Skip to content

Can Quantum Computers Forge Digital Signatures?

A sufficiently capable quantum computer could recover some private signing keys. Learn how that would allow a forged signature.

EveryoneIntro1 min read· Updated Oct 8, 2026

Free video lesson · 1:27

Can Quantum Computers Forge Digital Signatures?

Quantum Computing & Encryption for Beginners

Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.

A sufficiently capable quantum computer could recover private signing keys for vulnerable signature methods and create forgeries.

Read the video transcript

A powerful enough quantum computer could forge signatures made with some common digital-signature methods. No publicly demonstrated machine can do that at the scale those methods use today. This is a future capability being prepared for.

A digital signature is a mathematical check attached to a message. A secret private key creates it. A matching public key checks it. Normally, knowing the public key should not let someone create a new valid signature.

For vulnerable methods, a sufficiently capable quantum computer could work out the private key from the public one. Once an attacker has that private key, they can create signatures that pass the ordinary check.

Imagine an app checking a software update before installing it. If an attacker steals the signing power, a fake update could carry a signature that passes. The check cannot tell who was really holding the private key.

The weakness is in particular signing methods. It does not mean every digital signature is doomed. Replacement methods are designed to resist quantum attacks, so this useful checking system can continue with different mathematics.

For the basic check, watch What Is a Digital Signature? To see why signatures matter for money, watch Can Quantum Computers Steal Bitcoin?

TL;DR

The short answer

A powerful enough quantum computer could forge signatures made with some common digital-signature methods. No publicly demonstrated machine can do that at the scale those methods use today. This is a future capability being prepared for.

A simple example

A digital signature is a mathematical check attached to a message. A secret private key creates it. A matching public key checks it. Normally, knowing the public key should not let someone create a new valid signature.

For vulnerable methods, a sufficiently capable quantum computer could work out the private key from the public one. Once an attacker has that private key, they can create signatures that pass the ordinary check.

Imagine an app checking a software update before installing it. If an attacker steals the signing power, a fake update could carry a signature that passes. The check cannot tell who was really holding the private key.

The weakness is in particular signing methods. It does not mean every digital signature is doomed. Replacement methods are designed to resist quantum attacks, so this useful checking system can continue with different mathematics.

Verification can be fooled by a stolen signing power

The checker uses a public key to test a signature. If an attacker can calculate the matching private key, they can create new signatures that pass that check. This is a risk for particular signature methods and a sufficiently capable quantum computer.

Check your understanding

Does a valid signature always prove the original owner personally pressed Send?

Decision

Answer

No. Someone else may have gained control of the signing key.

Keep learning

Follow the free video course one question at a time. For help applying these ideas at work, explore team training or a cryptography audit.