Timeline consensus is split but compressing rapidly. Several expert warnings point to 2028 as a possible "Q-Day" — the moment a quantum computer can break live wallet cryptography . Vitalik Buterin told developers in Buenos Aires that elliptic-curve cryptography "is going to die" and that quantum computers could break it as early as 2028 . A crypto analyst's "Quantum Doom Clock" model projects March 8, 2028, as the threshold when private keys could be derived from exposed public keys .
More conservative academic forecasts (arXiv 2606.14484) put CRQC arrival at about a one-in-six chance by 2035, ~30% by 2040, and ~60% by 2050 . But Google's own March 2026 research compressed the threat dramatically — showing that breaking ECDSA-256 may require only ~500,000 physical qubits, a 20x reduction from prior estimates . Justin Drake, a researcher who co-authored the Google paper, estimated a 50% likelihood of Q-Day occurring by 2032 .
| Target | Why It's Lucrative | Sources |
|---|---|---|
| Tether (USDT) minting authority | The most lucrative quantum objective — controlling the mint gives the attacker power over a ~$120B stablecoin supply | |
| Centralized exchange hot wallets | Large pools of BTC/ETH with public keys exposed onchain; high liquidity for immediate theft | |
| Institutional custodian wallets | Massive single-point holdings with exposed public keys from frequent transactions | |
| Older P2PK (Pay-to-Public-Key) addresses | ||
| Smart contract platform keys | Ethereum validators, bridge operators, and protocol multisigs whose keys have been onchain |
Chaincode's August 2026 report estimates 6.26M BTC ($650B) is already vulnerable — roughly 25-30% of all Bitcoin . Deloitte has similarly estimated ~25% of circulating BTC is at risk . These are not future victims; they are already exposed via the "harvest now, decrypt later" attack, where attackers can scrape public keys today and wait for a quantum computer to crack them retroactively .
Google set 2029 as its hard deadline for migrating all internal systems to post-quantum cryptography (PQC), and warned that the quantum threat could arrive earlier than industry-wide expectations . This was paired with a whitepaper co-authored with the Ethereum Foundation and Stanford researchers that formally outlined the threat vectors .
Key industry responses:
The overarching challenge is that Bitcoin and Ethereum lack a built-in upgrade path for their core signature schemes. A PQC migration requires a consensus-layer fork that all nodes adopt, and the transition for coins in exposed P2PK addresses is particularly difficult — those funds must be moved by their owners before a quantum computer arrives, and no fork can protect coins whose public keys are already public .