VOIDEXJournal

Quantum Threat to Crypto Wallets: Bitcoin, Ethereum, Exposed Keys

How a quantum computer could forge Bitcoin and Ethereum signatures, why exposed public keys matter most, and what 2026 research changes. Not financial advice.

By · 7 min read ·
Quantum Threat to Crypto Wallets: Bitcoin, Ethereum, Exposed Keys

Cryptocurrency is, at its core, a system of signatures. Whoever can produce a valid signature for a set of coins controls them. There is no bank to call and no chargeback. That design is elegant, and it has an unusually sharp exposure to one specific quantum attack.

This article explains, factually and without speculation about prices, how a quantum computer could threaten Bitcoin and Ethereum wallets, why some coins are more exposed than others, and what the research published in 2025 and 2026 actually says. It also explains why VOIDEX, which has no token or coin, cares about the same mathematics. Nothing here is investment advice.

What protects a wallet

Bitcoin and Ethereum both use elliptic-curve cryptography on a curve called secp256k1. A wallet's private key is a secret 256-bit number. Its public key is a point on the curve derived from that number. Signing a transaction proves knowledge of the private key without revealing it.

The security assumption is the elliptic-curve discrete logarithm problem (ECDLP): given a public key, it is infeasible to work backwards to the private key. On classical computers that holds at 256 bits by an enormous margin.

A large, error-corrected quantum computer running Shor's algorithm would remove that margin. Given a public key, it could compute the private key, and with the private key it could sign anything. We explain the algorithm itself in How Shor's algorithm breaks RSA and elliptic curves.

What the 2026 research says

For years the assumption was that a machine capable of this was far off. The estimates have been moving.

In March 2026, Google Quantum AI reported that 256-bit ECDLP, the problem protecting Bitcoin and Ethereum signatures, could be solved with fewer than 500,000 physical qubits and minutes of runtime. The team withheld the attack circuits and instead published a zero-knowledge proof that its resource count is correct. The result appeared weeks after Iceberg Quantum's simulated "Pinnacle" architecture for RSA-2048 and follows Craig Gidney's May 2025 estimate that RSA-2048 could fall to fewer than one million noisy qubits. The Quantum Insider summarised all three.

Important caveats: no such machine exists today, these are resource estimates rather than demonstrations, and nobody can give an honest date for when one will. What the research does establish is that elliptic curves are a smaller quantum target than RSA, and that the gap between today's hardware and the required machine has narrowed.

Hashes, addresses and exposed keys

Here is the detail that makes the risk uneven. A quantum attacker needs your public key to derive your private key. Whether your public key is visible depends on how your coins are held.

Bitcoin. The earliest Bitcoin outputs, known as pay-to-public-key (P2PK), place the public key directly on the blockchain. Many of the oldest coins, including coins mined in Bitcoin's first years, sit in outputs like these. Later formats such as pay-to-public-key-hash (P2PKH) and SegWit addresses store only a hash of the public key. The public key itself is revealed only when the owner spends from that address, because the spending transaction must include it.

Two habits undo that protection:

  • Address reuse. Once you spend from an address, its public key is public. Any coins left at or later sent to the same address are protected only by elliptic curves.
  • Taproot outputs. Bitcoin's Taproot upgrade, activated in 2021, uses outputs that commit to a public key directly rather than to a hash of it. That brought real benefits for privacy and efficiency, and it also means the key is visible on chain.

Ethereum. An Ethereum address is derived from a hash of the public key, so a fresh account that has never sent a transaction keeps its key hidden. But every outgoing transaction carries a signature from which the public key can be recovered, and Ethereum accounts are normally reused for many transactions. In practice, any account that has ever sent a transaction has an exposed public key.

At rest versus in flight

Security researchers usually separate two scenarios.

Keys at rest. Coins sitting in outputs with visible public keys could, in principle, be attacked at leisure once a capable machine exists. The attacker has as long as they like. This is the larger and more obvious exposure.

Keys in flight. Even a hash-protected address reveals its public key the moment its owner broadcasts a spending transaction. A fast enough quantum attacker could derive the private key while that transaction waits to be confirmed, and race it with a conflicting transaction. Bitcoin blocks arrive roughly every ten minutes on average, so this requires a very fast machine. The March 2026 estimate of minutes of runtime is why researchers now discuss this scenario more seriously than before.

What migration would involve

Protecting a blockchain is harder than protecting a messenger, for structural reasons.

  • Consensus. Adding post-quantum signature schemes requires network-wide agreement and software upgrades across wallets, exchanges and nodes. Proposals and discussions exist in both the Bitcoin and Ethereum communities, but at the time of writing no post-quantum signature scheme is active on either main network.
  • Owners must act. A new signature type protects only coins that are moved to it. Coins whose owners have lost their keys, or who never return, cannot be migrated by anyone else. How a network should treat such coins is a difficult, unresolved social question.
  • Bigger signatures. Post-quantum signatures such as ML-DSA, standardised by NIST in FIPS 204 in August 2024, are much larger than elliptic-curve signatures. On a blockchain, where every byte is replicated and paid for, that has real costs.

For individuals, the widely cited general hygiene points are simply these: avoid reusing addresses, understand whether the format you use exposes your public key, and follow the security guidance published by the projects and wallet software you rely on. We are not offering financial advice, and nothing here is a recommendation to buy, sell or hold any asset.

The same mathematics, a different domain

The curves that protect wallets are close cousins of the ones that protect conversations. X25519 and Ed25519, used across modern messaging, rely on the same class of problem as secp256k1. A quantum computer that can forge a Bitcoin signature could, in principle, also break a messenger's classical key exchange and read recorded traffic.

The difference is that a messenger can migrate without a global vote. VOIDEX did so from the start.

How VOIDEX handles quantum risk

Every direct conversation in VOIDEX Messenger begins with a PQXDH-style handshake combining X25519 with the post-quantum ML-KEM-768, so the resulting key does not depend on elliptic curves alone. A double ratchet with post-quantum re-keying gives each message its own key. Device identities are signed with hybrid Ed25519 plus ML-DSA-65, and every device key change is appended to a public, append-only transparency log that clients check before trusting a key. We explain the reasoning in Why hybrid post-quantum encryption wins.

It is also worth being clear about what VOIDEX is not. VOIDEX has no token or coin. The collectibles in VOIDEX Market, from Astro Phantoms and Cosmic Bears to the weekly Void Artifacts, are bought with VOIDEX Points, and VOIDEX Points cannot be bought with money or crypto. There is nothing to invest in and nothing to speculate on. VOIDEX is free, has no ads, and nobody can pay for reach.

For people who hold digital assets, the most practical overlap is communication. Seed phrases, deal terms, wallet addresses and custody arrangements are exactly the information you would not want recorded today and read later. Keeping those conversations off channels that rely on classical key exchange alone is a sensible step regardless of what any blockchain decides. The broader reasoning is in Harvest now, decrypt later.

The honest summary

  • Bitcoin and Ethereum signatures rely on secp256k1, which Shor's algorithm would break on a large error-corrected quantum computer.
  • March 2026 research estimates that under 500,000 physical qubits could do it, with circuits withheld. No such machine exists yet.
  • Exposure depends on whether a public key is visible: old P2PK outputs, reused addresses, Taproot outputs and any Ethereum account that has sent a transaction.
  • Migration requires network consensus and action by each owner, which makes it slower than for a messenger.
  • VOIDEX has no coin, and its messaging is post-quantum today.

VOIDEX is invite-only. Request access to join, or read the VOIDEX security report for the full design.

Sources

  • The Quantum Insider, "Q-Day just got closer" (31 March 2026): https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
  • Gidney, C. "How to factor 2048 bit RSA integers with less than a million noisy qubits" (2025): https://arxiv.org/abs/2505.15917
  • NIST Post-Quantum Cryptography Standardization (FIPS 203, 204, 205): https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps