Two rigorous views, one missing variable
Estimates of Bitcoin's quantum exposure differ because they count vulnerable coins differently and assume different trajectories for quantum computing. A linear projection can imply decades; investment and breakthrough-driven projections can imply much less time.
Both approaches face the same limitation: breakthrough technologies do not follow a schedule we can forecast reliably.
Prepare without panicking
Moving too slowly risks catastrophic loss if usable quantum systems arrive early. Moving too quickly risks deploying immature cryptography and creating a new vulnerability in the attempt to solve the old one.
- Stop address reuse and improve address hygiene
- Continue protocol-level post-quantum research
- Monitor algorithmic breakthroughs, not only qubit counts
- Develop multiple upgrade and fallback paths
- Avoid treating a speculative date as certainty
The middle ground
Uncertainty is not permission to ignore the threat. It is also not a reason to rush untested cryptography.
Bitcoin can treat quantum computing as a tail risk with unclear timing: build optionality now, improve operational hygiene, and preserve the ability to migrate deliberately when evidence changes.