← Back to Blog
Web3 Security · 7 min read · September 28, 2026

Will Quantum Computers Break Crypto Wallets? What Changed in 2026

A MEV sandwich attack does not steal your keys or break a contract — it simply makes you trade at a worse price and pockets the difference. In 2026 sandwich bots extract tens of millions every month from DEX traders. Here is how front-running works, how to check whether you have already been hit, and the six defenses that remove the opportunity.

The Short Answer: Not Yet, but the Clock Has Started

No quantum computer in 2026 can break the cryptography that protects Bitcoin, Ethereum or your wallet. A machine capable of running Shor's algorithm at the scale required does not exist, and the honest expert consensus puts a cryptographically relevant quantum computer years away, not months. That is the good news. The bad news is that three things moved this year: the engineering estimates got dramatically smaller, the migration plans became concrete, and the data a future machine would need is already being collected.

Why Your Public Key Is the Weak Link

Bitcoin and Ethereum sign transactions with ECDSA over the secp256k1 elliptic curve. Shor's algorithm solves the underlying discrete-logarithm problem, which means a powerful enough quantum computer could derive a private key directly from a public key. Your address is not the same thing as your public key: addresses are hashed with SHA-256 and RIPEMD-160, and hashing survives Shor's attack. The exposure starts when a public key becomes visible on-chain.

That happens more often than most holders realise. A legacy P2PKH address reveals its public key the first time it spends, and every later transaction from that address keeps it exposed. Early P2PK outputs revealed the key immediately. Ethereum accounts expose their public key routinely through ordinary activity. An address that has never sent a transaction is meaningfully safer than one that has.

What Actually Changed in 2026

The headline development was a Google Quantum AI paper published in March 2026 whose authors included Craig Gidney, Justin Drake and Dan Boneh. It showed that breaking 256-bit elliptic-curve cryptography could theoretically be done with roughly 1,200 logical qubits, around 90 million Toffoli gates and under 20 minutes of runtime, on an estimated 500,000 physical qubits with realistic error correction. That is about twenty times more efficient than previous estimates.

Follow-up work pushed the numbers further, with some neutral-atom architectures claiming theoretical thresholds in the low tens of thousands of qubits. A public “quantum doomsday clock” tracking the risk put roughly a 5–10% probability on a cryptographically relevant machine appearing by March 2028. These are estimates, not predictions — but the direction of travel is unmistakable.

Harvest Now, Decrypt Later Is Already Running

The most important attack model today needs no quantum computer at all. Adversaries are assumed to be archiving public blockchain data — every transaction, every revealed public key, every signature — and waiting. When a suitable machine arrives, they can retroactively derive keys from data collected years earlier. You cannot un-expose a public key. That is why the practical deadline is not “when quantum computers arrive” but “how long your keys have been sitting in the open”.

How Much Crypto Is Actually Exposed

Estimates vary, and the honest range is wide. A Citi analysis in May 2026 put roughly 6.9 million BTC in legacy addresses with exposed or potentially exposed keys, and community estimates have suggested that some 20–30% of the Bitcoin supply sits in formats that would need migration. Across all chains the value at risk has been framed in the trillion-dollar range. Not all of it is reachable — coins whose owners lost their keys are no payday for anyone — but the sheer volume of exposed keys is why serious projects treat this as an engineering deadline rather than a research curiosity.

What the Chains and Standards Bodies Are Doing

NIST finalised three post-quantum standards in August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), giving the industry a shared set of vetted algorithms. Under NIST IR 8547, quantum-vulnerable algorithms are slated for deprecation by 2030 and removal from standards by 2035, with high-risk systems expected to move much sooner.

On-chain progress is uneven. The Ethereum Foundation published a formal post-quantum roadmap in February 2026, targeting meaningful progress around December 2029, and Ethereum's account abstraction makes experimentation easier. Bitcoin merged its first proposal for a quantum-resistant address format, BIP 360, in early 2026 — but consensus-driven change is slow. A handful of chains were built post-quantum from genesis: QRL uses lattice-based signatures natively, CKB runs NIST-standardised SPHINCS+ lock scripts while staying crypto-agile, and Algorand has demonstrated hybrid quantum-safe transaction authorisation on a live network.

What Wallet Holders Should Do Now

None of this is a reason to sell or panic. It is a reason to plan, and the steps that help are cheap:

The Real Lesson: Crypto Agility

The chains that handle this well will not be the ones with the cleverest algorithm today, but the ones that can swap cryptography without a crisis. The same principle applies to your own stack: rotating keys, retiring weak ciphers and keeping an inventory of what depends on which primitive is ordinary good hygiene. Quantum computing simply raises the stakes on work you should already be doing.

Frequently Asked Questions

Will quantum computers break Bitcoin in 2026?

No. No quantum computer in 2026 can run Shor's algorithm at the scale needed to derive a private key from a public key. The risk is real but forward-looking: the resource estimates improved sharply this year, and exposed public keys are already being harvested for a future break.

What is harvest now, decrypt later?

It is the tactic of recording data today so it can be broken once a quantum computer exists. On a blockchain the data is already public: every revealed public key and every signature is permanently archived and cannot be revoked, so a future break applies retroactively.

Which crypto is most at risk from quantum computers?

Any format that exposes a public key on-chain. For Bitcoin that means legacy P2PK outputs and reused P2PKH addresses, and a Citi analysis in May 2026 estimated around 6.9 million BTC sit in legacy addresses. Ethereum accounts expose their public key routinely through normal activity.

Should I move my crypto because of quantum computing?

Not in a panic, and not because of a headline. There is no cryptographically relevant quantum computer in 2026. The sensible move is hygiene: stop reusing addresses, keep keys unexposed, and adopt hybrid ECDSA plus post-quantum support as your existing wallets ship it.

Are quantum-resistant blockchains worth using today?

For most holders the practical answer is to stay on major chains and adopt post-quantum support as it arrives. Chains built post-quantum from genesis, such as QRL, or crypto-agile designs like CKB, are worth watching — but do not trade away liquidity and battle-tested security for a label.

See what your infrastructure is exposing

RootCrak's autonomous scanner checks your domains, servers, APIs and Web3 surfaces from the outside — surfacing exposed services, leaked credentials and misconfigurations before someone turns them into a loss.

Get a Free Security Scan