The potential of quantum computing to compromise bitcoin's security has been a topic of increasing concern, with many speculating that the advent of powerful quantum machines could spell disaster for the cryptocurrency. However, recent academic research presents a more nuanced picture, suggesting that the energy requirements for such an attack would be prohibitively high, while also casting doubt on the significance of recent quantum factoring breakthroughs.

Bitcoin's security relies on two types of mathematical problems, which are vulnerable to quantum attacks in different ways. The first, known as Shor's algorithm, poses a threat to wallet security by potentially allowing a powerful quantum computer to derive a private key from a public key.

The second, known as Grover's algorithm, applies to mining and offers a theoretical speedup, but its advantages are largely negated when the energy requirements and technical constraints of building such a machine are taken into account. Two recent papers highlight the impracticality of quantum attacks on bitcoin. The first, by Pierre-Luc Dallaire-Demers and the BTQ Technologies team, calculates that running Grover's algorithm against the bitcoin blockchain would require a quantum computer with an enormous number of qubits, drawing an amount of energy equivalent to that of a small star.

The second paper, by Peter Gutmann and Stephan Neuhaus, replicates recent quantum factoring breakthroughs using a 1981 home computer and a dog, demonstrating that these achievements are often based on simplified problems that do not reflect real-world cryptography. The researchers argue that the steady stream of headlines claiming quantum computers are breaking encryption is largely exaggerated, with many demonstrations relying on rigged numbers or classical preprocessing to achieve their results. While the threat of quantum computing to bitcoin is real, it is primarily a concern for wallet security, with millions of bitcoin stored in older or reused addresses that are vulnerable to attack if quantum machines improve. Developers are already working on fixes, including reducing key exposure and developing new types of signatures that can withstand quantum attacks.

The markets reflect a view that the threat is still largely theoretical, with traders assigning low odds to the possibility of bitcoin replacing its mining algorithm before 2027, but higher odds to upgrades aimed at reducing wallet risk.