The U.S. government is increasing its investment in the quantum computing industry, bringing the “quantum threat” that Bitcoin has long faced from theoretical risk closer to real-world engineering concerns. On September 8, the U.S. Department of Commerce officially finalized CHIPS R&D incentives for Rigetti, D-Wave, and Quantinuum. Each company could receive up to $100 million; the total across the three companies could reach up to $300 million. The funding will be used for technologies such as quantum chips, cryogenic systems, error-rate improvements, and fault-tolerant quantum computing.

Notably, the $300 million figure is not the entirety of Washington’s quantum investment. On the same day, the photonic quantum computing company PsiQuantum also received an R&D incentive of up to $100 million. GlobalFoundries received up to $375 million, including the establishment of U.S.-based quantum wafer-fabrication capabilities. As early as May this year, the U.S. Department of Commerce had announced planned investments totaling $2.013 billion in the quantum industry across nine companies, indicating that policy is gradually shifting from fundamental research toward manufacturing and large-scale hardware.

This round of investment also amplifies a long-tail risk for the cryptocurrency market: if a future quantum computer capable of cracking cryptography emerges, Shor’s algorithm could, in theory, derive private keys from public keys, threatening the elliptic-curve digital signatures used by Bitcoin.

At present, there is no evidence showing quantum computers are close to practically cracking Bitcoin. What is really worth the market’s attention is that completing the global migration of wallets, exchanges, and UTXOs may take years; therefore, developers cannot afford to wait until “Q-Day” truly arrives before starting to deal with it.

BIP-360 first addresses the risk of “long-term exposure”

The currently more mature first step being discussed is BIP-360, Pay-to-Merkle-Root (P2MR). It proposes a new type of Bitcoin output that retains the script-tree functionality similar to Taproot, but removes the key-path spend that would directly reveal the public key.

This means that P2MR can reduce the risk of public keys being cracked by quantum computers after long-term exposure, but it is not the same as a complete post-quantum signature scheme. The BIP-360 document clearly states that if quantum computers are already fast enough to crack public keys between when a transaction enters the mempool and when it is confirmed, truly post-quantum signature technologies like ML-DSA and SLH-DSA must still be introduced.

BIP-361 is even more aggressive: eventually phasing out legacy signatures

BIP-361 then tackles the trickier question of “how to get the whole network to move.”

According to the current draft, the first phase will gradually prohibit funds from flowing into quantum-vulnerable addresses; then it will consider limiting ECDSA and Schnorr signature spending, forcing users to migrate to post-quantum addresses before a planned deadline. BIP-361’s data estimates that, as of March 2026, more than 34% of the Bitcoin supply has had public keys exposed on-chain, meaning the potentially affected asset amount reaches millions of BTC.

The issue is that if a large amount of early Bitcoin— including lost private keys, early P2PK addresses, and possibly holdings belonging to Satoshi Nakamoto—does not proactively migrate, then in the future whether those assets should be frozen, whether quantum crackers should be allowed to take them, or whether special “rescue proofs” should be established all involve huge property-rights and consensus disputes.

Therefore, BIP-361 is still only a Draft at this time; it even explicitly relies on a post-quantum signature BIP that has not yet been finalized. It is still a long way from official activation on the mainnet.

Quantum risk is still far off—the migration clock has already started ticking

NIST officially published three sets of post-quantum cryptography standards—ML-KEM, ML-DSA, and SLH-DSA—as early as 2024, and urged system operators to begin preparing for migration. The reason is not that quantum cracking is imminent, but that large cryptographic infrastructure transitions often take years.

As of September 10, Bitcoin’s price is still roughly fluctuating around $78,000, and quantum risk has not yet become a major factor affecting short-term prices.

But from a financial-market perspective, the U.S. government is putting billions of dollars into quantum hardware, while Bitcoin developers are starting to discuss how millions of BTC can be moved securely—two timelines are gradually converging.

The real risk is not “a quantum computer cracks Bitcoin tomorrow,” but whether Bitcoin has already completed what could be the largest cryptographic migration in history—potentially involving global exchanges, custodians, cold wallets, and millions of UTXOs—when quantum hardware truly crosses the critical point.

“The U.S. pours $300 million into three major quantum companies! Bitcoin BIP-360, 361 anti-quantum migration heats up”—this article was first published on (BlockBeater).