R11Signals From Elsewhere
The quantum milestone that would actually matter
Quantum news usually arrives as a machine count and leaves as a Bitcoin obituary. The missing middle is enormous. A better experimental computer is not automatically capable of breaking a deployed signature, and a standardized post-quantum signature is not automatically integrated into a decentralized monetary network.
The short answer
The meaningful signal is a chain of milestones: error-corrected logical capability, a demonstrated resource path to attack relevant elliptic-curve signatures, credible timing, standardized alternatives, protocol support, usable wallets and migration of exposed keys. Risk rises along the chain; it does not flip on with one headline.
Original GapLimit object
From laboratory progress to spend risk
Each rung is necessary context. None alone proves that Bitcoin keys can be attacked today.- 01Physical systemMore components and lower error
- 02Logical machineSustained corrected operations
- 03Attack resourcesRelevant algorithm, depth and runtime
- 04Protocol pathAccepted signature and address rules
- 05User migrationWallets, hardware and dormant funds move
Physical qubits are not the finish line
Noise forces quantum systems to spend many physical components protecting fewer logical operations. A cryptographic threat assessment therefore needs error rates, logical depth, connectivity and runtime, not a single vendor's qubit count. Progress can be real without yet being relevant to Bitcoin keys.
Standards exist; migration does not
NIST finalized ML-DSA and SLH-DSA as post-quantum digital-signature standards in 2024. That is a major defensive milestone. Bitcoin still needs its own engineering and governance path: transaction rules, address formats, software, hardware support, fee consequences and a way to move old holdings.
Exposure is uneven
Bitcoin addresses and scripts expose different information at different moments. Reused or already-spent public keys may present a different future migration urgency from outputs whose public key has not appeared on-chain. Exact attack practicality remains a moving research question, but network-wide risk will not be evenly distributed.
The hard part is coordination
A replacement signature can be secure and still fail operationally. Users must update, hardware must sign, exchanges must recognize new addresses, fees must remain workable and dormant owners must act. Coins that cannot or will not move create a political question: leave them exposed, restrict them, or alter ownership expectations.
Thesis audit
Pressure the bridge
- Causal bridge
- Error-corrected capability → credible attack resources → protocol urgency → mass key migration → governance conflict around unmoved coins.
- Counterforce
- Cryptographic research, standards and protocol migration can advance long before a relevant attacker exists.
- What would prove it wrong?
- Alarm tied to a specific machine should be rejected if no transparent resource estimate connects its logical capability to the relevant signature attack.
- Largest uncertainty
- No reliable date for a cryptographically relevant quantum computer exists. Resource estimates and defensive designs can change.
Source ledger
Evidence carrying this piece
Sources accessed 2026-09-06. Links point to the originating institution where available.- NIST · First finalized PQC standardsStatus and purpose of the finalized standards↗
- NIST FIPS 204 · ML-DSAPrimary post-quantum digital-signature standard↗
- NIST · Migration to Post-Quantum Cryptography FAQCurrent standards and migration context↗
- Bitcoin developer guide · TransactionsBitcoin transaction and signature structure↗
Follow the thread