On July 30, 2026, IBM CEO Arvind Krishna appeared on CNBC's Mad Money and stated that quantum computing will begin having "a measurable impact" on IBM's top line and bottom line by 2028 or 2029 . He added that by the end of the 2030s, quantum could become a "trillion-dollar" addressable market
.
Krishna reaffirmed IBM's commitment to its ~$10 billion quantum investment roadmap despite recent softness in infrastructure revenue. In a July 2026 letter to investors, he noted that the company remains on track to deliver the first large-scale fault-tolerant quantum computer by 2029 .
The threat to Bitcoin centers on Shor's algorithm applied to ECDSA-256 (secp256k1) — the elliptic curve signature scheme that secures every Bitcoin transaction.
Google Quantum AI's March 2026 whitepaper provided new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem over the secp256k1 curve. The research demonstrated that Shor's algorithm for this problem could execute with either ≤1,200 logical qubits and ~90 million Toffoli gates, or ≤1,450 logical qubits with ~70 million gates . On a superconducting architecture with 10⁻³ physical error rates, those circuits could run in minutes using fewer than 500,000 physical qubits — a roughly 20× reduction compared to prior 2019 estimates
.
With a precomputed first phase, the actual runtime on a sufficiently advanced machine could be as little as ~9 minutes .
The asymmetric risk is significant: addresses that have already spent from them (exposed public keys) are vulnerable retroactively. An attacker could extract the private key from the public key using Shor's algorithm and drain the funds. Google's research identifies approximately 6.9 million BTC (~32% of supply) in wallets with exposed public keys . The widely cited figures of ~34% of supply (~6.8 million BTC, ~$437 billion) align closely with this risk pool, though no source in this search independently confirmed that exact percentage.
An independent July 2026 academic paper (arXiv:2606.14484) confirms the logical qubit estimate (1,200–2,330) but estimates a wider physical qubit range of 0.5–320 million, and notes that no cryptographically-relevant quantum computer (CRQC) exists today — the largest demonstrated devices operate with roughly 1,000–1,200 physical qubits .
The institutional response to the compressed threat window arrived on July 23, 2026, with the formation of the Bitcoin Security Consortium.
Nine firms — BlackRock, Fidelity Digital Assets, Coinbase, Strategy, Block, Galaxy Digital, Anchorage Digital, ARK Invest, and Blockstream — collectively pledged $15 million over three years to fund Bitcoin security research and open-source development, with quantum resistance as a primary focus . The consortium is structured as a coordinated funding mechanism, not a central fund; each member directs its own funds independently to developers, researchers, and organizations of its choice
.
The Migration Path Gap remains the core unresolved problem. Bitcoin's protocol currently lacks any agreed-upon, activated migration path to post-quantum cryptography. The BIP-361 draft (which would introduce a quantum-resistant signature scheme) remains contested within the Bitcoin development community, with no consensus reached on activation . The consortium's entire purpose is to fund the work needed to close this gap
.
No CRQC exists today. The gap remains large. But the landscape has shifted significantly in 2026: