Q-Day: When Will Quantum Computers Actually Break Bitcoin?
No one can say exactly when quantum computers will break Bitcoin (BTC), but two experts warn the industry is treating a trillion-dollar risk far too casually. The right question is not the date, but the odds and the cost.
Stefano Gogioso and Daniela Herrmann made the case during the latest BeInCrypto Experts Council. Both call themselves optimists, yet both argue that preparation cannot wait for proof.
Q-Day Could Break a Trillion-Dollar Industry
Readers ask constantly when “Q-Day” will arrive. That is the day a quantum computer can break Bitcoin’s cryptography. Speaking on the BeInCrypto panel, Gogioso argued that fixating on a date misses the point.
“The question isn’t ‘will it be 2030?’ It’s what’s the probability of a tail event by 2030, and how much would we lose. Even at 2%, the impact on Bitcoin and crypto, if we’re not prepared, is essentially most of crypto going to zero. That’s trillions of dollars. And even 1% of that is more than enough to pay every cryptographer in the world to spend six months fixing it.”
Stefano Gogioso, a quantum computing lecturer at the University of Oxford and co-founder of Spooqy, said.
The logic is insurance, not prediction. You do not insure a house because you expect a fire. You insure it because the loss would be ruinous, and the premium is small. The same math turns a distant science story into a decision for today.
When Quantum Computers Could Break Bitcoin
The estimates for practical quantum computing keep shrinking. Herrmann has watched them fall in real time.
“In 2024, I was on stage and we said quantum computing will be here in 30 years. Then in 2025 it dropped to 15 to 20 years. Then in 2026, three to five to ten. And suddenly, in October, we hear two years, one year. The market moves faster, innovation moves faster, than it was communicated,” Daniela Herrmann, CEO and co-founder of Dynex, said.
Her advice was blunt. Stop naming a year, and prepare for the surprise instead. Gogioso explained why progress speeds up. The hardest step is the first one, not the last.
“The difference between no logical qubits and one logical qubit is an enormous gap. The difference between one and a million is a smaller gap. Once you get it to work, scaling up is actually quite easy.”
The research supports him. In May 2025, Google researcher Craig Gidney showed that breaking RSA-2048 might need fewer than 1 million qubits. That was down from his own 2019 estimate of about 20 million.
The next result aimed straight at crypto. In March 2026, Google Quantum AI worked with the Ethereum Foundation and Stanford. The team estimated that breaking Bitcoin’s elliptic-curve cryptography could take fewer than 500,000 physical qubits.
It studied secp256k1, the exact curve behind Bitcoin and Ethereum (ETH) signatures. That figure is roughly 20 times lower than the previous best estimate.
The reductions are steep across both targets.
One caveat keeps the picture honest. Gidney has said he does not expect another tenfold drop without new assumptions. Each reduction also shifts the burden onto harder engineering problems that remain unsolved.
Why 2% is Enough to Act On
Whether the machine lands in 2030 or 2035 matters less than the asymmetry. A small chance of total loss still justifies action. The cost of preparing is trivial next to the cost of being wrong.
Migration is also slow. Moving a financial system to new cryptography takes years. So the work has to begin well before any machine exists.
The clearest signal comes from the builders. Google has set an internal 2029 target to move its own products onto quantum-resistant encryption. When the leading quantum lab treats this as a this-decade problem, delay looks reckless.
How Quantum Computers Would Break Bitcoin
The popular image of Q-Day is a single dramatic morning. The reality the panel described is quieter and more dangerous. The damage lies in belief, not in the code.
The mechanism is now clear. When you spend Bitcoin, your public key is briefly exposed. A capable quantum computer could then derive your private key.
Google’s figures suggest the core computation could run in about nine minutes. Bitcoin’s average block time is roughly 10 minutes. That narrow window is the whole attack surface.
Gogioso stressed that the real weakness is psychological.
“It’s not a technical problem. It’s a PR problem. The moment one Satoshi-era coin moves off its wallet with ‘you’ve been quantum punked’ in the message, that’s it. It doesn’t matter that 75% of coins are protected, they’ll be worth nothing. Everybody panics and exits.”
Herrmann reached for a historical parallel, the tulip mania. Belief can stay near-universal until the instant it breaks.
“The moment one coin moves, it’s the end of the story. Imagine you’re an institutional asset manager. You wake up and your portfolio isn’t secure anymore. You have an obligation to get rid of it, if you still can. And if you can’t, you’re done.”
The March 2026 result was disclosed with care. Google published the resource estimates but hid the circuit designs behind a zero-knowledge proof. That choice signals a live risk, not a thought experiment.
Why No One Is Fixing It
If the threat is real and the fix is cheap, why has Bitcoin not moved? Gogioso pointed to governance, or the lack of it.
“Bitcoin has a completely different governance structure, in that it doesn’t have one. Some of those independent voices fall into quantum denialism. They don’t believe it’s a threat. There’s a conservative tendency. They don’t want to make changes they don’t have to. But this is a change you have to make.”
Ethereum offers a contrast. Vitalik Buterin has urged migration to quantum-resistant cryptography within about four years. He warned that elliptic-curve cryptography could be at risk around 2028.
His team published a formal roadmap in early 2026, following the Ethereum Foundation’s creation of a dedicated post-quantum research group.
The wider clock is also ticking. The US standards body NIST plans to deprecate the current elliptic-curve signature standard by 2030 and disallow it by 2035. Bitcoin has no equivalent body to coordinate such a change.
Gogioso’s warning about denial was sharp.
“It might be tomorrow. For all you know, it’s already happened.”
What Preparing Now Looks Like
None of this means Bitcoin is doomed. Both guests were firm optimists about the technology. Herrmann said solutions already exist in outline.
“There are already concrete ideas for transitioning from Bitcoin to a quantum-secure Bitcoin. Ways to move from the old coins to the new ones, with an offset between them. It’s never a linear consequence.”
The tools for a migration are on the table. What is missing is the will to start. For most large organizations, Herrmann noted, the threat is not yet part of strategic planning. A large institution cannot change course the day the danger appears.
The panel did not call for panic. It calls for treating a low-probability, high-impact event seriously, while the fix is cheap and the timeline is still generous. The one thing no one can promise is that the timeline will stay the same.
The post Q-Day: When Will Quantum Computers Actually Break Bitcoin? appeared first on BeInCrypto.
Read more





