The 256-bit elliptic curve cryptography that Bitcoin uses could be broken sooner than we think. Google targets 2029 for its own post-quantum migration.
BIP 360 (Pay-to-Merkle-Root or P2MR) is the first official for step toward ensuring Bitcoin is prepared. Proposed by Hunter Beast and now merged into the official Bitcoin BIPs repository, it introduces a new output type that removes the vulnerable key-path spend while keeping a subset of Taproot functionality.
Today, Google's Quantum AI team published a whitepaper showing that future quantum computers could break the 256-bit elliptic curve cryptography (ECC) protecting Bitcoin with fewer qubits than previously estimated. Google has set an internal 2029 deadline to migrate its own systems to post-quantum cryptography. A EUROCRYPT 2026 paper narrows the estimate to just 1,098 logical qubits - down from 2,124.
The 256-bit elliptic curve cryptography that Bitcoin uses could be broken sooner than we think. Google targets 2029 for its own post-quantum migration.
BIP 360 (Pay-to-Merkle-Root or P2MR) is the first official for step toward ensuring Bitcoin is prepared. Proposed by Hunter Beast and now merged into the official Bitcoin BIPs repository, it introduces a new output type that removes the vulnerable key-path spend while keeping a subset of Taproot functionality.
Today, Google's Quantum AI team published a whitepaper showing that future quantum computers could break the 256-bit elliptic curve cryptography (ECC) protecting Bitcoin with fewer qubits than previously estimated. Google has set an internal 2029 deadline to migrate its own systems to post-quantum cryptography. A EUROCRYPT 2026 paper narrows the estimate to just 1,098 logical qubits - down from 2,124.