The Quantum FUD Narrative Persists

Since Bitcoin's inception, waves of fear, uncertainty, and doubt have repeatedly targeted the asset's survival. The cryptocurrency has nonetheless grown into a multi-trillion-dollar component of the global monetary system. In recent months, a fresh iteration of that skepticism has resurfaced: the claim that a cryptographically relevant quantum computer (CRQC) could allow an attacker to derive private keys from public ones and forge signatures to redirect other people's coins.

Brandon Black, writing for Bitcoin Magazine, pushes back firmly. His central thesis is straightforward: there is no evidence that a CRQC will materialize within the next ten years, and it remains genuinely open whether such a machine can ever be constructed. In his view, the quantum threat is, for all practical purposes, another chapter in the FUD playbook.

The Gap Between Hype and Hardware Reality

Black points out that, to date, no quantum computer has accomplished a calculation beyond the reach of a precocious six-year-old. He acknowledges that these machines represent extraordinary engineering feats, drawing on technologies such as optical tweezers, laser cooling, superconducting flux qubits, electromagnetic traps, and dilution refrigerators. Individual qubits are forced into specific subatomic states, entangled into superpositions, manipulated to perform computations, and then read out and interpreted. The remarkable fact is that these devices exist and can produce meaningful results across a small number of inputs.

The sobering counterpoint, however, is that executing a computation a young child could manage demands enough electrical power to air-condition a Texas high school, coupled with many hours of setup and additional hours of post-processing.

Why Capital Inflows Do Not Guarantee Breakthroughs

A common rebuttal to skepticism is the sheer volume of money pouring into quantum computing. Black questions whether financial investment in a field actually tracks real-world technological progress. He argues that, until the correct underlying technology is identified and product-market fit is confirmed, heavy capital inflows can even correlate negatively with the probability of a usable solution emerging.

He illustrates this with a comparison between NASA's Space Shuttle program and SpaceX's Falcon 9. SpaceX took largely known science and turned it into a practical system addressing a clear market need for reliable, low-cost access to orbit, reaching its first crewed mission at a program cost under five billion dollars. By contrast, the Space Shuttle required roughly fifty billion dollars before its first crewed flight. Falcon 9 not only cost an order of magnitude less to develop but has maintained a flawless crew safety record. The lesson, Black argues, is that no quantity of money can make an unready technology practicable. In the quantum context, enormous funding can produce impressive but expensive technology demonstrations; it tells us nothing about whether additional spending will yield stable, low-error qubits comparable to the reliability of Falcon 9.

Just as no amount of continued investment in the Shuttle could have produced Falcon 9's cost and reliability, it is entirely plausible that no amount of continued development, at any price, will render any current quantum computing platform reliable enough to break even a single key pair.

Advancements That Are Mostly Theater

Black addresses the recent wave of published quantum computing advances with two caveats. First, many of these results are advances in pure mathematics rather than engineering. He cites the recent Google paper whose authors chose to redact the theoretical quantum circuit from publication, citing the risk that it could be used to break important cryptographic systems. On its face this looks like a major step toward CRQCs, but Black contends it changes nothing in practice. Until the quantum hardware achieves its own "Falcon 9 moment," no device comes close to the stability and scale required to execute the redacted circuit. Hiding a circuit designed for a machine that may never exist is, in his words, pure theater.

Second, on the hardware side, a given year may see numerous new results published, but many relate to different candidate technologies or represent a fresh start after a previous approach hit a dead end. These advances do not trace a linear trajectory toward success. They reflect a breadth-first search through an effectively infinite possibility space, with researchers hoping to find a path they can follow for at least a modest distance before colliding with yet another dead end.

Looking ahead, the quantum computing landscape remains hazy at best. Black notes that neutral atom devices, in particular, look promising to his eye, but it is far too early to determine whether any currently known branch opens a viable route to a CRQC or whether further restarts lie ahead. He suggests that the conversation should be revisited only when multiple iterations of the same candidate technology produce progressively more capable devices computing results beyond a precocious child's reach.

Two Explanations and the Case for Continued Bitcoin Development

Black offers two possible explanations for decades of failed progress toward a CRQC. One is that it is simply a hard problem and human ingenuity will eventually prevail, as it has with the Internet, the smartphone, social media, and Bitcoin itself. The other is that building a CRQC may be impossible or permanently beyond our reach. He elaborates on the physics: for a quantum machine to be cryptographically relevant, its superposition would need to represent a field of possibilities equal in complexity to the cryptographic problem being solved. Breaking the 128-bit security level of the elliptic curve discrete logarithm on Bitcoin's secp256k1 curve would require the superposition to span all possible values of a 128-bit number. In classical computing, storing all such values would demand more memory than humanity has ever produced, by many orders of magnitude. If even the slightest granularity exists in the quantum superposition, or if the energy required to maintain it scales with the complexity of the field, a quantum computer can never become cryptographically relevant. Current quantum physics does not rule out either scenario.

None of this, Black stresses, excuses complacency on the Bitcoin development front. A quantum attack is not imminent, but other vulnerabilities could emerge. Certain elliptic curves are already known to carry weaknesses, and secp256k1 could be the next to fall. Bitcoin has endured because every attack has ultimately strengthened the system, and that pattern will likely continue as the quantum FUD cycle plays out. Ongoing work on post-quantum signature schemes such as P2MR, P2TRv2, SHRINCS, SPHINCS, IBC, and ML-DSA will improve Bitcoin's resilience against future threats, regardless of whether a CRQC is ever built.

The column appears in the latest print edition of Bitcoin Magazine, subtitled "The Quantum Issue," and is shared online as a preview of the broader themes explored in that edition.