Thirty years of trading derivatives taught me a rule about tail risk: the dangerous ones aren’t the risks people argue about. They’re the ones where both sides of the argument are wrong — the camp that says “panic now” and the camp that says “never think about it.” Quantum computing’s threat to Bitcoin is currently being argued by exactly those two camps. This piece is for everyone in neither.
The framework position, stated up front the way I state everything: quantum computing is a real, bounded, slow-moving structural risk to digital assets. It is not a reason to exit. It is not ignorable. It is a risk to be sized — monitored against specific triggers, like any position. Below is what the threat actually is, what changed this spring, what the exposure really looks like, and — because this publication doesn’t do vibes — the specific developments that would change my read.
What the threat actually is (and isn’t)
Bitcoin’s security rests on two different kinds of cryptography, and the quantum threat treats them very differently.
Mining — the SHA-256 hashing that orders the ledger — is largely safe. Quantum computers get only a modest theoretical speedup against hashing, and the practical consensus is that proof-of-work survives the quantum era with parameter adjustments at most. Anyone telling you quantum computers will “break the blockchain” or rewrite history is selling something.
Ownership is the real question. Every Bitcoin is controlled by a private key, and the network verifies spending through elliptic-curve signatures. A classical computer cannot reverse a public key into a private key before the sun burns out. A sufficiently large quantum computer running Shor’s algorithm — a piece of math discovered in 1994, waiting three decades for hardware to catch up — could.
The critical nuance: Shor’s algorithm needs a public key to work on. A Bitcoin address is a hash of the public key — the key itself stays hidden until the moment coins are spent from that address. Which means the threat divides all coins into two classes: coins whose public keys are already exposed on-chain, and coins still hiding behind hashes. That division is where the real numbers live.
What changed in March 2026
For years, the honest answer to “when could this matter?” was “decades, probably.” This spring, the estimate moved.
On March 30, 2026, Google Quantum AI — with co-authors from the Ethereum Foundation and Stanford — published Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, the most substantial update to quantum resource estimates in years. The specific result: Shor’s algorithm against Bitcoin’s curve can run with 1,200–1,450 logical qubits, compiling to fewer than 500,000 physical qubits on a superconducting architecture, with a runtime measured in minutes — roughly a twenty-fold reduction from the prior best physical-qubit estimate of about nine million. The timeline conversation shifted from “someday” to “plausibly within a decade or two” — and in some serious quarters, from “decades” to “possibly within one.”
Perspective, because this publication deals in it — and because the qubit arithmetic is where most coverage cheats: today’s largest machines run on the order of 1,500 physical qubits, and those are noisy, uncorrected ones. The paper’s half-million figure assumes error-corrected logical qubits, each assembled from hundreds of physical ones, under a fault-tolerance regime that has never been demonstrated at any meaningful fraction of the required scale — and a serious school of physicists argues it may never be. Measured honestly, the gap isn’t 300-to-1; it’s closer to three orders of magnitude of hardware plus an engineering discipline that does not yet exist. What March changed wasn’t the distance to the finish line. It changed the slope of the track. Twenty-fold reductions in required resources are how “impossible” becomes “expensive” becomes “inevitable” — a sequence every technologist has watched before.
A trader’s translation: the option is still far out of the money. But implied volatility just repriced, and the smart money noticed — which is exactly why the defense formally started this year.
The real exposure: the coins that can’t defend themselves
Here is the number that matters. Roughly 6.9 million BTC — over a third of the circulating supply, including Satoshi’s untouched stack — currently sit in outputs whose public keys are already visible on-chain. Early pay-to-public-key coins from the 2009–2010 era. Every address ever reused after spending. And Taproot outputs — which expose the public key in the address itself, before any spend — meaning the exposed set grows with modern adoption rather than shrinking as a legacy relic. At today’s price, that is on the order of $445 billion in coins that are, in quantum terms, standing in the open.
This creates the strangest risk profile I’ve encountered in four decades of markets. The most vulnerable coins are precisely the ones least able to act — dormant for a decade or more, keys lost or held by the dead or by a founder who vanished. When quantum capability arrives, these coins can’t migrate to safety. They can only be taken, or preemptively handled by the network itself. The Bitcoin community is already having the argument this implies — whether vulnerable legacy outputs should eventually be sunset to prevent a quantum thief from harvesting them. It’s an ugly debate that pits property rights against network survival, and there is no clean answer. Iron Law’s read: the debate itself is healthy; the absence of it would be the red flag.
There is a second, subtler exposure: the moment any coin is spent, its public key hits the mempool — and a fast-enough quantum attacker could theoretically race to derive the key and hijack the transaction before it confirms. Researchers call these on-spend attacks, and proposed mitigations exist. This attack requires a much faster machine than harvesting dormant coins, which is why the dormant exposure is the first-order concern.
There’s a colder version of the threat that the “Bitcoin is the last target” crowd misses, and it takes an options trader to see it. A quantum attacker doesn’t need stolen coins to hold value — he needs a catalyst he alone can time. Position for the downside first, then publicly move a handful of Satoshi-era coins, and the demonstration is the payday: the collapse is the mechanism, not the flaw. And the market has quietly made the positioning easier, not harder. Bitcoin’s downside is no longer one options chain — it’s an entire correlated complex of ETF options, futures options, exchange equities, treasury-company proxies, and miners, spread across venues and jurisdictions that don’t watch each other. Distributed across that surface, no single position ever looks like anything. The trade only works once, and it still leaves one footprint fragmentation can’t erase: synchronized downside skew across the whole complex with no macro catalyst to explain it. Nobody currently monitors for that. Somebody should. Sometimes the seismograph is the options chain — all of them at once.
The defense: math solved, coordination not
Here is the part the panic camp omits: the cryptography that survives quantum computing already exists. NIST finalized post-quantum signature standards in 2024. Bitcoin’s first structural response, BIP-360 — introducing quantum-resistant output types — has been merged as a draft proposal: a milestone of process, not of activation. Nothing quantum-resistant is spendable on Bitcoin today, and the broader migration framework remains under active debate. Ethereum stood up a dedicated post-quantum security team in January 2026 and has quantum resistance threaded through its 2026 fork schedule. Other chains are building resistance in from the start.
So the binding constraint is not mathematics. It is coordination — moving a decentralized, leaderless, deliberately conservative network of millions of holders onto new cryptography. Serious estimates put a full Bitcoin migration at five to seven years. That duration is the actual risk: the race is between quantum hardware maturing and a notoriously slow-moving community completing the largest key rotation in monetary history. Both runners are now visibly on the track. Bitcoin’s anti-central-planning culture — its greatest defensive asset against every other threat — is, for this one threat specifically, a liability. That irony deserves more attention than it gets.
The framework: what would change my read
Iron Law publishes invalidation for every position, and this one is no different. Today, quantum risk does not enter the cycle framework — it is a structural, multi-year overhang, not a cycle input, and it should be watched, not traded. Here is the trigger ladder that would escalate it:
One limitation, stated in the open because the framework would be dishonest without it: this ladder watches the public track — papers, demonstrations, announcements. The actors most likely to reach capability first publish nothing. A classified program could cross the Elevate line in silence and this ladder would stay green while it happened. There is no fix for that; unobservable risk can’t be traded by anyone. The ladder manages the component that can be seen and priced — and now you know exactly what it doesn’t cover.
Note what this ladder implies about price before capability ever arrives: quantum risk will trade as episodic headline shocks — every hardware announcement reported as “Bitcoin’s death,” bought or sold in a day — long before it trades as fundamental. The framework treats those shocks as noise unless a ladder trigger fires. That distinction is the entire reason to have written the ladder down in advance.
The bottom line
Quantum computing cannot touch Bitcoin today, and nothing close to the required machine exists. But March 2026 legitimately compressed the timeline, a third of the supply is structurally exposed and cannot defend itself, and the defense — begun, real, and underway — needs the better part of a decade that is no longer guaranteed to be available. That is not a crisis. That is a race with a posted start time and an unposted finish line.
The oldest rule I trade by applies: you don’t get paid for predicting the storm. You get paid for having written down, in advance, exactly what you’ll do when the first cloud shows up. Consider the clouds enumerated.