The United States is putting $215 million on the table to accelerate the development of fault-tolerant quantum computers. The Department of Energy’s goal is to demonstrate machines with hundreds of logical qubits by 2028. For Bitcoin, the news deserves attention. A sufficiently powerful quantum machine could one day attack the signatures that protect certain bitcoins. And this week, an Ethereum researcher added another concern: AI could accelerate the threat even before the famous “Q-Day” arrives.

In brief
- The United States plans up to $215 million to accelerate quantum computing.
- No current quantum computer is capable of breaking Bitcoin’s cryptography.
- Justin Drake warns that AI could also speed up the discovery of mathematical flaws.
Bitcoin now eyes the American quantum race
The American program has a name: Quantum Genesis Q Competition. The Department of Energy wants to fund companies capable of building quantum computers that can actually be used for scientific research. This acceleration comes at a time when AI is already making it possible to significantly reduce the cost of certain quantum protections for Bitcoin.
The competition has up to $215 million in planned funding. The first phase will pay for several intermediate stages. Next, $100 million will be distributed among teams capable of demonstrating a scientific machine with at least 100 logical qubits. Two additional envelopes of 50 million each concern the thresholds of 150 and 200 logical qubits.
The DOE wants to have systems with “a few hundred” logical qubits by 2028. This figure deserves an explanation. Current quantum computers often boast hundreds or thousands of physical qubits. They remain extremely sensitive to errors. A logical qubit groups together many physical qubits in order to obtain a sufficiently reliable calculation.
It’s these logical qubits that really matter when we talk about attacking modern cryptography. The American government does not hide its ambitions. The Quantum Genesis program must combine quantum computing, supercomputers and artificial intelligence. Priority applications concern in particular chemistry, materials physics, applied mathematics and nuclear sciences.
Bitcoin is not an announced target. But advances in science may eventually produce machines capable of solving the mathematical problems that secure cryptocurrencies today. This is where the subject becomes much more interesting.
Why a quantum computer could threaten some BTC
Bitcoin uses several cryptographic mechanisms. SHA-256 notably secures mining and intervenes in the network hashing system. Transactions are also based on secp256k1 elliptic curve cryptography.
It is especially this second part that is worrying. A private key allows you to sign a transaction. The associated public key allows the network to verify that the signature is valid. With a traditional computer, finding the private key from the public key is considered practically impossible.
A sufficiently powerful quantum computer using Shor’s algorithm could change this equation. It could theoretically solve the mathematical problem on which this protection is based and reconstruct a private key from an exposed public key.
Not today.
The official page dedicated to the quantum resistance of Ethereum, which also uses elliptical cryptography for its accounts, cites a Google Quantum AI study published in March. She estimates that around 1,200 logical qubits could be needed to attack a 256-bit elliptical cryptography, far fewer than some old estimates.
Bitcoin facing quantum: a threat still distant, but very real
The DOE is targeting 100 to 200 logical qubits in its competition. The gap therefore remains significant. And even this comparison is not enough: the number of qubits is not the only factor. It is also necessary to consider the number of operations that can be carried out, the error correction, the stability of the machine and the duration necessary for the attack.
No quantum computer in existence today can steal Bitcoins by calculating the private keys of their owners.
However, the threat is no longer ignored by developers. The BIP-361 project estimates that as of March 1, 2026, more than 34% of bitcoins had already revealed an on-chain public key. This does not mean that 34% of BTC can be stolen now. This simply identifies a part of the supply that would be a more direct target if a cryptographically relevant quantum machine appeared.
Ethereum Researcher Now Adds AI to the Problem
The debate took on another dimension this week. Justin Drake, a researcher at the Ethereum Foundation, called on the blockchain industry to calmly begin preparing for what he calls “bunker mode.” His concern is not just quantum. Drake believes that rapid advances in artificial intelligence in mathematics could eventually uncover unknown shortcuts against ECDSA. In its most pessimistic scenario, the problem could become serious in “months rather than years”.
It doesn’t say that ECDSA was broken. No practical attack allowing the private key of a Bitcoin wallet to be found today from its public key has been publicly demonstrated. Rather, the warning comes from the speed of progress in AI-assisted mathematics. OpenAI recently published hundreds of mathematical works produced by an internal model. Drake sees this as a sign that AI systems are becoming capable of very quickly exploring problems long reserved for human researchers.
Bitcoin is precisely based on the hypothesis that certain mathematical problems remain extraordinarily difficult to solve. If AI found a new algorithm that was much more efficient, the raw power needed could decrease. Vitalik Buterin took this hypothesis seriously enough to publicly respond to Drake.
It goes even further: certain solutions considered to be quantum-resistant, notably cryptography based on Euclidean networks or “lattices”, could also undergo attack progress thanks to mathematics produced by AI.
But Buterin refuses to panic. It does not recommend users to rush their assets. A poorly prepared migration can itself cause losses. This nuance is important. A researcher alert is not broken cryptography.
Not all Bitcoin addresses are equally exposed
Drake nevertheless offers a simple measure to large holders: when it is easy to do so, favor new addresses whose public keys are not yet visible on-chain. For what ? Some forms of Bitcoin addresses hide the public key behind a hash until the funds have been spent. This removes from a possible attacker the starting point necessary to find the private key.
But this mechanism does not protect all the parts. Legacy Pay-to-Public-Key outputs directly expose public keys. Taproot also has some special features of this type. And when a modern address is reused after a spend, its public key may have been revealed.
This debate has existed for several months in the ecosystem. Adam Back had already called on Bitcoin to gradually prepare for its transition to quantum. However, opinions differ greatly on the urgency.
Some researchers talk about a window of a few years. Others estimate that the necessary hardware is still decades away. Current experiments remain tiny in the face of the real cryptographic problem. It is precisely to avoid having to decide at the last moment that the developers are already working on different solutions. Bitcoin was never built with full post-quantum cryptography. It will likely need to evolve before the threat becomes real.
Bitcoin is already preparing several exit doors
One of the most popular proposals is BIP-360. This project introduces a new type of output called Pay-to-Merkle-Root, or P2MR. In particular, the idea is to remove the key spend path used in Taproot, which exposes a public key.
BIP-360 does not make Bitcoin completely quantum-resistant. It reduces part of the attack surface and prepares an architecture to more easily integrate new signatures. The project currently remains in the proposal stage and is not enabled on Bitcoin.
Another project, BIP-361, goes much further. He imagines that after the introduction of a true post-quantum method, Btc can gradually stop accepting certain old types of vulnerable signatures. The objective would be to encourage holders to migrate before Q-Day.
The proposal is also still in draft form. However, institutions are starting to look at the subject closely. BlackRock, Coinbase, Strategy and several others have joined a $15 million consortium to work on Bitcoin’s quantum security. Preparation therefore now goes beyond a few discussions between developers. It becomes a financial subject. And states are not slowing down their own research.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
