- What Quantum Computing Actually Threatens – and What It Doesn’t
- The Bitcoin Security Consortium: Nine Institutions, One Mission
- Coinbase’s Internal Preparations: PQ-CoreKMS and the Advisory Board
- Expert Opinions: What the Industry’s Most Authoritative Voices Are Saying
- Armstrong’s Core Message: Calm, Coordinated, Pre-emptive
Brian Armstrong‘s message on July 25, 2026 was measured, precise, and deliberately calm: quantum computing is not an immediate threat to Bitcoin. Then he announced the industry coalition that makes sure it never becomes one.
In a post on X shared on July 25, 2026, Coinbase CEO Brian Armstrong stated what may be the most responsible framing any major industry leader has offered on one of crypto’s most complex long-term challenges: “While quantum computing isn’t an immediate threat to Bitcoin, we’re making sure Coinbase and the broader ecosystem are prepared well before a sufficiently powerful quantum computer arrives.”
The statement arrived two days after Coinbase co-founded the Bitcoin Security Consortium – a nine-institution alliance including BlackRock, Fidelity Digital Assets, Strategy, Galaxy, ARK Invest, Block, Blockstream, and Anchorage Digital, collectively committing $15 million over three years to fund Bitcoin’s long-term security research. Armstrong’s X post was not an alarm. It was a programme announcement, delivered with the confidence of someone who has already started doing the work.
Read Also
That combination – calm assessment of the current risk paired with decisive institutional action – is exactly what the Bitcoin ecosystem needs right now, as technical evidence mounts that the quantum threat is real, distant, but not infinitely distant.
What Quantum Computing Actually Threatens – and What It Doesn’t
The Cryptographic Foundation Under Attack
Bitcoin’s security rests on two cryptographic foundations: the elliptic curve digital signature algorithm (ECDSA), which protects wallet private keys, and the SHA-256 hashing algorithm, which secures the proof-of-work mining process. Quantum computing threatens these foundations through two specific algorithms.
ETH / USD Real-Time Chart
A quantum computer powerful enough to run Shor’s algorithm could theoretically derive a private key from a public key, potentially enabling the theft of funds from any address where the public key is visible on the blockchain. Bitcoin currently relies on elliptic curve cryptography for proof of ownership and transaction authorisation.
A sufficiently powerful quantum computer – a machine that uses quantum physics to perform certain calculations millions of times faster than a conventional computer – could theoretically reverse-engineer a wallet’s private key from its public key, exposing funds.
Stay Ahead of the Curve
Join our weekly newsletter for exclusive insights.
The emphasis on “theoretically” and “sufficiently powerful” is crucial. No such computer exists today. Google’s Willow chip, the most powerful quantum processor currently operating, runs 105 qubits. A Google Quantum AI paper published March 31, 2026 concluded that a quantum computer with fewer than 500,000 physical qubits could crack elliptic curve cryptography – a figure that dramatically revised previous estimates which had pegged the requirement at 10 million qubits or more.
The revision of that estimate downward – from 10 million to 500,000 qubits – is what accelerated institutional attention in 2026. The threat did not arrive. But the timeline for its possible arrival got meaningfully shorter.
The $460 Billion Exposure Problem
The quantum risk to Bitcoin is not evenly distributed. It concentrates in a specific subset of addresses where the public key is permanently visible on-chain – a design feature of older address formats that was not a security problem when Bitcoin launched, because no computer could exploit it. More than 7 million BTC, worth approximately $460.8 billion at current prices, sits in outputs with public keys exposed to future quantum attacks.
Approximately 6.9 million BTC are held in UTXOs where the public key is exposed onchain, including about 1.7 million BTC stored in legacy P2PK addresses from the Satoshi era – some potentially belonging to Bitcoin’s anonymous creator.
The mention of Satoshi Nakamoto‘s coins is not merely symbolic. It is the single most politically charged question in the quantum Bitcoin debate: what happens to the roughly 1.1 million BTC attributed to Satoshi, sitting in early P2PK addresses, if a sufficiently powerful quantum computer eventually exists? Galaxy Digital‘s head of research, Alex Thorn, noted that the threat to so-called “Satoshi coins” may be smaller than is often assumed, since these assets are spread across roughly 22,000 separate addresses, which significantly complicates a potential quantum attack. But the question will need a technical and governance answer before Q-Day arrives – not after.
The Bitcoin Security Consortium: Nine Institutions, One Mission
Who Joined and What They Committed
Nine of the biggest institutional names in Bitcoin went public on July 23 with the joint initiative to fund the network’s long-term security – including defences against quantum computers – backed by a combined $15 million in member pledges over the next three years. The group, called the Bitcoin Security Consortium, includes BlackRock, Coinbase, Strategy, Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets, and Galaxy. Day-to-day coordination falls to Mike Schmidt, executive director of Brink – a non-profit that funds Bitcoin open-source developers – who takes on the role as a volunteer.
The structure of the consortium is as important as its membership. The $15 million will not be held or allocated by the consortium itself. Instead, members will choose independently which developers, researchers, or organisations they fund. The group has explicitly stated it will not direct Bitcoin development or take positions on proposed protocol changes.
That design choice is fundamental to how Bitcoin governance works. No corporation – not even Coinbase, not even BlackRock – can direct changes to the Bitcoin protocol. The consortium’s role is to fund the researchers and developers who will do the technical work, not to dictate what that work produces. It is influence through funding, not control through instruction.
Galaxy’s Parallel $5 Million Initiative
Galaxy separately announced a $5 million developer grant programme for quantum-resistant Bitcoin solutions two days before the consortium launch – offering funding for post-quantum cryptographic tools, quantum-resistant signature schemes, wallet migration tools, and security audits. The $15 million consortium total may or may not include Galaxy’s separate commitment.
The overlap between Galaxy’s initiative and the broader consortium is a feature, not a bug. Multiple funding streams for the same class of research problem – with different governance structures and different technical priorities – create a more robust research ecosystem than a single concentrated fund.
Coinbase’s Internal Preparations: PQ-CoreKMS and the Advisory Board
Building a Post-Quantum Key Management System
While the consortium addresses the ecosystem level, Coinbase has been building its own internal quantum defences in parallel. Coinbase is developing PQ-CoreKMS, a post-quantum version of its proprietary key management system that protects approximately 99.9% of the assets it holds in custody. Its existing CoreKMS system relies on multiparty computation (MPC), which distributes control of private keys so that no single party can reconstruct them.
The upgrade from MPC-based CoreKMS to post-quantum PQ-CoreKMS is the most operationally significant step Coinbase is taking. It is not a whitepaper exercise. It is a live engineering project affecting the custody of billions of dollars in customer assets.
Coinbase has also established an Independent Advisory Board on Quantum Computing and Blockchain to assess realistic risks and recommend practical solutions. The Advisory Board has expressed high confidence that a fault-tolerant quantum computer will eventually be developed.
NIST Standards: The Regulatory Backdrop
Coinbase’s preparations align with a shifting regulatory landscape. In June 2026, the U.S. National Institute of Standards and Technology released draft updates to federal post-quantum cryptography standards incorporating newly standardised quantum-resistant algorithms for identity verification and authentication, underscoring that organisations should continue preparing for the transition to post-quantum security.
A June executive order directed federal agencies to move high-value systems to post-quantum key establishment by the end of 2030 and post-quantum digital signatures by the end of 2031. The U.S. government is not treating post-quantum cryptography as a theoretical future concern. It is treating it as a current operational transition with hard deadlines – and Coinbase’s preparations are running on a similar timeline.
Expert Opinions: What the Industry’s Most Authoritative Voices Are Saying
Jeff Lunglhofer, Coinbase CISO: Start the Work Now
The clearest internal statement of Coinbase’s position came not from Armstrong’s X post but from his Chief Information Security Officer. Jeff Lunglhofer wrote in a July 23 blog post: “A large-scale quantum computer capable of breaking current cryptography will eventually be built. No one knows exactly when. But the work to prepare needs to start now, not when it’s urgent.”
That sentence – “not when it’s urgent” – is the operational philosophy that distinguishes proactive security planning from reactive crisis management. The history of technology security is full of systems that waited until urgency arrived to begin preparation, and paid the price.
Robert Mitchnick, BlackRock Digital Assets: Funding the Long-Term Security Work
BlackRock’s voice on the consortium carried particular institutional weight. “Bitcoin Core developers do incredibly important work,” said Robert Mitchnick, BlackRock’s head of digital assets, explaining the group’s commitment to making additional funding available for Bitcoin’s long-term security.
BlackRock managing $10+ trillion in assets and choosing to co-found a Bitcoin quantum security consortium is not a casual decision. It reflects an institutional assessment that Bitcoin’s long-term security is a prerequisite for continued institutional adoption – and that the quantum threat, while not immediate, is material enough to warrant strategic investment now.
Adam Back, Blockstream CEO: Hash-Based Signatures Already Being Tested
Blockstream CEO Adam Back previously called for beginning an upgrade of the Bitcoin network to protect against future quantum attacks. According to him, a dedicated team is already exploring possible blockchain compromise scenarios, and one of the first practical steps was the implementation of hash-based signatures on the Liquid network.
Back’s credentials on this topic are unmatched: as the inventor of hashcash – the proof-of-work system that inspired Bitcoin’s mining mechanism – his assessment of cryptographic threats carries weight that extends well beyond corporate advocacy.
Project Eleven: Q-Day Could Arrive Between 2030 and 2042
Project Eleven’s 2026 quantum threat report placed its baseline estimate for Q-Day – when a quantum computer could break current public-key cryptography – in 2033. Its early scenario placed the date in 2030, while its later case extended to 2042. These estimates remain uncertain and depend on advances in hardware, error correction, and algorithms.
The range – 2030 to 2042 – is wide enough to make precise planning difficult, but narrow enough to make current preparation clearly justified. If Q-Day is 2030, the industry has four years. If it is 2042, it has sixteen. Neither scenario permits the luxury of waiting until the threat is certain.
Dan Robinson, Paradigm: Protecting Satoshi-Era Wallets Without Moving Funds
Paradigm researcher Dan Robinson proposed the PACTs model, which allows owners of inactive wallets – including addresses from the Satoshi Nakamoto era- to preemptively prove control over funds without needing to move them. The PACTs model addresses one of the most technically and politically delicate aspects of the quantum migration: how to protect dormant wallets, including Satoshi’s, without requiring their owners – who may be deceased, lost, or unreachable – to take action.
Jameson Lopp and BIP-361: A Migration Roadmap
BIP-361, a draft proposal co-authored by Casa co-founder Jameson Lopp and other developers, outlines a phased migration away from ECDSA and Schnorr signatures. The proposal would first prevent users from sending additional BTC to outputs considered vulnerable to quantum attack, then provide migration windows for holders to move funds to quantum-resistant addresses.
The BIP process – Bitcoin Improvement Proposals – is the formal mechanism through which protocol changes are proposed, debated, and eventually adopted by the Bitcoin network. BIP-361 is early-stage, and adoption is far from guaranteed. But its existence signals that the technical community is no longer merely discussing the quantum threat. It is writing the code to address it.
Armstrong’s Core Message: Calm, Coordinated, Pre-emptive
The framing Brian Armstrong chose for his July 25 X post is not accidental. “Quantum computing isn’t an immediate threat to Bitcoin” addresses the fear. “We’re making sure Coinbase and the broader ecosystem are prepared” provides the action. “Well before a sufficiently powerful quantum computer arrives” establishes the timeline.
The quantum threat to Bitcoin is not unique to crypto. If quantum computers become powerful enough to break modern cryptography, banks, governments, payment networks, cloud platforms, and secure websites would also need to upgrade. The bigger question is whether the ecosystem can prepare early before the risk becomes practical.
Armstrong’s answer, backed by $15 million in institutional commitments, a new Advisory Board, a live PQ-CoreKMS development programme, and a nine-institution consortium that includes the world’s largest asset manager, is: yes, and the work has already started.
The quantum threat to Bitcoin is not today’s problem. But it is being treated, by the most serious institutional actors in the space, as tomorrow’s priority. That is precisely the right response to a risk that operates on a decadal timeline – and the Bitcoin Security Consortium’s launch on July 23, 2026 is the most consequential institutional signal the Bitcoin security community has received since the network’s inception.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any investment decisions.
