The US government has put up to $215 million to build a machine that could mark a turning point for quantum computing — with long-term consequences for Bitcoin.
The Department of Energy on Thursday launched the Quantum Genesis Q Competition. It wants private companies to demonstrate “scientifically relevant” fault-tolerant quantum computers with at least 100 logical qubits and hundreds of millions of reliable operations.
The wider program targets deployment by 2028.
Today’s quantum computers are still far from perfection. Errors quickly ruin long calculations. Fault tolerance uses error correction to keep those calculations running reliably, making the technology far more useful for serious science.
For Bitcoin, this could create a critical risk.
The Gap to Breaking Bitcoin Is Still Large
Bitcoin uses elliptic-curve cryptography to prove who can spend coins. A powerful enough quantum computer running Shor’s algorithm could work backwards from a public key and recover the private key.
Google researchers said this year that breaking the 256-bit elliptic-curve system used by Bitcoin could require roughly 1,200 to 1,450 logical qubits, depending on the design.
DOE is targeting a minimum of 100. Reaching that goal would still show that large, error-corrected quantum computations can work at a meaningful scale.
Bitcoin’s Hardest Problem May Be the Upgrade
The risk grows as those machines scale. Estimates of Bitcoin’s exposure vary.
Glassnode calculated in May that about 6.04 million BTC, or 30.2% of issued supply, already sat in outputs where the public key was visible on-chain. Those coins would offer the clearest targets once quantum key-breaking becomes practical.
Bitcoin developers are already discussing defenses. Draft proposals BIP 360 and BIP 361 outline paths to reduce public-key exposure and eventually migrate away from today’s vulnerable signature schemes.
Such a migration would involve wallets, exchanges, custodians, and users. It could take years.
The DOE competition brings fault-tolerant quantum computing closer to a real engineering target. Bitcoin still has time based on current hardware and research estimates.
The deadline remains unknown, which is why the migration debate is becoming harder to ignore.









