Education • 10 min read
By Bitpanda
21.07.2026
The rise of quantum computing has sparked concerns about the future security of blockchain technology and cryptocurrencies. Headlines warn of a "quantum apocalypse" that could break cryptographic algorithms and render digital assets worthless overnight. But how much of this fear is grounded in reality? And are we really looking at the full picture? In this instalment of our Bitpanda Blog series Mythbusters, we cut through the noise to present the facts fairly so you can decide for yourself. Let's take a closer look!
Quantum computing represents a significant technological leap, with machines capable of solving certain complex problems exponentially faster than classical computers. This has fuelled concerns that one day quantum computers could crack the cryptographic algorithms securing blockchain networks. Headlines often present this as an existential threat to crypto. The reality, however, is more nuanced.
Quantum computers leverage the principles of quantum mechanics — specifically superposition and entanglement — to process information in fundamentally different ways than classical computers. While traditional computers use bits (0s and 1s), quantum computers use quantum bits, or qubits, which can exist in multiple states simultaneously. (Think of a flipped coin mid-air, where you do not yet know if it is going to be head or tail.) This allows quantum machines to explore many possible solutions to a problem at once, making them particularly powerful for specific tasks like factoring large numbers or searching unsorted databases.
The security of most blockchain systems relies on cryptographic algorithms that are computationally impractical to break with classical computers. Bitcoin, for instance, uses two main cryptographic schemes: the Elliptic Curve Digital Signature Algorithm (ECDSA) for transaction signing and Secure Hash Algorithm 256-bit (SHA-256) for mining and address generation. Both are considered secure against classical attacks. However, theoretical quantum algorithms, particularly Shor's algorithm for factoring and Grover's algorithm for searching, could potentially threaten these systems. Shor's algorithm could break ECDSA, while Grover's algorithm could reduce the effective security of SHA-256.
The short answer is that quantum computing is a genuine long-term challenge for blockchain, recent research has made the challenge feel a little closer than it did a year ago, and the industry has been preparing for it for years. None of those things are in tension with each other. What they add up to is a technical deadline, not a disaster, and not nothing.
Here are a few key facts:
So what has actually changed, and what does it mean? Let's unpack this.
A recent research paper^1 published an updated estimate of how large a quantum computer would need to be to break the cryptography Bitcoin relies on. The headline number was roughly twenty times smaller than what the field had assumed before. That sounds alarming, and it is genuinely significant. However, it needs context.
First, "twenty times smaller" does not mean "twenty times sooner." It means the engineering target has moved closer, but the target is still well beyond anything that exists today. The largest quantum computers currently demonstrated operate at around a thousand qubits. The research suggests an attack on Bitcoin would need a machine with roughly half a million of the right kind of qubits, working together with error correction that has not yet been built at scale. We are not there. Most experts still place the arrival of such a machine somewhere in the 2030s, with meaningful uncertainty in either direction.
Second, what the researchers actually argued is that the crypto industry should migrate to quantum-resistant cryptography sooner rather than later. That is a call to action, not a prediction of imminent collapse. It is a message from people who work on this technology to an industry that already agrees a transition is eventually necessary, which is a nudge to get on with it, not a warning that the sky is falling.
The most useful way to interpret the recent news is this: the timeline may be shorter than previously assumed, but there is still time to prepare, and that preparation is already underway.
TL;DR: The new research brought the quantum challenge closer, not to the doorstep. The practical takeaway is "keep building the defences," not "panic."
Bitcoin was not designed with quantum computers in mind, but it does have some useful properties that blunt the threat.
The most important one is simple. A Bitcoin address that has never been used to send a transaction does not reveal the cryptographic information a quantum computer would need to attack it. Only when you spend from an address does the relevant data become visible on the blockchain. So for anyone following the standard good-practice advice (use a fresh address, don't reuse old ones) a large share of holdings are already behind a meaningful layer of protection [^2].
There is an honest caveat here. A notable chunk of Bitcoin's supply, including the coins that belong to Bitcoin's pseudonymous creator Satoshi Nakamoto, which have sat untouched since 2009, was created using an older address format that does expose the relevant information. Those coins cannot easily be moved to safer ground, because in many cases the private keys are presumed lost. What to do about this is an open debate in the Bitcoin community, and there is no consensus yet. It is a real problem, and we would rather name it than paper over it.
But for ordinary users with ordinary wallets, the tools to protect yourself already exist, and they are things you should probably be doing anyway. Don't reuse addresses. Use a reputable wallet. Keep your software up to date. These are the same habits that protect you from classical threats, which, as we will come back to, are still the bigger danger today.
TL;DR: Good wallet hygiene may reduce certain address-level quantum risks for users, particularly where addresses are not reused. It should not be understood as complete protection against quantum-related risks, protocol-level risks, custody risks or market losses.The harder problem is the coins no one can move because the keys are lost.
The part of the quantum conversation that gets the least coverage is also the most reassuring: the replacement already exists. In August 2024, the US government's standards body (NIST) finalised a new set of cryptographic algorithms specifically designed to resist quantum attacks. These are not prototypes. They are published, peer-reviewed, production-ready standards that are being rolled out across the wider internet and not just in crypto.
Several blockchains have already deployed them. A project called the QRL has been running quantum-resistant cryptography since 2018. Algorand processed its first quantum-resistant transaction in 2025. The XRP Ledger has been testing the new algorithms on its test network. Bitcoin and Ethereum have active proposals in development to integrate quantum-resistant signatures into their protocols, BIP-360 on the Bitcoin side, EIP-7932 on the Ethereum side. The Ethereum Foundation has been funding post-quantum cryptography research for years.
None of this is a finished job. Rolling out new cryptography across a decentralised network is slow and messy by design, which is the same property that makes blockchains hard to attack in the first place. But "slow and messy" is a very different picture from "defenceless." The work is underway, and it is well past the starting line.
TL;DR: Quantum-resistant cryptography is not a future research project. It is a present-day standard, already deployed on multiple blockchains, with clear paths to integration on the major chains.
Now, step back from quantum for a moment and look at where crypto holders actually lost money last year. According to Chainalysis, roughly $1.7 billion was stolen from the crypto ecosystem in 2023. The culprits, as always, were smart-contract exploits, bridge hacks, compromised private keys and phishing attacks. Not one of those incidents involved a quantum computer. Zero.
As we explored in our Bitcoin Energy Mythbuster, the most visible debate is not always the one that matters most in practice. Quantum is the story with the better headline, but the boring stuff, such as writing secure smart contracts, using good wallets, being careful with phishing, keeping your seed phrase offline, is where the actual damage happens.
This is not an argument that quantum doesn't matter. It does, and it is worth preparing for. But it is an argument against putting quantum at the top of your personal worry list. The things most likely to cost you money in the next twelve months are the things that have always cost crypto users money. Guard against those first.
TL;DR: The real security risks for ordinary crypto holders today are classical, not quantum. That has not changed, and will not change in the short term.
If you hold crypto on Bitpanda or anywhere else, here is a fair summary of where things stand.
Quantum computing is a real challenge on a timescale of probably a decade or more. The recent research tightened that timeline but did not shorten it dramatically. The crypto industry, including the chains you are most likely to hold, is actively migrating to quantum-resistant cryptography, and that migration has visible milestones rather than vague promises. For ordinary users, the things you can do to protect yourself e.g. using modern wallets, avoiding address reuse when using Bitcoin, keeping software current, are already good practice for reasons that have nothing to do with quantum.
The myth that blockchain is defenceless against a quantum apocalypse is just that: a myth. The reality is a manageable long-term transition that is already underway, with a narrower margin than last year and a wider margin than the scariest headlines suggest. Neither end of the spectrum is quite right, and that middle ground is where most big technology transitions actually live.
The reality is more nuanced that either the most optimistic or the most alarmist narratives suggest. Quantum computing is a challenge the industry will need to address, but it is not an existential threat to blockchain today.
So let us consider this myth demystified.
Disclaimer
This article is distributed for general informational purposes, and it is not to be construed as an offer or recommendation to transact in any crypto-asset or use any crypto-asset service. It does not constitute and cannot replace investment advice. Investing in crypto-assets involves risks, including high volatility, total loss of capital and cybersecurity.
This article discusses technological developments. Statements about future developments, timelines, adoption, upgrades, or resilience are forward-looking and uncertain, and actual outcomes may differ materially.
Nothing in this article is a guarantee that any blockchain network, crypto-asset, wallet, protocol, or service will adopt quantum-resistant protections or avoid future security risks.
Bitpanda does not make any representation or warranty as to the accuracy, completeness, or continued availability of this information. Information may become outdated and should not be the sole basis for any decision involving crypto-assets or crypto-asset services.
[^2]: This applies to all address formats except for the new Taproot addresses which are usually not default on wallets. For these there is a new proposal Pay to merkle root, to fix this https://bip360.org/bip360.html
We use cookies to optimise our services. Learn more
The information we collect is used by us as part of our EU-wide activities. Cookie settings
As the name would suggest, some cookies on our website are essential. They are necessary to remember your settings when using Bitpanda, (such as privacy or language settings), to protect the platform from attacks, or simply to stay logged in after you originally log in. You have the option to refuse, block or delete them, but this will significantly affect your experience using the website and not all our services will be available to you.
We use such cookies and similar technologies to collect information as users browse our website to help us better understand how it is used and then improve our services accordingly. It also helps us measure the overall performance of our website. We receive the date that this generates on an aggregated and anonymous basis. Blocking these cookies and tools does not affect the way our services work, but it does make it much harder for us to improve your experience.
These cookies are used to provide you with adverts relevant to Bitpanda. The tools for this are usually provided by third parties. With the help of these cookies and such third parties, we can ensure for example, that you don’t see the same ad more than once and that the advertisements are tailored to your interests. We can also use these technologies to measure the success of our marketing campaigns. Blocking these cookies and similar technologies does not generally affect the way our services work. Please note, however, that while you’ll still see advertisements about Bitpanda on websites, the adverts will no longer be personalised for you.