The quantum threat to Bitcoin is usually reduced to a dramatic image: a sufficiently powerful computer derives a private key from a public key and drains a wallet. That scenario belongs to a real category of technical risk. But it misses the harder problem. Even if developers select a resistant signature scheme in advance, the network cannot move millions of owners, old wallets, cold-storage systems and long-forgotten coins into a new cryptographic regime with one update.
That is why Coinbase's new plan matters, but not because it predicts an imminent breach. The company has started building PQ-CoreKMS, a custody system intended to support post-quantum signatures when blockchains are ready to adopt them. Coinbase describes the threat as non-immediate while arguing that coordination will be the harder challenge. This reframes the discussion. The question is no longer only whether a suitable algorithm exists. It is who must migrate, when they must do it and what happens to those who do not.
What a quantum computer would actually threaten
Bitcoin uses cryptography for several different tasks. Hashing links blocks, participates in mining and hides some public keys until coins are spent. Digital signatures prove that a transaction was authorized by the holder of a private key. Quantum computing affects these components differently.
The most discussed problem comes from Shor's algorithm. A sufficiently advanced quantum computer could theoretically recover a private key from a published public key for elliptic-curve schemes. That directly affects ECDSA and Schnorr signatures used by Bitcoin. Hash functions also lose some security margin under quantum algorithms, but they do not collapse in the same way. The statement that a quantum computer will "break Bitcoin" is therefore too broad. The first practical target is the signature layer and outputs whose public keys are already visible.
This distinction creates two attack windows. In a long-exposure attack, the adversary can see a public key well in advance, for example because an address was reused or because the output structure reveals it. In a short-exposure attack, the public key becomes visible when a transaction is broadcast, and the adversary must recover the private key and replace the transaction before confirmation. The second scenario requires much faster hardware. The first could become relevant earlier.
Draft BIP 360 proposes a Pay-to-Merkle-Root output that can reduce long-exposure risk by hiding keys inside a script tree until spending. The proposal itself makes clear that protection from fast, short-exposure attacks would still require a separate post-quantum signature scheme. This illustrates why there is no single quantum upgrade. Different risks require different changes.
Standards exist, but Bitcoin is not a corporate IT system
NIST has approved ML-DSA and SLH-DSA as digital signature standards designed to resist large-scale quantum computers. In June 2026, the agency also updated guidance on cryptographic agility and continued urging organizations to begin migration before the threat becomes urgent. That provides an important technical foundation, but standardizing an algorithm does not make it automatically suitable for Bitcoin.
Post-quantum signatures are generally larger than signatures used by Bitcoin today. Larger keys and signatures increase transaction size, storage demand and verification cost. The network must determine how much security margin it needs, whether several schemes should be supported and how to avoid dependence on one young algorithm. Adding redundancy can reduce algorithm risk while increasing consensus and wallet complexity.
A corporation can set a deadline, replace servers and disable obsolete authentication. Bitcoin has no owner that can order every participant to upgrade. A change must pass technical review, gain implementation support in nodes, and be adopted by wallets, exchanges, custodians, miners and users. Even after activation, old coins remain where they are.
The hardest users are the ones who will never return
An active user can receive a warning and move BTC to a new address type. An exchange can migrate balances in batches. An institutional custodian can test signing procedures before the change is needed. But a significant share of Bitcoin sits in wallets whose owners lost keys, died, forgot about the funds, stopped updating software or intentionally left coins untouched for years.
The network then faces three unpleasant choices.
The first is to keep legacy signatures valid forever. If a capable quantum computer eventually arrives, vulnerable coins become an enormous prize. The extraction of long-dormant BTC could sharply increase market supply and undermine confidence in the practical scarcity of accessible coins.
The second is to disable ordinary spending through legacy signatures after a long transition. That protects the network from theft, but may make funds inaccessible to legitimate owners who failed to migrate. For Bitcoin, where control is defined by valid keys, this creates a direct conflict with property expectations.
The third is to design a special recovery procedure that proves legacy ownership through more complicated conditions. Draft BIP 361 explores this general approach. It proposes first preventing new payments to vulnerable address types, then restricting legacy signatures after a pre-announced period and using a quantum-safe rescue path. The document remains a draft. It demonstrates a possible direction, not a decision made by Bitcoin.
Every path redistributes risk. Protecting dormant coins may preserve the supply but restrict living owners. Preserving all old rules respects prior conditions but leaves a future attacker with a huge target.
Migration would become a market event
Even under a calm and well-announced transition, millions of outputs would need to move. That creates demand for block space. Owners would compete for confirmation, especially if a deadline approached. Fees could rise because of a mandatory technical migration rather than speculation.
Large institutions would have an advantage. They have engineering teams, procedures, support channels and the ability to consolidate many outputs efficiently. Ordinary users may face obsolete wallets, confusing instructions and scammers offering a fake "quantum upgrade" or requesting seed phrases. The more important the migration becomes, the more attractive it becomes for social engineering.
Markets may also begin distinguishing coins by technical state. BTC held in a new protected output and BTC exposed through an old public key remain the same nominal asset, but they carry different risk during the transition. Custodians, lenders and insurers could impose different collateral requirements. A cryptographic upgrade could temporarily create economic classes inside one Bitcoin supply.
Custodians can move first, but they cannot solve the network problem
Coinbase is unlikely to be the only major institution preparing internal infrastructure. Quantum readiness offers a competitive advantage to custodians because they can promise to support new output types immediately after activation.
Early readiness has a second effect. It reduces operational risk for institutional balances while widening the gap between professional infrastructure and self-custody. A hardware-wallet user depends on a manufacturer, firmware and interface. A node operator depends on software compatibility. Coins restored from an old backup may require an application that no longer exists.
If migration becomes difficult, some users may temporarily move BTC to exchanges or custodians simply to update their addresses. That would increase custody concentration at the exact moment when security matters most.
Rushing can be dangerous too
Quantum panic can cause damage before a quantum computer does. A young signature scheme may contain an ordinary mathematical weakness. A software error in a new transaction type could place real funds at risk. A severe deadline may push users toward untested tools.
A responsible transition should not depend on one forecast date. It needs measurable triggers: progress in fault-tolerant quantum hardware, cryptographic research, standard maturity, several independent implementations, wallet audits and infrastructure readiness.
The most plausible path is gradual. Bitcoin may first gain a new output type without disabling old coins. Wallets would begin using it by default. Exchanges could stop withdrawals to vulnerable addresses. Later, the network might prevent creation of new legacy outputs. Only after several years would it confront the treatment of signatures that remain.
The final test will be political
Bitcoin is often described as a system where rules replace trust. A quantum migration would reveal the limits of that formula. A rule can be written only after the community decides which rights it is protecting: the right of an owner to spend under an old signature, the right of other participants to prevent quantum theft, or the economic integrity of the limited supply.
No option produces a perfect result. Full backward compatibility preserves vulnerability. Disabling old cryptography changes ownership conditions after the fact. A recovery mechanism adds new implementation and governance disputes.
The quantum threat therefore does not begin when a machine derives the first Bitcoin key. It begins much earlier, when the network must agree on a migration process. Technology can provide tools. The harder task is coordinating millions of people, applications and coins whose owners may never respond.



