Experts Say Bitcoin May Expose Quantum Computing Risks Before Traditional Finance
Key Takeaways
- •Eddy Zervigon said cryptocurrencies could be the first visible target of quantum-enabled attacks because of their decentralized structure.
- •A cryptographically relevant quantum computer capable of breaking elliptic-curve signatures does not currently exist, but some industry timelines point to around 2029.
- •Google researchers estimated that breaking cryptography protecting major cryptocurrencies would require fewer than 500,000 physical qubits, far below earlier estimates.
- •The White House aims to build a powerful quantum computer by 2028 and shift high-value federal assets and data to post-quantum cryptography by 2030.
- •Experts cited Bitcoin’s governance process, including the need for broad miner consensus and ecosystem coordination, as a key obstacle to quantum-safety upgrades.

Quantum computing poses a potential risk to every encrypted system, including those used by major banks. But because of the way decentralized networks operate, experts say cryptocurrency may be the first sector where that risk becomes visible.
Eddy Zervigon, CEO of Quantum Xchange, described cryptocurrencies as an early warning signal for the broader threat in an interview with CoinDesk. Quantum Xchange builds infrastructure designed to protect networks, including financial networks, from quantum-enabled attacks.
"Cryptocurrencies are the canary in the coal mine," Zervigon said. "That's the first place of attack because of the decentralized nature. Once you see it happening there, then you know that someone somewhere has a cryptographically relevant quantum computer."
A cryptographically relevant quantum computer — one capable of breaking the elliptic-curve cryptography that underpins Bitcoin blockchain signatures, as well as encryption used in bank payment rails — does not yet exist. In Bitcoin, those signatures are what prove a spender controls the private key associated with coins being moved, which is why a practical break of elliptic-curve signatures would be a protocol-level security issue rather than a conventional software bug. But estimates for when such machines could arrive have been moving closer rather than further away, Zervigon said.
"The folks spending billions of dollars, like Microsoft, IBM, and others developing quantum computers, generally believe there will be a commercially relevant, cryptographically relevant quantum computer in the 2029 timeframe," he said. "That's not me making stuff up. That's based on what people like Arvind Krishna at IBM have said."
That timeline is in line with recent hardware research. Earlier this year, Google researchers said breaking the elliptic-curve cryptography protecting leading cryptocurrencies such as bitcoin and ether would require fewer than 500,000 physical qubits, a 20-fold reduction from previous estimates. The finding led several observers, including Google, to move the so-called Q-Day deadline forward to 2029.
The White House is also targeting quantum and post-quantum security milestones. It aims to develop a powerful quantum computer by 2028 and move high-value assets and federal data to post-quantum cryptography by 2030. The U.S. standardization effort has already begun: in 2024, the National Institute of Standards and Technology finalized its first post-quantum cryptography standards for algorithms intended to withstand attacks from both classical and quantum computers. "That sets the clock. It creates a sense of urgency,” Zervigon said.
Governance speed, not cryptography, is the key concern
Zervigon is not alone in arguing that crypto’s main vulnerability may be governance rather than cryptography.
Deutsche Digital Assets has framed the issue as a speed gap between traditional finance and decentralized networks. "The difference — and this is the honest answer to the 'Bitcoin is uniquely vulnerable' narrative — is governance speed," the bank wrote on July 23.
The firm said an investment bank such as JPMorgan does not need approval from millions of pseudonymous participants around the world before upgrading its cryptographic infrastructure.
“It needs a board resolution, a budget, and a vendor. Large financial institutions can and will migrate to post-quantum standards faster, more quietly, and more predictably than a decentralised public blockchain. That is not an argument against Bitcoin. It is an argument for taking its governance process seriously,” Deutsche Digital Assets added.
Academic research has made a similar point. The 2024 arXiv paper "Downtime Required for Bitcoin Quantum-Safety" cited Bitcoin’s own upgrade history as a warning about how difficult major protocol changes can be.
"Before any upgrade process can be commenced, a 90% consensus among Bitcoin miners has to be achieved over the particular details of the upgrade," the researchers wrote. "Historically, considerable changes to the Bitcoin network have been met with high resistance. A notable example of this was the SegWit upgrade in 2017."
The SegWit upgrade caused enough disagreement within the community that the Bitcoin blockchain eventually split into several versions through hard forks, creating the Bitcoin Cash and Bitcoin Gold networks.
The issue, according to that argument, is not whether post-quantum cryptography can be ready in time. The uncertainty is whether Bitcoin’s governance process can reach the 90% consensus needed to deploy such defenses, and whether wallet providers, exchanges, miners and users can coordinate any required migration once a standard is chosen.
Q-Day may be gradual rather than binary
Markets often describe Q-Day as a single moment when encryption works until a specific date and then suddenly fails. Zervigon said that framing is too simplistic and may understate how early the risk becomes relevant.
"Everybody talks about the moment you can break an algorithm," he said. "You don't necessarily need to do it in one moment to be effective. If it takes me three months or six months to decrypt data that still has value, I've achieved the same goal."
That changes the usual timeline calculation. A quantum computer would not necessarily need enough speed to break a cryptographic signature in real time to become a threat. It would only need enough capability to decrypt data or compromise funds before the underlying information or assets lose value.