Author: CryptoSlate
Compiled by Deep潮 TechFlow
Shenchao Summary: Quantum computers cannot crack Bitcoin today, but the real challenge lies in the fact that it will take years for developers, miners, wallets, exchanges, custodians, and users to coordinate a defensive upgrade. Galaxy Digital’s $5 million funding initiative aims to accelerate this marathon-like migration before the threat becomes reality—but funding can only speed up technological development, not replace the most difficult part of Bitcoin’s decentralized governance: achieving consensus and synchronized action across the entire network.
Galaxy Digital pledged up to $5 million on July 21 to help Bitcoin prepare for the quantum era. The initiative will provide funding as developers reach key milestones, while also supporting research and establishing a Quantum Advisory Board.
Quantum computers cannot currently break Bitcoin’s signature security, but this initiative aims to begin migration efforts before such a threat becomes reality.
The program addresses multiple stages of the transition chain: reviewing post-quantum transaction proposals, integrating post-quantum signatures, conducting formal security audits, and developing software and institutional migration tools.
Funding can accelerate these workflows, but Bitcoin’s decentralized governance still requires coordination among developers, miners, node operators, wallets, exchanges, custodians, and users to upgrade. Galaxy says the design, testing, and deployment of this upgrade could take several years.
There are two time windows for this technical risk. A sufficiently powerful quantum computer could use Shor’s algorithm to recover private keys from exposed elliptic curve public keys and forge valid signatures. Keys already visible on-chain provide attackers with a long window of opportunity. Additionally, most Bitcoin spending exposes public keys while transactions are pending in the mempool, creating a shorter window for faster attacks.
Bitcoin encryption is not threatened by quantum computers, simply because it doesn't actually exist.
The BIP 360 draft states that pay-to-public-key, bare multisig, and Taproot outputs are exposed long-term. Address reuse, extended public keys, and wallet descriptors may also expose vulnerable material. Hash-protected outputs conceal public keys until spending or other disclosure occurs.
BIP 360 will add a new Pay-to-Merkle-Root output via a soft fork. This P2MR scheme弃用 Taproot 的密钥路径,限制长期暴露,并为未来更强的签名方案留出空间。
This proposal is still a draft and covers only the first exposure window. Protecting transactions after the key appears in the mempool may require post-quantum signatures.
This "quantum-safe" Bitcoin solution removes Taproot's key path—and intentionally increases transaction fees.
This is where Galaxy’s grant program can help turn research into reviewed code and migration tools, but funding cannot determine Bitcoin’s final design or schedule its adoption.
The second proposal, BIP 361, outlines the scale of the operation. This informative BIP draft relies on a post-quantum signature proposal that has not yet been specified, and sketches a two-phase transition occurring approximately five years after activation. Its timeline is merely a scenario, not an adopted roadmap.
After selecting a design, the network still requires proposal and signature review, auditing, wallet and node releases, institutional upgrades, and holder migrations. Users need time to transfer funds to protected outputs, while existing signatures remain safely usable. Each dependency makes last-minute responses more difficult.
Bitcoin's quantum migration plan forces the network to choose between freezing and stolen coins.
Broader cryptographic initiatives have been underway for many years. In August 2024, NIST finalized three post-quantum standards, including two digital signature standards, and urged early integration, as migration takes time. Executive Order 14412 directs the Office of Management and Budget to require designated federal systems to adopt post-quantum signatures by December 31, 2031.
These federal rules apply only to government systems and do not predict when quantum hardware will arrive. However, they explain why Galaxy must begin early: Bitcoin still requires a thoroughly vetted signature design, broad community consensus, and sufficient time for users to transfer their funds, so research and tools cannot wait until the threat is imminent.

