Bitcoin’s Quantum Problem Is Really a Governance Problem

As quantum computing advances accelerate, Bitcoin faces a challenge deeper than cryptography: how a decentralized network governs irreversible change. Unsplash+

Earlier this month, Avihu Levy, chief product officer at StarkWare, said Posted a proposal This has been the focus of active debate within the Bitcoin community. Its scheme, Quantum Safe Bitcoin (QSB), allows users to transact in a way that remains secure even against a large-scale quantum computer using Shor’s algorithm, and it does so without requiring any change to the Bitcoin protocol itself. The engineering is really clever and deserves the attention it’s gotten.

It was Levy’s suggestion It is seen in some directions As a kind of relief valve for Bitcoin: finally, a way to make the network quantum secure without the slow and controversial protocol upgrade process. The urgency for quantum resilience has intensified over the past year as governments and major technology companies accelerate planning for post-quantum migration. But the proposal answers a much smaller question than many people think.

One type of solution for one type of user

Quantum Safe Bitcoin replaces Bitcoin’s elliptic curve signatures with a hash-based signature puzzle that a quantum computer cannot efficiently shorten, all within Bitcoin’s existing legacy script framework. The trade-off is cost: each transaction requires an estimated $75 to $150 in GPU computation, which is why the researchers themselves positioned the scheme as a last-resort mechanism for securing large balances rather than a scalable replacement for everyday transactions.

What QSB offers is a way for an individual owner to make a quantum resistant transaction today without waiting for a network-wide upgrade. This is useful, especially for institutions, custodians, and large Bitcoin holders looking for contingency options against future quantum threats.

What it does not offer, and was never designed to provide, is a path for Bitcoin itself to reach network-level post-quantum security. The great enthusiasm surrounding the proposal has caused confusion between these two questions, even though they are fundamentally different problems. The cryptographic component of Bitcoin’s transition has been, in many ways, the least difficult part for years.

The National Institute of Standards and Technology (NIST) has completed its first study Post-quantum standards In August 2024. Governments across the United States, UK and European Union Since then, it has published migration roadmaps stretching back to the early 2030s, while proposals for post-quantum address types already exist within Bitcoin’s BIP process. Traditional finance, cloud infrastructure providers, and national security systems are already actively planning a migration toward post-quantum cryptography, underscoring how relatively unresolved Bitcoin’s path remains.

The technical basis for a quantum-resistant address type in Bitcoin is largely in place. A much more difficult problem is the coordination required to move the decentralized network into a single network.

Problems that actually are

Remove encryption, and you find yourself with two problems that Bitcoin has yet to solve. First, how does Bitcoin migrate hundreds of millions of addresses, spread across exchanges, custodians, hardware wallets, paper backups, dormant cold storage, and lost devices? A move of this magnitude to a post-quantum address standard would require at least a soft fork, and perhaps a hard fork later, along with years of coordination across a decentralized ecosystem that has historically struggled to reach consensus on even relatively narrow technical upgrades. Bitcoin’s years-long battles over SegWit activation and block size limits offer a reminder of how contentious governance changes can become even when much less is at stake.

Central systems can force the migration, but Bitcoin has no similar mechanism.

The second question is bigger. Almost there 1.7 million bitcoins trapped In early public key payment (P2PK) addresses, where the public key is already exposed on-chain. Some of them are believed to belong to Satoshi Nakamoto, the pseudonymous creator of Bitcoin. Many others are almost certainly lost forever. Researchers from Google Quantum AI have separately estimated that up to 6.9 million Bitcoins across all types of scripts could eventually face some level of quantum exposure depending on implementation details and wallet behavior. As soon as a sufficiently capable quantum computer emerges, these addresses can (and probably will) be exploited immediately.

The expected timeline is narrowing. In March, the Google Quantum AI team published revised estimates suggesting that cracking Bitcoin’s elliptic curve encryption would require approx. 20 times smaller than physical qubits From predictions calculated just one year ago. It is still widely believed that practical attacks will take years, but the trend of travel is becoming difficult for the industry to ignore.

The Bitcoin community has not reached a consensus on what to do with these weak currencies, and every available option carries significant trade-offs. Leave it untouched, and it effectively becomes a free harvest for whoever reaches quantum power first. By freezing it, Bitcoin’s once credible principle of neutrality is at risk. If you burn it, the network will cross a different but equally important line of management. Underneath these three possibilities, there is a political question that no one has answered either: Who really gets to decide?

Bitcoin Core developers can write code, but they cannot move coins, and any solution that touches dormant balances will require approval from miners, exchanges, custodians, node operators, and the broader owner community.

The precedent of any of these groups deciding what happens to someone else’s BTC is the kind of thing Bitcoin was specifically designed to prevent. This is the part of the problem that QSB does not address, and it is also the part that no standalone cryptographic proposal can solve.

Decisions that don’t get a second pass

The default assumption behind much decentralized infrastructure was that anything could eventually be developed, given enough time and enough consensus. The Bitcoin quantum problem is the first serious test of this assumption against a deadline that the network does not control. Unlike previous managerial disputes over measurement or productivity, the pressure is imposed externally by advances in physics, computing, and cryptography.

If the migration succeeds, it will succeed on the terms dictated by the network owners, which almost certainly means slowly and at great expense. If it fails, it fails because a technological timeline hits an external deadline before Bitcoin’s internal coordination mechanisms can catch up.

Either way, the result is the same: cryptographic decisions made at launch are not meant to last forever, and the assumption that a decentralized network can adapt to anything with enough runway is one that will challenge this shift.

The problem is underneath the problem

None of this diminishes what QDB actually achieves. It provides quantitative resistance at the transaction level to individual holders who can afford the associated account costs, and this is a useful capability to bring to the table.

But the problem the network has to solve is the problem behind cryptography itself: How does a decentralized system with no central authority migrate hundreds of millions of addresses to a new cryptographic standard, and what does it do about coins that will never move on their own?

Any solution ultimately reached will depend on management, coordination and collective agreement. These operations move much slower, and much more easily, than encryption breaches do. In other words, Bitcoin’s quantum problem may ultimately reveal less about the limits of cryptography than about the limits of decentralized coordination under technical pressure.

Quantum computing tests Bitcoin's most important assumptions


Leave a Comment