Author: Omkar Godbol
Compilation: AididiaoJP, Foresight News
Quantum computing poses a potential risk to all global systems relying on encryption technology, from major banks to government networks, without exception. However, due to its inherently decentralized nature and public ledger design, cryptocurrency is likely to be the first technology truly "tested."
"Cryptocurrency is the canary in the coal mine," said Eddy Zervigon, CEO of Quantum Xchange, in an interview with CoinDesk. The company focuses on building cybersecurity infrastructure resilient to quantum attacks, covering finance and other fields. He explicitly stated that the most likely place for issues to appear first is cryptocurrency networks.
"Because it's decentralized, it will be the first place to be attacked," Zervigon said. "Once you see that happening there, it means a quantum computer with cryptography-related capabilities has emerged somewhere."
What is referred to as a "quantum computer with cryptography-related capabilities" is a machine capable of effectively running Shor's algorithm, cracking the elliptic curve cryptography (ECDSA over secp256k1) that Bitcoin and other cryptocurrencies rely on. This algorithm can efficiently solve the elliptic curve discrete logarithm problem, thereby deriving the private key from the public key and gaining control over assets in the corresponding wallet. Currently, such a machine does not exist. However, industry estimates for its emergence are being compressed, not pushed back.
"Companies like Microsoft, IBM, and others investing tens of billions in developing quantum computers generally believe that commercially relevant, cryptography-related quantum computers will appear around 2029," Zervigon said. "This isn't something I made up; it's based on public statements from people like IBM's Arvind Krishna."
This timeline aligns closely with recent hardware and algorithmic progress. Earlier this year, research from Google's Quantum AI team showed that the number of physical qubits required to crack the elliptic curve cryptography protecting major cryptocurrencies like Bitcoin and Ethereum has dropped to less than 500,000, a reduction of about 20 times from previous common estimates in the millions. The research also noted that, with certain parameters fixed in a precomputation phase, an attack targeting exposed public keys could potentially be completed in as little as about 9 minutes. Considering Bitcoin's average block time is about 10 minutes, this means an attacker has a certain probability of forging a signature and transferring funds before a transaction is confirmed, after it enters the mempool. These findings have prompted observers, including those at Google, to move forward their estimates for so-called "Q-Day" (the point when cryptography-relevant quantum computers become practically available) to around 2029.
Simultaneously, the White House is striving to develop a powerful quantum computer before 2028 and plans to migrate high-value assets and federal data to post-quantum cryptography standards by 2030. "This sets the timetable and creates a sense of urgency," Zervigon said.
Consensus Speed Is the Real Risk Factor
Zervigon is not alone in pointing out that cryptocurrency's core weakness lies in its slow governance processes, not the cryptography itself.
Deutsche Digital Assets explicitly framed this issue as a speed difference between traditional finance and decentralized rails.
The institution wrote in a July 23rd analysis: "The real difference—and the honest answer to the 'Bitcoin is particularly vulnerable' narrative—lies in governance speed."
It explained that an investment bank like JPMorgan Chase doesn't need permission from millions of anonymous global participants before upgrading its cryptographic infrastructure. "It just needs a board resolution, a budget, and a vendor. Large financial institutions can and will migrate to post-quantum standards faster, quieter, and more predictably than decentralized public blockchains. This is not anti-Bitcoin; it's a call to take its governance processes seriously."
Academic research further supports this assessment. A 2024 paper published on arXiv, titled "Downtime Required for Making Bitcoin Quantum-Safe," points to Bitcoin's own upgrade history as a cautionary precedent.
The researchers wrote: "Before any upgrade process can begin, 90% consensus must be reached among Bitcoin miners on the specific details of the upgrade. Historically, major changes to the Bitcoin network have met with high resistance. A prominent example is the SegWit upgrade in 2017."
That upgrade caused severe division within the community, ultimately leading to the Bitcoin blockchain splitting via a hard fork into multiple versions, giving rise to networks like Bitcoin Cash and Bitcoin Gold. The paper also estimated that, even under ideal conditions (full network bandwidth dedicated to the upgrade, zero overhead), the cumulative minimum processing time required to migrate all currently quantum-vulnerable unspent transaction outputs (UTXOs) to post-quantum secure addresses is about 76 days. If spread over a longer period, it would significantly slow normal transaction speeds. More critically, due to the risk of "immediate attack"—where an attacker could potentially complete a crack before block confirmation once a user initiates a transaction and exposes a public key—the entire migration must be completed *before* a cryptography-relevant quantum computer emerges, otherwise existing assets could still be exposed.
Therefore, the post-quantum cryptographic algorithms themselves (such as NIST-standardized ML-DSA, etc.) may be ready in time. The real uncertainty is whether Bitcoin's governance layer can reach sufficiently high consensus within a sufficiently short timeframe and complete network-wide deployment.
'Q-Day' Is Not a Point in Time, But a Trend
The market often models the quantum threat as a binary event: encryption algorithms work perfectly until a specific date, after which they suddenly fail completely. Zervigon believes this framework is flawed, as it underestimates how early the risk actually begins to materialize.
"Everyone talks about the moment you can crack the algorithm," he said. "You don't actually need to crack it in an instant to achieve the effect. If I take three months or six months to decrypt data that still has value, I've already achieved the same goal."
This compresses the typical timeline calculations. A quantum computer doesn't need sufficient throughput to crack a signature in real-time to pose a threat; it only needs enough throughput to complete the crack before the underlying data or funds lose their value to the attacker. In reality, a significant portion of Bitcoin (estimated by research to be around one-third, corresponding to millions of coins) already has its public keys permanently exposed on-chain. These assets could face a "static attack" once a capable quantum computer is available—attackers could compute slowly, without racing against block times.
For the entire crypto industry, this is both a warning and a stress test. Traditional financial institutions can migrate quickly via centralized decisions, while the decentralized advantage of public blockchains like Bitcoin may become an implementation obstacle when facing an external technological threat requiring high coordination. The industry consensus is that technical solutions already exist; the true test is whether governance can keep pace with the closing time window.
Cryptocurrency may become the earliest area to sound the alarm in the quantum era. Once the canary falls, broader financial infrastructure will also have to confront the same challenge.





