Securing Elliptic Curve Cryptocurrencies Against Quantum Vulnerabilities [pdf]
quantumai.google
quantumai.google
And once you get to that point, you need to harness the output energy of a million degrees plasma through something that yields a pretty high efficiency (so that pumping energy into the plasma is not only worthwhile, but makes financial sense) and requires a reasonably low maintenance.
I see fusion more practical as a rocket technology (which is just basically impossible) than as an actual energy facility asset.
Oh wait: thousands of programmers started working on this in the early 90s so that there would be so few failures people thought it was a scam.
The entire financial and government infrastructure was based on ecdsa until the shift to pqc. The consequences of not preparing are literal threats to global economy. That can’t be understated. The cost to switch to (hybrid) pqc is essentially zero when compared to the costs for not doing it.
You seem to be conflating the theory with pitches to investors?
The number of qubits is increasing exponentially, and the error rates are getting lower. People have factored numbers larger than 21 (not that Shor's algorithm is commonly used benchmarks by experimentalists at this point but people with little knowledge about quantum computers and device physics love it, https://link.springer.com/chapter/10.1007/978-3-032-12983-3_... did 221 and and in fact, you can do it yourself using Qiskit on IBM's publicly available devices [or on a local simulator for few qubits] following their tutorial https://qiskit.qotlabs.org/docs/tutorials/shors-algorithm if memory serves the largest instance for public is ibm_kingston with 156 qubits https://quantum.cloud.ibm.com/computers?limit=25&system=ibm_...) but it will take more time until we have millions of good qubits to harvest your Satoshis.
For the programmer folks here, as a physicists working on the device side of things for many years now, the best analogy I have is: we didn't get from a few hand-made vacuum tubes to billions of transistors with 18A manufacturing process overnight, and we won't get from hundreds to millions of better qubits overnight either. A realistic expectation would be thousands within this decade, but keep in mind that the growth has so far been exponential in various types of qubits, much like Moore's law, so reaching to millions of qubits shouldn't take us 10 millenia.
If a nation state develops a sufficiently powerful quantum computer. Seizure of the Satoshi-era bitcoin wallets without post quantum protections would fund either rogue actors or nation states.
> Indeed, some governments will have the option of using CRQCs (or paying a bounty to companies) to acquire these assets (possibly to burn them by sending them to the unspendable OP RETURN address [321]) as a national security matter. As before, blockchain’s loss of the ability to reliably identify asset owners combined with the laches doctrine [319] enables governments to argue that the original owners, through years of inaction, have failed to assert their property rights
Quantum computers don't break SHA256, nor would this attack be "reasonably attributable" to a SHA256 break.
In fact, if you have funds in a wallet that has never spent a transaction before (only received), it's still reasonably difficult for a CRQC to steal your funds. The trick is, the moment you've ever spent a transaction, now your public key is known (and therefore breakable).
(Yes, I'm aware of the literature on quantum search vs hash functions, but it's not a complete break like RSA or ECC.)
The very early days of Bitcoin had addresses created using the now-deprecated P2PK address variant—Pay To Public Key. These addresses are simple encoded secp256k1 public keys with no hashing.
There are still > 1.5 million BTC stored in P2PK UTXOs as of this post, all of which are up for grabs to the first person who can derive the private keys for the known public keys
>On superconducting architectures with 10−3 physical error rates...
So good old 0.1% noise performance again. That seems to have come from the "20 million noisy qubits to break RSA" scheme[1] from back in 2019. That level of noise performance is still wildly out of reach and for all we know might be physically impossible.
It's only ~1 order of magnitude away from current capability. current gen QCs are around 1% gate error rate, and a decade ago SOTA was ~10% error rate, so if progress continues it should be achievable relatively soon.
Let's say you start adding water to a fish tank drop by drop, and double the number of drops each time. One drop, two, four, eight, and so on. When is the fish tank half full? When it's like 1/16 of the way full, or something like that.
This is false. When Fowler et al assumed 0.1% gate error rates would be reached for his estimates in 2012 [0], that was ostentatious. Now it's frankly a bit overly conservative. All the big architectures are approaching or surpassing 0.1% gate error rates.
From 2022 to 2024, the google team improved mean two qubit gate error rate from 0.6% [1] to 0.4% [2]. Quantinuum's Helios has a two qubit gate error rate of 0.08% [3]. IBM has Heron processors available on their cloud service with two qubit gate error rates ranging from 0.2% to 0.7% [4]. Neutral atom machines have demonstrated 0.5% gate error rates [5].
[0]: https://arxiv.org/abs/1208.0928
[1]: fig 1c of https://arxiv.org/pdf/2207.06431
[2]: fig 1b of https://arxiv.org/pdf/2408.13687
[3]: https://arxiv.org/abs/2511.05465
[4]: https://quantum.cloud.ibm.com/computers?processorType=Heron (numbers may vary as the website is not static)
The analytics of thousands of accounts sending tokens to new accounts. Better use a VPN a migrate on an unusual hour in your time zone :D