Blog

Bitcoin and quantum: when cryptography becomes a financial continuity issue

Bitcoin still occupies a relatively limited place within the global financial system as a whole. Its growth, its increasing integration into financial markets, the development of the investment products associated with it and the interest of major institutional players nonetheless give it an importance that now extends well beyond that of a technological experiment reserved for a few enthusiasts. This growth brings a consequence rarely addressed when we talk about cryptocurrencies: the greater the economic value a technology protects, the more the durability of its cryptography becomes a financial question.

Bitcoin relies on several cryptographic mechanisms that allow the network to function without a central authority having to confirm each transaction. Digital signatures play an essential role in particular, since they make it possible to demonstrate that whoever wishes to spend bitcoins holds the private key corresponding to the public key associated with the funds. This architecture works because classical computers have no practical means of recovering that private key from the public key.

A sufficiently powerful quantum computer would change this assumption. Shor’s algorithm theoretically allows a cryptographically relevant quantum machine to efficiently solve the mathematical problems underlying the elliptic curve signatures used by Bitcoin. When a public key is exposed, such a machine could theoretically make it possible to recover the corresponding private key and produce a signature that the network would consider valid. The legitimate owner and the attacker could then present the same kind of cryptographic proof.

This possibility remains out of reach of today’s quantum computers, and no one knows with certainty when a machine capable of carrying out such an attack might exist. The problem nonetheless deserves to be prepared for well before that deadline, precisely because Bitcoin is a distributed system in which any significant transformation must be developed, tested and accepted by a vast ecosystem.

Work that emerged in 2026 in fact illustrates just how interesting this preparation is becoming. Rather than simply asking bitcoin holders to move their funds to new post-quantum addresses before a threat arrives, researchers are exploring mechanisms that would allow the true owner to demonstrate that they already held their wallet before a quantum computer could reproduce its signature. This seemingly subtle difference profoundly transforms the problem: how do you preserve the notion of ownership when the cryptographic mechanism that historically served to demonstrate it can no longer be considered sufficient?

To understand what is at stake, we must return to the fundamental workings of the cryptographic keys used by Bitcoin. A private key allows its owner to authorize a transaction, and the corresponding public key allows the network to verify that authorization. With current mechanisms, knowing the public key makes it practically impossible to reconstruct the private key. Quantum computing threatens precisely this asymmetry.

Not all bitcoins, however, present the same level of exposure today. Depending on the type of address and how it has been used, the public key may already be visible on the blockchain or may remain temporarily concealed behind a hash. An analysis published by Glassnode in May 2026 estimated that approximately 6.04 million BTC, or 30.2% of the issued supply, had a public key already exposed on the chain. Part of this exposure is said to stem directly from the type of output used, while another part is linked to certain operational practices, notably address reuse and certain custody methods.

This figure must be interpreted with a great deal of caution. It in no way means that 30% of bitcoins can currently be stolen with a quantum computer, since the machine with the necessary capabilities does not exist today. It represents, rather, according to the methodology used, the quantity of bitcoins that would be immediately exposed if a quantum machine capable of efficiently deriving a private key from a public key became available. This nuance makes it possible to take the debate out of sensationalism and approach it as a risk management problem.

For addresses whose public key is revealed only at the time of a transaction, the scenario would be different. A quantum attacker would theoretically have to recover the private key and produce a competing transaction quickly enough to act before the legitimate transaction is confirmed. Researchers thus distinguish attacks against keys that have long been exposed from those that would attempt to exploit the short period during which a key becomes visible in the course of a transaction.

This distinction explains why several solutions are being explored. BIP-360 notably aims to introduce into Bitcoin a new type of output reducing the prolonged exposure of public keys. This approach nonetheless has its limits, since reducing long-term exposure does not necessarily resolve the scenario in which a public key becomes visible while a transaction awaits confirmation. More complete protection could eventually require introducing genuine post-quantum signature mechanisms.

The problem therefore goes well beyond simply replacing an algorithm. Bitcoin has a characteristic that makes its transition particularly complex: considerable financial value is already associated with cryptographic rules defined years ago. Changing the cryptography of a new system before its launch is one thing; changing that of a global network in operation since 2009, without interrupting its functioning, without introducing new attack vectors and without compromising ownership of existing assets, is another.

It is in this context that a line of research that emerged in 2026 becomes particularly interesting. Researchers are working on zero-knowledge proof mechanisms allowing the owner of certain hierarchical deterministic wallets to demonstrate that they hold cryptographic material located higher up in the derivation tree that produced a particular Bitcoin address. Such a proof could establish this relationship without revealing the secret itself.

The idea profoundly changes how a potential post-quantum scenario is approached. After the arrival of a cryptographically relevant quantum computer, a traditional signature associated with an exposed public key could lose an essential part of its meaning. An attacker who had managed to reconstruct the private key could produce a valid signature, leaving the blockchain facing two parties able to demonstrate knowledge of the same key. It would then become extremely difficult to determine which of them actually owned the funds before the attack based on that proof alone.

Modern wallets can, however, contain another form of information. They are generally built from a recovery phrase or a master secret from which many keys are derived. A quantum attacker who reconstructed the private key corresponding to an exposed address would obtain that particular key without necessarily holding the cryptographic material located upstream in the derivation tree that had allowed the legitimate owner to generate it.

This difference could become a new proof of provenance. A zero-knowledge proof could allow the owner to demonstrate that they know this earlier cryptographic material, that it does indeed make it possible to derive the key corresponding to the address and that this proof authorizes a specific operation, all while keeping the secret. The demonstration of ownership would then no longer rest solely on the current ability to produce a signature, but could also take into account the wallet’s cryptographic history.

This approach is particularly interesting because it could help solve one of the most difficult problems of a Bitcoin migration: the fate of funds that will not have been moved in time. A post-quantum transition could provide for a period during which holders would migrate their assets to new quantum-resistant mechanisms. Some wallets, however, will not be moved. Their owners may be inattentive, their custody systems may be complex, their keys may have been stored for many years, or the assets may be held in institutional structures requiring substantial procedures before any migration.

Once a quantum threat had become real, simply continuing to accept the old signatures would create an obvious problem, since both the owner and the attacker could be able to sign. Permanently freezing all funds that had not migrated would create another difficulty by potentially depriving certain legitimate owners of their assets. The possibility of subsequently providing a post-quantum proof demonstrating prior knowledge linked to the generation of the wallet could then offer a path to recovery.

This avenue nonetheless has significant limits. Not all older bitcoins were created with modern hierarchical deterministic wallet architectures. Some very old outputs do not necessarily have the derivation structure that would make it possible to produce this additional proof. Current prototypes also remain experimental and would require changes to Bitcoin’s rules before they could genuinely protect assets on the network.

This limit reveals a much more general reality concerning cryptographic migrations: architectural decisions made fifteen or twenty years ago can determine the options available to us tomorrow. Bitcoin thus becomes an extraordinary laboratory for crypto-agility. In a traditional company, crypto-agility consists notably in being able to identify and then replace the cryptographic algorithms present in applications, certificates, equipment, VPNs and infrastructure. In Bitcoin, the same problem is amplified to the scale of a decentralized global financial system.

The network will eventually have to be capable of integrating new cryptographic mechanisms while preserving assets protected by the old ones, maintaining the compatibility needed for it to function, managing millions of holders and obtaining enough consensus to modify a protocol over which no single organization has authority. Technology therefore represents only part of the problem. Governance also becomes a component of the cryptographic transition.

This dimension explains why part of the Bitcoin community is working on the subject well before a quantum computer capable of attacking the network exists. In September 2026, a workshop bringing together Bitcoin developers, cryptographers, researchers, institutional custodians and hardware wallet specialists, among others, highlighted a particularly important idea: preparing for the transition matters more than precisely predicting the date of the threat. The risk can be taken seriously without being presented as an immediate crisis, all the more so since no definitive solution has yet emerged.

This attitude is far more useful than the permanent search for the famous Q-Day. Its date remains unknown, whereas the time needed to prepare a complex transition is much more concrete. The new cryptographic mechanisms must be designed, their properties analyzed, their implementations tested, the software modified, hardware wallets adapted, the various participants coordinated, the rules applicable to older funds established, and holders given enough time to migrate their assets. Each of these steps can take several years.

The financial ecosystem is in fact beginning to pay more attention to Bitcoin’s long-term security. Institutional players are now helping to fund open source research and development work devoted to the network’s security. This mobilization does not mean that they control the protocol’s development, but it shows that its durability has become important enough to warrant specialized investment.

This evolution deserves the attention of the traditional financial sector because Bitcoin presents a governance model radically different from that of a centralized institution. A bank can decide that a protocol will be abandoned, that a certificate must be replaced or that a system must be modernized before a specific date. Bitcoin operates through a distributed environment where every significant change requires coordination among developers, miners, node operators, platforms, custodians, wallet manufacturers and holders.

Quantum risk thus becomes at once a problem of cryptography, engineering, governance and financial continuity. For institutions holding digital assets directly or indirectly, their own preparation therefore cannot depend solely on what the protocol may eventually decide. They must know their exposure and understand the mechanisms on which ownership of their assets depends.

An institution should in particular know which digital assets it holds, in what forms, who controls the keys, which types of addresses are used, whether the public keys are already exposed, whether certain addresses are reused and whether the assets are held directly or by a custodian. When a third party is involved, its post-quantum strategy itself becomes a dependency. The ability of hardware wallets to support future signature mechanisms and the procedures needed to carry out a migration also become elements of financial continuity.

Cryptography is then no longer solely a cybersecurity matter. It becomes a component of the risk associated with the asset itself. This reality does not, moreover, concern Bitcoin alone. Many blockchains also rely on digital signatures that would in principle be vulnerable to Shor’s algorithm. The technical details and migration mechanisms vary considerably from one network to another, but the fundamental problem remains similar: any financial infrastructure resting on a cryptographic assumption must have a path allowing it to evolve when that assumption changes.

The current risk must not, however, be exaggerated. The quantum computers available today are still very far from the fault-tolerant machines needed to attack Bitcoin’s signatures at scale, and estimates concerning the arrival of a cryptographically relevant quantum computer remain highly uncertain. The fact that research on Bitcoin’s post-quantum mechanisms is advancing now is precisely an advantage, since the ecosystem still has time to explore and test different solutions.

This period makes it possible to avoid a migration carried out under emergency conditions. BIP-360 explores better protection against certain forms of prolonged public key exposure, researchers are studying different families of post-quantum signatures, others are working on recovery mechanisms and zero-knowledge proofs, while some initiatives seek to establish in advance relationships between existing Bitcoin addresses and future quantum-resistant keys. None of these avenues yet constitutes, on its own, a definitive solution.

That is precisely what the financial sector should take away. Post-quantum preparation does not consist in finding today the product or algorithm that will definitively settle the problem. It consists in retaining enough knowledge, control and crypto-agility to be able to adopt the solutions that will emerge. This philosophy connects directly to the post-quantum preparation of companies and government organizations.

An organization that holds digital assets should therefore include them in its cryptographic inventory and its risk analysis. It should understand the mechanisms that protect their ownership, the dependencies on platforms and custodians, the custody horizons and the migration possibilities. This knowledge makes it possible to transform an uncertain technological threat into a governance problem that can be progressively analyzed, prioritized and prepared for.

Quantum Beyond can work alongside cybersecurity, risk management and technology teams to incorporate this dimension into Post-Quantum Readiness & Cryptographic Transition initiatives. Crypto Asset Discovery takes on an almost literal meaning here, since it makes it possible to identify the assets and the cryptographic mechanisms they depend on. Crypto Dependency Mapping then makes it possible to understand the relationships among protocols, wallets, custodians, infrastructure and suppliers. Risk assessment and crypto-agility finally make it possible to prepare several transition paths rather than depending on a solution that may not yet exist.

This expertise becomes particularly relevant for financial organizations because cryptographic migration here has an unusual characteristic: it can change the very way ownership of an asset is demonstrated. In a traditional banking database, an institution can generally reconstruct an account’s history and legally determine its owner even when a technical mechanism has to be replaced. In Bitcoin, possession of the private key is a fundamental component of the ability to dispose of the funds. If a future technology allows a third party to reconstruct that key, the problem goes well beyond confidentiality and directly touches on the notion of digital ownership.

Bitcoin does not today face an imminent quantum attack. No existing quantum computer currently has the capabilities needed to use Shor’s algorithm to reconstruct, at scale, the private keys protecting bitcoins. The problem is nonetheless serious enough for preparatory work to be under way now.

The available analyses show that a significant portion of the bitcoin supply already has exposed public keys according to certain methodologies. Several proposals seek to reduce this exposure or to introduce new post-quantum mechanisms. Researchers are also exploring zero-knowledge proofs making it possible to demonstrate a prior cryptographic relationship with certain wallets, while the institutional ecosystem is beginning to invest more in research devoted to the network’s long-term security.

This mobilization is probably the most rational response to quantum uncertainty. You do not need to know the exact date of Q-Day to understand that an infrastructure protecting considerable financial value must have a plan allowing it to change its cryptography. The time needed to design, test, govern and deploy that transition is already reason enough to start preparing for it.

For financial institutions and organizations exposed to digital assets, Bitcoin also offers a much more general lesson. Cryptography is not an eternal foundation that you install once and then forget. It has a life cycle, and the assets that depend on it necessarily inherit that cycle. Post-quantum preparation must therefore progressively join risk governance, vendor management, custody strategies, architectural decisions and continuity plans.

Quantum Beyond can support internal teams in this work by assessing their post-quantum readiness, their cryptographic assets, their dependencies, their suppliers and their real migration capacity. The objective is to integrate quantum risk into current governance while organizations still have the time needed to analyze their options, test solutions and build their crypto-agility.

Bitcoin ultimately offers us a particularly spectacular demonstration of a reality that already concerns the entire digital economy. When cryptography protects information, its failure can threaten the confidentiality and integrity of data. When it participates directly in the proof that allows a financial asset to be disposed of, its evolution can also call into question the way ownership itself is demonstrated. That is precisely why Bitcoin’s post-quantum preparation deserves the financial world’s attention well before the quantum computer capable of attacking it exists.