Library · Crypto, word by word · Cryptography

What is quantum risk in crypto?

Quantum risk is the possibility that a large future quantum computer could break the signature cryptography that protects crypto wallets, letting someone work out a private key from its public key. No such machine exists today, and NIST has published replacement algorithms designed to resist one.

What it means for you

The most exposed coins are those whose public key is already visible on chain: old pay-to-public-key outputs, Taproot outputs, and coins left on an address that has already spent and been reused. Hashed address types reveal the key only when spent. Moving to quantum-resistant signatures needs changes to each network, and coins then have to be moved by their owners.

A common mistake: “Quantum computers can already crack Bitcoin wallets.”

In fact: NIST's 2024 draft transition plan states that no cryptographically relevant quantum computer currently exists. The concern is future machines, which is why standards bodies and blockchain developers are preparing migrations now.

How it works

NIST notes that ECDSA, EdDSA and RSA are vulnerable to Shor's algorithm on a cryptographically relevant quantum computer, while hash functions and symmetric ciphers are less vulnerable and NIST does not expect to replace them. NIST published post-quantum standards FIPS 203, 204 and 205 in August 2024. Its draft transition plan, IR 8547, states that no such computer currently exists and proposes disallowing ECDSA and EdDSA in NIST standards after 2035. A Bitcoin proposal, BIP-360, separates long exposure, keys already public on chain, from short exposure while a transaction waits to confirm, and takes no position on timelines.

Sources: NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards, NIST: Post-Quantum Cryptography project, BIP-360: Pay-to-Merkle-Root (draft) · checked 4 October 2026

Related words

Elliptic curveECDSAPublic keyTaprootHash

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.