A new grant program funds post-quantum cryptography for Bitcoin — the slow, unglamorous work of an upgrade that will take years to coordinate.
Bitcoin's cryptography is not broken, and the machine that could break it does not exist yet. That is exactly why Galaxy Digital chose this week to start paying for the fix. The firm launched a Bitcoin Quantum Readiness Initiative, a $5 million grant program funding the integration of post-quantum cryptography into Bitcoin — work aimed at a threat that is years, probably more than a decade, away.
The concern is specific. Bitcoin secures coins with elliptic-curve cryptography: your public key is safe today because deriving the private key from it is computationally hopeless. A sufficiently powerful quantum computer would change that math, turning an exposed public key into a path to the funds behind it.
Not every coin is equally exposed. Addresses that have never been spent from keep their public key hidden until the moment of spending. But an estimated several million BTC sit in addresses whose public keys are already visible on-chain — reused addresses, older pay-to-public-key outputs, and coins that reveal a key at creation. Those are the balances a future quantum attacker would target first.
Galaxy's grants are meant to fund the unglamorous middle of the problem: research and reference implementations for quantum-resistant signature schemes that Bitcoin could eventually adopt. Money for research is the easy part.
The math is solvable. The hard problem is social: convincing millions of holders to move their coins before they have to.
Bitcoin has no CEO to order an upgrade. A migration to quantum-safe addresses would require a protocol change, wallet software support, and — the real bottleneck — every holder actively moving funds to new address types. Lost keys, dormant wallets, and inattentive users do not migrate on schedule. A meaningful share of the supply, including long-lost coins, may never move at all.
That is why "calm and optional" has become the responsible framing among engineers: start the research now, so the tools are ready and tested long before any quantum threat is credible, rather than scrambling under deadline. Galaxy is buying time, not reacting to an emergency.
Quantum risk is the long horizon. The near-term governance battle is a different one. Bitcoin faces a contentious proposal, BIP-110, that would restrict embedding non-payment data in transactions, with miner signaling scheduled to begin in August. That debate — over what the blockchain is for — has already split developers and miners, and it will test the network's ability to coordinate on anything before quantum ever arrives.
The skeptic's case deserves airing: no cryptographically relevant quantum computer exists, timelines are guesswork, and some argue quantum-proofing is a solution shopping for a problem. Fair. But cryptographic migrations take years, and the cost of starting early is a few million dollars in grants. The cost of starting late is measured in coins.
Galaxy's $5 million will not quantum-proof Bitcoin. It funds the research so the option exists when it is needed. The technical fix is tractable; the coordination is the mountain. Watch the August BIP-110 signaling for a preview of how well Bitcoin can agree on hard changes.
Editor's note: no cryptographically relevant quantum computer is known to exist; timelines for the threat are speculative. Estimates of exposed-key supply vary by methodology. Nothing here is financial advice.
Free. Five minutes. No hype.
Subscribe free