Quantum computers can’t break Bitcoin’s cryptography today. But the gap is closing faster than most people realize.
Q-Day is the name security researchers use for the moment a sufficiently powerful quantum machine can crack Bitcoin’s digital signatures. When that happens, old addresses with exposed public keys become vulnerable. An attacker could forge transactions and drain wallets. At current prices, over $452 billion in Bitcoin could be at risk.
That date keeps getting pulled forward. In March 2026, a Google whitepaper suggested quantum computers could break cryptographic systems sooner than expected. Caltech researchers published findings showing fewer qubits and fewer computational steps were needed than previously estimated. Justin Drake, a Bitcoin security researcher, put the odds at “at least 10%” that a quantum computer could recover a secp256k1 private key from an exposed public key by 2032.
How would this work? An attacker copies a public key from the blockchain and runs it through Shor’s algorithm on a quantum computer. That algorithm can factor large numbers and solve discrete logarithms — the exact problems Bitcoin’s elliptic-curve cryptography relies on. The private key is recovered. The transaction is forged. The network sees nothing suspicious.
Some organizations are taking it seriously. Coinbase launched a quantum advisory board in January. France stopped certifying technologies that aren’t quantum-safe in June. President Trump signed two executive orders on quantum development and quantum-resistant encryption. The US Department of Commerce committed $2 billion to quantum advancement.
But upgrading Bitcoin itself will take years. There’s no agreed-upon plan yet. The community is still debating post-quantum signature schemes and migration paths. The clock is ticking, and nobody knows exactly when it runs out.
