Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Stanford Cryptographer Says Quantum Computers Could Threaten Bitcoin Sooner Than Expected, But Not Yet

Stanford cryptographer Dan Boneh has spent 2026 delivering a message crypto holders don't love: the math protecting Bitcoin and Ethereum is more breakable than the industry assumed, but not breakable yet.
A paper published in March 2026 by Google Quantum AI, co-authored by Boneh and Ethereum researcher Justin Drake, revised the qubit count needed to crack the elliptic-curve cryptography behind Bitcoin and Ethereum transactions. The new estimate puts the number at roughly 1,200 to 1,450 logical qubits and tens of millions of Toffoli gates, according to Crypto Briefing. That's far below older projections that ran into the thousands of logical qubits.
The financefeeds outlet reported a related figure from the same research window: fewer than 500,000 physical qubits, about 20 times lower than a 2019 estimate, according to altFINS. Current quantum hardware sits far below either threshold. IBM's Starling program targets 200 logical qubits by 2029, according to financefeeds.
The Exposure Problem
Bitcoin's vulnerability isn't hypothetical wallets sitting untouched forever. When someone sends Bitcoin, their public key is exposed on the network during the roughly 10-minute window before a transaction confirms into a block. A powerful enough quantum computer could, in theory, derive the private key from that exposed public key and hijack the funds before confirmation.
Google Quantum AI modeled that exact scenario, a real-time hijacking attempt during Bitcoin's confirmation window, and the simulated attack succeeded 41% of the time, according to financefeeds, citing CoinDesk's reporting.
Separately, an estimated 6.9 million BTC already sit in wallets where the public key has been revealed on-chain, whether through past spending or through Taproot outputs that expose keys before spending, according to Crypto Briefing and financefeeds. That includes over 1 million BTC believed to belong to Satoshi Nakamoto's early holdings, per financefeeds. Fortune reported on August 15, 2026, that more than $2 trillion in digital assets, nearly the entire crypto market's value, sits exposed to a future quantum break, and Galaxy Digital estimated roughly 7 million BTC (about $470 billion at the time of its March 2026 estimate) already sit in the exposed condition an attacker would need, according to shattered.io's summary of that research.
On Ethereum's side, developers filed a draft proposal in August 2026, tentatively numbered EIP-8394, to rebuild the network's validator deposit contract so it can eventually support quantum-resistant signatures, according to BigGo Finance. The proposal would protect roughly $104 billion in staked ETH by replacing hard-coded BLS key formats with a flexible system supporting keys up to 8,192 bytes. A companion proposal, EIP-8141, would let ordinary accounts upgrade their cryptography without changing addresses. The Ethereum Foundation is targeting 2029 to complete the core protocol changes, BigGo Finance reported, with Ether trading near $2,475 at the time of that report.
Boneh's Actual Position: Don't Panic, Don't Wait
Coverage of Boneh's position has been confusing, with different outlets framing his statements in opposite ways.
CryptoRank and Crypto News both reported, based on comments from mid-August 2026, that Boneh "dismissed concerns" and said quantum computers "won't break Bitcoin," arguing the issue is well understood and solvable by moving to post-quantum addresses. Crypto News quoted Boneh saying those who think quantum computing will break blockchain security "are mistaken."
But Crypto Briefing and coinfomania, both citing a Boneh lecture shared through a16z later in August 2026, frame his message as considerably more urgent: that the exposed 6.9 million BTC represents real risk, that a quantum computer could forge blockchain signatures, and that the industry needs to move on quantum-resistant signatures now.
These aren't necessarily contradictory once you separate the timeframes. Boneh's consistent technical position, per financefeeds, is that "a hasty transition to post-quantum is more likely to cause a catastrophic bug than we'll be attacked by a quantum computer." He's arguing against both extremes: dismissing the threat entirely, and panicking into a rushed fix that breaks things.
Boneh has shifted his own preferred solution during this period. He previously backed lattice-based cryptography but now favors hash-based signature schemes like SLH-DSA (SPHINCS+), according to Crypto Briefing, because they fit better with existing blockchain infrastructure despite producing larger signatures.
How Far Off Is the Actual Threat?
Blockstream CEO Adam Back argues the practical quantum threat to Bitcoin sits 20 to 40 years out, according to financefeeds. ARK Invest's March 2026 report concluded quantum computing remains at "Stage 0," meaning the hardware exists but lacks commercially relevant capability, per the same report.
On April 24, 2026, researcher Giancarlo Lelli cracked a 15-bit elliptic curve key using publicly accessible quantum hardware and won a 1 BTC bounty from quantum security firm Project Eleven, a 512-fold improvement over a September 2025 demonstration, according to Intellectia's reporting via financefeeds. Bitcoin uses 256-bit encryption. The gap between 15 bits and 256 bits is, in financefeeds' words, "enormous." Expert consensus cited in that reporting now places a cryptographically relevant quantum computer somewhere between 2030 and 2040, compressed from older estimates stretching past mid-century.
Bitcoin developers have proposed BIP-360, a new output type meant to reduce exposure by keeping public keys off-chain until coins are spent, though the actual post-quantum signature scheme is left to a future proposal, according to financefeeds. Google has set an internal 2029 deadline to migrate its own infrastructure to post-quantum cryptography, the same report noted.
None of this means anyone's coins are at risk today. Current quantum hardware isn't remotely close to the qubit counts these papers describe. The open question is whether Bitcoin and Ethereum can finish migrating tens of billions of dollars in exposed value to quantum-resistant addresses before the hardware catches up, and whether that migration itself introduces new bugs Boneh warns could be worse than the threat it's meant to solve.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.