Can Quantum Computers Steal Bitcoin?
A sufficiently capable quantum computer could threaten vulnerable Bitcoin spending signatures. Learn the conditions behind the risk.
Free video lesson · 1:22
Can Quantum Computers Steal Bitcoin?
Quantum Computing & Encryption for Beginners
Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.
A sufficiently capable quantum attacker could forge spending signatures for exposed, vulnerable public keys.
Read the video transcript
A powerful enough quantum computer could let an attacker steal some bitcoin by forging spending signatures. No publicly demonstrated machine can carry out that attack at Bitcoin scale today. The risk is about authorizing payments.
When you spend bitcoin, your wallet signs a transaction: a request to move the coins. It uses a private key, a secret that gives signing power. The network checks the signature using the matching public key.
For Bitcoin signature methods, a sufficiently capable quantum computer could work out that private key from an exposed public key. The attacker could then sign a request to send the coins somewhere else.
Not every coin exposes its public key in the same way. Some ways of holding coins reveal it from the start. Others keep it hidden until spending. That changes when an attacker has the information they need.
So the danger is a fake payment that passes the signature check. It is not a machine opening every wallet at once. Protecting against it requires changes to how spending is authorized.
How does that check work? Watch What Is a Digital Signature? For the attack behind it, watch Can Quantum Computers Forge Digital Signatures?
The short answer
A powerful enough quantum computer could let an attacker steal some bitcoin by forging spending signatures. No publicly demonstrated machine can carry out that attack at Bitcoin scale today. The risk is about authorizing payments.
A simple example
When you spend bitcoin, your wallet signs a transaction: a request to move the coins. It uses a private key, a secret that gives signing power. The network checks the signature using the matching public key.
For Bitcoin signature methods, a sufficiently capable quantum computer could work out that private key from an exposed public key. The attacker could then sign a request to send the coins somewhere else.
Not every coin exposes its public key in the same way. Some ways of holding coins reveal it from the start. Others keep it hidden until spending. That changes when an attacker has the information they need.
So the danger is a fake payment that passes the signature check. It is not a machine opening every wallet at once. Protecting against it requires changes to how spending is authorized.
Separate the address from the signature
A Bitcoin payment needs authorization under its spending rules. This lesson focuses on the digital signatures used to authorize spending. It does not predict a date when theft becomes possible, and it does not say that every coin has the same exposure.
Check your understanding
Would a faster mining machine and a machine that can forge a spending signature be doing the same job?
Answer
No. Mining and authorizing a payment are different jobs.
Keep learning
Follow the free video course one question at a time. For help applying these ideas at work, explore team training or a cryptography audit.