Will Quantum Computers Break Bitcoin and Solana?
What a quantum attacker would target
The realistic target is digital signatures. If an attacker could work out a private key from a public key, they could sign transactions as the owner. Hashing, used in mining and for block links, is affected much less.
Bitcoin
Bitcoin uses elliptic curve signatures. A public key is revealed on the blockchain when coins are spent, so old reused addresses are the most discussed exposure. Developers have debated migration paths.
Solana
Solana accounts use Ed25519 signatures, another elliptic curve scheme, so the same class of future risk applies. Solana tokens such as QNT inherit the chain's security properties.
How far away is it?
Nobody knows. A machine able to break these signatures would need many error corrected logical qubits, far beyond today's hardware. See error correction.
What you can do
Nothing special today. Use good wallet hygiene, and follow upgrades in the ecosystem. For the standards that are emerging, read post-quantum cryptography and crypto.
Exposed versus hidden public keys
A blockchain address is usually a hash of a public key. While coins sit unspent in such an address, the public key itself is hidden behind the hash, which Shor's algorithm cannot attack directly. Once you spend, the public key is revealed, and during the time before a transaction confirms an attacker would have a short window. Coins in older address types that already expose a public key, or addresses reused after spending, are the most exposed. On Solana, an account address is the public key itself. See exposed public keys and address reuse and elliptic curve cryptography.
What would a real attack need?
| Item | Today | Needed (estimates) |
|---|---|---|
| Largest chips | About 100 physical qubits (Willow 105, Helios 98) | Hundreds of thousands to millions of physical qubits |
| Error correction | Early below-threshold demos | Thousands of reliable logical qubits |
| RSA-2048 estimate | Not possible | Under 1 million noisy qubits, under a week (Gidney 2025) |
The Gidney figure is for RSA, not elliptic curves, but both fall to Shor's algorithm and estimates for both keep dropping. See elliptic curve estimates. Experts disagree on timing, see expert surveys and early warning signs.
What is changing in 2026
- Bitcoin: BIP-360 was merged as a draft in February 2026. It would add a way to receive coins without the quantum-vulnerable spending path. It is not active, and a full fix needs post-quantum signatures. A separate proposal, BIP-361, is more contentious. See BIP-360 and BIP-361.
- Solana: users can opt into a Winternitz Vault, which uses one-time hash-based signatures. It is not applied to the whole network. See chain plans.
- Hashing: Grover's algorithm gives only a square-root speed-up, so mining and block links are far less exposed. See hash functions and quantum.
Common mistakes
- Panic-selling or buying anything based on quantum headlines. This page is education, not financial advice, and makes no prediction about any asset price.
- Trusting sites that sell "quantum-proof wallets" with no named signature scheme.
- Assuming developers are ignoring the issue. Proposals exist; the hard part is community agreement.
How to check this yourself
Look up the chain's signature scheme, read the current proposals, and compare with the standards in post-quantum cryptography. For practical habits, see what individuals can do today and the wallet review checklist.
Sources
- Gidney: RSA-2048 with under a million noisy qubits
- BIP 360 text
- Cointelegraph: what BIP-360 changes and what it does not
- The Quantum Insider: Solana Winternitz Vault
- Grassl et al.: Grover's algorithm and AES resource estimates
Frequently asked questions
Can a quantum computer steal my Solana tokens?
Not with any machine that exists today. It would need a far larger, error corrected quantum computer.
Is Bitcoin mining threatened by quantum computers?
Much less than signatures. Quantum computers give only a modest speed-up on the hashing used in mining.
Which is more at risk, Bitcoin or Solana?
Both use elliptic curve signatures that Shor's algorithm would break. The practical exposure differs by address type, and neither is at risk from a machine that exists today.
Could Bitcoin or Solana switch to quantum-safe signatures?
Yes in principle. It needs code, community agreement and a way for users to move coins. Proposals and opt-in tools exist.
What is the harvest now, decrypt later threat?
Collecting encrypted data today to decrypt later. It matters for secrets that must stay private for years. See the explainer.
Does this affect the QNT token?
It shares Solana's signature scheme like any token on the chain. This is education, not financial advice, and the memecoin is independent of Quantinuum Ltd.
Keep reading
- Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it. - Quantum Error Correction Explained
Qubits are fragile, so quantum computers need error correction. Learn how logical qubits are built and why this is the key challenge. - Exposed Public Keys and Address Reuse: Who Is Actually Vulnerable to Quantum?
Why some coins are more exposed to a future quantum attack than others, and how address reuse and Taproot play into it. - Bitcoin BIP-360 and BIP-361 Explained: The Quantum Upgrade Proposals
What the draft Bitcoin proposals P2MR (BIP-360) and the migration and sunset plan (BIP-361) actually say, and what they leave open. - Ethereum and Solana Post-Quantum Plans: What Is Real in 2026
Ethereum's four-part quantum roadmap and Solana's Winternitz Vault and testnet work, with dates and honest caveats.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary