Q-Day: When Will Quantum Computers Actually Break Bitcoin?
- No one can say exactly when quantum computers will break Bitcoin (BTC), but two experts warn the industry is treating a trillion-dollar risk far too casually.
- The right question is not the date, but the odds and the cost.
- Stefano Gogioso and Daniela Herrmann made the case during the latest BeInCrypto Experts Council.
- Both call themselves optimists, yet both argue that preparation cannot wait for proof.
What Happened
Stefano Gogioso and Daniela Herrmann made the case during the latest BeInCrypto Experts Council. Both call themselves optimists, yet both argue that preparation cannot wait for proof.
Readers ask constantly when “Q-Day” will arrive. That is the day a quantum computer can break Bitcoin’s cryptography. Speaking on the BeInCrypto panel, Gogioso argued that fixating on a date misses the point.
Stefano Gogioso, a quantum computing lecturer at the University of Oxford and co-founder of Spooqy, said.
Market Context
“In 2024, I was on stage and we said quantum computing will be here in 30 years. Then in 2025 it dropped to 15 to 20 years. Then in 2026, three to five to ten. And suddenly, in October, we hear two years, one year. The market moves faster, innovation moves faster, than it was communicated,” Daniela Herrmann, CEO and co-founder of Dynex, said.
The mechanism is now clear. When you spend Bitcoin, your public key is briefly exposed. A capable quantum computer could then derive your private key.
Why It Matters
No one can say exactly when quantum computers will break Bitcoin (BTC), but two experts warn the industry is treating a trillion-dollar risk far too casually. The right question is not the date, but the odds and the cost.
Q-Day Could Break a Trillion-Dollar Industry
“The question isn’t ‘will it be 2030?’ It’s what’s the probability of a tail event by 2030, and how much would we lose. Even at 2%, the impact on Bitcoin and crypto, if we’re not prepared, is essentially most of crypto going to zero. That’s trillions of dollars. And even 1% of that is more than enough to pay every cryptographer in the world to spend six months fixing it.”
The logic is insurance, not prediction. You do not insure a house because you expect a fire. You insure it because the loss would be ruinous, and the premium is small. The same math turns a distant science story into a decision for today.
When Quantum Computers Could Break Bitcoin
The research supports him. In May 2025, Google researcher Craig Gidney showed that breaking RSA-2048 might need fewer than 1 million qubits. That was down from his own 2019 estimate of about 20 million.
The next result aimed straight at crypto. In March 2026, Google Quantum AI worked with the Ethereum Foundation and Stanford. The team estimated that breaking Bitcoin’s elliptic-curve cryptography could take fewer than 500,000 physical qubits.
One caveat keeps the picture honest. Gidney has said he does not expect another tenfold drop without new assumptions. Each reduction also shifts the burden onto harder engineering problems that remain unsolved.
The clearest signal comes from the builders. Google has set an internal 2029 target to move its own products onto quantum-resistant encryption. When the leading quantum lab treats this as a this-decade problem, delay looks reckless.
Details
The estimates for practical quantum computing keep shrinking. Herrmann has watched them fall in real time.
Her advice was blunt. Stop naming a year, and prepare for the surprise instead. Gogioso explained why progress speeds up. The hardest step is the first one, not the last.
“The difference between no logical qubits and one logical qubit is an enormous gap. The difference between one and a million is a smaller gap. Once you get it to work, scaling up is actually quite easy.”
It studied secp256k1, the exact curve behind Bitcoin and Ethereum (ETH) signatures. That figure is roughly 20 times lower than the previous best estimate.
The reductions are steep across both targets.
Why 2% is Enough to Act On
Whether the machine lands in 2030 or 2035 matters less than the asymmetry. A small chance of total loss still justifies action. The cost of preparing is trivial next to the cost of being wrong.
Migration is also slow. Moving a financial system to new cryptography takes years. So the work has to begin well before any machine exists.
How Quantum Computers Would Break Bitcoin
The popular image of Q-Day is a single dramatic morning. The reality the panel described is quieter and more dangerous. The damage lies in belief, not in the code.