The increasing presence of quantum computing in headlines has led to speculation about the potential collapse of bitcoin, with claims that future machines could rapidly crack its cryptography or overwhelm the network. However, academic research presents a more nuanced picture, indicating that some widely cited breakthroughs rely on simplified problems that do not accurately represent real-world cryptography. Furthermore, the energy required for a quantum attack on bitcoin is equivalent to that of a small star, according to research papers shared by Bitcoin hardware entrepreneur Rodolfo Novak.
Bitcoin's security is based on two types of math, and quantum computers pose a threat to them in two different ways. The first, known as Shor's algorithm, targets wallet security by deriving a private key from a public key, potentially allowing an attacker to take control of funds.
The second, known as Grover's algorithm, applies to mining and offers a theoretical speedup on the trial-and-error search miners perform. However, the advantage of Grover's algorithm largely disappears when attempting to build the machine, as the energy requirements become prohibitively expensive.
Two recent papers highlighted the challenges of launching a quantum attack on bitcoin. The first paper, published in March 2026, examines whether a quantum computer could out-mine BTC using Grover's algorithm.
The researchers argue that running Grover against SHA-256, the math formula bitcoin miners use to solve and add new blocks to the blockchain, would be physically impossible due to the enormous energy requirements. The estimated energy needed for a quantum mining fleet to attack bitcoin is roughly 10²³ qubits drawing 10²⁵ watts, approaching the energy output of a star. The second paper, from Peter Gutmann and Stephan Neuhaus, aims to replicate every major quantum factoring breakthrough of the past two decades. They successfully replicated these breakthroughs using a 1981 VIC-20 home computer, an abacus, and a dog, highlighting the fact that many quantum factoring demonstrations have cheated by picking numbers with hidden prime factors that are easy to guess or running the hard part of the problem on a regular computer first.
The authors propose new evaluation standards for quantum factoring demonstrations, including the use of random numbers, no preprocessing, and factors kept secret from the experimenters. While the papers do not dismiss the quantum threat entirely, they suggest that the real vulnerability lies in bitcoin wallets, not mining.
Millions of bitcoin sit in older or reused addresses where key information is already exposed on the blockchain, making them the most likely long-term target if quantum machines improve. Recent research has warned that progress in this field may not always be shared openly, and developers are working on fixes, including ways to reduce key exposure and new types of signatures designed to withstand quantum attacks.