The Signature Is Not the System
On the machine that has been arriving for three decades, and on what would actually have to change if it ever showed up
This is an opinion essay. It reflects the author's own view and reasoning, and it is not financial advice.
Peter Shor published his algorithm in 1994. In the thirty-two years since, the largest number anyone has factored with it on real quantum hardware is 35.
That sentence is worth reading twice, because it is not a rhetorical trick and it is not cherry-picked. A 2025 review by Dennis Willsch and six co-authors surveyed the entire published record and found that "only very small integers N ≤ 35 have been successfully factored with Shor's algorithm on a digital QC". They go further. Larger claims exist, they write, but the experiments behind them "often rely on a certain kind of oversimplification that makes them equivalent to coin flipping". And even for 15, 21 and 35, they note that the circuits "might not have been found without previous knowledge about the answer".
Thirty-two years. Thirty-five.
The machine that has never factored 36
I want to be careful about what that number does and does not prove, because the temptation to swing it like a club is strong and the swing would be dishonest.
It does not prove that quantum computers are impossible. It proves that nobody has yet built a general-purpose one large enough to be interesting, which everybody in the field already concedes. The gap between 35 and RSA-2048 is not a gap in ambition. It is a gap in error-corrected qubits, and closing it is a stated, funded, well-staffed engineering programme with credible people behind it.
But the number does something else, and this is why I keep returning to it. It calibrates. When a headline says quantum computers are five years from breaking Bitcoin, the honest question is: five years from what starting point? The answer, measured by results rather than by roadmaps, is thirty-five.
There is a second data point of the same kind, and it is more directly relevant. In April 2026 Project Eleven paid out one bitcoin for the largest quantum attack ever performed on elliptic curve cryptography. The key that fell was 15 bits long. Bitcoin's keys are 256 bits. Project Eleven, to its credit, reported the number plainly rather than burying it, and framed the remaining distance as an engineering problem rather than a physics one.
Maybe they are right that it is engineering. Engineering problems still take time, and this one has been taking time for three decades.
Thirty-two years of arriving soon
The pattern I find most instructive is not that the predictions have been wrong. It is who made them and how carefully.
In 2017, five serious researchers published a paper in Ledger examining exactly this question. Aggarwal, Brennen, Lee, Santha and Tomamichel concluded that Bitcoin's proof of work was safe for a decade, which has held, and that the signature scheme "could be completely broken by a quantum computer as early as 2027, by the most optimistic estimates".
2027 is next year. The optimistic estimate was for a machine that, as of this writing, has 48 error-corrected logical qubits at its public state of the art, against a requirement in the high hundreds to low thousands.
This is not a gotcha. The authors said optimistic, they meant optimistic, and they were reporting the field's own upper bound rather than inventing one. That is precisely the point. The field's most aggressive published estimate, from careful people acting in good faith, was wrong by a wide margin, and it was wrong in the direction the field's funding depends on.
I do not think that is corruption. I think it is what happens when a discipline has to justify itself annually to people holding budgets, and when the honest answer to "when" is "we do not know". Nobody gets a grant for saying that. And the same pressure operates in reverse on the other side: a Bitcoin publication that runs "quantum computers will never crack Bitcoin" gets more attention than one that runs "the required machine got smaller again". Both audiences are being fed what they came for.
So the first half of my position is simply this. On a question where every party with a microphone has a stake in the answer, the results are the only thing not for sale, and the results say 35 and 15 bits.
The case that it may never arrive at all
Now the more interesting possibility, and the one I think deserves far more attention than it gets.
Every argument above is about lateness. There is a separate argument, published this year in a serious venue by someone with no stake in the outcome, that the machine may not be buildable at all.
Tim Palmer is a physicist at Oxford. In March 2026, PNAS published his theory of Rational Quantum Mechanics, which proposes that the state space of quantum physics is finely discrete rather than continuous, and that standard quantum mechanics is what you get in the singular limit as the discreteness vanishes. The consequence he draws is specific: the information available in N qubits grows linearly with N, while the dimensions those qubits would have to fill grow exponentially, so above some threshold the state simply cannot be specified. He puts that threshold at roughly 200 for quantum dot qubits, 300 for photonic, 400 for ion traps, and an absolute ceiling of about 1,000. Above it, algorithms that depend on spreading a calculation across the full state space stop having an exponential advantage.
He closes the obvious escape hatch, too. You cannot isolate your way out of it, because by the principle of equivalence a quantum computer "will always be gravitationally coupled to the rest of the universe". Building it on the far side of the moon changes nothing.
If Palmer is right, there is no Q-Day. Not a delayed one. Not a distant one. None.
I want to state clearly what I think of this, and then state just as clearly why I am not going to build a position on it.
What I think: it is the most substantial argument in this entire debate, and it is being both over-claimed and under-read. Over-claimed, because his paper does not mention Bitcoin anywhere, not once, and neither does his own department's announcement of it. His worked example is RSA-2048. Under-read, because it is peer reviewed in PNAS, which is a great deal more than can be said for most of what circulates as quantum scepticism, and because Palmer is a climate physicist with no commercial interest in Bitcoin, in quantum hardware, or in cryptography. Almost nobody else in this argument can say that.
Why I will not build on it: because Palmer himself would not want me to. He presents the theory as falsifiable within about five years and predicts a specific observable signature as machines approach the threshold. A theory offered as a bet against the standard model of quantum mechanics is a theory that might lose. Treating it as reassurance is exactly the wrong response to a scientist handing you a testable claim.
And there is a smaller lesson buried in how his argument gets repeated. Palmer's roughly 400 is often paired with a 2007 result by Paul Davies, who derived a similar figure from the information content of the universe, and the pairing is presented as independent confirmation. It is not, quite. Davies called his own analysis "overly simplistic" one paragraph later, and named Shor's algorithm as the most likely thing to escape his bound, because its input state is "algorithmically simple by definition". Palmer handles this honourably and claims only that the numerical agreement is unlikely to be coincidence. The people citing Davies as a second witness have mostly not read past the abstract.
So: is a permanent ceiling possible? Yes, and for the first time it is a serious, published, falsifiable possibility rather than a hope. Is it something to rest on? No. The honest formulation is that we now have two open questions instead of one. We do not know when. And we do not know if.
The strongest case against everything I have just said
Here is the argument I would make if I were on the other side, and I think it is a good one.
Nothing above addresses the trend. Between 2017 and 2026 the published estimate of what an attack on Bitcoin's curve requires fell from 2,330 logical qubits and 1.26 x 10^11 gate operations to 1,200 logical qubits and 9 x 10^7. The gate count dropped by a factor of roughly 1,400. Craig Gidney revised his own estimate for RSA-2048 from 20 million physical qubits down to under one million in six years. In March 2026 a group including John Preskill argued that 26,000 neutral atom qubits would do a comparable job in days. These are not press releases. They are papers, with methods, that other people can check.
The steelman continues: pointing at 35 is like pointing at the Wright brothers' 37 metres and concluding that transatlantic flight is speculative. Early results in a field are always embarrassing, right up until they are not, and the interval between embarrassing and routine has historically been short once error correction crosses its threshold.
And there is a timing argument that is genuinely uncomfortable. Migration takes years. Glassnode measured 6.04 million bitcoin exposed at rest in May 2026. If the work begins only when the threat is visible, it begins too late, which means the rational moment to act is always earlier than the moment it feels justified. Waiting for certainty is a strategy that guarantees being late.
I accept most of this. I think the trend argument is the strongest thing anyone has said on the subject, and I think the timing argument is simply correct: the engineering should proceed now, regardless of what anyone believes about dates. If that were the whole disagreement, there would be no essay to write.
What Bitcoin would actually have to change
But it is not the whole disagreement, because underneath the timeline argument sits a much larger and much vaguer claim, and it is the one that actually moves people. The claim is that a quantum computer would change Bitcoin.
So let us be concrete about what would change.
Bitcoin proves ownership with a signature over an elliptic curve. If that curve becomes breakable, Bitcoin adds a signature scheme that is not. The leading candidate, Blockstream's SHRINCS proposal, rests entirely on hash functions, which are the part of Bitcoin's cryptography quantum computing does not meaningfully threaten. NIST standardised a scheme of the same family in 2024. Signatures get bigger. Wallets get more complicated. Some of the state management is genuinely unpleasant.
That is the change. A different way of proving that a key holder authorised a transaction.
Now list what does not change. The supply is still capped at 21 million, because that is a consensus rule and no signature scheme touches it. Anyone can still run a node and verify the entire chain independently, because verification cost is bounded by block size and not by which curve the signatures sit on. Nobody can inflate the supply, because nothing about a new signature format grants that power to anyone. Blocks are still ordered by proof of work, which is physical rather than mathematical and which no quantum algorithm meaningfully accelerates. Difficulty still adjusts. Halvings still happen on schedule.
Every property that makes Bitcoin worth arguing about survives the transition untouched.
Why that is not a change
There is a distinction here that the debate keeps collapsing, and I think collapsing it is the source of most of the fear.
A system has rules and it has tools. The rules are what the system promises. The tools are how it currently keeps those promises. Bitcoin has already replaced tools without anyone claiming it stopped being Bitcoin. It went from Pay-to-Public-Key to Pay-to-Public-Key-Hash. It added SegWit. It added Schnorr signatures with Taproot in 2021, which was a signature scheme replacement, exactly the category of change under discussion, and nobody wrote an essay asking whether Bitcoin had ceased to exist.
The reason nobody did is that the promise never mentioned ECDSA. When you hold bitcoin, what you are relying on is that the supply is fixed, that the rules apply equally, that you can check them yourself, and that no one can take your balance or print more. None of those sentences contains the word signature.
Satoshi understood this in 2010, before any of it was urgent. Asked what would happen if SHA-256 broke, the answer was not cryptographic. It was procedural: "If the hash breakdown came gradually, we could transition to a new hash in an orderly way. The software would be programmed to start using a new hash after a certain block number. Everyone would have to upgrade by that time." That is a maintenance plan, written with visible calm, about the failure of the primitive the whole system rests on. The system was designed on the assumption that its tools would eventually need replacing.
Is a hard problem the same as an existential one? No, and conflating them is how a five-year engineering project gets discussed as an extinction event.
The one part that should frighten you
I have argued that swapping the signature scheme is a tool change and not a real change. I owe you the case where that argument fails, because it does fail, and it fails in the place almost nobody is looking.
BIP-361, drafted in February 2026 by Jameson Lopp and five co-authors, proposes a deadline. Roughly three years after activation, no more sends to quantum-vulnerable addresses. Roughly two years after that, legacy signatures stop validating and whatever has not moved is frozen. Permanently.
The reasoning is not stupid and I will not pretend it is. Several million bitcoin sitting in publicly exposed keys is a standing bounty, and the day a machine exists that can collect it, the resulting theft is visible to everyone and does damage that no amount of "it was always technically possible" repairs. Freezing coins whose owners are almost certainly dead or lost is, on that view, the responsible thing.
But look at what it requires. It requires the network to agree to stop honouring signatures that are otherwise perfectly valid, on balances belonging to people who did nothing wrong except fail to act. That is not a tool change. It is the network establishing that a balance can be revoked by sufficient social agreement, given a sufficiently good reason. And having established it once, the interesting question is not whether the reason was good. It is what counts as a good enough reason next time.
Adam Back has argued the alternative, that optional upgrades and roughly a decade of voluntary migration are safer than a scheduled expiry, on the grounds that Bitcoin's developers have coordinated fast before when something became urgent. BIP-360 takes the conservative path of removing the vulnerable spending path and specifying no deadline at all.
I find the freeze proposal far more consequential than any qubit count, and I notice that it gets a small fraction of the attention. A quantum computer would take coins from people who exposed their keys. A sunset takes coins from people who exposed their keys, and does it by consensus, in advance, deliberately. Only one of those is Bitcoin changing.
What would have to be true for me to be wrong
Three things, and I would rather name them now than be reminded of them later.
If a machine holds a thousand logical qubits through a deep circuit. Palmer says that cannot happen and that the failure should be visible on the way. If it happens cleanly, the ceiling argument is dead, the "never" branch closes, and the question collapses back to a date. I would have to say so.
If the freeze happens and nothing bad follows. My argument treats a consensus-enforced sunset as a category error with long consequences. If BIP-361 or something like it activates, the network survives it, and no comparable proposal follows within a decade, then the precedent I am worried about was not a precedent and I overweighted it.
If a quantum theft appears on chain first. Google's group noted that early capability might be "detected on the blockchain rather than announced". If a dormant, exposed output moves without its owner before any of the migration work ships, then the leisurely reading of the timeline, mine included, was wrong in the only way that matters.
Until one of those happens, my position is this. The threat is real, specific, measurable, and confined to one component. That component is replaceable, the replacement is designed, and the work should proceed on schedule and without drama. The machine has been arriving for thirty-two years and may never arrive at all, and Bitcoin should build as though neither of those facts were known, because neither of them is.
The lock can be changed. What matters is that nobody gets to rewrite the deed while the locksmith is working. The numbers behind all of this are worth reading in full, and the mechanics of what is actually exposed are simpler than the coverage suggests. But the argument that will decide how this goes is not about physics at all. It is the one Bitcoin has always had, about who is permitted to change the rules, and about the difference between a rule that prohibits and a system that prices its own abuse, which is the distinction Bitcoin usually gets right.
Frequently Asked Questions
35. A 2025 review by Willsch and co-authors found that only integers of 35 or below have been successfully factored with Shor's algorithm on digital quantum hardware, and that many claims of larger factorisations rest on simplifications that make them, in the authors' words, equivalent to coin flipping. They add that even the circuits for 15, 21 and 35 may not have been found without prior knowledge of the answer.
Not in any sense that touches what the system guarantees. The 21 million limit, the ability of anyone to run a node and verify the whole chain independently, and the impossibility of inflating the supply or seizing a balance are all properties of the consensus rules. A signature scheme is the tool that proves ownership, not the rule that defines it. Swapping it is closer to changing a lock than to changing the deed.
There is one thing, and it is not the cryptography. BIP-361 proposes freezing bitcoin that has not migrated by a deadline. That is not a tool change. A network that can agree to stop honouring otherwise valid signatures has demonstrated that balances are revocable by social agreement, which is a change to something the signature scheme never guaranteed on its own. That deserves far more scrutiny than the qubit counts get.
Sources
- 1.Willsch, Hanussek, Hoever, Willsch, Jin, De Raedt, Michielsen — The State of Factoring on Quantum Computers
- 2.Aggarwal, Brennen, Lee, Santha, Tomamichel — Quantum Attacks on Bitcoin, and How to Protect Against Them
- 3.Palmer — Rational Quantum Mechanics: Testing Quantum Theory with Quantum Computers, PNAS
- 4.Palmer — Solving the Mysteries of Quantum Mechanics: Why Nature Abhors a Continuum
- 5.University of Oxford Department of Physics — Rational Quantum Mechanics: A New Theory of Quantum Physics
- 6.Davies — The Implications of a Cosmological Information Bound for Complexity, Quantum Information and the Nature of Physical Law
- 7.Babbush, Zalcman, Gidney et al. — Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities
- 8.Cain, Xu, King, Picard, Levine, Endres, Preskill, Huang, Bluvstein — Shor's Algorithm Is Possible with as Few as 10,000 Reconfigurable Atomic Qubits
- 9.Gidney, Ekerå — How to Factor 2048 Bit RSA Integers in 8 Hours Using 20 Million Noisy Qubits
- 10.Gidney — How to Factor 2048 Bit RSA Integers with Less than a Million Noisy Qubits
- 11.Project Eleven — Q-Day Prize Awarded for Largest Quantum Attack on Elliptic Curve Cryptography to Date
- 12.Satoshi Nakamoto — Dealing with SHA-256 Collisions, Bitcointalk, 14 June 2010
- 13.Quantinuum — Introducing Helios
- 14.IBM Quantum — IBM Lays Out Clear Path to Fault-Tolerant Quantum Computing
- 15.BIP-361 — Post Quantum Migration and Legacy Signature Sunset
- 16.BIP-360 — Pay-to-Merkle-Root
- 17.Glassnode Research — Measuring Bitcoin's Quantum-Exposed Supply
- 18.Nick, Blockstream Research — OP_CHECKSHRINCS, a Hash-Based Signature Opcode for Post-Quantum Bitcoin
- 19.NIST FIPS 205 — Stateless Hash-Based Digital Signature Standard