Market data shows fidelity Digital Assets, the crypto arm of the $4.9 trillion asset manager, published research Thursday warning that sufficiently powerful quantum computers could derive Bitcoin private keys from public keys exposed during transactions, a threat that would compromise every coin secured by the network's current elliptic-curve cryptography.
The pivot arrived in a Fidelity research note dated September 3: quantum algorithms, specifically Shor's algorithm, could reverse the one-way mathematical function that protects Bitcoin's key pairs. Today's quantum hardware lacks the error-corrected qubits to execute this attack.
Fidelity's analysis argues the risk horizon is years, not decades, and that preparation must begin before the threat materializes.
Before this warning, Bitcoin's security model relied entirely on the computational infeasibility of deriving a private key from its public counterpart. The network's hashrate exceeded 650 exahashes per second in August, making classical brute-force attacks economically impossible.
Miners have invested billions in specialized ASIC hardware that would become obsolete only if the cryptographic primitive itself breaks.
Fidelity's researchers propose migrating to hash-based signature schemes such as SPHINCS+ or XMSS. These constructions rely on hash-function security rather than number-theoretic problems, making them resistant to both classical and quantum attacks. The trade-off is concrete: signatures grow from 64-72 bytes to roughly 200-500 bytes per transaction input.
Per market reports, | XMSS | ~2,000+ bytes | Yes | -70%+ |
Larger signatures mean fewer transactions fit in a 4 MB block weight limit. At current usage patterns, a 4x signature expansion could reduce effective throughput from roughly 7 transactions per second to 2-3, increasing fee pressure during congestion.
Wallet software would also need to handle larger key material and stateful signing for schemes like XMSS, which cannot safely reuse keys.
No Bitcoin Improvement Proposal for post-quantum signatures has reached the activation threshold. The last major cryptographic upgrade, Taproot, took three years from proposal to activation in November 2021.
A quantum-resistant migration would likely require a soft fork with a multi-year timeline, during which coins in addresses with exposed public keys, including all reused addresses and any spent outputs, remain vulnerable.
Miners face a coordination problem: activating a soft fork that increases signature size reduces fee revenue per block in the short term, while the quantum threat remains theoretical. Fidelity's note frames this as an insurance problem, the cost of early migration versus the existential loss if migration arrives too late.
Reader desk
Discuss the signal
Verified readers · 2 comments per post / 24h
No comments yet. Be the first verified reader to add context.