Key Takeaways
The quantum threat to Bitcoin just got a lot more concrete. Justin Drake, a researcher at the Ethereum Foundation and co-author of Google’s landmark March 2026 quantum paper, now places 50% odds on ‘Q-Day’ arriving by 2032, with a 10% chance as early as 2030.

Q-Day is the moment a quantum computer successfully breaks the cryptography protecting real wallets on a live blockchain. For Bitcoin, it would not announce itself. It could arrive silently.
On March 31, Google’s Quantum AI team published research that permanently shifted the conversation. The paper showed a 10-fold improvement in cracking secp256k1, the elliptic curve underpinning every Bitcoin and Ethereum transaction.
The attack could theoretically be executed using fewer than 500,000 physical qubits, a roughly 20-fold reduction from the previous best estimate of 9 million. On a superconducting architecture, that means cracking a Bitcoin private key in under nine minutes.
Google hid its key circuit optimizations behind a zero-knowledge proof after coordinating with the US government. It is the first known instance of academic censorship using ZK proofs in history.
The vulnerability targets wallets where the public key has already been revealed onchain. That happens automatically every time a user spends from an address, and in all early-format Bitcoin outputs from the network’s first years.
Approximately 6.8 million Bitcoin, around 32% of all BTC ever mined, fall into this exposed category. Satoshi Nakamoto‘s original wallets, which have never moved and use an older address format, sit squarely in that group.

The scenario researchers fear most is not a visible heist. It is a slow, silent one: a state-level actor building a quantum machine in secret, quietly draining wallets, and disappearing before markets notice.
Drake called the day “a momentous day for quantum computing and cryptography,” saying the results were “shocking” and that his confidence in Q-Day by 2032 had risen significantly.
Charles Guillemet, CTO of Ledger, used the rediscovery moment to settle something that had been speculation in April. The US government did not simply advise Google on responsible disclosure. It blocked publication outright.
“Google did not choose to keep the circuits private. The US government prevented publication,” he wrote, calling the blog post’s phrase ‘we engaged with the US government’ diplomatic cover for a publication block.
He also reframed what Google’s zero-knowledge proof actually did in practice. By publishing a verifier that could confirm whether any candidate circuit correctly computes ECC point addition, Google inadvertently handed researchers a tool to reverse-engineer the very thing it was trying to hide.
The community used it, reproduced Google’s numbers, and then improved them by 11.5% in two months with no access to the original circuits.
His closing was a deliberate recalibration against panic. No quantum computer capable of running these circuits exists today, he noted. But the public timeline for post-quantum cryptography is now demonstrably thinner than reality, squeezed from one end by government classification and from the other by open research that moves faster than anyone expected.
“In security, the moment you start doubting the foundation is the moment you start rebuilding it. Not the moment you panic. The moment you plan, ” Guillemet further noted.
Sreeram Kannan, founder of EigenLayer, illustrated the entire threat landscape with a single anecdote. An undergraduate on his team with no formal quantum training, using a Codex subscription and spare evenings, improved one of the best published quantum cryptography circuits by roughly 2x. That researcher then built a platform for collaborative agent-based optimization.
Over the weekend, an 18-year-old named Gajesh used a custom agent swarm to reach 80% of Google’s unpublished breakthrough independently.
“We believe this heralds a new era of open agentic science,” Kannan wrote, “where anyone and their agents can build upon others’ results on frontier scientific problems, hitherto possible only for elite academics.”
He announced the Quantum ECC Addition Challenge, developed alongside Dan Boneh at Stanford and Justin Drake at the Ethereum Foundation.
However, not everyone shares the urgency. Eli Ben-Sasson, co-founder of StarkWare and one of the architects of modern ZK proof systems, pushed back sharply on Tuesday.
“My turn to call out quantum FUD,” he wrote, calling the open community’s improvement on Google’s circuit a nothingburger.
His argument is straightforward: shaving down circuit size is interesting but not the bottleneck. The real question, he says, is whether anyone can actually build a machine with 1,000 or more reliable logical qubits and run it at scale. That engineering challenge, in his view, remains enormous and largely unsolved. Optimizing a theoretical circuit does not bring that machine any closer to existing.

Nonetheless, the message is hard to miss. The barriers to cracking quantum cryptography are falling not just in elite government labs, but in dorm rooms.
The US government’s working deadline for transitioning off quantum-vulnerable cryptography is 2035, originating at the NSA and adopted by NIST. Drake calls that date a joke.
Guillemet noted that most organizations have not even started a cryptographic inventory. The gap between classified research and public knowledge is narrowing faster than anyone anticipated.
Ethereum has committed to a 2029 post-quantum migration target. Bitcoin’s community is debating BIP-360, a quantum-resistant signature proposal, but no timeline exists.
As Guillemet put it:
“Cryptography exists to create mathematical trust in the security of systems. That trust is now being eroded, not by a working attack, but by the increasingly credible prospect of one. In security, the moment you start doubting the foundation is the moment you should be rebuilding it.”
For ordinary holders, the step is simple: stop reusing Bitcoin addresses. Any address from which you have already spent has an exposed public key permanently onchain.
Drake’s 50% odds by 2032 are not a prediction that the world ends in six years. They are a warning that the coin has already been flipped.