them.
Meanwhile my timeline has spent the last year insisting quantum computers are about to end Bitcoin. We are staring at the horizon while the floor gives way.
I should say up front that I’m a chef, not a cryptographer. What follows is what I’ve pieced together from reading and asking a lot of questions. If I’ve gotten something wrong, tell me and I’ll fix it. But nobody explains this in plain language, and I think that’s most of why the panic works.
* *What it isn’t
First, the thing I hear most often, and it’s simply wrong: quantum computing does not break AI. These get bundled into the same doom sentence and they have nothing to do with each other. Quantum computers threaten specific mathematical problems. Neural networks aren’t one of them.
Second, quantum is not a faster computer. It’s an accelerator for a narrow class of problems that have exploitable structure. Spreadsheets, video, databases, machine learning: no speedup, ever. Anyone selling you “quantum makes computers faster” is selling you something.
Here’s the shortest, honest version I can give you. A qubit is a single atom, or a tiny circuit chilled colder than deep space, held so still that one stray photon ruins your whole afternoon. You don’t get answers out of it by brute force. You arrange the math so that every wrong answer cancels itself out and the right one is the only thing left standing. It’s reduction. You boil off everything that isn’t the sauce.
Which is also why it only works on problems that have something to reduce. Point it at a random haystack and it shrugs. Maybe a sigh. It helps a little, but not the kind of little that breaks anything.
* What it does threaten
Shor’s algorithm, published in 1994, efficiently solves the two problems that underpin most public-key cryptography: factoring large numbers and a related one called the discrete logarithm. That kills RSA (the old workhorse of internet encryption, named for the three researchers who published it) and elliptic curve cryptography, which is what Bitcoin uses to sign transactions. This part is settled mathematics, not speculation.
And here’s the detail that gets left out when people tell you quantum kills Bitcoin: the same math secures your bank. The padlock in your browser rests on elliptic curve cryptography too. Different curves, same underlying problem, and Shor breaks it just as cleanly.
The difference is what happens next. The web has already started moving. As of April 2026, more than two-thirds of human browser traffic reaching Cloudflare’s network negotiates a post-quantum key exchange, and almost nobody noticed. Bitcoin has migrated nothing, because a browser vendor can flip a default for everyone and Bitcoin needs the entire network to agree first.
To be fair, a broken browser session and a broken Bitcoin key are not the same kind of loss. One lets someone read or impersonate a connection. The other hands over the coins, permanently, with no bank to call. Bitcoin is not uniquely vulnerable to math. It is uniquely exposed by it, and uniquely hard to patch, and that is the conversation worth having.
As for timelines, be skeptical. The machines are real. IBM and Google have hardware you can run jobs on, and Google’s 2024 error correction results crossed the important threshold: adding physical qubits made the logical qubit better rather than worse. That was the make-or-break question, and it came out favorable.
But current devices hold hundreds to low thousands of noisy physical qubits, and it takes roughly a thousand of those to make one you can trust. Breaking a Bitcoin key needs millions of trustworthy ones. That’s not a tweak away. It’s several engineering generations, and some of the required inventions don’t exist yet. NIST, the US standards body, finalized post-quantum standards in 2024 and wants the old algorithms retired by 2035. That’s a planning horizon, not a prediction.
My honest read: the likeliest payoff from quantum computing isn’t breaking anything. It’s chemistry. Simulating molecules is the one job where a quantum system is the natural tool for modeling a quantum system, and it pays off at modest scale. Catalysts, batteries, ETC., and the big one, nitrogen fixation. Making fertilizer industrially burns somewhere between one and two percent of the world’s energy, under enormous heat and pressure, because we cannot model the enzyme that performs the same reaction in a clover root at the temperature of a spring afternoon.
Here’s where my bias shows. I cook for a living, and the growers I buy from fix nitrogen the old way. Legumes seeded between the vine rows. Cattle moved to fresh grass so the pasture rests and the soil does its own work. If this overlap between sound money and sound soil interests you, David Bennett has been covering it on the Bitcoin And podcast for years, and better than I can here. Those growers are solving, with clover and hooves and patience, the exact problem we are proposing to solve with a machine that has to be kept colder than deep space.
That doesn’t make the research pointless. Understanding nitrogenase properly would be an enormous thing. But the application quantum computing gets sold on already has a working solution, and it’s been running quietly in pastures the whole time. A tool for understanding matter that happens to threaten some cryptography as a side effect. The side effect got the headlines.
* The part that actually matters for Bitcoin
Bitcoin needs a post-quantum signature scheme and adding one is the easy half. Drafts already exist. It’s a soft fork.
The hard half is that a new address type only protects coins that move to it. Roughly four million BTC sit in addresses with exposed public keys, including the million or so attributed to Satoshi. Nobody can migrate those. The owners are gone.
So, a faction has proposed the obvious solution: set a deadline, and after it, make those outputs unspendable. Freeze them. The argument isn’t stupid. You can’t cleanly tell an abandoned address from a patient one, a deadline forces everyone to actually move, and leaving the coins there is leaving a bounty that funds building the very machine that threatens the rest of us.
I still think it’s the worst idea in Bitcoin right now.
Bitcoin’s value was never that the rules are good. It’s that the rules don’t bend. Nobody, however well-motivated, can decide your coins don’t count. The moment we demonstrate a procedure for invalidating valid outputs, the question stops being “can they” and becomes “under what circumstances would they,” and every future crisis arrives with a precedent attached.
We don’t have to guess how the network feels about that. Between the Coldcard sweep and the Liquid drain, BIP-110 tried to write a spam filter into consensus. The impulse was understandable. It got two and a half percent of miners, and the fork had to change its own proof of work to stay alive, which is a polite way of saying it stopped being Bitcoin. A freeze would get the same welcome, and it should.
Which leaves the cleaner path. Migrate early, while the threat still looks distant and slightly silly. Leave the old coins alone. If someone eventually spends fifteen years and a national lab’s budget to claim abandoned coins under the rules as written, that’s the protocol working, not failing. Dormant supply recirculates. The mystery resolves. And Bitcoin becomes the only financial system that survived a cryptographic transition without confiscating a single coin.
Any cook knows the boring answer: mise en place. Prep while the kitchen is quiet, and don’t invent dishes once the tickets are flying. Historically, we do it in the other order.
- Chef Tommy
Write a comment