Nine Bitcoin-linked firms have put $15 million over three years behind a problem the market keeps trying to file under “later”: quantum computing.
- 9 firms formed the Bitcoin Security Consortium
- $15 million pledged over three years
- Post-quantum cryptography is the first focus
- Bitcoin is not broken today, but the long-term risk is real
The new Bitcoin Security Consortium brings together Strategy, BlackRock, Coinbase, Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets and Galaxy. Its stated goal is to fund long-term Bitcoin security research, starting with post-quantum cryptography, the class of defenses meant to withstand attacks from powerful future quantum computers.
Brink Executive Director Mike Schmidt will coordinate the group’s day-to-day work as a volunteer. Each company will direct its own funding independently instead of sending money into one central pot. That may sound like a small detail, but in Bitcoin land it matters. This is a coordination effort, not a governance grab.
The consortium says it will not develop or direct Bitcoin’s protocol, endorse specific changes, or speak for Bitcoin developers. Good. Bitcoin does not need a committee in business casual trying to “optimize” the rules like it’s a quarterly software rollout. The network’s open-source culture tends to swat down that kind of overreach anyway.
The real issue is narrower and more serious. Bitcoin today relies on elliptic curve cryptography to prove ownership and authorize transactions. That system is secure against classical computers. The concern is that a sufficiently powerful quantum computer could one day use Shor’s algorithm to attack today’s public-key cryptography by making the underlying mathematical problem tractable.
That is not an immediate failure. Large-scale quantum computers cannot break Bitcoin’s cryptography today, and Galaxy says no cryptographically relevant quantum computer exists today. So this is not a panic button. It is a long-term security bill the network is being asked to prepare for before the invoice arrives.
Strategy CEO Phong Le put the incentive plainly:
“As long-term holders, we have every incentive to see Bitcoin remain secure for generations, ”
BlackRock global head of digital assets Robert Mitchnick said the member firms will make more funding available for Bitcoin Core developers and long-term security work. Bitcoin Core is the main open-source software implementation of Bitcoin, so support there goes straight to the people maintaining the code most of the network actually runs on.
There’s also a broader backdrop here. A June executive order in the U.S. directed federal agencies to move high-value systems toward post-quantum key establishment by the end of 2030 and post-quantum digital signatures by the end of 2031. In other words, this is no longer just a cryptography seminar topic. Governments are starting to treat quantum migration as an operational requirement.
That matters for Bitcoin because the network’s upgrade process is deliberately slow and decentralized. No CEO can force a patch. No foundation can rewrite the rules. Any major cryptographic migration would need broad technical agreement, wallet support, exchange coordination, and plenty of testing. That protects Bitcoin from reckless changes, but it also means a quantum-resistant transition could take years.
Galaxy’s own Bitcoin giants unite with $15M plan to fight quantum threat arrived just two days before the consortium announcement, and Galaxy committed up to $5 million in grants for post-quantum tools, wallet migration systems, signature research, and security audits. Galaxy also warned that upgrades may take years because of decentralized governance. That’s the part a lot of hype merchants skip. Hard upgrades are easy to announce and brutally hard to deploy across a network that refuses to be bossed around.
The practical risk is worth spelling out clearly. In Bitcoin, a public key can become visible through certain address types or spending patterns. A private key is the secret that controls the coins. If a future quantum computer becomes powerful enough, exposed public keys could become vulnerable. That means address reuse is not harmless sloppiness. It could become a real liability.
Researchers disagree on how much BTC is exposed, and those estimates are not interchangeable. Project Eleven’s Bitcoin Risq List estimated 6, 982, 462 BTC sat in addresses with exposed public keys as of June 15. Glassnode estimated in May that 1.92 million BTC faced structural exposure because their output types reveal public keys by design, while another 4.12 million BTC fell into an operational category tied to address reuse and wallet practices.
Those are different methods measuring different things. One is not a clean substitute for the other. The honest takeaway is that there is a meaningful exposure surface, but the size of that surface depends heavily on how you define it. Anyone pretending those numbers are settled gospel is selling certainty where none exists.
The Quantum Threat to Blockchains: 2026 Report puts its baseline estimate for Q-Day, the point when quantum computers could break current public-key cryptography, in 2033, with an early scenario in 2030 and a later one in 2042. Those are scenario estimates, not prophecy. Q-Day is a useful shorthand, but it is not a countdown clock etched in stone.
The same research also pushes back on the lazy “just add more qubits” narrative. Progress toward a cryptographically relevant quantum computer depends on physics, error correction, system integration and algorithm efficiency. A machine can look impressive on a slide deck and still be a long way from cracking real-world cryptography. That doesn’t make the threat imaginary. It just means the engineering path is messier than the headlines suggest.
There are already signs that parts of the industry are trying to get ahead of it. Coinbase’s independent advisory board has urged Bitcoin developers to begin a quantum migration plan now. BitGo and Silence Laboratories completed a simulation using a post-quantum signing system in an institutional custody workflow. Developers are also discussing BIP-360, a proposed Bitcoin improvement designed to reduce future quantum exposure.
BIP stands for Bitcoin Improvement Proposal, which is the formal way changes are discussed in the ecosystem. A proposal is not a standard, and it is definitely not a done deal. In Bitcoin, “we should probably do this” and “this is widely adopted” can be separated by years of argument, testing and a few bruised egos.
The upside of the consortium is straightforward: more money, more research, more coordination, and a better chance that Bitcoin’s security work stays ahead of the curve instead of sprinting behind it. The downside is equally clear: funding does not magically produce consensus, and the moment big institutions get involved, people start worrying about influence, optics and soft pressure.
That skepticism is healthy. Bitcoin’s open-source model has survived because it makes control hard. If this consortium stays in its lane, funding research, supporting developers and educating users without trying to steer protocol decisions, it could be useful. If it starts acting like it owns the steering wheel, the community will rightly tell it to get lost.
For ordinary Bitcoin users, the practical lesson is simple enough: avoid address reuse, pay attention to wallet guidance, and keep an eye on migration plans if and when quantum-resistant options become part of the standard path. No need for doomsday cosplay. Just basic hygiene, which is usually the least glamorous advice and the most useful.
Key questions readers will ask
-
Is Bitcoin broken because of quantum computing?
No. Bitcoin’s current cryptography is not broken today, and no quantum computer exists today that can threaten it in a cryptographically relevant way. The concern is future risk, not present collapse. -
Why does post-quantum cryptography matter?
It is designed to hold up against attacks from both classical computers and future quantum machines. If quantum hardware becomes powerful enough, Bitcoin and other public-key systems will need stronger defenses. -
Does the Bitcoin Security Consortium control Bitcoin?
No. The consortium says it will not direct Bitcoin’s protocol, endorse specific changes, or speak for developers. It is funding research and education, not running the network. -
Which Bitcoin holdings are most exposed?
Coins tied to exposed public keys, especially where address reuse has occurred, are the most concerning in a future quantum scenario. Not every BTC output is equally exposed, which is why the estimate varies depending on methodology. -
Will Bitcoin upgrade quickly if needed?
Probably not. Bitcoin’s decentralized governance means major security changes require broad agreement, careful testing, and support across wallets, exchanges, and users. That slows bad ideas down, and good fixes too. -
What should users do now?
Avoid address reuse and follow wallet security guidance. The quantum threat is still long-term, but better habits now reduce exposure later.
Bitcoin Takes First Steps Toward Post-Quantum Resistance shows the direction of travel: Bitcoin’s best defense has always been boring discipline, conservative engineering, skeptical users and upgrades that survive real scrutiny. Quantum risk fits that model perfectly. It is real enough to fund, uncertain enough to avoid hype, and awkward enough that the network will probably spend years arguing before it does the sensible thing.
For more context on this theme, see our previous coverage of the Coinbase Council Warns Quantum Computing Could Expose 7 and how Coinbase Warns Quantum Computing Could Threaten Bitcoin wallet security soon.