CatBitcoin
A brass padlock on a paper notebook page, lit from one side, in a quiet room interior

Quantum

Shor versus the puzzle box

Updated 6 October 2026

That is the box, and the lock on it. It is not a uniform threat, and it never was.

Two algorithms, two jobs

Two abstract circuit boards arranged like puzzle pieces on a dark desk, soft daylight from a window

What Grover actually touches

Mining is the obvious target. A 2^256 preimage search halving to 2^128 is meaningless to an attacker but a real gift to a quantum miner running Grover on a quantum oracle. The runway ends only when enough quantum work hashes faster than silicon, and a quadratic speed-up is a useful but not decisive edge. Network difficulty absorbs it the way it absorbed every other jump in hash rate.

Hashing inside Bitcoin also secures the chain. A block header is double-SHA-256, so the same quadratic rule applies. To rewrite history, an attacker needs a second preimage for a given hash, which is again a 2^128 job, not a 2^256 one. Still colossal, still impractical at any announced hardware roadmap.

What Shor actually opens

Shor opens the box when the lock is a secp256k1 signature. Taproot, as the arrival rule shows, spends from a tweaked Schnorr key. Native SegWit spends from a hashed ECDSA key. Every spend path exposes a public key on chain, which is the only material Shor needs. Any box whose public key has already been broadcast is, in principle, a target.

Hash-locked addresses are different. Pay-to-Public-Key-Hash boxes hide the public key behind HASH160 until spend time. The same hiding applies to P2WPKH. As long as the box is unspent, the attacker has only a hash to invert, which is Grover territory, and quadratic is not enough.

Reading the IonQ estimate again

IonQ's 2025 paper placed a 26-day window on breaking a single secp256k1 key on a fault-tolerant machine, at resource counts that are aspirational, not delivered. The interesting number was not 26 days, it was the qubit bill. Hitting a real key on real coins would need a network-scale machine, with error correction overhead that pushes the wall clock years, not weeks, away from any individual box.

Estimates compress. A 2025 paper with a 20 million physical qubit figure for 24 hours becomes, by 2027, a smaller machine over a longer window. The trajectory is what matters, and the trajectory says: a Shor-capable attacker first sees the boxes whose public keys are already on chain.

Where the box is still closed

Address reuse is the single biggest gift to a future Shor attacker. Every reused box has its public key on chain from the first spend. Boxes that are still P2PKH or P2WPKH with the public key hidden are safer than the rest, until they are spent. The mitigation is mechanical, not cryptographic, and the BIP-360 family proposes a new output type whose witness is hashed and whose signature scheme is post-quantum.

Lightning is a separate ledger. PQLN protects channel state but cannot close a static funding box whose public key is already broadcast. The channel can be made quantum-safe in transit and still vulnerable at rest, which is why QSB-style overlays draw a careful line between layers.

The right way to think about it

Grover is a sledgehammer. Shor is a lockpick. The sledgehammer changes the cost of guessing hashes, and the cost stays above any announced budget. The lockpick changes the cost of deriving a private key from a public key, and that cost falls to zero for any box whose public key is on chain.

The defensive question is not which algorithm wins. It is which boxes have their public keys on chain today, which boxes will by the time a Shor machine exists, and how many of those boxes a fork or a freeze can keep closed. Most of the rest of Bitcoin's post-quantum work flows from that one distinction.

Quick answers

Does Grover break Bitcoin?
Not in any useful sense. A quadratic speed-up halves the effective security of SHA-256, which leaves 128 bits of work, still beyond any credible attacker.
Does Shor break Bitcoin?
Shor breaks secp256k1 in polynomial time, so any box whose public key is on chain is, in principle, openable. Closed boxes are not, because the public key is still hidden.
Which boxes are safe longest?
P2PKH and P2WPKH boxes that have never been spent, and any post-quantum output type that hashes the witness until spend time.
Is mining the real risk?
Grover helps a quantum miner, but difficulty adjusts. The existential risk is Shor on spent outputs, not Grover on the hash.