Coinbase Quantum Committee Chair Dan Boneh: Quantum Threats Focus on Wallet Signature Systems, Not Bitcoin Itself
The Coinbase Quantum Computing and Blockchain Independent Advisory Committee released its first position paper, systematically assessing the long-term impact of quantum computing on the cryptocurrency industry. The conclusion is that current quantum computers are insufficient to crack mainstream blockchains, but quantum machines capable of undermining existing public key cryptography are "likely" to emerge in the future. The industry's mainstream expectation is over ten years, but earlier occurrences cannot be ruled out. The report emphasizes that "user assets are overall still safe today"; Bitcoin's proof-of-work and underlying hash structure are relatively robust against known quantum attack models, with the real vulnerability concentrated in the digital signature algorithms at the wallet level, especially for addresses where public keys have been exposed on-chain. Research estimates that about 6.9 million BTC are at a higher risk of exposure, aligning with other studies suggesting that "about one-third of Bitcoin is potentially exposed to quantum threats."
The committee points out that Ethereum and other proof-of-stake networks face additional challenges in validator signatures and long-term online key management: on one hand, validators need to frequently sign on-chain, increasing the exposure of public keys and potential private key inference; on the other hand, redesigning staking and exit mechanisms to accommodate quantum-resistant algorithms will be much more complex than a one-time user migration, but these networks are already researching upgrade paths. The report also outlines advancements in post-quantum cryptography, noting that various quantum-resistant solutions such as lattice-based cryptography, hash signatures, and coding theory have matured over the past 20 years, with the first batch of standardization completed under the U.S. NIST framework (e.g., Kyber/ML-KEM, Dilithium/ML-DSA, and SPHINCS+), marking a turning point from research to industrial deployment. However, the committee warns that large-scale on-chain deployment still faces engineering and governance challenges such as system migration, on-chain coordination, and handling "sleeping wallets," urging major public chains to formulate upgrade routes as soon as possible, treating quantum risks as "infrastructure updates that need to be planned a decade in advance," rather than responding passively when quantum hardware approaches.
Source: Public Information
ABAB AI Insight
The real focus of Coinbase's report is not on whether quantum computing will "kill Bitcoin" today, but on redefining which layer is the main battlefield for quantum risks. Many past discussions have suggested that "quantum computing will end Bitcoin," but the committee's conclusion aligns more closely with the consensus of research over the past few years: blockchain consensus and hashing itself are not the weakest links; the public key-private key signature system is the key attack surface—especially for those public keys that have been publicly exposed on-chain and addresses that have remained inactive for a long time. Once quantum computing achieves the ability to reverse-engineer private keys from public keys within the transaction confirmation window, attackers could "pre-sign" before transactions are packaged or systematically sweep exposed public keys from old addresses. This represents a "temporal dimension" security challenge: shifting from static unbreakability to needing to race against attackers within the confirmation window.
The report marks about 6.9 million BTC as being in a high exposure range, indicating a highly uneven risk distribution: not all Bitcoin is simultaneously exposed, but rather concentrated in early P2PK addresses, reused addresses, and UTXOs that have seen transactions. This means quantum risk is more like a "targeted strike against history and habits," rather than a one-time destruction of the entire system—truly dangerous are those wallets that have lost their private keys or whose holders have been offline for a long time; they will struggle to migrate once quantum capabilities emerge, becoming future "first come, first served" attack targets. The committee highlights these assets separately, essentially alerting the community: how to handle "permanently dormant or unmovable old coins" must be addressed in advance through soft forks, script upgrades, or social consensus discussions; otherwise, once large-scale theft occurs, it will create irreparable wounds on the ledger and narrative levels.
The committee's judgment on the "additional challenges" for Ethereum and PoS chains hits another structural issue: in proof-of-stake systems, keys are not just for spending, but also for consensus—validators sign frequently and are online for long periods; once signing keys are cracked by quantum computing, attackers can not only steal assets but also forge votes, disrupt consensus, and even initiate long-range reorganization attacks under certain conditions. This makes the quantum migration for PoS chains not just a wallet layer upgrade, but involves the rotation of the entire validator set, rewriting staking protocols, and restructuring penalty rules, making coordination much more complex than "users simply switching to a new address." The committee emphasizes that "there is already a clear migration roadmap," which more acknowledges that technical solutions exist (such as hybrid signatures, Merkle multi-key structures, and time-lock designs), but in governance and execution, how to synchronize the decentralized validators and economic entities to migrate at different times and across different chains remains a collective action problem that requires years of negotiation.
The report's emphasis on post-quantum cryptography standards reveals a commonly overlooked yet crucial time mismatch: NIST has provided an "algorithm menu," but the real difficulty lies in securely and gradually integrating these algorithms into a global ledger system worth trillions of dollars and operating 24/7. This involves key length expansion, signature size and bandwidth costs, node performance differences, old client compatibility, and interoperability challenges arising from different projects adopting different quantum-resistant solutions in a multi-chain environment. Coinbase's committee calls for "starting to formulate upgrade plans now," essentially reminding the industry that this migration is more akin to IPv4 to IPv6—it will not be completed overnight but will require a long "dual-stack period": traditional elliptic curves and new generation quantum-resistant algorithms will be used in parallel, constructing a "switchable" security escape route for the system through hybrid modes and multi-signatures.
From a longer structural perspective, this report pulls quantum computing back from the "apocalyptic narrative" to the real issue of "infrastructure update cycles": quantum will not automatically destroy blockchains, but will force the entire crypto-financial system to undergo a profound reconstruction of its security architecture. The true determinants of the cost of this reconstruction are two variables—the determination to act early and the ability to coordinate between the protocol layer, wallet layer, and user layer. If mainstream public chains and large custodial institutions can complete quantum resistance within the next decade, the quantum threat will manifest more as a "technical upgrade cost"; if the industry continues to treat it as a distant technological news item, waiting for Google or other labs to provide feasible attack demonstrations before taking action, then the cost will not only be development expenses but also an overall depreciation of core narratives such as "immutability" and "secure value storage." Coinbase's Quantum Committee's choice to speak out at this time is essentially ringing the "start the timer" bell for this long and inevitable migration.