Since the birth of Bitcoin, various new fears, doubts, and uncertainties have been used to predict its end. Nevertheless, Bitcoin has grown into a trillions-of-dollars asset and has begun to occupy a place in the global monetary order. In recent months, the threat of so-called "cryptographic quantum computers" ( CRQC ) that could allow attackers to reconstruct private keys from public keys, sign Bitcoin transactions, and transfer others' funds has resurfaced in the form of an upgraded version of panic. Is this threat realistic for Bitcoin's continued growth? In a word, no. There is no evidence that such a computer will be built within ten years, and it is still unknown whether such a machine will ever be constructed at all. The quantum threat remains a speculative claim.
Current Situation
To date, no quantum computer has achieved results that surpass the capabilities of a child who is 6 years older than their developmental age (as confirmed by empirical evidence). Quantum computing is an astonishing technology that demonstrates capabilities with a truly sci-fi quality in the modern world. These devices utilize fundamental technologies such as optical tweezers, laser cooling, superconducting magnetic flux qubits, electromagnetic traps, and dilution refrigerators. In these devices, a single quantum bit is forced to enter a specific subatomic state (which varies depending on the technical approach), entangled into a superposition state, manipulated to perform calculations, and then its subatomic properties are read and interpreted. The amazing fact is that such devices do indeed exist and are capable of producing meaningful computational results with minimal input. However, the cold reality is that, taking one candidate technology as an example, to perform a calculation that a child could do, it would require enough energy to power the air conditioning in a high school in Texas, several hours of preparation time, and even more hours for post-processing.
Read the Future
I know what you’re thinking: “But so much money is flowing into the field of quantum computing.” Does the influx of funds necessarily mean that a field will experience faster technological progress? Not necessarily. In fact, it’s even possible that the arrival of funds in a certain direction could be inversely correlated with the likelihood of viable technologies being developed, until the underlying technologies are mature and the products match the market demands. The Space Shuttle program and Falcon 9 can illustrate this point clearly. Falcon 9 utilized (for the most part) well-known scientific principles and put them into practice to meet the clear market demand for reliable, low-cost space access; it achieved its first manned mission at a cost of less than 5 billion dollars. The Space Shuttle’s first manned mission cost around 50 billion dollars. Falcon 9 not only had a significantly lower development cost but has also maintained a perfect record of safety in manned flights to this day. There are many reasons for these differences, but they show that no amount of funding can make an immature technology viable. Applying this to quantum computing, we can see that despite substantial investments, there have still been costly technical demonstrations. However, this doesn’t mean that more funding will lead to the stable, low-error-rate quantum bits we’re dreaming of (as reliable as Falcon 9). Continuing with the Space Shuttle program, no matter how much money is invested, it would never achieve the low cost and high reliability of Falcon 9. Similarly, it’s entirely possible that no current quantum computing technology, no matter how much investment is made or how long it develops, will ever reach the level of reliability required to crack a single key pair.
You might be thinking now, “So what about the recent progress?” There are two things to keep in mind regarding the recently published advancements. First, many of these advancements are actually at a purely mathematical level. For example, a recent paper published by Google concluded with such an important finding that they chose to omit the theoretical quantum circuits to prevent them from being used to crack important cryptographic systems. This might seem like a huge step towards the future of CRQC, but in reality, nothing has changed. Unless (or until) quantum hardware reaches its “Falcon 9 moment,” there is no device that even comes close to having the stability and scale required to run those omitted circuits. Hiding circuits designed for a device that may never exist is essentially just for show. Second, at the hardware level, we see many new results and some progress every year, but how many of these belong to the same candidate quantum computing technologies? And how many are just new starts after previous efforts have reached dead ends? The reality is that these advancements do not represent a linear path towards ultimate success. They are more like a breadth-first search in an infinite space of possibilities, where researchers hope to find a way to move forward at least a little bit, rather than hitting another dead end.
If we look at the future reality of quantum computing, at most it is just a vague prospect. There are indeed some promising technological advancements. In my opinion, neutral atom devices are particularly worth paying attention to. However, it is still too early to determine whether there is a real path leading to the ultimate goal along any of the currently known branches, or whether we will have to start over in the future. If at some point in the future we see the same candidate technology undergoing multiple rounds of iteration, resulting in increasingly powerful devices that can perform meaningful computations even children who are precocious cannot accomplish, then we can revisit this issue based on different evidence.
Theoretically
There are perhaps two explanations for why quantum research has repeatedly failed to develop CRQC over the course of several decades. Firstly, it is indeed a challenging problem, and we continue to use science and engineering to try to solve it. One day, human creativity may prevail, just as it did in the development of the internet, smartphones, social media, and Bitcoin (whether these are positive developments is up to the readers to judge). On the other hand, it is also possible that developing CRQC is either simply impossible or always beyond our grasp. Consider what CRQC truly entails: such a machine must be able to represent an entire space of possibilities on a scale equivalent to the complexity of the cryptographic problem at hand. In other words, to crack the 128-bit security of the elliptic curve discrete logarithm on Bitcoin’s secp256k1 curve, a quantum superposition state would need to represent all possible values of a 128-bit number. In classical computing, the amount of storage required to represent these values far exceeds the capacity of any computer ever built by humans. If there is even the slightest imperfection in the granularity of the quantum superposition state (that is, if it is not perfectly continuous across all possible values), then quantum computers will never be capable of having cryptographic relevance. If the energy required to maintain the superposition state increases with the complexity it represents, then quantum computers will also never be capable of having cryptographic relevance. The current understanding of quantum physics does not rule out either of these possibilities.
Conclusion: Bitcoin cannot stop moving forward.
Despite all the above viewpoints, the development of new cryptographic algorithms for Bitcoin must continue. Although a quantum attack on Bitcoin's cryptography is not imminent, it is entirely possible that new vulnerabilities could be discovered through other means. We know that certain elliptic curves have been found to have weaknesses, and secp256k1 could be the next one. The reason Bitcoin has survived to this day is that attacks on the system have made it stronger, and this will still be true when quantum attacks occur. The development of P2MR, P2TRv2, SHRINCS, SPHINCS, IBC, ML-DSA, and more post-quantum signature schemes will ultimately help enhance Bitcoin's resilience in the face of future attacks, even if the real CRQC is never developed.

Label
- Quantum computer
- Quantum noise
- Quantum problems












