One Door, Two Keys: What Quantum Computers and Super Intelligence Could Actually Do to Bitcoin

OCTOBER 8, 2026

Two views of the curve y squared equals x cubed plus seven. On the left, a smooth orange curve with two points added by a line. On the right, the same equation worked modulo 127 as a scatter of orange dots.
Original diagram made for this page. The right-hand dots are every solution of y² = x³ + 7 modulo 127, computed directly.

Overnight Matthew Green, the Johns Hopkins cryptographer who has spent a career being politely alarmed on the internet's behalf, replied to a thread with one line: "I think we might lose public key cryptography." It was seen well over a million times, and every Bitcoiner reading it silently swapped in "my coins".

Update, 8 October evening. I first wrote this without the context, assuming he meant quantum computers. He was answering a different argument, which started the day before when Ethereum Foundation researcher Justin Drake said a break of ECDSA might arrive from Super Intelligence (SI) maths before any quantum computer does. I've added a section on that below, "The Other Threat: Maths That Writes Itself", and left the quantum material as it was, because the lock and its exposure are the same either way.

So here is the version with the drama taken out and the arithmetic left in. I was asked three things, and they make a good outline: what is the math actually protecting, doesn't Bitcoin use two signature schemes (and would an attacker have to break both?), and how worried should anyone be? The short answers: a very specific lock, no, it would not need to break both, and "worried about the transition, not about the end of cryptography."

The Lock: A Curve That Turns Into Dots

Bitcoin's keys live on a curve called secp256k1, whose equation is about as unglamorous as math gets: y² = x³ + 7. Draw it over ordinary numbers and you get the smooth, slightly smug shape in the picture above. The trick that makes it a cryptosystem is a way of adding two points on it. Draw a straight line through the two, find where it meets the curve a third time, and flip that point over the horizontal axis.

How two points on the curve make a third The smooth curve y squared equals x cubed plus seven. A dashed line through points P and Q hits the curve a third time; flipping that third point over the horizontal axis gives P plus Q. P Q third hit P + Q Elliptic-curve “addition” in three moves 1 Pick two points, P and Q, on the curve. 2 Draw the straight line through them. It hits the curve exactly one more time. 3 Flip that third point over the horizontal axis. That point is P + Q. Adding P to itself (a tangent line) gives 2P. Do that 256 times in a row and you reach “k × P” for a k around 10⁷⁷, in a blink. Nothing here is secret. Anyone can add points. The secret is how many times it was done.
Point addition on the real-number curve. This is the whole operation; everything else in Bitcoin's key math is this move repeated. (Drawn from the actual equation, with P and Q chosen for the picture.)

Add a point to itself, 256 times in the right pattern, and you can reach "k times the starting point" for a k that is a 256-bit number, in the time it takes to blink. Your private key is that number k. Your public key is the point it lands on. Anyone can check that a point is where it should be. Nobody can easily look at the point and say how many hops it took.

Computers don't use the smooth curve, though. They work in a finite field, where the numbers wrap around like a clock, and that makes the smooth line shatter into scattered dots. The picture below is the real thing in miniature: the same equation, on a clock with 127 hours instead of one with 78 digits. The numbered dots are G, 2G, 3G and so on, one addition apart each, and they hop around the grid with no visible order.

Walking G, 2G, 3G on a toy curve: the dots land everywhere A scatter of 126 dots on the toy curve y squared equals x cubed plus seven modulo 127. Numbered points show G, 2G, 3G and so on up to 12G, which jump around the grid with no visible pattern. Toy Bitcoin: same equation, field of 127 numbers G 2 3 4 5 6 7 8 9 10 11 12 The numbered dots are 1·G, 2·G, 3·G … Each is one more addition from the last, yet they hop around with no visible order. The private key is the number k. The public key is the dot k·G lands on. Hand someone the dot and ask “which k?” On this toy grid you could just try all 127. Bitcoin’s real grid has about 1.16 × 10⁷⁷ points Trying them all is not an option; it is within a few orders of magnitude of the atoms in the observable universe. Toy curve: y² = x³ + 7 mod 127, G = (1, 32), 127 points including the point at infinity. Built for this page.
A toy version of Bitcoin's key math. On a grid of 127 you could find k by trying every dot. On Bitcoin's grid of about 1.16 × 10⁷⁷ points you could not.

That asymmetry, easy forward and hopeless backward, is the entire security argument. It's called the elliptic-curve discrete logarithm problem, and the best classical attack needs roughly 2¹²⁸ steps. Quantum computers matter because of a 1994 algorithm by Peter Shor that doesn't take 2¹²⁸ steps. It takes a polynomial number, if you can build a machine big and clean enough to run it.

The one-way street and what Shor's algorithm does to it Private key k to public key Q equals k times G takes about 256 steps. The reverse needs about two to the 128 steps classically, but a large quantum computer running Shor's algorithm needs roughly 1,200 to 1,450 logical qubits and 70 to 90 million gates. Private key k a 256-bit secret number Public key Q = k·G a point on the curve EASY: ~256 doublings and additions milliseconds on a phone HARD (classical): ~2¹²⁸ steps thousands of times the age of the universe, even at a billion billion steps a second Shor’s algorithm (1994) turns “hard” into “tens of millions of gates”, if the machine exists: Google, March 2026: <1,200 logical qubits and <90 million Toffoli gates (or <1,450 and <70 million). That is the paper’s own estimate for a 256-bit curve like Bitcoin’s. No such machine exists today.
The one-way street. The quantum attack is a design on paper; the numbers are from Google's March 2026 resource estimate, which reports two circuit variants.

"Doesn't Bitcoin Use Two? Wouldn't They Have to Crack Both?"

Good instinct, and it would be great news if it were true. It isn't. Bitcoin does have two signature schemes: ECDSA from the beginning in 2009, and Schnorr (BIP-340) added with the Taproot upgrade in 2021. But they are not layers. They are two different ways of proving you know k, and both of them run on the same curve with the same hard problem underneath. Find k from the public point and you can forge either one. Shor's algorithm doesn't care which signature you wrapped around the key.

Bitcoin's two signature schemes share one lock ECDSA from 2009 and Schnorr signatures from the 2021 Taproot upgrade both rest on the same discrete-logarithm problem on the secp256k1 curve, so one successful quantum attack breaks both. SHA-256 hashing is a separate lock that quantum computers only weaken modestly. Signatures: two schemes, one hard problem ECDSA 2009 · addresses starting 1 and bc1q Schnorr (BIP-340) 2021 Taproot · addresses starting bc1p The same lock discrete log on secp256k1 (find k from k·G) Shor’s algorithm opens both One lock with two kinds of key, not two locks in a row. A different lock: hashing SHA-256 / RIPEMD-160 mining, txids, address hashes Grover’s algorithm only gives a square-root speedup: 256-bit work becomes ~2¹²⁸, which is still out of reach.
Two signature schemes, one lock. The lower box is the one genuinely separate defence, and it is a hash function, not a curve.

The thing that really is a second lock is the hash sitting in front of most addresses. If your coins sit at an address that starts with 1 or bc1q, the blockchain doesn't hold your public key at all, only a 160-bit fingerprint of it. A quantum computer helps against hashes too, but only by a square root (Grover's algorithm), which turns a hopeless job into a merely hopeless one. That fingerprint is why a big chunk of Bitcoin is quietly protected today. It is not protected by the curve.

What's Actually Exposed

The fingerprint comes off the moment you spend. A transaction has to reveal the public key so others can verify the signature, and from that instant the key is out in the open. This gives two different attack shapes, which Google's authors separate in their paper:

When Bitcoin's public key is visible, by address type A table-like graphic. Pay-to-public-key outputs from 2009 to 2010 show the key all the time. Pay-to-public-key-hash and native SegWit addresses hide the key behind a hash until the coins are spent, or forever if never reused. Taproot addresses show a key from the start. Below, a bar shows an estimated 6.9 million of about 20.1 million bitcoin sit behind exposed keys. Is the public key visible? Coins at rest In the mempool Risk shape P2PK early coinbase, 2009–10 YES YES long-term target P2PKH (1…) hash of key; reuse leaks it hidden YES race at spend time P2WPKH (bc1q…) hash of key, SegWit hidden YES race at spend time P2TR (bc1p…) Taproot: tweaked key on-chain YES YES long-term target The hash is the only thing standing between an unspent, never-reused address and Shor. Spending removes it. How much sits behind an exposed key (reported estimate, not my count) ≈ 6.9 million BTC exposed the rest: key hidden until spend Out of about 20.1 million mined (this site’s Bitcoin Board). The estimate includes roughly 1 million BTC attributed to Satoshi.
Which address types show the public key, and when. The 6.9 million figure is a widely repeated third-party estimate that I did not recompute; it comes from news coverage of the BIP-360 and BIP-361 proposals.

Estimates of the at-rest pile run around 6.9 million BTC, about a third of everything mined, including the roughly million coins attributed to Satoshi. That's an unusual position for an asset sold partly as "digital gold": a third of the vault sits behind glass that is thick today and of unknown thickness tomorrow. For the full supply picture see how many bitcoins there really are, and the live numbers are on the Bitcoin Board.

How Far Away Is the Machine?

Here's where the drama and the data part ways. The largest physical-qubit arrays in 2026 are about 1,000 to 1,200 qubits, and what they can do reliably as logical qubits is in the tens. Bitcoin's curve needs, by Google's March 2026 estimate, fewer than 1,200 to 1,450 logical qubits, which on superconducting hardware means fewer than half a million physical ones, running for minutes. That paper, by Babbush, Gidney, Boneh, Drake and colleagues, cut the earlier resource estimate by roughly twenty times, and Google published a zero-knowledge proof of its claim rather than the attack circuits themselves.

The other recent number comes from IonQ, in September: about 19,400 trapped ions, but around 26 days per attempt. Slower machines like that can only attack at-rest coins; they cannot race a ten-minute block. So which hardware wins matters as much as how many qubits it has.

Physical qubits needed, on a log scale A logarithmic bar chart. Largest physical-qubit machines today are about 1,200. IonQ's estimate for Bitcoin's curve is about 19,400 ions but 26 days per attempt. Google's is under 500,000 superconducting qubits for minutes. For comparison, factoring RSA-2048 was estimated at 20 million qubits in 2019 and under 1 million in 2025. How many physical qubits does the attack need? (log scale) 100 1,000 10,000 100,000 1 million 10 million Largest machines today ≈1,200 noisy qubits; logical qubits only tens IonQ, Sept 2026: secp256k1 19,397 ions · ~26 days per try · on paper Google, Mar 2026: secp256k1 <500,000 · minutes · on paper Gidney, May 2025: RSA-2048* <1 million · <1 week · on paper Gidney, 2019: RSA-2048* 20 million · 8 hours · on paper *RSA is a different public-key system (it rests on factoring, not curves), shown for scale. “On paper” = a published design, not a built machine. Sources: Babbush et al. 2026; IonQ 2026; Gidney 2019, 2025. Hardware: 2026 press reports of the largest arrays.
The shrinking target, on a log scale. Every bar except the top one is a published design, not a machine that exists. RSA bars are shown only to illustrate the same downward trend.

I'd read this chart two ways at once. One: the trend is steady and runs in the wrong direction for the defender. The headline estimates have fallen several-fold in the last few years. Two: from the top bar to the second bar is still a gap of more than one order of magnitude in qubits, and the headline assumptions (error rates, decoding, running for days without a fault) are exactly the parts that haven't been built at scale. Both are true. The sensible posture is the one Google itself adopted for its own systems, which is to migrate on a schedule (it has said 2029) rather than waiting to see the machine.

The Other Threat: Maths That Writes Itself

Everything above assumes the attack needs a machine nobody has built. The argument that set off this week's thread assumes the opposite: that the attack is software, a better algorithm for the same curve, found by a system that is good at maths.

The trigger was OpenAI's release on 6 October of several hundred maths manuscripts, credited to an internal model the company hasn't named or released, claiming solutions to hundreds of previously open problems. (Outlets disagree on the counts. I've seen 372, 377 and 722 for different things, problems versus manuscripts, so I won't quote one.) Fortune reports that some of the proofs were machine-checked and some were not, and that OpenAI had withdrawn at least three by Thursday over errors. None of it, as far as I can find, is an attack on elliptic curves.

The next day Drake wrote that it was now "reasonable to brace for the possibility that ECDSA breaks before qday, in the worst case in months not years," and called for "bunker mode": moving funds in a controlled way to fresh addresses that keep their public keys hidden. Reactions split:

So what does it change for the door picture? Less than the volume suggests, and in one way more.

The evidence on the other side is plain too: so far there is no public result, from OpenAI or anyone else, showing a break, and Lindell is right that a claim that "cannot be proven wrong" is a weak basis for moving money. Buterin's counterpoint matters as much. Hurried migrations are how people lose coins, and Bitcoin's history has more of those stories than of successful curve attacks. I'd describe the fair reading as: probability low and unmeasurable, cost of the cheap precautions (no address reuse, don't leave coins on Taproot or old pay-to-public-key outputs longer than needed) also low, and the expensive precautions (emergency forks) not justified by anything published. That's a description of the positions, not a recommendation to move any coin.

So What Is Bitcoin Doing About It?

As of today, the answer is "discussing it carefully," which in Bitcoin means slowly. As reported, there are three live ideas:

Notice what all three dodge: the hardest question is political, not mathematical. If a million coins from 2009 are exposed and their owner never moves them, do you freeze them (and burn a founding principle), leave them (and hand them to whoever builds the machine first), or wait? There is no neutral option. It's the lost-coin problem with a clock on it. Meanwhile, the practical hygiene is dull and available now: don't reuse addresses, and move long-dormant coins to fresh addresses on current formats. If you want the self-custody angle, the hardware wallet piece covers the key-handling side.

And Is Public-Key Cryptography Itself Going Away?

No. This is where Green's sentence needs the most care, since it's easy to read it as "the whole idea is dead." Public-key cryptography is the idea; elliptic curves and RSA are two implementations of it. In 2024 NIST finalized replacements that run on ordinary computers: ML-KEM for key exchange, and ML-DSA and SLH-DSA for signatures. They're built on lattices and on hash functions, neither of which Shor's algorithm touches. Browsers and messaging apps already use the hybrid versions.

What Bitcoin would pay is space. A Schnorr signature is 64 bytes. An ML-DSA signature is about 2,400 bytes, close to forty times larger, with a public key to match. Block space is the scarce resource Bitcoin charges rent on, so a post-quantum Bitcoin is a Bitcoin with a very different fee market. That's a real cost and a solvable one. It isn't the end of anything.

The honest fear is a different one, and Green is exactly the person to hold it: that the new schemes are young. In 2022 SIKE, a candidate that had made it to the fourth round of NIST's own process, was broken on a laptop by a classical attack. Nobody is saying the lattices will fall. But "we replaced the old lock with a newer one" is a weaker sentence than it sounds, and it's why hash-based signatures, which lean on far older assumptions, keep coming up as the fallback.

What I'll Be Watching

Where I Could Be Wrong

Sources

  1. Babbush, Zalcman, Gidney, Broughton, Khattar, Neven, Bergamaschi, Drake and Boneh. Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations. Google Quantum AI, March 2026. arxiv.org/abs/2603.28846
  2. Google Research. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly. 2026. research.google
  3. PostQuantum.com. IonQ secp256k1 Estimate: 20,000 Qubits, 26 Days per Try. September 2026. postquantum.com
  4. Gidney, C. How to factor 2048 bit RSA integers with less than a million noisy qubits. May 2025. arxiv.org/abs/2505.15917
  5. BIP 360: Pay-to-Merkle-Root (P2MR). bip360.org
  6. CoinDesk. Bitcoin's quantum debate splits as Adam Back pushes optional upgrades over forced freeze. 16 April 2026. coindesk.com
  7. Bitcoin Magazine. Bitcoin Developers Propose Bitcoin Quantum Migration Plan That Would Freeze Legacy Coins (BIP-361). 2026. bitcoinmagazine.com
  8. Matthew Green (@matthew_d_green). Reply post, 8 October 2026, read via the fxtwitter mirror. x.com
  9. Yehuda Lindell (@LindellYehuda). Reply thread, 8 October 2026. x.com
  10. The Block. Crypto industry split over Justin Drake's AI warning. 8 October 2026. theblock.co
  11. Gizmodo. Cryptographers Urgently Debating Whether AI Could Break Bitcoin's Security 'in Months'. October 2026. gizmodo.com
  12. Fortune. OpenAI publishes solutions to more than 370 outstanding math challenges. 7 October 2026. fortune.com
  13. Matthew Green (@matthew_d_green). Follow-up post announcing a longer reply, 8 October 2026. x.com
  14. NIST. FIPS 203, 204 and 205 (ML-KEM, ML-DSA, SLH-DSA), August 2024. The signature and key sizes quoted here are from memory of those standards, not rechecked today. csrc.nist.gov

Keep reading