The Fundstrat strategist told CNBC a quantum computer could crack bitcoin’s cryptography within two years. The claim is early — but the clock behind it is real.
Tom Lee spends most of his television time telling investors why bitcoin goes up. On August 5 he went on CNBC to explain how it could go to zero. Quantum computers, the Fundstrat co-founder and head of research said, could break bitcoin’s cryptography as soon as 2028 — and the network, he argued, has not agreed on how to stop them.
“Google thinks all encryption could break by 2028,” Lee said, adding that the risk was specific to bitcoin’s signature scheme and that the community “has not come up with a consensus on how to prevent it.” Coming from a reliable bull, the warning traveled fast. It also compressed a real, slow-moving engineering problem into a scary round number.
Bitcoin leans on two kinds of math. Its mining and its addresses use SHA-256, a hashing algorithm that quantum computers weaken only modestly. The vulnerable part is the other kind: the elliptic-curve digital signature (ECDSA) that proves you own the coins in an address. A large, error-corrected quantum computer running Shor’s algorithm could, in principle, derive a private key from a public key — and spend those coins.
The catch is the phrase “large, error-corrected.” No such machine exists. IBM’s chief executive, Arvind Krishna, has told CNBC that quantum will start affecting revenue around 2028–2029, and the company has demonstrated what it calls “trusted quantum advantage” on a roughly 70-qubit system — impressive, and still orders of magnitude short of the millions of physical qubits most estimates require to break ECDSA.
In March, Google Quantum AI researchers cut the estimated resources needed to break elliptic-curve cryptography by roughly 20-fold, to under 500,000 qubits. That did not build the machine — but it moved the finish line closer, which is why 2026 is the year the quantum debate stopped being theoretical.
Every bank, government, and messaging app relies on the same public-key cryptography, so quantum threatens far more than one asset. Bitcoin is simply the most legible target: its ledger is public, its rewards are enormous, and its exposure is measurable. By common estimates, more than a third of all bitcoin sits in addresses whose public keys are already visible on-chain — including, famously, the roughly one million coins attributed to Satoshi Nakamoto, which will never move to safety because no one will move them.
That is the asymmetry Lee is pointing at. A bank can quietly migrate its systems to post-quantum algorithms on a schedule. Bitcoin has to do it in the open, by consensus, across millions of self-interested holders — and it cannot force anyone to upgrade.
Lee’s claim that there is “no consensus” is true and incomplete. There is no activated solution, but there is active work. Developers have circulated proposals to add post-quantum signature schemes to bitcoin and, in some drafts, to eventually freeze or force-migrate coins in exposed addresses — each a contentious soft fork that would take years to debate and deploy. Galaxy Digital has funded a quantum-readiness effort; custodians such as BitGo have begun scoring wallets by their quantum exposure. The tools are early. They are not absent.
His side note — that a break would not hurt Ethereum or Solana — is the weakest part of the pitch. Those chains use the same elliptic-curve family bitcoin does; a working cryptographic attack would threaten most of the industry at once, not spare the competitors. The quantum threat, if it arrives, is an internet problem wearing a bitcoin costume.
The signal is not the price reaction, which faded within the day. It is the pace of two clocks: the qubit count on real hardware, and the progress of post-quantum proposals through bitcoin’s glacial governance. The White House has said it wants a working quantum computer by 2028 and federal systems on post-quantum cryptography by 2030. Bitcoin has roughly the same window and a harder coordination problem. It also has the strongest incentive ever devised for millions of people to move their coins to safety: keeping them.
Why it matters: quantum won’t break bitcoin in 2026, but the timeline for the fix is now shorter than the timeline for the threat — and closing that gap is a governance test, not just a math one.
Editor’s note: qubit-count and timeline estimates vary widely between researchers and are moving targets; Tom Lee’s remarks are his own forecast, not a technical claim of a working attack. Nothing here is financial advice.
Free. Five minutes. No hype.
Subscribe free