Somewhere right now, someone could be quietly copying encrypted blockchain traffic, filing it away, and waiting. Not because they can break it today — because they're betting they'll be able to in a few years. That's not a hypothetical. It's already happening, and it has a name: Harvest Now, Decrypt Later.
Here's the mechanic. Every time you spend from a Bitcoin or Ethereum address, your raw public key gets exposed on the network to verify the transaction. A powerful enough quantum computer running Shor's Algorithm can take that exposed public key and derive your private key directly — not by guessing, but by solving the underlying math in a way classical computers simply can't. Researchers estimate that takes roughly 1,200 logical qubits against standard 256-bit elliptic curve encryption. Nobody has built that machine yet. But an adversary doesn't need it today — they just need your public key recorded now, so they can run the math the moment the hardware exists. That puts an estimated $470 billion in digital assets at risk, concentrated in wallets and legacy address formats where public keys are already sitting exposed on-chain.
Worth knowing: not every part of blockchain crypto is equally fragile. Quantum computers attack hash functions like SHA-256 differently, through Grover's Algorithm, which only delivers a quadratic speedup — it effectively cuts SHA-256's security in half, from 2²⁵⁶ down to 2¹²⁸ operations. That's still an astronomically large number. Hashing gets fixed by just using longer hashes. The real emergency is entirely on the public-key side.
That's also why address hashing has quietly been buying the industry time — Bitcoin doesn't display your raw public key until you actually spend from an address, so a dormant, never-spent wallet is currently shielded. The exposure moment is the spend itself, or a transaction sitting in the mempool waiting to confirm.
$ETH and $BTC are handling the fix on completely different clocks. Ethereum's roadmap includes a proposed fork targeting native post-quantum signatures directly at the protocol level, alongside an account-abstraction upgrade designed to let wallets switch to quantum-safe contracts without changing addresses. Bitcoin's path is messier — an estimated 6.9 to 7 million BTC sit in old, exposed-public-key addresses, much of it presumed lost. Migrating means either leaving that Bitcoin permanently vulnerable or the community agreeing to freeze coins nobody can prove they still control — a governance fight, not just an engineering one.
Regulators aren't waiting for the debate to resolve. NIST has already finalized its post-quantum standards, and federal migration deadlines land in 2030-2031 — which means any chain wanting continued institutional money has a clock running whether its community has agreed on a plan or not.
So here's the actual dilemma sitting under all of this: if the choice eventually comes down to freezing billions in dormant, exposed coins to protect the network, or leaving them as an open invitation — which one do you think a decentralized community actually agrees to first?