Bankless
Bankless

Will Quantum Computing Kill Bitcoin? | Scott Aaronson & Justin Drake

Quantum computing is advancing rapidly, raising significant questions for cryptography and blockchain. In this episode, Scott Aaronson, quantum computing expert, and Justin Drake, cryptography researcher at the Ethereum Foundation, join us to explore the impact of quantum advancements on Bitcoin, Et

Featured Speakers

Scott Aronson GuestJustin Drake Guest

Episode Summary

Executive Summary: The episode explains quantum computing from first principles and then applies it to crypto. Scott Aronson argues quantum progress is now an engineering problem, not a theory mystery: useful fault-tolerant machines may arrive within a decade, but breaking cryptography depends on scale, cost, and architecture. Justin Drake then maps the risks to Bitcoin and Ethereum, concluding Ethereum has a plausible upgrade path to post-quantum security, while Bitcoin faces a deeper social and technical dilemma around lost coins, hard forks, and proof-of-work mining.

Main Topics: Quantum computing 101: what makes it different (Priority: 5/5): Scott explains qubits, superposition, amplitudes, interference, and why quantum computers are not just faster classical computers but a fundamentally different computational model. Google Willow and the engineering milestone (Priority: 5/5): The discussion frames Willow as a major experimental threshold: improved error correction and a first demonstration that scaling surface codes can reduce effective error, without yet enabling full fault-tolerant quantum computation. Quantum algorithms and why they matter (Priority: 5/5): Shor’s algorithm threatens RSA, Diffie-Hellman, and elliptic curves through period-finding and the quantum Fourier transform, while Grover’s algorithm offers only a square-root speedup for search and mining. Cryptography risk to Bitcoin and Ethereum (Priority: 5/5): The speakers break down how quantum computers could forge signatures, steal funds, and eventually affect proof-of-work mining; Ethereum appears easier to upgrade than Bitcoin because of account abstraction and prior design choices. Bitcoin’s social and governance dilemma (Priority: 5/5): Bitcoin may need to choose between freezing vulnerable coins, hard-forking to new cryptography, or leaving old coins exposed, creating a conflict between immutability and survival. Ethereum’s post-quantum migration path (Priority: 4/5): Ethereum already has a route to post-quantum signatures, consensus upgrades, and data-structure changes, though with trade-offs like larger signatures and bandwidth pressure. Quantum money and future payment systems (Priority: 3/5): The conversation ends on quantum money, one-shot signatures, and physically unclonable cash as a long-term frontier that could outperform today’s cryptographic money for simple transfers and finality.

Key Arguments: Quantum computing is not a generic supercharged computer; it only yields major advantages on specialized problems where interference can be engineered to amplify the right answer. The Willow chip matters because it demonstrates the error-correction threshold predicted decades ago, suggesting fault-tolerant quantum computing is becoming an engineering, not conceptual, challenge. Shor’s algorithm is the main threat to crypto because it breaks the public-key systems used by Bitcoin and Ethereum, including RSA-like and elliptic-curve schemes. Grover’s algorithm is more limited; it could eventually help with proof-of-work mining, but only after large error-correction overheads are overcome. Ethereum can plausibly migrate to post-quantum signatures via account abstraction and planned protocol upgrades, making it comparatively resilient. Bitcoin faces a harder problem because old addresses and lost coins cannot easily opt in to upgrades, forcing a social decision about property rights and immutability. If quantum capability arrives unevenly, early movers could dominate mining or target high-value wallets before the ecosystem can adapt. Quantum money and one-shot signatures are presented as long-term sci-fi-adjacent concepts that could enable unclonable cash and perfect finality, but they require much more mature quantum hardware. The timeline is uncertain, but listeners holding secrets they want protected for a decade or more should already be considering post-quantum migration.

Data Points: Physical qubits in Google Willow: 103 - Scott describes Willow as a superconducting chip with roughly 103 physical qubits arranged in a grid. Year surface code theory emerged: 1996-1997 - Scott notes that quantum error correction and the surface code were predicted in theory in the mid-to-late 1990s. Fidelity improvement over 25 years: 50% -> 90% -> 99% -> 99.8%/99.9% - He uses fidelity gains to show the field’s long engineering progress. Temperature of superconducting qubits: ~10 millikelvin - Quantum chips must be cooled extremely close to absolute zero to maintain coherence. Coherence time mentioned: ~50 microseconds - Scott says superconducting qubits persist long enough to do interesting computation, though briefly by human standards. Estimated physical qubits to break cryptography: Millions of physical qubits - Scott says breaking cryptographic codes likely requires millions of physical qubits and many dilution refrigerators. Estimated logical qubits for ECDSA/RSA attacks: Thousands of logical qubits - Justin says breaking cryptography requires only a few thousand logical qubits, but each needs heavy error-correction overhead. Error-correction overhead: ~100 physical qubits per logical qubit - Justin summarizes the rough ratio between physical and logical qubits. Estimated R&D to break ECDSA: $10 billion - Justin cites a Riverlane founder’s estimate for the cost to break ECDSA. Global quantum R&D spending: ~$40 billion/year - Justin cites a conference estimate for annual global quantum information spending. Estimate for breaking a 2048-bit key: ~1 week per key - Scott says one estimate suggests a week might be needed to break a single key, depending on architecture. More optimistic attack estimate: seconds - Justin relays a much more aggressive estimate from Riverlane, showing wide uncertainty. Post-quantum signature size overhead: ~10x larger - Justin says post-quantum signatures are roughly ten times larger than current ones. NIST deprecation timeline: ECDSA deprecated in 2030; disallowed in 2035 - Justin uses NIST’s timeline to argue regulated institutions will need migration. Bitcoin lost/vulnerable supply estimate: 1-4 million BTC - Justin estimates this range could be at risk if old public keys remain exposed. Satoshi’s holdings: ~1 million BTC - Justin and Scott discuss Satoshi’s unspent coins as the biggest symbolic and practical vulnerability. Ethereum lost coins estimate: ~100,000 ETH - Justin says exposed lost coins on Ethereum are far smaller in proportion than Bitcoin. Ethereum vulnerable share estimate: ~0.1% - Justin estimates Ethereum’s vulnerable supply could be around 10 basis points. Current ETH staked: ~$100 billion - Used to explain economic finality and the scale of potential slashing incentives. Finality attack cost: ~$33 billion - Justin says an attacker would need to slash at least one-third of staked ETH. BTC open perpetuals: ~$40 billion - Justin warns that an attacker could short large amounts of BTC via perp markets.

Pivotal Quotes: "“The hard part with a quantum computer is that in order for it to be useful, you have to beat a classical computer.”" — Scott Aronson: Scott explains why quantum computing is fundamentally different from ordinary performance scaling. "“It sounds like about as good of a guess as anyone’s.”" — Scott Aronson: Scott responds to the estimate that it could take $10 billion in R&D to break ECDSA, emphasizing uncertainty in forecasting. "“I think the Bitcoiners are very, very purist and don't want to touch the supply of Bitcoin because that impedes and violates the property rights of some people.”" — Justin Drake: Justin frames Bitcoin’s biggest nontechnical challenge as a governance and property-rights dilemma.

Implications: Quantum risk is real but not immediate. Ethereum appears upgradeable; Bitcoin faces a harder political and technical fork over vulnerable coins and mining. Long term, post-quantum cryptography is becoming mandatory, and quantum money may eventually reshape the idea of digital cash.

🔓 Sign Up for Unlimited Episode Search

About Bankless

View all episodes from Bankless