Bitcoin's Quantum Problem: Three Approaches Researchers Are Testing to Counter Q-Day
Key Takeaways
- •A quantum computer running Shor's algorithm could theoretically derive a Bitcoin private key from an exposed public key, but public keys only become visible on-chain once coins are spent from an address.
- •StarkWare's open competition, with AI models topping the leaderboards, reduced the estimated cost of building a quantum-safe Bitcoin transaction from about $320 to roughly $67 in a single week.
- •The StarkWare approach is a nonstandard workaround that protects only coins whose public keys have not been exposed, and the company views a soft fork as the better long-term solution.
- •Coinbase, which safeguards roughly $250 billion in assets, is developing post-quantum custody designed to adapt to Bitcoin's eventual signature standard, including a hardware fallback if that standard proves incompatible with current key-splitting techniques.
- •Researchers published a separate Zcash-style design for shielded Bitcoin transfers, reflecting overlap between quantum-defense cryptography and privacy efforts.

Bitcoin could one day face a moment the industry calls "Q-Day": the point at which a sufficiently powerful quantum computer derives private keys from exposed public keys and drains wallets. No such machine exists today, and estimates for when one might arrive vary widely—but the timelines keep compressing, and preparation has accelerated.
This week alone produced developments across all three categories of potential fixes: quantum-safe transactions executed under Bitcoin's current rules, protocol upgrades such as a soft fork, and defenses at the custody layer—a good moment to separate the real threat from the noise.
The problem
Bitcoin secures wallets using elliptic-curve cryptography, the math that links a private key to a public one. A quantum computer capable of running Shor's algorithm could, in theory, derive a private key from an exposed public key, forge a signature, and drain the wallet. The word "exposed" is the operative one: a Bitcoin address hides the underlying public key behind a hash, and the key only becomes visible on-chain once coins are spent from it—a detail that determines which defenses can help which coins. The hypothetical arrival of such a machine is known as "Q-Day." No such computer exists, and projections of when one might range widely—but forecasts keep shortening, which is why preparation efforts have intensified.
Fix 1: Quantum-safe transactions under current rules
StarkWare, which mined the first quantum-safe Bitcoin transaction on mainnet last month, said an open competition—with AI models the leaderboards—cut the estimated cost of building one such transaction from about $320 to roughly $67 in a single week.
By the company's own admission, the approach is only a workaround. The transactions are nonstandard, and they protect only coins whose public key has not already been exposed. StarkWare still considers a soft fork the better long-term answer.
Fix 2: A protocol upgrade
The durable fix is to change Bitcoin itself by adopting post-quantum signatures—signature schemes built to hold up against quantum computers. Bitcoin's decentralized governance, however, means such upgrades take years to design, test, and deploy, and none can activate without broad consensus. The soft fork—a backward-compatible rule change and the path Bitcoin has historically used for upgrades—is the mechanism most often floated for this transition. The community has only recently begun engaging with the challenge in earnest.
Fix 3: Custody-layer defenses
Also this week, Coinbase's head of cryptography laid out how the exchange, which safeguards roughly $250 billion in assets, is building post-quantum custody designed to adapt to whatever signature scheme Bitcoin eventually adopts. That includes a hardware fallback in case the chosen standard proves incompatible with the key-splitting techniques custodians rely on today. The layer matters beyond any single company: because custodians hold coins on behalf of many customers at once, defenses here can shield large pools of bitcoin before the base protocol itself changes.
The privacy angle
A related thread runs alongside the quantum effort: privacy. The same cryptographic machinery being marshaled against quantum threats overlaps with attempts to make Bitcoin more private, and researchers this week published a separate "Zcash-style" design for shielded Bitcoin transfers.
The bottom line
Q-Day remains hypothetical and is likely years away, and nothing shipped this week makes Bitcoin quantum-safe on its own. What the week showed is a field moving from theory to logistics—driving down what defense costs while measuring how fast the threat is closing. The gap between those two numbers is, in effect, how much time the crypto industry has to prepare. The signs to watch from here are correspondingly practical: whether the cost curve from efforts like the StarkWare competition keeps bending downward, and whether the community's engagement hardens into a concrete fork proposal.
Source: Decrypt