“Cryptocurrencies are the canary in the coal mine,” Eddy Zervigon, CEO of Quantum Xchange, told CoinDesk in an interview last week. His firm builds infrastructure to protect financial networks from quantum-enabled attacks, and his assessment of where those attacks will land first is direct: Bitcoin and its decentralized peers.
The timeline for so-called Q-Day, when quantum computers become powerful enough to crack the encryption securing crypto wallets and bank rails alike, is compressing. IBM, Microsoft, and other firms spending billions on quantum hardware now target 2029 for a cryptographically relevant machine. Google researchers this year slashed the estimated qubit requirement for breaking elliptic-curve cryptography by 20x, down to fewer than 500,000 physical qubits. The White House is pushing to shift federal systems to post-quantum standards by 2030.
But the emerging consensus among security researchers and institutional observers is that the cryptography itself may not be the bottleneck. Bitcoin’s governance layer, the slow, consensus-driven process by which the network adopts protocol changes, could leave holders exposed even if quantum-resistant algorithms are ready in time.
The 2029 Deadline Is Now Consensus, Not Fringe
Zervigon pointed to statements from IBM CEO Arvind Krishna and hardware timelines from Microsoft as the basis for the 2029 estimate. “That’s not me making stuff up,” he said. “That’s based on what people spending billions of dollars on this problem have said publicly.”
Google’s research earlier this year gave that timeline additional credibility. The company’s quantum team published findings showing that breaking the elliptic-curve cryptography protecting Bitcoin and Ethereum would require dramatically fewer qubits than previously modeled. Where earlier estimates suggested millions of error-corrected qubits, the revised figure sits below 500,000 physical qubits.
That revision prompted several observers, including Google itself, to pull forward Q-Day projections to 2029. The shift matters because quantum hardware roadmaps are advancing faster than most crypto participants assumed. IBM’s 2025 Heron processor already demonstrated improved error correction, and the company’s public roadmap targets 100,000-qubit systems by the end of the decade.
The White House timeline adds regulatory urgency. A 2025 executive order directed agencies to migrate high-value assets and federal data to post-quantum cryptography by 2030. That means the U.S. government is treating 2029-2030 as a hard deadline for institutional preparedness, not a theoretical horizon.
For anyone tracking quantum computing threats to crypto, the message is clear: the window for preparation is shorter than most market participants assumed two years ago.
Why Bitcoin Gets Tested First
Zervigon’s “canary” framing rests on Bitcoin’s unique exposure. Unlike a bank, which encrypts data in transit and at rest but doesn’t broadcast cryptographic signatures to a public ledger, Bitcoin publishes every transaction signature to a globally replicated chain.
That architecture means an attacker with a sufficiently powerful quantum computer doesn’t need to penetrate a private network. The signatures are already public. An adversary could, in theory, work offline against harvested signatures until the quantum machine cracks them.
“Once you see it happening there, then you know that someone somewhere has a cryptographically relevant quantum computer,” Zervigon said. The implication is that a successful attack on Bitcoin would serve as a public signal that all elliptic-curve-dependent systems, including major bank rails, are now vulnerable.
This framing aligns with earlier warnings from venture capitalist Andrew Gault, who argued that adversaries are already harvesting encrypted traffic for future decryption. The “harvest now, decrypt later” strategy means that data transmitted today under current encryption could be cracked retroactively once quantum machines mature.
For Bitcoin, the risk is more immediate. Addresses that have ever sent a transaction have already exposed their public keys. Dormant wallets that received coins but never spent them remain safer, since their public keys haven’t been broadcast. But the estimated 6.7 million BTC in wallets with exposed public keys, including Satoshi Nakamoto’s presumed holdings, sit in the direct blast radius.
Governance Speed Is the Real Bottleneck
Deutsche Digital Assets published an analysis on July 23 that reframed the Bitcoin quantum debate. The firm argued that the “Bitcoin is uniquely vulnerable” narrative misses the point. The cryptographic math is the same everywhere. What differs is how quickly institutions can deploy new defenses.
“An investment bank like JPMorgan does not need to get a go-ahead from millions of pseudonymous global participants before upgrading its cryptographic infrastructure,” Deutsche Digital Assets wrote. “It needs a board resolution, a budget, and a vendor.”

Large financial institutions can migrate to post-quantum standards “faster, more quietly, and more predictably than a decentralised public blockchain.” The firm was careful to note this isn’t an argument against Bitcoin. It’s an argument for taking Bitcoin’s governance process seriously as a risk factor.
The 2024 academic paper “Downtime Required for Bitcoin Quantum-Safety” from arXiv quantifies this concern. The researchers noted that any significant Bitcoin upgrade requires 90% consensus among miners before activation. Historically, even modest changes have met fierce resistance.
The SegWit upgrade in 2017 is the cautionary precedent. That proposal aimed to increase block capacity and fix transaction malleability. The community disagreement was so severe that the blockchain eventually split through hard forks, creating Bitcoin Cash and Bitcoin Gold as separate networks. The main chain eventually adopted SegWit, but only after years of debate and permanent fracturing of the community.
A quantum-defense upgrade would require far more invasive changes than SegWit. Addresses would need to migrate to new cryptographic schemes. Dormant wallets, including coins that haven’t moved in over a decade, would face forced migration or permanent vulnerability. The governance challenge isn’t just technical. It’s political.
The 90% Consensus Problem
Bitcoin’s upgrade mechanism was designed to prevent unilateral changes by any single party. That’s a feature when the goal is censorship resistance. It’s a liability when the network needs to move quickly against an existential threat.
The 90% miner consensus requirement means that even a well-designed post-quantum proposal could stall for years. Miners have heterogeneous interests. Some operate in jurisdictions with different regulatory pressures. Others have hardware investments that could be affected by protocol changes. Reaching supermajority agreement on anything controversial has historically proven difficult.
The SegWit experience showed that contentious upgrades can trigger permanent splits. A quantum-defense proposal would face even higher stakes. The question of what to do with dormant wallets, particularly Satoshi’s estimated 1.1 million BTC, is politically radioactive. Any proposal that freezes or force-migrates those coins would face opposition from purists who view immutability as inviolable.
A Coinbase-convened panel of cryptographers recently urged Bitcoin to begin quantum-defense planning but declined to take a position on frozen coins. The panel’s non-answer illustrates the governance paralysis that makes timely action difficult.
Meanwhile, competing protocols face different constraints. Solana and other chains with more centralized governance structures could theoretically deploy post-quantum upgrades faster, though they would face their own coordination challenges. The tradeoff between decentralization and adaptability becomes stark when the threat requires rapid, coordinated response.
Q-Day Is a Trend, Not a Binary Event
Markets often model quantum risk as binary: encryption holds until a specific date, then it doesn’t. Zervigon pushed back on this framing. Q-Day, he suggested, is better understood as a gradual degradation than a single moment of failure.
“It’s not like someone announces they have a quantum computer and then everyone panics at once,” industry observers have noted. The more realistic scenario involves incremental capability gains where attackers can crack some keys but not others, where nation-states may possess capabilities they don’t disclose, and where the boundary between “safe” and “compromised” blurs over months or years.
For Bitcoin holders, this gradual model creates uncomfortable asymmetries. An attacker doesn’t need to break all encryption to profit. Breaking a small number of high-value wallets could generate returns that fund further development. The incentive structure favors offense.
The “harvest now, decrypt later” strategy compounds this problem. Adversaries can collect encrypted data today knowing that future quantum capabilities will unlock it. For blockchain transactions, which are permanently recorded, this means that today’s signatures become tomorrow’s attack surface.
Institutional holders tracking derivatives markets and managing large positions face particular exposure. A quantum-capable adversary could theoretically target specific wallets based on on-chain analysis, prioritizing high-value targets before the broader market recognizes the threat.
What Happens to Dormant Bitcoin
The fate of dormant wallets represents the hardest governance question. Roughly 6.7 million BTC sits in addresses with exposed public keys, meaning their signatures have been broadcast and could theoretically be cracked by a future quantum machine.
Among those coins are an estimated 1.1 million BTC believed to belong to Satoshi Nakamoto. Any proposal that freezes or force-migrates Satoshi’s coins would face enormous opposition. Some argue that immutability is Bitcoin’s core value proposition and that compromising it for any reason, even quantum defense, would undermine the network’s legitimacy.
Others counter that allowing those coins to be stolen by quantum attackers would be equally catastrophic. A successful theft of Satoshi’s holdings could crash the market and permanently damage confidence in Bitcoin’s security model.
The AmericanFortress proposal claims to offer a technical solution that could freeze vulnerable coins without forcing mass migration. Whether such an approach could achieve 90% miner consensus remains deeply uncertain.
For holders managing Bitcoin treasury positions, the governance uncertainty creates planning challenges. Corporate treasuries like Strategy (formerly MicroStrategy) hold billions in BTC. Their fiduciary obligations may require engaging with quantum risk even if the broader community remains divided on solutions.
The honest assessment is that post-quantum cryptography could be ready before Bitcoin’s governance layer is prepared to deploy it. That gap, not the math itself, may determine whether crypto serves as an early warning system or an early casualty.




