A new a16z crypto research paper argues that apocalyptic narratives about quantum computers instantly killing Bitcoin are badly misaligned with reality, and that the real risk for blockchains lies in long, messy migrations rather than a sudden “Q-Day” collapse. The piece has already triggered a sharp rebuttal on X from investors who say the threat […]A new a16z crypto research paper argues that apocalyptic narratives about quantum computers instantly killing Bitcoin are badly misaligned with reality, and that the real risk for blockchains lies in long, messy migrations rather than a sudden “Q-Day” collapse. The piece has already triggered a sharp rebuttal on X from investors who say the threat […]

Bitcoin Quantum ‘Doomsday’ Fears Are Overblown, a16z Research Says

2025/12/08 15:00

A new a16z crypto research paper argues that apocalyptic narratives about quantum computers instantly killing Bitcoin are badly misaligned with reality, and that the real risk for blockchains lies in long, messy migrations rather than a sudden “Q-Day” collapse. The piece has already triggered a sharp rebuttal on X from investors who say the threat is closer and harder than a16z suggests.

Bitcoin Isn’t Doomed By Quantum Computing: a16z

In the article “Quantum computing and blockchains: Matching urgency to actual threats,” a16z research partner and Georgetown computer science professor Justin Thaler sets the tone early, writing that “Timelines to a cryptographically relevant quantum computer are frequently overstated — leading to calls for urgent, wholesale transitions to post-quantum cryptography.” He argues that this hype distorts cost–benefit analyses and distracts teams from more immediate risks such as implementation bugs.

Thaler defines a “cryptographically relevant quantum computer” (CRQC) as a fully error-corrected machine capable of running Shor’s algorithm at a scale where it can break RSA-2048 or elliptic-curve schemes like secp256k1 in roughly a month of runtime. In his assessment, a CRQC in the 2020s is “highly unlikely,” and public milestones do not justify claims that such a system is probable before 2030.

He stresses that across trapped-ion, superconducting and neutral-atom platforms, no device is close to the hundreds of thousands to millions of physical qubits, with the required error rates and circuit depth, that would be needed for cryptanalysis.

Instead, the a16z piece draws a sharp line between encryption and signatures. Thaler argues that harvest-now-decrypt-later (HNDL) attacks already make post-quantum encryption urgent for data that must remain confidential for decades, which is why large providers are rolling out hybrid post-quantum key establishment in TLS and messaging.

But he insists that signatures, including those securing Bitcoin and Ethereum, face a different calculus: they do not protect hidden data that can be retroactively decrypted, and once a CRQC exists, the attacker can only forge signatures going forward.

On that basis, the paper claims that “most non-privacy chains” are not exposed to HNDL-style quantum risk at the protocol level, because their ledgers are already public; the relevant attack is forging signatures to steal funds, not decrypting on-chain data.

Bitcoin-Specific Headaches

Thaler still flags Bitcoin as having “special headaches” due to slow governance, limited throughput and large pools of exposed, potentially abandoned coins whose public keys are already on-chain, but he frames the time window for a serious attack in terms of at least a decade, not a few years.

“Bitcoin changes slowly. Any contentious issues could trigger a damaging hard fork if the community cannot agree on the appropriate solution,” Thaler writes, adding “another concern is that Bitcoin’s switch to post-quantum signatures cannot be a passive migration: Owners must actively migrate their coins.”

Moreover, Thalen flags a “final issue specific to Bitcoin” which is its low transaction throughput. “Even once migration plans are finalized, migrating all quantum-vulnerable funds to post-quantum-secure addresses would take months at Bitcoin’s current transaction rate,” Thaler says.

He is equally skeptical of rushing into post-quantum signature schemes at the base-layer. Hash-based signatures are conservative but extremely large, often several kilobytes, while lattice-based schemes such as NIST’s ML-DSA and Falcon are compact but complex and have already produced multiple side-channel and fault-injection vulnerabilities in real-world implementations. Thaler warns that blockchains risk weakening their security if they jump too early into immature post-quantum primitives under headline pressure.

Industry Split On The Risk

The most forceful pushback has come from Castle Island Ventures co-founder Nic Carter and Project 11 CEO Alex Pruden. Carter summed up his view on X by saying the a16z work “wildly underestimates the nature of the threat and overestimates the time we have to prepare,” pointing followers to a long thread from Pruden.

Pruden begins by stressing respect for Thaler and the a16z team, but adds, “I disagree with the argument that quantum computing is not an urgent problem for blockchains. The threat is closer, the progress faster, and the fix harder than how he’s framing it & than most people realize.”

He argues that recent technical results, not marketing, should anchor the discussion. Citing neutral-atom systems that now support more than 6,000 physical qubits, Pruden points out that “we now have a non annealing system with more than 6000 physical qubits in the neutral atom architecture,” directly contradicting any implication that only non-scalable annealing architectures have reached that scale. He notes that work such as Caltech’s 6,100-qubit tweezer array shows large, coherent, room-temperature neutral-atom platforms are already a reality.

On error correction, Pruden writes that “surface code error correction was experimentally demonstrated last year, moving it from a research problem into an engineering problem,” and points to rapid advances in color codes and LDPC codes.

He highlights Google’s updated “Tracking the Cost of Quantum Factoring” estimates, which show that a quantum computer with about one million noisy physical qubits running for roughly a week could, in principle, break RSA-2048 — a twenty-fold reduction from Google’s own 2019 estimate of twenty million qubits. “Resource estimates for a CRQC running Shor’s algorithm have dropped by two orders of magnitude in six months,” he notes, concluding, “To say that this trajectory of progress might potentially deliver a quantum computer before 2030 is not an overstatement.”

Where Thaler emphasizes HNDL as an encryption problem, Pruden reframes blockchains as uniquely attractive quantum targets. He stresses that “public keys used in digital signatures are just as easy to harvest as encrypted messages,” but in blockchains those keys are directly tied to visible value. He points out that “these public keys are distributed & directly associated with value ($150B for Satoshi’s BTC alone),” and that once a quantum adversary can forge signatures, “If you can forge a signature, you can steal the asset regardless of when that original UTXO/account was created.”

For Pruden, this economic reality means “the economic incentives simply and clearly point to blockchains as being the first cryptographically relevant quantum use case,” even if other sectors also face HNDL risks. He adds that “blockchains will be far slower to migrate than centralized systems. A bank can upgrade its stack. Blockchains must reach global consensus, absorb performance trade-offs from PQ signatures, and coordinate millions of users to migrate their keys.”

Invoking Ethereum’s multi-year shift from proof of work to proof of stake, he writes, “The closest thing was the ETH 1.0 to 2.0 transition which took years, and as complex as that was, a PQ migration is much harder. Anyone who thinks this is a matter of swapping a few lines of signature code has simply never shipped, deployed, or maintained a production blockchain.”

Pruden agrees with Thaler that panic is dangerous, but flips the conclusion: “I agree that rushing is dangerous. But that is exactly why work must begin now. The most likely failure mode is that the industry waits too long, and then a major QC milestone triggers a panic.” He closes by saying he disagrees that “quantum computing is progressing slowly,” that “blockchains are less vulnerable than systems exposed to HNDL risk,” or that “the industry has years of slack before action is needed,” arguing that “All three assumptions are at odds with reality.”

At press time, Bitcoin stood at $91,616.

Bitcoin price
Piyasa Fırsatı
QUANTUM Logosu
QUANTUM Fiyatı(QUANTUM)
$0.003207
$0.003207$0.003207
+3.88%
USD
QUANTUM (QUANTUM) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen service@support.mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Volante Technologies Customers Successfully Navigate Critical Regulatory Deadlines for EU SEPA Instant and Global SWIFT Cross-Border Payments

Volante Technologies Customers Successfully Navigate Critical Regulatory Deadlines for EU SEPA Instant and Global SWIFT Cross-Border Payments

PaaS leader ensures seamless migrations and uninterrupted payment operations LONDON–(BUSINESS WIRE)–Volante Technologies, the global leader in Payments as a Service
Paylaş
AI Journal2025/12/16 17:16
Fed Acts on Economic Signals with Rate Cut

Fed Acts on Economic Signals with Rate Cut

In a significant pivot, the Federal Reserve reduced its benchmark interest rate following a prolonged ten-month hiatus. This decision, reflecting a strategic response to the current economic climate, has captured attention across financial sectors, with both market participants and policymakers keenly evaluating its potential impact.Continue Reading:Fed Acts on Economic Signals with Rate Cut
Paylaş
Coinstats2025/09/18 02:28
Google's AP2 protocol has been released. Does encrypted AI still have a chance?

Google's AP2 protocol has been released. Does encrypted AI still have a chance?

Following the MCP and A2A protocols, the AI Agent market has seen another blockbuster arrival: the Agent Payments Protocol (AP2), developed by Google. This will clearly further enhance AI Agents' autonomous multi-tasking capabilities, but the unfortunate reality is that it has little to do with web3AI. Let's take a closer look: What problem does AP2 solve? Simply put, the MCP protocol is like a universal hook, enabling AI agents to connect to various external tools and data sources; A2A is a team collaboration communication protocol that allows multiple AI agents to cooperate with each other to complete complex tasks; AP2 completes the last piece of the puzzle - payment capability. In other words, MCP opens up connectivity, A2A promotes collaboration efficiency, and AP2 achieves value exchange. The arrival of AP2 truly injects "soul" into the autonomous collaboration and task execution of Multi-Agents. Imagine AI Agents connecting Qunar, Meituan, and Didi to complete the booking of flights, hotels, and car rentals, but then getting stuck at the point of "self-payment." What's the point of all that multitasking? So, remember this: AP2 is an extension of MCP+A2A, solving the last mile problem of AI Agent automated execution. What are the technical highlights of AP2? The core innovation of AP2 is the Mandates mechanism, which is divided into real-time authorization mode and delegated authorization mode. Real-time authorization is easy to understand. The AI Agent finds the product and shows it to you. The operation can only be performed after the user signs. Delegated authorization requires the user to set rules in advance, such as only buying the iPhone 17 when the price drops to 5,000. The AI Agent monitors the trigger conditions and executes automatically. The implementation logic is cryptographically signed using Verifiable Credentials (VCs). Users can set complex commission conditions, including price ranges, time limits, and payment method priorities, forming a tamper-proof digital contract. Once signed, the AI Agent executes according to the conditions, with VCs ensuring auditability and security at every step. Of particular note is the "A2A x402" extension, a technical component developed by Google specifically for crypto payments, developed in collaboration with Coinbase and the Ethereum Foundation. This extension enables AI Agents to seamlessly process stablecoins, ETH, and other blockchain assets, supporting native payment scenarios within the Web3 ecosystem. What kind of imagination space can AP2 bring? After analyzing the technical principles, do you think that's it? Yes, in fact, the AP2 is boring when it is disassembled alone. Its real charm lies in connecting and opening up the "MCP+A2A+AP2" technology stack, completely opening up the complete link of AI Agent's autonomous analysis+execution+payment. From now on, AI Agents can open up many application scenarios. For example, AI Agents for stock investment and financial management can help us monitor the market 24/7 and conduct independent transactions. Enterprise procurement AI Agents can automatically replenish and renew without human intervention. AP2's complementary payment capabilities will further expand the penetration of the Agent-to-Agent economy into more scenarios. Google obviously understands that after the technical framework is established, the ecological implementation must be relied upon, so it has brought in more than 60 partners to develop it, almost covering the entire payment and business ecosystem. Interestingly, it also involves major Crypto players such as Ethereum, Coinbase, MetaMask, and Sui. Combined with the current trend of currency and stock integration, the imagination space has been doubled. Is web3 AI really dead? Not entirely. Google's AP2 looks complete, but it only achieves technical compatibility with Crypto payments. It can only be regarded as an extension of the traditional authorization framework and belongs to the category of automated execution. There is a "paradigm" difference between it and the autonomous asset management pursued by pure Crypto native solutions. The Crypto-native solutions under exploration are taking the "decentralized custody + on-chain verification" route, including AI Agent autonomous asset management, AI Agent autonomous transactions (DeFAI), AI Agent digital identity and on-chain reputation system (ERC-8004...), AI Agent on-chain governance DAO framework, AI Agent NPC and digital avatars, and many other interesting and fun directions. Ultimately, once users get used to AI Agent payments in traditional fields, their acceptance of AI Agents autonomously owning digital assets will also increase. And for those scenarios that AP2 cannot reach, such as anonymous transactions, censorship-resistant payments, and decentralized asset management, there will always be a time for crypto-native solutions to show their strength? The two are more likely to be complementary rather than competitive, but to be honest, the key technological advancements behind AI Agents currently all come from web2AI, and web3AI still needs to keep up the good work!
Paylaş
PANews2025/09/18 07:00