Bitcoin Q-Day by 2028? How Real Is the Quantum Computing Threat?
TL;DR
- Bitcoin’s “Q-Day” could arrive as early as 2028, according to one industry estimate.
- Most experts disagree with such an aggressive timeline, with many estimates placing a credible Bitcoin quantum threat in the 2030s or later.
- Bitcoin is not currently at practical risk from quantum computers. Today’s hardware remains far below the scale needed to break Bitcoin’s cryptography.
- Around 6.9 million BTC may eventually face greater quantum exposure because their public keys have already been revealed on-chain, according to one cited estimate.
- TRON plans to introduce a post-quantum network upgrade by the end of 2026, according to Sun, though implementation details still need independent verification.
- The bigger issue isn’t whether Q-Day happens in 2028 or 2038 — it’s whether Bitcoin and the broader crypto industry can migrate to quantum-resistant security before it arrives.
Concerns over Bitcoin’s potential “Q-Day” are gaining attention as some industry estimates suggest a quantum computer capable of breaking Bitcoin’s cryptography could emerge as early as 2028. That timeline is far more aggressive than most published expert and institutional estimates, which generally place a credible quantum threat to Bitcoin in the 2030s or later. For traders and exchange users, the bigger question isn’t whether any single prediction proves correct — it’s whether Bitcoin and the broader crypto industry can migrate to quantum-resistant security before the technology becomes a practical threat.
As the industry prepares for long-term risks like quantum computing, Bitcoin remains one of the market’s most closely watched assets.
Trade BTC spot or futures on WEEX:
What Is Q-Day and How Could Quantum Computing Threaten Bitcoin?
"Q-Day" refers to the point at which a quantum computer becomes powerful enough to break the elliptic-curve cryptography (ECC) that secures Bitcoin, Ethereum, and most other blockchains. The underlying concern is Shor's algorithm, a quantum computing method that can theoretically reverse the math connecting a public key to its private key — something that would take classical computers longer than the age of the universe, but which a sufficiently advanced quantum machine could, in theory, do quickly.
If Q-Day arrived and the industry hadn't migrated, attackers could potentially forge signatures and drain wallets whose public keys are already exposed on-chain — which includes any address that has ever sent a transaction (see box below on why this distinction matters).
When comparing qubit counts, it's important not to mix up two different units. A logical qubit is a stable, error-corrected unit of quantum information — the kind actually needed to run an attack. A physical qubit is a raw hardware qubit; because today's hardware is error-prone, many physical qubits must be combined to produce one reliable logical qubit, so physical-qubit counts are always much larger than logical-qubit counts and the two figures shouldn't be compared directly. A technical analysis published on arXiv estimates that breaking Bitcoin's or Ethereum's signature scheme would require roughly 1,200 to 2,330 logical qubits. The same paper puts the best hardware built as of 2026 at roughly 1,000–1,200 physical qubits, capable of producing at most about 100 logical qubits after error correction — a gap the paper describes as 400–500x even under aggressive assumptions. IBM's separate roadmap target of "a few thousand qubits by 2033," cited by Cointelegraph, refers to physical qubits and is not directly comparable to the ~1,200 logical qubits the attack requires.
Why Could Bitcoin Q-Day Arrive as Early as 2028?
One of the more aggressive industry estimates suggests Bitcoin’s Q-Day could arrive as early as 2028. The argument is that while quantum computing does not pose a practical threat to Bitcoin today, the risk could increase rapidly as hardware advances. At the same time, Bitcoin’s decentralized ecosystem — involving miners, exchanges, long-term holders, wallet providers, and wrapped-asset issuers such as WBTC — means any migration to quantum-resistant cryptography could take years to coordinate.
The 2028 timeline should not be treated as an industry consensus. It represents the aggressive end of current projections and sits well ahead of most published expert and institutional estimates. The more important takeaway is that preparation may need to begin long before quantum computers become capable of breaking Bitcoin’s cryptography.
When Will Bitcoin Q-Day Happen? Expert Predictions From 2028 to 2050
Estimates for Bitcoin’s Q-Day vary widely depending on assumptions about quantum hardware development, error correction, and the computing power required to break elliptic-curve cryptography. Current projections range from aggressive estimates around 2028 to more conservative forecasts extending into the 2030s, 2040s, or beyond.
Source | Estimated Q-Day Timeline | Case |
Justin Sun, TRON founder (Bitcoin Asia 2026) | Within ~2 years (by 2028) | Bull (sooner) |
Project Eleven quantum security report, via Decrypt | As soon as 2030, >50% probability by 2033 | Bull-leaning |
Dr. Michele Mosca, University of Waterloo, via Kavout | 1-in-7 chance by 2026 | Bull-leaning |
Google's internal "Q-Day" target, via Decrypt | Around 2032 | Middle |
arXiv "Quantum Horizon" expert survey aggregate | ~1-in-6 chance by 2035; ~30% by 2040; ~60% by 2050 | Middle to bear |
National Institute of Standards and Technology (NIST) migration guidance, via Cointelegraph | Recommends migration completed by 2035 | Middle to bear |
Adam Back, Blockstream CEO, via Kavout | "Decades away" | Bear (later) |
Read across these estimates, Sun's two-year window sits well outside the range most cryptographers and quantum-hardware researchers currently consider plausible. Even the most aggressive independent estimates — Project Eleven's report cited by Decrypt and Mosca's 2026 probability figure — describe a chance of an early breakthrough, not a two-year near-certainty. That doesn't mean the broader concern is baseless; it means the specific date is the most uncertain part of the conversation.
Bitcoin Quantum Risk: Key Numbers and Q-Day Estimates
Data point | Value | Source | As of |
Bitcoin held in addresses with exposed public keys | ~6.9 million BTC (roughly one-third of eventual 21M supply) — i.e., coins in addresses that have sent at least one transaction, not all BTC in circulation | Decrypt, citing Project Eleven | May 6, 2026 |
Logical qubits needed to break Bitcoin ECC | ~1,200–2,330 logical qubits (error-corrected units actually needed to run the attack) | 2026 | |
Best current quantum hardware, translated to attack-relevant capacity | ~1,000–1,200 physical qubits (raw hardware units) yielding at most ~100 logical qubits after error correction | 2026 |
Figures above are the most recent publicly available estimates at the time of writing and should be reconfirmed against primary sources before republication, as quantum hardware progress is moving quickly and estimates are regularly revised.
Can Quantum Computers Break Bitcoin Today?
Not in practice. Every source reviewed for this article — including estimates cited by Kavout, the Bitcoin
It helps to separate three different things that often get blended together in coverage of this topic:
- What's established as fact: no quantum computer built today comes close to the scale needed to break Bitcoin's cryptography. Every source reviewed for this article — including estimates cited by Kavout, the Bitcoin Foundation, and the arXiv technical paper — agrees on this point.
- What's a research estimate: how fast that gap closes, and even whether it's a serious concern at all, is genuinely disputed among experts — not just a timing question. The arXiv survey aggregate gives a probability distribution (roughly 1-in-6 by 2035, up to 60% by 2050); Adam Back, by contrast, argues the threat is overstated at any timeframe worth planning around today, which is a disagreement about severity, not just speed. Analysis from crypto-focused venture firm a16z frames a related, more actionable question: because migrating billions of dollars of coins to quantum-resistant addresses is a slow, coordination-heavy process, the case for starting preparations now rests on migration logistics, not on an imminent quantum computer.
- What's Justin Sun's individual prediction: his two-year window is one specific point estimate sitting at the aggressive edge of this range, made by someone with a commercial incentive to position TRON as ahead of the curve on this issue. It shouldn't be read as representative of where researchers or institutions currently stand.
What Should Bitcoin and Crypto Users Do About Quantum Risk?
For most retail users, quantum risk isn't a near-term reason to change trading behavior — the entire industry, from Google's own roadmap to NIST's guidance, is planning around a 2030s-or-later timeline. That said, a few habits reduce exposure regardless of when Q-Day arrives:
- Avoid re-using addresses. Public keys are only exposed once a wallet has sent a transaction; addresses that have only ever received funds are cryptographically better protected.
- Keep an eye on exchange and wallet migration announcements. Platforms that support post-quantum signature schemes early will typically publish migration guides well in advance.
- Treat single-source predictions with caution. As the comparison table above shows, published Q-Day estimates span from 2026 to 2060 — a wide enough range that no single prediction, including Sun's, should be treated as settled fact.
Bitcoin Q-Day and Quantum Computing FAQ
What is "Q-Day" in crypto?
Q-Day is the point at which a quantum computer becomes powerful enough to break the cryptographic signatures securing Bitcoin, Ethereum, and similar blockchains.
Do most experts agree with Justin Sun's two-year timeline?
No. Most published estimates from cryptographers, NIST, and hardware manufacturers place a credible quantum threat to Bitcoin in the 2030s at the earliest, with some estimates extending to 2050 or beyond.
How many Bitcoin are considered vulnerable to a quantum attack?
One widely cited estimate from Project Eleven puts the figure at roughly 6.9 million BTC — approximately a third of the eventual total supply — held in addresses whose public keys have already been exposed on-chain.
Is TRON building quantum-resistant technology?
Sun said at Bitcoin Asia 2026 that TRON plans to complete a post-quantum network upgrade by the end of 2026; implementation details have not yet been independently verified at the time of writing.
Should I move my crypto because of quantum computing risk?
Most current guidance, including NIST's migration framework, treats this as a multi-year planning issue rather than an urgent action item for individual holders. Avoiding address reuse is a simple, low-cost precaution regardless of timeline.
What is Shor's algorithm and why does it matter for Bitcoin?
It's a quantum algorithm that can theoretically reverse the elliptic-curve math linking a public key to a private key — the core assumption that keeps Bitcoin wallets secure today.
About WEEX
Founded in 2018, WEEX has developed into a global crypto exchange with over 10 million users across more than 170 countries. The platform emphasizes security, liquidity, and usability, providing over 1,600 spot trading pairs and offering up to 400x leverage in crypto futures trading. In addition to the traditional spot and derivatives markets, WEEX is expanding rapidly in the AI era delivering real time AI news, empowering users with AI trading tools, and exploring innovative trade to earn models that make intelligent trading more accessible to everyone. Its 1,000 BTC Protection Fund further strengthens asset safety and transparency, while features such as copy trading and advanced trading tools allow users to follow professional traders and experience a more efficient, intelligent trading journey.
Follow WEEX on social media
Instagram: @WEEX Exchange
Tiktok: @weex_global
Youtube: @WEEX_Official
Discord: WEEX Community
Telegram: WeexGlobal Group
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

US Open Partners with Kalshi for Last-Minute Deal, Officially Introducing Prediction Market

Sui to Host 'Basecamp 2026' in Singapore, Highlighting Agentic Economy
![[ETH Letter] Ethereum's Upcoming Upgrade 'Hegota' Scope Confirmed](/public-static/33_70806c0ee0.png?format=avif)
[ETH Letter] Ethereum's Upcoming Upgrade 'Hegota' Scope Confirmed

Robinhood Chain's DEX Volume Reaches Record Approximately 140 Billion Yen in One Day

Meme Coin BONER Raises $70 Million in Just 3 Days, Top Address Gains $1.73 Million

The Market Doesn't Move with Information Alone: Considering Web3 in the Era of Prediction Markets and AI Agents|HashHub Research

Dollar in September: The City Projects How High It Could Rise After Recent Official Intervention

Cook Bids Farewell as Apple Enters the Ternus Era

Cryptocurrency Treasury Firms Buy Bitcoin and Ethereum Again: What’s Behind It?

Renewed Clashes After a Month of Silence: Why the US-Iran Conflict Resumed and How the Market Reacted?

30-Year U.S. Treasury Yield Days Above 5% Reach Highest Level Since 2006

Is it a good time to take out a UVA mortgage? What experts think and what to understand before doing it

a16z Growth Fund Expands to $8.5 Billion with Additional $1.1 Billion AI Hardware Fund

a16z Reveals: Why Argentinians Buy Crypto as a Way to Buy Dollars? After the Crisis, Stablecoins Have Become a National Habit

Debate on Fed's 2% Inflation Target Influences Interest Rate Path

Bitwise Solana ETF Surpasses $1 Billion in Assets Under Management

Polymarket Discusses $1 Billion Funding, Valuation of 29 Trillion Won Mentioned

AI data centers are learning the power trick Bitcoin miners mastered first

Crypto market moves ‘as one block’ despite broader rally: Cryptex co-founder

Bitcoin needs ETF demand to hold as Fed rate hike risk grows: analysts

Solana Crypto Partnership Achieves Record 169.9 Million Transactions

Surge in IPOs in China: AI and Robotics Companies Lead Debuts in Shanghai and Hong Kong

HKDAP could take HKD beyond payments into on-chain finance, HashKey researcher says

NASA and SpaceX Delay Crew-13 Due to Leak in Dragon Spacecraft

Coinhouse Acquires Tilvest and Strengthens Its Position in Crypto Management

"Technology Takes a Backseat": How Stablecoins Transition from Savings to Everyday Payments

BTC Drops 62% Against Nasdaq, Resistance at 78500

Banks Improved Their Profitability, But Concerns Over Delinquency Persist: Key Insights from Recent Financial Statements

CME Targets ETFs: The First FCA-Regulated Multi-Asset Crypto Indices Are Born










