{"id":74056,"date":"2026-10-07T23:24:32","date_gmt":"2026-10-07T20:24:32","guid":{"rendered":"https:\/\/lwallet.com.ua\/?p=74056"},"modified":"2026-10-08T16:50:23","modified_gmt":"2026-10-08T13:50:23","slug":"bitcoin-quantum-protection","status":"publish","type":"post","link":"https:\/\/lwallet.com.ua\/en\/bitcoin-quantum-protection\/","title":{"rendered":"Protecting Bitcoin from quantum computers"},"content":{"rendered":"\r\n\r\n\r\n<p class=\"wp-block-paragraph\">With a sufficiently powerful quantum computer, an attacker could calculate a private key from its public key and transfer someone else&#8217;s coins to themselves. They would not need access to your hardware wallet or seed phrase, because the attack exploits a weakness in the way transactions are signed. Google Quantum AI has estimated what hardware such an attack would require.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Bitcoin quantum protection requires changes to the network itself, including new ways to sign transactions. Until those changes arrive, you can check the addresses holding your funds and choose formats that <strong>hide the public key until you send coins<\/strong>. The blockchain initially shows only a hash, a short digital fingerprint of that key. Below, we explain which addresses work this way, why you should retire them after a transfer and what a hardware wallet cannot do in this situation.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Bitcoin quantum protection: why transaction signatures need to change<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-1024x573.jpg\" alt=\"Bitcoin quantum protection: diagram showing the relationship between private and public keys\" class=\"wp-image-74032\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic2.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A private key is the secret number a wallet uses to sign transactions, so anyone who knows it can spend the coins. The public key is calculated from it and lets the network verify the signature. Knowing the public key does not let someone spend your funds using an ordinary computer, but a sufficiently powerful quantum computer could use it to recover the private key. Your wallet handles the routine calculations automatically, so you do not need to work with the keys yourself.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Calculating a public key from a private key is straightforward, but <strong>recovering the private key from the public key is practically impossible on a modern conventional computer<\/strong>. Trying the enormous number of possible keys one by one would take far too long to be a practical attack.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Bitcoin and ordinary Ethereum accounts use the same mathematical foundation for their signatures, but expose public keys under different conditions. Understanding the quantum threat therefore means looking at the address type and its past transactions, as well as the network.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How Shor&#8217;s algorithm could recover a private key<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-1024x573.jpg\" alt=\"Shor&#039;s algorithm: recovering a private key from a public key with a quantum computer\" class=\"wp-image-74035\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic3.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In 1994, mathematician Peter Shor proposed a quantum algorithm that can calculate a private key from a public key without trying every possible value. An attacker would need a sufficiently powerful and reliable quantum computer to use it.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Qubits are the units of information a quantum computer works with. Physical qubits are the actual hardware elements, which are prone to errors. To make long calculations more reliable, many physical qubits are combined into a logical qubit, with errors corrected within the group.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A thousand physical qubits are not the same as a thousand logical qubits<\/strong>: one logical qubit may require hundreds of physical qubits or more. A processor&#8217;s advertised qubit count alone therefore does not tell you whether it could recover a Bitcoin private key.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What quantum hardware would an attacker need?<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On March 30, 2026, Google Quantum AI, together with researchers from the Ethereum Foundation and Stanford, published a <a href=\"https:\/\/arxiv.org\/abs\/2603.28846\" rel=\"nofollow noopener\" target=\"_blank\">study of quantum vulnerabilities in cryptocurrencies<\/a>. The authors revised estimates of how many qubits and how much time would be needed to recover a Bitcoin private key from its public key.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The researchers considered two approaches to the calculation:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>Fewer than 1,200 logical qubits<\/strong>, requiring fewer qubits but more computing operations.<\/li>\r\n\r\n\r\n\r\n<li><strong>Fewer than 1,450 logical qubits<\/strong>, using more qubits to reduce the number of computing operations.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The authors estimate that either approach would need <strong>fewer than 500,000 physical qubits<\/strong>, provided the hardware achieves the required speed and reliability. That is roughly twenty times fewer than earlier estimates. The result depends on the hardware&#8217;s capabilities and how effectively the system corrects errors during the calculation.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The full calculation would take about 18\u201323 minutes. Some of the work could be done in advance, before obtaining the victim&#8217;s public key. If that preparation were preserved on the quantum computer, about 9 or 12 minutes of computation would remain after obtaining the key, depending on the approach.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">An attacker could try to steal the coins while your transfer is waiting for confirmation. Sending funds from an address that hid the public key makes that key visible in the transaction. Before being included in a block, the transaction waits in the mempool, the pool of unconfirmed transactions. A fast enough quantum computer could calculate the private key during that wait, allowing the attacker to send the same coins to themselves and offer the miner a higher fee.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Assuming the calculation takes nine minutes and Bitcoin blocks arrive every ten minutes on average, the authors estimated a <strong>roughly 41% chance of stealing the coins before the transfer is confirmed<\/strong>. This assumes the attacker obtains the public key immediately, the network is not congested and their transaction can be included in a block instead of yours. In the same model, the chance is below 3% for Litecoin and less than one in eight thousand for Dogecoin. These are possible future attacks that would require the necessary hardware.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>Google calculated the requirements for future hardware; it did not recover a Bitcoin private key on an existing quantum computer. The researchers also provided a mathematical proof that allows their estimates to be checked without publishing full instructions for the attack.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">When the public key becomes visible on the blockchain<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-1024x573.jpg\" alt=\"Public key exposure in P2PK and Taproot outputs and after spending P2PKH and P2WPKH outputs\" class=\"wp-image-74038\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic4.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">An attack using Shor&#8217;s algorithm requires the public key. <strong>A Bitcoin address and a public key are different things<\/strong>: some address formats expose the key immediately, while others initially show only its digital fingerprint. Other formats hide the spending rules behind a fingerprint, such as a requirement for multiple signatures.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For P2PKH and P2WPKH addresses, the public key is initially hidden behind a hash and becomes visible when you send coins from the address. Shor&#8217;s algorithm needs the public key itself, so its fingerprint alone is not enough for this attack. After a transfer, that advantage is lost: if coins remain at the same address or you receive more funds there, an attacker can already see the public key they would need.<\/p>\r\n\r\n\r\n\r\n<figure class=\"wp-block-table\"><table><thead><tr><th>Format<\/th><th>How to identify it<\/th><th>When the public key is visible<\/th><\/tr><\/thead><tbody><tr><td>P2PK<\/td><td>An older format that records the public key directly on the blockchain<\/td><td>The public key is visible as soon as the coins are received.<\/td><\/tr><tr><td>Taproot, P2TR<\/td><td>The address starts with bc1p<\/td><td>The public key is visible immediately, before any coins are sent.<\/td><\/tr><tr><td>Legacy, P2PKH<\/td><td>The address starts with 1<\/td><td>The public key becomes visible when coins are sent, unless it has already been disclosed elsewhere.<\/td><\/tr><tr><td>Native SegWit, P2WPKH<\/td><td>The address starts with bc1q<\/td><td>The public key becomes visible when coins are sent, unless it has already been disclosed elsewhere.<\/td><\/tr><tr><td>P2SH<\/td><td>The address starts with 3<\/td><td>Initially, only a hash of the spending rules is visible. In typical wallets, the public keys become visible when funds are sent.<\/td><\/tr><tr><td>Native SegWit, P2WSH<\/td><td>The address also starts with bc1q<\/td><td>Initially, only a hash of the spending rules is visible. Whether a transfer reveals public keys depends on those rules.<\/td><\/tr><\/tbody><\/table><\/figure>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Some coins mined in Bitcoin&#8217;s early years are held in P2PK outputs. Taproot also makes the public key visible immediately, although it offers privacy benefits and more flexible spending rules. A newer address format therefore does not necessarily hide the public key, and <strong>the bc1q prefix alone cannot distinguish P2WPKH from P2WSH<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/www.projecteleven.com\/blog\/project-eleven-awards-1-btc-q-day-prize-for-largest-quantum-attack-on-elliptic-curve-cryptography-to-date\" rel=\"nofollow noopener\" target=\"_blank\">post published on April 24, 2026<\/a>, Project Eleven estimated that approximately <strong>6.9 million BTC<\/strong> were held with the public keys used to verify their transfers already visible on the blockchain.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Why Bitcoin wallets create new change addresses<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-1024x573.jpg\" alt=\"A 5 BTC UTXO: sending 1 BTC and returning change to a new P2WPKH address after fees\" class=\"wp-image-74041\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic5.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In Ethereum, funds arrive in an account and are spent from it. For an ordinary account controlled by a private key, the first transaction it sends already allows the public key to be recovered from the signature. Moving to a different address means transferring assets and separately managing funds and approvals in DeFi services, so users often keep their existing address.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In Bitcoin, your balance consists of separate amounts received in earlier transactions that have not yet been spent. These are called <strong>UTXOs, or unspent transaction outputs<\/strong>. Suppose you received 5 BTC in a single payment and want to send 1 BTC. Your wallet uses that entire amount: 1 BTC goes to the recipient, while slightly less than 4 BTC comes back to you as change because part of the amount pays the fee.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Your wallet can send the change to a new address with a different public key. If it is a P2WPKH address and the key has not been disclosed elsewhere, that key will not yet be visible on the blockchain. This avoids leaving change at the old address you have already spent from.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A new change address does not by itself protect against a quantum attack<\/strong>: Taproot makes the public key visible immediately. If your wallet returns change to an old address you have already spent from, that address&#8217;s public key will also be known. Check your account type and change address format in the app, even if you use a Ledger, Trezor, Keystone or BitBox hardware wallet. For example, <a href=\"https:\/\/trezor.io\/learn\/supported-assets\/bitcoin\/what-is-a-change-address\" rel=\"nofollow noopener\" target=\"_blank\">Trezor Suite generates change addresses automatically<\/a>, but their format depends on the selected account.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>After sending coins from an address, stop using it for new payments. This prevents new funds from accumulating at a P2PKH or P2WPKH address whose public key is already visible on the blockchain. Changing addresses also improves privacy, but a new Taproot address does not hide its public key.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">How to check your wallet addresses<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-1024x573.jpg\" alt=\"Checking a Bitcoin address: output type, spending history, other funded addresses and xpub exposure\" class=\"wp-image-74044\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic6.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For an initial check, you can use <a href=\"https:\/\/quantumrekt.com\/\" rel=\"nofollow noopener\" target=\"_blank\">quantumrekt.com<\/a>, which assesses an address using its type and public blockchain data. It only needs the public address: <strong>do not enter your seed phrase or private key, connect your wallet or sign messages for this check<\/strong>.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Your wallet may have many addresses, including separate change addresses. Check every address holding coins, because a result for one address does not show the status of the others.<\/p>\r\n\r\n\r\n\r\n<ol class=\"nm-block-list wp-block-list\">\r\n<li><strong>Copy the address from your wallet app and identify its type.<\/strong> For example, bc1p at the start indicates Taproot: the public key is already visible on the blockchain.<\/li>\r\n\r\n\r\n\r\n<li><strong>Read the result.<\/strong> A REKT label means the service considers coins at that address potentially vulnerable to a quantum attack. That may be because of the address format or because it has already been used to send funds. The label does not mean the coins have been stolen.<\/li>\r\n\r\n\r\n\r\n<li><strong>Cross-check the history in a blockchain explorer.<\/strong> This is a website where you can view an address&#8217;s transactions. For ordinary P2PKH and P2WPKH addresses, a \u201cTotal sent\u201d value above zero means coins have already been sent from the address, making the public key visible in the transaction. If that statistic is unavailable, check whether any transfers have been sent from the address.<\/li>\r\n\r\n\r\n\r\n<li><strong>Check all other addresses holding coins, including change addresses.<\/strong> If your app has an address list or UTXO view, use it to find the addresses that still hold funds.<\/li>\r\n<\/ol>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For P2WSH and wallets requiring multiple signatures, known as multisig wallets, check the transfer rules in your app or explorer: quantumrekt.com does not support all these addresses. A multisig transfer requires several signatures, so check which public keys the wallet uses and whether others can access them.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A \u201cTotal sent\u201d value of zero does not mean the public key is hidden.<\/strong> Taproot and P2PK make it visible even before any coins are sent. You may also have shared an xpub with a third-party service: an extended public key that lets someone calculate the public keys of many addresses within an account.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If you have shared your xpub with a service or published it, take that into account. Even if a public key is not yet visible on the blockchain, someone with the xpub can calculate it. You do not need an xpub to check an individual address.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Are Solana, XRP and Cardano vulnerable to quantum attacks?<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Solana, XRP Ledger and Cardano use somewhat different ways to sign transactions, but they rely on mathematical problems that Shor&#8217;s algorithm can also solve. As a result, <strong>differences between their current signatures do not make these networks quantum-resistant<\/strong>. They also need post-quantum cryptography: protection designed to withstand quantum computers.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On April 27, 2026, <a href=\"https:\/\/solana.com\/news\/quantum-readiness\" rel=\"nofollow noopener\" target=\"_blank\">the Solana Foundation reported<\/a> that Anza and Firedancer had independently researched post-quantum signatures and chosen Falcon for their initial implementations. Falcon is a signature scheme designed to withstand quantum attacks. NIST, the US National Institute of Standards and Technology, selected it for standardization, though the final standard is still being developed. Solana&#8217;s plan includes further research and preparing wallets for new signatures if advances in quantum computing make a transition necessary.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">The ecosystem also includes Blueshift&#8217;s Winternitz Vault, which uses another signing method designed to withstand quantum attacks. Google cited it as an existing example, but it is a separate vault whose protection does not automatically extend to an ordinary Solana wallet.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">On Solana, an ordinary account&#8217;s address is already its public key, so an attacker does not need to wait for the first transfer to obtain it. Some Bitcoin address formats hide the public key until coins are sent. Despite this difference, both networks need signatures that can withstand quantum computers.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Q-Day and preparing for the quantum threat<\/h2>\r\n\r\n\r\n<div class=\"wp-block-image is-style-default blog-img\">\r\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"573\" src=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-1024x573.jpg\" alt=\"Google and NIST post-quantum migration deadlines and the unknown date of Q-Day\" class=\"wp-image-74047\" title=\"\" srcset=\"https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-1024x573.jpg 1024w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-300x168.jpg 300w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-766x429.jpg 766w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-1536x860.jpg 1536w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-349x195.jpg 349w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7-679x380.jpg 679w, https:\/\/lwallet.com.ua\/wp-content\/uploads\/2026\/10\/blog-quantum-computers-protection-07-10-2026-content-pic7.jpg 1631w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\r\n<\/div>\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Q-Day is the name given to the point when a quantum computer can break widely used forms of cryptographic protection, including digital signatures, in practice. The date is unknown; the frequently cited years 2029 and 2035 concern preparations for that threat:<\/p>\r\n\r\n\r\n\r\n<ul class=\"nm-block-list wp-block-list\">\r\n<li><strong>2029:<\/strong> Google has set this deadline for <a href=\"https:\/\/blog.google\/innovation-and-ai\/technology\/safety-security\/cryptography-migration-timeline\/\" rel=\"nofollow noopener\" target=\"_blank\">migrating its own systems to post-quantum cryptography<\/a>.<\/li>\r\n\r\n\r\n\r\n<li><strong>2035:<\/strong> <a href=\"https:\/\/csrc.nist.gov\/Projects\/Post-Quantum-Cryptography\" rel=\"nofollow noopener\" target=\"_blank\">NIST sets this deadline<\/a> for removing quantum-vulnerable algorithms from its standards, with high-risk systems expected to migrate earlier.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>These dates do not predict when attackers could steal coins using quantum computers.<\/strong> With a slower computer, an attacker could start with addresses whose public keys have long been visible on the blockchain. With fast enough hardware, they could also intercept coins during a transfer, so both forms of theft could become possible at roughly the same time.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">In April 2026, Project Eleven awarded the Q-Day Prize to Giancarlo Lelli for recovering a private key on a publicly accessible quantum computer. The experiment used a much simpler 15-bit problem, whereas Bitcoin uses 256-bit keys. It demonstrates the method on a small example, but does not show that existing hardware can recover a Bitcoin private key this way.<\/p>\r\n\r\n\r\n<p>[vc_message color=&#8221;warning&#8221; message_box_style=&#8221;classic&#8221; message_box_color=&#8221;alert-warning&#8221; style=&#8221;rounded&#8221;]<\/p>\r\n<p>Shor&#8217;s algorithm can recover a private key, but it does not help perform the calculations required for mining. A quantum computer could speed up the search involved in mining using a different algorithm, but that would not automatically give it an advantage over today&#8217;s specialized mining hardware: the outcome would depend on computing speed and competition on the network.<\/p>\r\n<p>[\/vc_message]<\/p>\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">Four steps to help keep your coins safer<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Changes to Bitcoin&#8217;s rules depend on its developers and network participants. You can check the addresses holding your coins, review your wallet settings and watch for updates that support new signature methods.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Step 1. Check the addresses holding your coins<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Identify each address type and check whether you have sent funds from it before. Taproot and P2PK make the public key visible immediately; P2PKH and P2WPKH reveal it on the blockchain when coins are sent. Also consider whether you have shared your xpub. Focus on addresses that still hold funds: there is nothing to move from an old, empty address.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Step 2. Move coins to a new address if needed<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">If the public key for an address holding your coins is already available to others, you can move the funds to a new address that hides a different public key. The old key could then no longer be used to prepare an attack on those coins. For an ordinary single-signature wallet, a new Native SegWit P2WPKH address beginning with bc1q is suitable. Check the account type in your app, because P2WSH addresses also start with bc1q.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>If you have shared your xpub, a new address in the same account may not be enough:<\/strong> its public key can also be calculated from that xpub. One way to avoid this is to move the coins to a new wallet with a new seed phrase generated independently of the old one. A different account under the same seed phrase may help only if the shared xpub cannot reveal its public keys; verify that separately. Follow the manufacturer&#8217;s instructions when creating a wallet, and check your current backup before resetting the device. Our <a href=\"https:\/\/lwallet.com.ua\/en\/how-to-store-a-seed-phrase\/\">guide to storing a seed phrase safely<\/a> explains how to protect that backup. You do not need to enter your seed phrase on a third-party website.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Verify the new address on your hardware wallet&#8217;s screen and allow for the transaction fee. Once the coins reach an address with a different public key, the old private key can no longer spend them. However, <strong>sending the coins again will reveal the new public key too<\/strong>, so changing addresses does not replace the network&#8217;s transition to post-quantum signatures. Taproot makes the public key visible even before a transfer.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Step 3. Follow changes to the Bitcoin protocol<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A BIP is a proposal to change how Bitcoin works. <a href=\"https:\/\/github.com\/bitcoin\/bips\/blob\/master\/bip-0360.mediawiki\" rel=\"nofollow noopener\" target=\"_blank\">BIP-360<\/a> describes a new format, <strong>Pay-to-Merkle-Root, or P2MR<\/strong>, which would not record a public key on the blockchain when coins are received, unlike Taproot. It would store a hash representing the spending rules instead. The proposed addresses would start with bc1z.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Without the public key, an attacker cannot use it to calculate the private key. P2MR is intended to let coins be held without publishing the public key on the blockchain. It does not add post-quantum signatures, however: once that key appears in a transaction, an attacker with a fast quantum computer could still try to intercept the coins.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">A separate proposal, <a href=\"https:\/\/github.com\/bitcoin\/bips\/blob\/master\/bip-0361.mediawiki\" rel=\"nofollow noopener\" target=\"_blank\">BIP-361<\/a>, considers a transition to post-quantum protection and restrictions on current transaction-signing methods. Both documents are drafts. <strong>Publishing or testing a proposal does not mean Bitcoin already operates under the new rules<\/strong>; users should follow adopted network upgrades and their support in their wallets.<\/p>\r\n\r\n\r\n\r\n<h3 class=\"nm-block-heading wp-block-heading\">Step 4. Check your wallet settings and device security<\/h3>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Check whether your wallet creates a new change address after a transfer and what format it uses. The hardware wallet itself helps keep private keys safe from malware on your computer or phone. It cannot change how Bitcoin transactions are signed; that requires a network upgrade. Our article on <a href=\"https:\/\/lwallet.com.ua\/en\/what-is-hardware-wallet\/\">how hardware wallets work<\/a> explains device security in more detail.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">For example, Trezor Safe 7 uses post-quantum signatures to verify genuine firmware, protect the device&#8217;s startup process and confirm that the wallet itself is authentic. <strong>The \u201cquantum-ready\u201d label refers to device security; it does not change Bitcoin transaction signatures.<\/strong> Whether the wallet can support future signing methods through an update depends on their requirements and the device&#8217;s capabilities. Our <a href=\"https:\/\/lwallet.com.ua\/en\/trezor-safe-7-review\/\">Trezor Safe 7 review<\/a> explains these protections in more detail. If you are choosing a wallet, compare supported networks, phone compatibility and transaction verification in our <a href=\"https:\/\/lwallet.com.ua\/en\/best-hardware-wallets-2026\/\">hardware wallet buying guide<\/a>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"nm-block-heading wp-block-heading\">What you can do to protect your coins<\/h2>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\">Start with the addresses holding your coins: check their types and whether you have sent funds from them before. After a transfer, retire the address for new payments and choose a change address format that hides the public key. If coins remain at an old address, consider moving them to a new P2WPKH address, following the rules above. Also account for any xpub you have shared; in that case, a new address alone may not be enough.<\/p>\r\n\r\n\r\n\r\n<p class=\"wp-block-paragraph\"><strong>A hardware wallet cannot protect the coins if an attacker can calculate the private key from the public key.<\/strong> As long as an address&#8217;s public key is unknown to others, they cannot use it to prepare this attack in advance. Sending coins removes that advantage, so protecting transfers will require the network to adopt post-quantum signatures; the timing remains undecided.<\/p>\r\n\r\n","protected":false},"excerpt":{"rendered":"<p>With a sufficiently powerful quantum computer, an attacker could calculate a private key from its public key and transfer someone else&#8217;s coins to themselves. They would not need access to your hardware wallet or seed phrase, because the attack exploits a weakness in the way transactions are signed. Google Quantum AI has estimated what hardware &hellip;<\/p>\n","protected":false},"author":10,"featured_media":74030,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2723],"tags":[],"class_list":["post-74056","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bitcoin"],"_links":{"self":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/74056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/comments?post=74056"}],"version-history":[{"count":3,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/74056\/revisions"}],"predecessor-version":[{"id":74092,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/posts\/74056\/revisions\/74092"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media\/74030"}],"wp:attachment":[{"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/media?parent=74056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/categories?post=74056"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lwallet.com.ua\/en\/wp-json\/wp\/v2\/tags?post=74056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}