Quantum computers will threaten Bitcoin in years. AI may be months away

A machine with about 20,000 qubits would crack a Bitcoin key in just over 26 days. This is what IonQ, an American company that builds quantum computers, calculated, and immediately stated that there is no such machine yet. This week, an Ethereum researcher warned that artificial intelligence may be faster. Glassnode data shows how many coins would then be targeted: 6.26 million BTC, almost a third of the total. This also applies to bitcoin holders in Poland, especially those who hold coins on exchanges.

  • IonQ estimates that a quantum computer with about 20,000 qubits would crack a bitcoin key in just over 26 days. The company states that such a machine does not exist and its plan dates back to around 2028.
  • Justin Drake of the Ethereum Foundation says that in a worst-case scenario, AI could do this within months. Critics, including Coinbase’s Adam Back and Yehuda Lindell, point out that there is no evidence for this.
  • According to Glassnode data, 6.26 million BTC, or 31.2 percent of the supply, lies on addresses with exposed public keys, mainly through reusing the same addresses.
  • The cheapest protection has been known for years and costs nothing: a new address for each payment.


26 days on a machine that doesn’t exist

IonQ published an estimate on September 8 of what it calls the first complete plan to crack the secp256k1 elliptic curve. Signatures in the Bitcoin network are based on this curve. According to the company, a machine with about 20,000 physical qubits would take just over 26 days to accomplish this.

IonQ disclaims that this is an architecture study and does not publish the circuitry that would perform the attack. There is no such machine yet. IonQ ties it to its development plan for around 2028.

Signatures would be at risk. Whoever breaks the key will sign the transfer in someone else’s name.

Ethereum researcher says AI could be first

On Wednesday, Justin Drake of the Ethereum Foundation wrote on X that in the worst-case scenario, AI could compromise the security of Bitcoin and Ethereum wallets. He added that it was a matter of months, not years. As a signal, he cites mathematical results published by OpenAI, in which cryptography appears suspiciously rarely, as Gizmodo reports. Drake did not indicate a specific result.

Readers’ opinion

Will Bitcoin hit $100,000 before the end of 2026?

Drake calls on the industry to calmly start planning for “bunker mode.” Large holders would gradually move funds to addresses whose public key never appeared on the chain. Vitalik Buterin partially supports him. However, he warns against rushing. “I have personally lost more money on failed migrations than on all hacks combined,” wrote Buterin, who was quoted by CoinDesk.

Adam Back from Blockstream called the warning a “fud-burger”, i.e. fear-mongering without foundation. Coinbase’s head of cryptography Yehuda Lindell responded that there was no evidence of elliptic curves being broken. No one has ever demonstrated a practical attack on keys, note CoinDesk and Gizmodo.

How many bitcoins does the public key have in view

The private key signs transfers and must remain secret. The public key does not have to be secret. It can be derived from the private one, but not the other way around, and the entire system is based on this one-directionality. A quantum attack or a hypothetical AI attack would have to reverse this path.

Glassnode’s data was shown on Thursday by company co-founder Rafael Schultze-Kraft. According to them, 6.26 million BTC lies in addresses with a disclosed public key, or 31.2 percent of the supply. More than two-thirds of this pool, approximately 4.33 million BTC, is exposed by reusing the same addresses. Another 1.94 million BTC lies in address types that show the key right away. This is the oldest format from the early years of the network (P2PK) and Taproot.

Stock exchanges are a separate item. The leaked public key has 57 percent of the bitcoins lying on it. The data itself says nothing about the attack or the weakness of the exchanges.

With a regular address, the public key appears in the chain only with the first outgoing transfer. Then you can see it permanently, also with each subsequent payment to the same address. Taproot shows it from the beginning.

Are you reading us? Add bitcoin.pl to your preferred sources on Google

What does this mean for the bitcoin owner?

The most effective protection has been known for years and costs nothing. This is a new address for each deposit. Most modern wallets generate it themselves. If your wallet still shows the same address, it’s worth checking its settings.

Taproot addresses start with bc1p and show the key immediately, older bc1q only when released. If you hold your coins at bc1p, it only matters once someone learns to recreate the keys.

Bitcoin’s rules already allow for a quantum-resistant signature, but in August one such transfer cost up to $200. In my opinion, rushing to migrate today carries a more real risk than a machine that doesn’t exist.

The Ethereum Foundation has already set a target for the transition to quantum-resistant cryptography: December 2029. Bitcoin does not yet have an agreed date for such a transition.