Fundstrat cofounder Tom Lee has warned that quantum computers might compromise the security of Bitcoin as soon as 2028 or 2029. Lee cited recent research from Google, claiming advancements in quantum technology could soon render Bitcoin’s existing protections obsolete, and cautioned that the crypto sector currently does not have a unified mitigation strategy.
Ethereum and Solana seen as less vulnerable
Lee also suggested that networks such as Ethereum and Solana may face lower risks from emerging quantum threats. He stated that their protocols offer stronger protection compared to Bitcoin’s, although he did not elaborate on specific security features in his brief remarks. Ethereum and Solana are both popular blockchain platforms supporting smart contracts and decentralized applications.
However, his statements drew immediate attention from Adam Back, the creator of Hashcash and a prominent figure in Bitcoin’s early development. Back challenged Lee’s assessment, emphasizing that Bitcoin does not use traditional encryption for transaction processing.
Adam Back pointed out that Bitcoin protects coin ownership with ECDSA-based digital signatures, and seed phrases are secured by an exceptionally high level of entropy, making them effectively immune to brute-force attacks even by quantum computers.
These digital signatures are cryptographic methods used to authenticate and secure transactions, rather than encrypt data. The security of Bitcoin wallets relies on the computational difficulty of deriving a private key from its corresponding public key.
Mini dictionary: ECDSA (Elliptic Curve Digital Signature Algorithm) is a cryptographic technique widely used in blockchain networks to ensure transaction authenticity without revealing private keys. Its security is based on the difficulty of solving certain mathematical problems efficiently, which quantum computers may potentially address with future advancements.
Focus on legacy addresses and public key exposure
The genuine quantum threat to Bitcoin centers on a subset of coins held in older wallet addresses, where public keys have already been exposed on the blockchain. Analysts believe around 7 million $BTC, or approximately 30%–35% of the total supply, reside in such addresses that have either been reused or have remained dormant for years.
If a sufficiently powerful quantum computer using Shor’s algorithm were built, attackers could theoretically derive the private keys associated with these exposed public keys and seize control of the funds. Shor’s algorithm is anticipated to solve certain cryptographic problems exponentially faster than classical computers.
However, there are currently no quantum computers capable of mounting this kind of attack. The threat remains theoretical, and Bitcoin developers have been researching post-quantum cryptographic solutions for several years with the goal of upgrading the protocol well before practical quantum threats emerge.
Potential network responses and the BIP-361 debate
In the event quantum threats become imminent, Bitcoin could implement a hard fork to integrate quantum-resistant signature schemes. Moving coins from exposed addresses to safer ones would be possible for active holders. However, assets in lost wallets or long-inactive addresses—including the approximately one million $BTC attributed to Satoshi Nakamoto—are unlikely to be secured by their original owners.
The network faces a difficult choice: freeze nearly a third of all Bitcoin through the contested BIP-361 proposal, or risk leaving these dormant coins vulnerable to potential quantum attacks.
BIP-361 is a controversial proposal that would allow the network to freeze coins at risk of quantum theft. If enacted, it would mark an unprecedented intervention, pitting the preservation of network integrity against long-standing principles of immutability and decentralization.
| Measure | Quantum Threat | Network Response |
|---|---|---|
| Legacy addresses (public key exposed) | High risk (approx. 7 million $BTC vulnerable) | BIP-361 freeze or move to new addresses |
| Modern addresses (public key not disclosed) | Low risk (quantum attack theoretical) | Monitor and implement post-quantum upgrades |