The quantum risk of Bitcoin is more like a coordination problem, involving the disposal of dormant tokens and consensus on upgrades.
Written by: Aaron Stanley, Forbes
Translated by: AididiaoJP, Foresight News
The Quantum Issue of Bitcoin is Actually a Social Issue
Whether Bitcoin will be cracked by quantum computers is often framed by outsiders as a physics or cryptography question: When will the machine be strong enough? How many qubits does Shor's algorithm require? When will elliptic curves become obsolete? This article shifts the focus: For Bitcoin, the more challenging issue may not be the algorithms themselves but whether a group of independent individuals can reach consensus on the upgrade path.
The introduction clearly states: The quantum threat "may be less about cryptography and more about coordination"; the post-quantum migration will test the social layer of this network.
There Are Answers on the Technical Level
Bitcoin wallets rely on ECDSA and Schnorr signatures. Once sufficiently powerful cryptographic-related quantum computers (CRQCs) emerge, they could potentially derive private keys from exposed public keys. SHA-256 mining is relatively more resistant to quantum attacks; the real sensitivity lies in the signature mechanism, that is, "who can spend this coin."
The industry does have contingency plans. Drafts like BIP-360 discuss introducing quantum-resistant address types; BIP-361 and other proposals envision a phased elimination of old signatures. NIST has announced post-quantum standards, and banks, cloud providers, and governments are migrating according to a timeline extending into the 2030s. What Bitcoin lacks is not "whether there are quantum-resistant algorithms in the world," but "how this network, which has neither corporations nor foundations making decisions, will choose solutions, how it will activate them, and how to enable holders to move their coins."
Upgrades like SegWit and Taproot faced minimal opposition, still requiring years of discussion, signaling, and activation processes. Quantum migration is more critical: It may require holders to transfer funds to new addresses within a specified timeframe. This is not as simple as releasing a single application update.
What's Exposed is Not Just the "Future," but Also Coins Already on the Chain
The issue is even more severe concerning existing stock. Early P2PK addresses directly wrote public keys on the chain; once quantum machines mature, these coins become ready targets. Approximately 1.7 million BTC are held in early addresses, commonly viewed as positions lost by Satoshi Nakamoto and related parties. When factoring in address reuse, various studies estimate the current quantum exposure scale at around 6 to 7 million coins, making up about 30% of the circulating supply.
Holders who can proactively migrate their addresses theoretically can transfer coins to a new format where the public key has not yet been exposed. Those who cannot migrate pose a political dilemma: Keys are lost, the owner is gone, or no one is claiming them. There are roughly three paths the community could take — to freeze or destroy upon expiration, limit the spending speed of vulnerable addresses, or do nothing and wait to see who grabs the coins first when quantum machines arrive.
All three paths are technically feasible; the difficulty lies in who has the authority to modify property rules. Freezing is nearly "moving someone else's coins without a private key"; allowing it may permit the earliest coins, including those identified as Satoshi's positions, to fall into the hands of the first individuals with quantum capabilities. Coinbase's assembled group of cryptographic advisors also returned the ball to the community this June: The technical migration should be planned immediately, but there is no standard answer for what to do with dormant coins, and the Bitcoin community must decide for itself.
The Social Layer is the Bottleneck
The design of Bitcoin inherently means that no one calls the shots. This protects against censorship and ensures rule stability, but also slows collective action. The debate over Ordinals taking up block space has dragged on for years, and neither side has reached an endpoint. The quantum issue is even more divisive: One side views it as a distant panic, while the other sees it as an existential risk; one side insists on "not touching coins without owners," while the other believes that letting quantum attackers take Satoshi's coins could pose an even greater legitimacy crisis.
With institutional entry, the game adds another layer. Large holders like BlackRock, exchanges, miners, nodes, and developers must, for the first time, sit at the same "social consensus" table. Some warn: If developers appear too slow, sovereign funds and institutions, motivated and weighted by the existing structure, may drive consensus outside the current framework. This contradicts Bitcoin's self-image of having "no centralized coordinator."
Zach Pandl, head of research at Grayscale, judged earlier: Bitcoin’s technology risk is lower than many other coins due to UTXO, proof of work, lack of native smart contracts, and some addresses not being directly exposed; the real problem lies in how the community makes decisions. Guillaume Girard from UTXO Management also dubbed the quantum issue a "governance crisis masquerading as a technical issue"—the protocol changes as slowly as state legislature, so one cannot wait for machines to appear first.
Migration Itself is Also a Social Mobilization
Even if a solution is chosen, execution remains a multi-year project. Charles Guillemet, Ledger's technology head, assessed in mid-September: Bitcoin does not face a quantum computing problem today, but a migration problem; wallets, hardware, backup habits, and user education could take years. Post-quantum signatures are often significantly larger than Schnorr signatures and could bring new risks such as state signatures and backup recovery. Choosing an algorithm may be a relatively easy step; enabling the global holders to safely transfer their old coins is the real challenge.
The market layer is equally sensitive. Quantum machines do not exist today, but the expectation will rewrite pricing ahead of the machines. Kevin O'Leary recently listed "whether quantum concerns are alleviated" as one of the conditions for institutions to dare raise Bitcoin from around 3% of their "gold-like scraps" to a core holding. The subtext of the Forbes article lies here: Threats can be far away, but the discount from coordination failure can be very near.
The Real Race
The physical timeline remains uncertain. Some say it could be over ten years; others have brought the timeline forward due to lower resource estimates from this year's papers by Google and others. What is more critical for Bitcoin is which of the two timelines arrives first: a quantum machine capable of breaking signatures or a level of social consensus equivalent to a soft fork.
Technology allows Bitcoin to survive; there are no physical laws stating it cannot defend itself. The prerequisite for that defense is an untrusting community willing to make collective decisions it is least adept at, all under the rhetoric of "emergency," which it resents the most. Forbes titled this article "Social Issues," referring to this matter: Algorithms can be replaced, but who will change the rules, who owns the dormant coins, and whether delayed upgrades will first shatter confidence are the core of the quantum story of Bitcoin.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。