Cryptocurrencies like Bitcoin have always touted “decentralization” and “unbreakable security” as their main selling points, but a groundbreaking study recently published by a Google research team has completely overturned the academic community’s traditional understanding of quantum threats. For a long time, experts generally believed that cracking the encryption mechanisms of Bitcoin or Ethereum would require millions of qubits, However, Google researchers have overturned this assumption, discovering that the actual number of qubits required may be less than 500,000. Even more shocking is that, through a carefully designed attack strategy, only approximately 1,200 to 1,450 high-quality qubits are needed to launch a substantive attack. This discovery not only significantly accelerates the timeline for the threat of quantum cracking but also underscores the urgency for the cryptocurrency industry to accelerate its “post-quantum migration.” Google further predicts that 2029 will be a key milestone when quantum computers begin to demonstrate practical capabilities, and calls on the industry to complete its security upgrades before then.

Challenging Conventional Wisdom: From Millions to 1,200 Qubits
Traditional academic assessments of quantum threats are based on theoretical models of universal quantum computers. According to existing estimates, cracking the elliptic curve cryptography (ECC) used by Bitcoin would require a quantum computer running Shor’s algorithm with millions of physical qubits: given the overhead of error correction, this is considered a threat far in the future.
However, two potential attack scenarios designed by the Google research team have completely rewritten this narrative. The research found that quantum algorithms optimized for specific attack scenarios require only about 1,200 to 1,450 high-quality qubits to launch an attack. This means that the quantum threat is no longer a problem “decades away,” but could become a reality within five years.

The significance of this finding lies in the fact that it shifts the timeline for the “end of cryptocurrency” from “a distant prospect” to “just around the corner.” If Google’s prediction is accurate—that quantum computers will be operational by 2029—then the Bitcoin and Ethereum ecosystems have less than four years left to complete a full migration.
Capture a Trade in Just 9 Minutes: The Critical Window for Instant Attacks
One of the most impactful findings from Google’s research is an attack model targeting “transactions in progress.” The study simulated real-world attack scenarios and found that hackers do not need to target historical wallets; instead, they can directly target real-time transactions that are currently in progress.
When a user sends Bitcoin, the public key data is briefly exposed on the network. If a quantum computer is fast enough, it can use the public key to deduce the private key and thereby steal funds. According to Google’s model, a quantum system could pre-compute certain operations, enabling it to carry out the attack in as little as 9 minutes once a transaction occurs.
This time window is extremely dangerous because it typically takes about 10 minutes for Bitcoin to confirm a transaction. This means that attackers have up to a 41% chance of intercepting the funds first. In contrast, because Ethereum confirms transactions more quickly, attackers have fewer opportunities to exploit this vulnerability, but it is not completely immune.
The danger of this type of “transaction interception” attack lies in its stealth and immediacy. Victims may watch their transactions get confirmed without realizing it, only to find that their funds have been diverted to the attacker’s wallet. Traditional on-chain analysis tools may struggle to identify such attacks immediately, as they appear to be nothing more than ordinary transaction failures or address errors.
Nearly 33% of Bitcoin Is at Risk: The Scale Is Far Greater Than Imagined
Another surprising finding from the Google study is a reassessment of the scale of “high-risk assets.” The study estimates that approximately 6.9 million bitcoins (equivalent to nearly 33% of the circulating supply) are currently held in wallets whose public keys have been exposed.
These high-risk assets include:
- 1.7 million bitcoins from the early days of the internet (public keys were exposed due to the early address format)
- Assets at risk due to the reuse of addresses (which expose the public key with every transaction)
This figure far exceeds the previous estimate by digital asset management firm CoinShares—which believed that only about 10,200 bitcoins were highly concentrated and vulnerable. Google’s research shows that the scale of the problem is hundreds of times greater than previously thought.
Could the Taproot Upgrade Actually Create a Quantum Vulnerability?
A Google study has also raised serious questions about Bitcoin’s Taproot upgrade, launched in 2021. Taproot, Bitcoin’s most significant protocol upgrade in recent years, was originally expected to enhance privacy and efficiency, but has inadvertently become an amplifier of quantum threats.

The problem is that Taproot’s design exposes public keys on the blockchain by default, removing the protective mechanism provided by the legacy address format. Prior to Taproot, Bitcoin addresses were hashed, and the public key was only exposed when a transaction was sent; with Taproot addresses, however, the public key is already exposed when funds are received.
Google researchers warn that this design could lead to a significant increase in the number of wallets vulnerable to quantum attacks in the future. This presents a dilemma for the Bitcoin community: Taproot does indeed offer improvements in privacy and efficiency, but at the expense of quantum resistance.
Responsible Disclosure: Google’s “Zero-Knowledge Proof” Strategy
Faced with such a sensitive discovery, the Google research team adopted an innovative and responsible disclosure strategy. To prevent the research from becoming a how-to guide for hackers, the team did not disclose the detailed steps used to crack the encryption system.
Instead, they use “zero-knowledge proof” technology to verify their research findings to the outside world. This cryptographic technique allows one party (the prover) to prove to another party (the verifier) that a certain statement is true without revealing any information beyond what is necessary to validate the statement itself.
This approach has set a new standard in the security research community: it both highlights the severity of the threat to spur industry action and avoids providing potential attackers with a blueprint. For decentralized ecosystems like cryptocurrency, this balance is particularly important—there is no single administrator who can enforce security updates, so the system must rely on community consensus.
Post-Quantum Transition: Collective Action Is Urgent
In response to the threats revealed by Google’s research, the cryptocurrency industry has been actively exploring “post-quantum cryptography” solutions. Several post-quantum cryptography standards published by the U.S. National Institute of Standards and Technology (NIST) in 2024 provide the technical foundation for this transition.
However, establishing technical standards is only the first step. For decentralized blockchains such as Bitcoin and Ethereum, protocol upgrades require broad community consensus, a process that has historically been fraught with controversy and delays. The Taproot upgrade took several years from proposal to activation, and the complexity of the post-quantum transition far exceeds that of Taproot.
There have been calls within the Bitcoin community to adopt post-quantum address formats, but since such an upgrade would require significant changes to the consensus mechanism, the timeline for implementation remains unclear. The Ethereum community is also exploring ways to integrate Layer 2 solutions with post-quantum signature algorithms.
Google’s research may accelerate industry discussions on post-quantum security. If quantum computers continue to advance faster than expected, whether Bitcoin can complete its security upgrades by 2029 will become one of the most closely watched issues in the cryptocurrency market.
Source: KOCPC Chinese