Hash Functions and Quantum Computers: Are They Safe?
What a hash function does
A hash function turns any input into a fixed length fingerprint. The same input always gives the same output, a tiny change gives a completely different output, and you cannot work backward from the fingerprint to the input. Blockchains use hashes to link blocks, build addresses and secure mining.
What Grover's algorithm changes
Grover's algorithm speeds up searching. To find an input matching a given hash, a normal computer needs about N tries, while Grover needs about the square root of N. That is a real speedup but a modest one. The usual fix is to use longer hashes, which makes the quantum advantage manageable.
Why this differs from signatures
Shor's algorithm gives a dramatic speedup against RSA and elliptic curves. Grover's gives only a quadratic one. That is why most experts treat signatures as the more urgent problem and hashes as the more comfortable one.
Mining and Grover
Proof of work mining uses hash searches, so quantum speedups to mining have been discussed. Practical limits matter, because Grover-style searches are hard to run in parallel and require long, error free quantum computations. Researchers generally do not see this as a near term threat. Solana does not use proof of work, as explained in what is Solana.
Where hashes help quantum safety
Some quantum resistant signature schemes are built mainly from hash functions, since hashes are trusted to hold up. See also post-quantum cryptography.
The numbers in plain terms
SHA-256 gives 256 bit outputs. Finding an input that matches a given output takes about 2 to the power 256 tries classically. Grover's algorithm cuts that to about 2 to the power 128 quantum steps, which is still far out of reach. NIST's post-quantum security categories use this logic. Category 1, 3 and 5 are pegged to how hard it is to find an AES-128, AES-192 and AES-256 key with Grover. AES-256 stays in the top category.
| Primitive | Classical security | Against Grover | Verdict |
|---|---|---|---|
| AES-128 | 128 bits | About 64 bits of quantum work in theory | Use AES-256 for long term |
| AES-256 | 256 bits | About 128 bits | Fine |
| SHA-256 preimage | 256 bits | About 128 bits | Fine |
| ECDSA, RSA | 128 and 112 bit class | Broken by Shor in principle | Replace |
Why Grover does not parallelize well
Spreading a Grover search across m machines yields only about the square root of m improvement in depth, while a classical search improves by a factor of m. The quantum circuit must also run long and error free. This is why researchers regard raw Grover attacks on 256 bit primitives as impractical, and why NIST evaluates security with circuit depth limits.
Bitcoin mining
Mining is a hash search, so Grover applies in principle. A preprint estimate found that even an optimistic single quantum machine would reach about 21 terahashes a second, around a tenth of one modern ASIC, against a network of hundreds of exahashes. That is one estimate, but it shows why mining is not the headline risk. The bigger Bitcoin issue is exposed public keys, covered in elliptic curve cryptography and BIP-360.
Common mistakes
- Thinking quantum breaks hashes entirely. It weakens them by a square root only.
- Mixing up preimage and collision attacks. Collisions are a different, slightly easier problem, and output length is chosen with that in mind.
- Using short truncated hashes for long term secrets.
How to check this yourself
Look at the security category of a standard. See Grover's algorithm explained and square root limits. For hash-based signatures used in practice, see the builder guide.
Sources and further reading
- PostQuantum.com: what is Grover's algorithm
- PostQuantum.com: NIST PQC security categories
- Conditions for advantageous quantum Bitcoin mining (arXiv)
- NIST: first three finalized post-quantum standards, 13 August 2024
Checked 2026-10-09. Research and standards change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, company and standards body named on this page.
Frequently asked questions
Can quantum computers break SHA-256?
Not in a practical sense. Grover's algorithm reduces its effective security but does not break it.
What does Grover's algorithm do to hashing?
It finds matches in roughly the square root of the usual number of tries, cutting the effective security bits about in half.
Is Bitcoin mining at risk from quantum?
It is discussed, but practical obstacles are large and most experts see signatures as the bigger issue.
Are hashes used in post-quantum cryptography?
Yes. Several quantum resistant signature designs rely mainly on hash functions.
Should I use AES-256 instead of AES-128?
For data that must stay secret for decades, AES-256 is the common recommendation, since Grover halves effective key length.
Does Grover threaten blockchain addresses?
Addresses based on hashes are far less exposed than raw public keys, though reuse matters. See elliptic curves.
What is a collision attack?
It is finding any two inputs with the same hash. It is easier than finding a match for a given hash, so outputs are sized accordingly.
Why trust hashes more than signatures?
The best known quantum attack gives only a quadratic speedup, which longer outputs offset.
Keep reading
- Quantum Algorithms Explained for Beginners
What is a quantum algorithm? Learn how Shor's, Grover's and other quantum algorithms work in plain English, and which ones matter for cryptography and crypto. - Quantum-Resistant Signatures Explained
What are quantum-resistant digital signatures? Learn the main families, the NIST standards and the trade-offs blockchains face when upgrading. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary