Can a quantum computer actually break Bitcoin?
In theory, yeah.
But real talk, we are still pretty far from that being an actual problem.
Today’s cryptography is basically impossible to brute force with normal computers.
Quantum computers change the game because they come with two tools:
• Shor’s algorithm can break public key systems like ECDSA and Schnorr. That matters because Bitcoin relies on them for signatures.
• Grover’s algorithm can speed up brute force attacks against symmetric encryption and hashes, but that side of the problem is much more manageable.
This is why the whole crypto and security world has already been working on PQC, post quantum cryptography for years.
NIST has already standardized algorithms like ML-KEM, ML-DSA, and SLH-DSA.
So... is Bitcoin safe right now? 🤔
Yes.
There is no quantum computer today that is anywhere close to breaking Bitcoin in practice.
The real issue is what happens if we eventually get a quantum computer powerful enough to run Shor’s algorithm at scale.
Once your public key is exposed, a sufficiently powerful quantum computer could theoretically derive the private key from it.
For P2PKH and P2WPKH addresses, the public key is usually hidden behind a hash until you spend from that address.
Once you spend, the public key becomes visible onchain.
Taproot, bc1p, is different.
Its output already contains a public key, so the key is exposed from the moment the BTC arrives.
That means if we ever reach the point where quantum computers can attack secp256k1, Taproot coins could theoretically be vulnerable even if they never move.
So what is the Bitcoin community doing about it? ✅
Quite a lot, actually.
• BIP 360 / P2MR proposes a new output type that removes Taproot’s key path spend and keeps the public key hidden until spending. The main goal is to reduce long exposure quantum risk.
• BIP 361 goes a step further and lays out a possible migration path for Bitcoin to eventually move away from ECDSA and Schnorr once post quantum signatures are ready.
Both are still drafts.
Bitcoin has not switched to post quantum signatures on mainnet yet.
And there is still another problem to solve.
Even if a public key stays hidden until spending, it becomes visible once the transaction hits the mempool.
That creates a short window where a future quantum attacker could theoretically try to steal the coins before confirmation.
Fully solving that likely means Bitcoin eventually needs a real post quantum signature scheme.
Bitcoin has time.
This is not something that suddenly shows up one morning and kills Bitcoin overnight.
There will be years of research, upgrades, migration plans, wallet updates, and plenty of warning before this becomes a real threat.
So what has OneKey done already? 🔑
The short version:
Our app and hardware are built to be quantum ready.
✅ App security
OneKey App currently uses AES-CBC-256 + PBKDF2-HMAC-SHA256.
AES-256 still has a huge security margin even under Grover style quantum attacks.
Under the current threat model, the design reaches security strength comparable to NIST PQC Level 5 grade protection.
✅ Bitcoin address management
OneKey supports BTC Multi-Address Mode and automatically uses fresh change addresses.
That helps reduce address reuse and limits how long public keys stay exposed.
✅ Hardware upgrade path
OneKey hardware wallets use a hardware root of trust plus Secure Boot and a Chain of Trust.
The boot process verifies the Bootloader and Firmware step by step.
Why does that matter?
Because when post quantum standards are ready for real world deployment, we can evolve the cryptography through firmware and software updates without rebuilding the entire security architecture from scratch.
We are also already working toward support for things like ML-KEM and ML-DSA.
So what should normal users do right now? 🔧
Honestly, not much.
• Don’t reuse BTC addresses if you can avoid it
• Minimize unnecessary public key exposure
• Keep an eye on Bitcoin’s post quantum upgrade path
• When migration eventually becomes necessary, move funds to the new quantum resistant address type
That day is probably still a long way off.
And when it comes, Bitcoin wallets will have migration tools and upgrade paths ready.
No need to panic.