← Bitcoin Encyclopedia

Post-Quantum Cryptography (PQC)

🌳 Advanced

💡 The Plain-English Definition

Post-quantum cryptography means cryptographic algorithms that can resist attacks from quantum computers — machines that use quantum mechanics to do certain calculations enormously faster than ordinary computers. For Bitcoin, quantum computing is a potential long-term threat to the elliptic-curve cryptography that secures private keys, and the community is actively developing responses.

Post-Quantum Cryptography (PQC)
IBM's Quantum System One — real quantum hardware, though still far from powerful enough to break Bitcoin's cryptography.Photo: OJB Quantum, 2024, CC BY 4.0, via Wikimedia Commons

🤔 But Why Though?

Bitcoin’s private-key security rests on elliptic-curve cryptography — specifically, the fact that deriving a private key from its public key is mathematically hard. Ordinary computers can’t solve that in any practical timeframe. But a quantum computer running Shor’s algorithm — a quantum method that efficiently cracks the hard math behind elliptic-curve cryptography — could in theory derive a private key from a public key, compromising any address whose public key is visible on-chain.

How close is this? In March 2026, Google Quantum AI published research showing the hardware needed to break 256-bit elliptic-curve cryptography is roughly 20 times lower than 2024 estimates had assumed — cutting the requirement from tens of millions of physical qubits (the basic units of a quantum computer) to about 400,000–500,000. That still doesn’t make the threat imminent: today’s quantum computers run at around 1,000–2,000 physical qubits, with high error rates. Most researchers put the ability to break Bitcoin’s cryptography within a 10-minute block window in the mid-2030s at the earliest, and only for the most well-resourced attackers.

The danger also depends on the address type. P2PK addresses (the earliest format, where the public key sits directly on-chain) and any address whose public key has already been revealed by spending from it are immediately vulnerable to a powerful enough quantum computer — an offline attack with no time limit. Unspent P2WPKH and P2TR addresses (Native SegWit and Taproot) only reveal their public key at the moment of spending, so an attacker would have to derive the private key within the roughly 10-minute confirmation window — a much harder task. A March 2026 report from ARK Invest and Unchained Capital estimated that about 34.6% of the circulating bitcoin supply sits in addresses with already-exposed public keys.

Solutions are taking shape. In August 2024, NIST — the US standards body — finalised its first post-quantum cryptographic standards: ML-DSA (formerly CRYSTALS-Dilithium) and SLH-DSA (formerly SPHINCS+). And BIP-360 has been proposed for Bitcoin, defining a quantum-resistant output type called Pay to Quantum Resistant Hash (P2QRH).

🌍 The Real-World Analogy

Think of the quantum threat like a lock-picking technology being developed in a research lab. Today, your lock is unpickable with any known tool. In ten to fifteen years, the tools to pick it might exist. The sensible response isn’t panic — it’s moving to a new lock type while there’s still plenty of time, rather than waiting until the picking tools are out in the world. Bitcoin’s response to the quantum threat is that migration: moving funds to quantum-resistant address types before the threat becomes practical.

⚡ So What?

For most holders, the practical step today is simple: move holdings to Taproot (bc1p) addresses, and avoid address reuse. In theory Taproot’s exposed internal key makes it slightly more vulnerable than unspent SegWit, but it’s better positioned than legacy formats overall, and any post-quantum upgrade to Bitcoin will build on Taproot’s architecture. The quantum threat is real, the timeline is uncertain, and the community is working on solutions — but this is a decade-horizon concern, not a 2026 emergency.

📩 The Daily Bit · free

Get one plain-English Bitcoin email each morning.

The Daily Bit — free, two minutes, unsubscribe anytime.

Bitcoin Myths & Legends: DebunkedPrefer a book? Bitcoin Myths & Legends: Debunked