Stefano Gogioso and Daniela Herrmann warned during a BeInCrypto Experts Council panel that the cryptocurrency industry is treating quantum computing's threat to Bitcoin as a trillion-dollar risk too casually. Gogioso, a quantum computing lecturer at the University of Oxford and co-founder of Spooqy, argued that even a 2% probability of a quantum break by 2030 justifies immediate preparation given the potential total loss. Herrmann, CEO and co-founder of Dynex, noted that timeline estimates for practical quantum computing have compressed dramatically, from 30 years in 2024 to potentially 1-2 years in recent assessments. The experts framed the issue as a risk management problem rather than a prediction exercise, emphasizing that migration to quantum-resistant cryptography requires years of preparation. This discussion occurs as Google research published in March 2026 estimated that breaking Bitcoin's elliptic-curve cryptography could require fewer than 500,000 physical qubits, roughly 20 times lower than previous estimates.
Gogioso argued during the panel that fixating on a specific date for quantum computers breaking Bitcoin cryptography misses the fundamental risk calculation. "The question isn't 'will it be 2030?' It's what's the probability of a tail event by 2030, and how much would we lose. Even at 2%, the impact on Bitcoin and crypto, if we're not prepared, is essentially most of crypto going to zero. That's trillions of dollars. And even 1% of that is more than enough to pay every cryptographer in the world to spend six months fixing it," Gogioso said. The experts compared the situation to insurance logic, where protection is purchased not because loss is expected but because the potential damage would be catastrophic while the cost of preparation remains small.
Herrmann described observing timeline estimates compress in real time. "In 2024, I was on stage and we said quantum computing will be here in 30 years. Then in 2025 it dropped to 15 to 20 years. Then in 2026, three to five to ten. And suddenly, in October, we hear two years, one year. The market moves faster, innovation moves faster, than it was communicated," Herrmann said. Gogioso explained that progress accelerates because initial breakthroughs are harder than subsequent scaling. "The difference between no logical qubits and one logical qubit is an enormous gap. The difference between one and a million is a smaller gap. Once you get it to work, scaling up is actually quite easy," Gogioso said. In May 2025, Google researcher Craig Gidney showed that breaking RSA-2048 might need fewer than 1 million qubits, down from his own 2019 estimate of about 20 million. In March 2026, Google Quantum AI worked with the Ethereum Foundation and Stanford to estimate that breaking Bitcoin's elliptic-curve cryptography could take fewer than 500,000 physical qubits, studying secp256k1, the exact curve behind Bitcoin and Ethereum signatures. Google has set an internal 2029 target to move its own products onto quantum-resistant encryption.
The experts described the attack mechanism as quieter than popular dramatic scenarios suggest. When Bitcoin is spent, the public key is briefly exposed, and a capable quantum computer could then derive the private key. Google's figures suggest the core computation could run in about nine minutes, while Bitcoin's average block time is roughly 10 minutes. Gogioso emphasized that the primary vulnerability is psychological rather than purely technical. "It's not a technical problem. It's a PR problem. The moment one Satoshi-era coin moves off its wallet with 'you've been quantum punked' in the message, that's it. It doesn't matter that 75% of coins are protected, they'll be worth nothing. Everybody panics and exits," Gogioso said. Herrmann added, "The moment one coin moves, it's the end of the story. Imagine you're an institutional asset manager. You wake up and your portfolio isn't secure anymore. You have an obligation to get rid of it, if you still can. And if you can't, you're done." Google published the March 2026 resource estimates but hid the circuit designs behind a zero-knowledge proof.
Gogioso pointed to Bitcoin's lack of formal governance as the primary obstacle to preparation. "Bitcoin has a completely different governance structure, in that it doesn't have one. Some of those independent voices fall into quantum denialism. They don't believe it's a threat. There's a conservative tendency. They don't want to make changes they don't have to. But this is a change you have to make," Gogioso said. Ethereum offers a contrast, with Vitalik Buterin urging migration to quantum-resistant cryptography within about four years and warning that elliptic-curve cryptography could be at risk around 2028. The Ethereum Foundation published a formal roadmap in early 2026 following creation of a dedicated post-quantum research group. The US standards body NIST plans to deprecate the current elliptic-curve signature standard by 2030 and disallow it by 2035. Bitcoin has no equivalent body to coordinate such a change.
Herrmann stated that technical solutions for transitioning Bitcoin to quantum-secure cryptography already exist in outline. "There are already concrete ideas for transitioning from Bitcoin to a quantum-secure Bitcoin. Ways to move from the old coins to the new ones, with an offset between them. It's never a linear consequence," Herrmann said. Both experts expressed optimism about the technology while noting that most large organizations have not yet incorporated the quantum threat into strategic planning. The panel emphasized that the tools for migration are available, but institutional response remains absent while the timeline for preparation remains uncertain.
What did quantum computing experts warn about Bitcoin during the BeInCrypto panel?
Stefano Gogioso and Daniela Herrmann warned that the cryptocurrency industry is treating quantum computing's threat to Bitcoin as a trillion-dollar risk too casually. Gogioso argued that even a 2% probability of a quantum break by 2030 justifies immediate preparation because the potential impact could send most crypto to zero. The experts framed this as a risk management problem requiring action before any quantum computer actually breaks Bitcoin's cryptography.
How many qubits does Google research estimate are needed to break Bitcoin?
In March 2026, Google Quantum AI worked with the Ethereum Foundation and Stanford to estimate that breaking Bitcoin's elliptic-curve cryptography could take fewer than 500,000 physical qubits. This figure is roughly 20 times lower than previous estimates. The research studied secp256k1, the exact curve behind Bitcoin and Ethereum signatures, and Google's figures suggest the core computation could run in about nine minutes compared to Bitcoin's roughly 10-minute average block time.
Why has Bitcoin not migrated to quantum-resistant cryptography according to the experts?
Gogioso pointed to Bitcoin's lack of formal governance structure as the primary obstacle. "Bitcoin has a completely different governance structure, in that it doesn't have one. Some of those independent voices fall into quantum denialism. They don't believe it's a threat. There's a conservative tendency. They don't want to make changes they don't have to. But this is a change you have to make," Gogioso said. This contrasts with Ethereum, which published a formal roadmap in early 2026 following creation of a dedicated post-quantum research group.
Related News