READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Crypto Industry Scrambles on Quantum Defense While a Real $130 Million Bitcoin Wallet Hack Already Happened

Crypto Industry Scrambles on Quantum Defense While a Real $130 Million Bitcoin Wallet Hack Already Happened
Bitcoin developers, exchanges, and wallet makers are racing to build quantum-resistant cryptography years before any quantum computer can actually break Bitcoin's encryption. Meanwhile, a boring old software bug in Coldcard hardware wallets already drained about $130 million in real bitcoin starting July 30, proving the more immediate threat isn't quantum physics, it's sloppy code.

Nobody has built a quantum computer that can crack Bitcoin. Everybody in the industry is spending money like one's coming anyway.

On August 11, Blockstream Research's Jonas Nick and a collaborator going by remix7531 released libshrincs, a proof-of-concept code library posted to the Delving Bitcoin forum. It implements part of a signature scheme called SHRINCS, first proposed in December 2025, designed to keep Bitcoin transactions secure if quantum computers ever get powerful enough to break current encryption. According to Crypto Briefing, the project leaned heavily on AI tools including ChatGPT and Fable to generate roughly 19,600 combined lines of formal verification code, checked by humans rather than written from scratch by them.

The developers are upfront that this isn't finished. Crypto Briefing reported the current security proof doesn't yet cover a complete post-quantum bound under the standard quantum security model, and nothing here is headed into Bitcoin Core anytime soon. This is research, not a product.

Same day, on the other side of the industry, BitGo launched a free public tool that checks whether a Bitcoin address's public key has been exposed onchain, according to Bankless. Exposed public keys are the specific thing a quantum computer would need to steal funds via Shor's algorithm. The tool requires no login, doesn't store the addresses people type in, and builds on quantum-risk scoring BitGo already sells to institutional clients.

Binance's chief security officer, Jimmy Su, tried to put a number on how worried people should actually be. In an August 11 company post reported by crypto.news, Su said plainly that "current quantum computers are nowhere near the scale and reliability needed to break the cryptography protecting digital assets." He called it a long-term concern, not an active threat.

That's the honest baseline. Google Quantum AI estimated in March that breaking 256-bit elliptic curve cryptography, the math underlying Bitcoin and Ethereum wallets, could eventually take fewer than 500,000 physical qubits, about 20 times less than an earlier estimate, according to crypto.news. That's a real drop driven by algorithmic improvements. It is not evidence that hardware capable of the attack exists today. It doesn't.

Su also pushed back on vendors selling "quantum proof" products, warning users "you could actually introduce more security risk today trying to protect yourself against a future threat." That's a fair point directed squarely at any wallet company marketing quantum concerns to sell gear nobody needs yet.

The money backing this research is real and substantial. Strategy, BlackRock, Coinbase, Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets and Galaxy Digital formed the Bitcoin Security Consortium, pledging $15 million combined over three years, according to a Bitcoin Foundation report citing a Strategy press release. Brink, the nonprofit coordinating the group through executive director Mike Schmidt, already awarded its first post-quantum grant in June to a researcher known as Conduition. Galaxy Digital separately committed up to $5 million on July 21, two days before joining the consortium, though it's unclear if that pledge is folded into the $15 million total.

Outside Bitcoin, the cryptography world is moving too. Security researcher Bruce Schneier noted on August 10 that post-quantum algorithms ML-KEM and ML-DSA, both finalized as NIST standards in 2024, are now built into the widely used Python cryptography library, funded by Germany's Sovereign Tech Agency. Schneier's framing is worth repeating directly: "the reason to do this now is because there's no emergency," and doing it anyway builds crypto agility, which he calls "always a good idea."

While the industry debates a threat that doesn't exist yet, a very real and very ordinary bug already drained bitcoin from thousands of wallets. Coinkite disclosed in late July that a firmware flaw in its popular Coldcard hardware wallet, dating back to a 2021 update, bypassed the device's dedicated randomness chip during key generation, sometimes tying private keys to predictable values like device serial numbers, according to Bitcoin.com. Attackers started draining funds July 30. Losses hit roughly 594 BTC in the first wave, about 1,082 BTC by August 1, and an estimated 2,055 BTC, close to $130 million, from more than 7,700 addresses. Galaxy Research's head of research, Alex Thorn, said at least 15 separate attackers exploited the flaw.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Crypto BriefingBitcoin developers unveil libshrincs, a proof-of-concept library for post-quantum security
unknown
banklessBitGo Launches Public Bitcoin Quantum Risk Checker on Bankless
unknown
schneierschneier.com
unknown
crypto.newsBinance CSO says crypto faces no immediate quantum threat
unknown
news.bitcoinSui Co-Founder Is Building Quantum-Safe Hardware Wallets For $10
unknown
bitcoinfoundationBlackRock, Coinbase Join $15M Bitcoin Quantum Push