GapLimit

R11Signals From Elsewhere

The quantum milestone that would actually matter

Supported
Quantum news usually arrives as a machine count and leaves as a Bitcoin obituary. The missing middle is enormous. A better experimental computer is not automatically capable of breaking a deployed signature, and a standardized post-quantum signature is not automatically integrated into a decentralized monetary network.

The short answer

The meaningful signal is a chain of milestones: error-corrected logical capability, a demonstrated resource path to attack relevant elliptic-curve signatures, credible timing, standardized alternatives, protocol support, usable wallets and migration of exposed keys. Risk rises along the chain; it does not flip on with one headline.

Original GapLimit object

From laboratory progress to spend risk

Each rung is necessary context. None alone proves that Bitcoin keys can be attacked today.
  1. 01
    Physical systemMore components and lower error
  2. 02
    Logical machineSustained corrected operations
  3. 03
    Attack resourcesRelevant algorithm, depth and runtime
  4. 04
    Protocol pathAccepted signature and address rules
  5. 05
    User migrationWallets, hardware and dormant funds move
01

Physical qubits are not the finish line

Noise forces quantum systems to spend many physical components protecting fewer logical operations. A cryptographic threat assessment therefore needs error rates, logical depth, connectivity and runtime, not a single vendor's qubit count. Progress can be real without yet being relevant to Bitcoin keys.

02

Standards exist; migration does not

NIST finalized ML-DSA and SLH-DSA as post-quantum digital-signature standards in 2024. That is a major defensive milestone. Bitcoin still needs its own engineering and governance path: transaction rules, address formats, software, hardware support, fee consequences and a way to move old holdings.

03

Exposure is uneven

Bitcoin addresses and scripts expose different information at different moments. Reused or already-spent public keys may present a different future migration urgency from outputs whose public key has not appeared on-chain. Exact attack practicality remains a moving research question, but network-wide risk will not be evenly distributed.

04

The hard part is coordination

A replacement signature can be secure and still fail operationally. Users must update, hardware must sign, exchanges must recognize new addresses, fees must remain workable and dormant owners must act. Coins that cannot or will not move create a political question: leave them exposed, restrict them, or alter ownership expectations.

Thesis audit

Pressure the bridge

Causal bridge
Error-corrected capability → credible attack resources → protocol urgency → mass key migration → governance conflict around unmoved coins.
Counterforce
Cryptographic research, standards and protocol migration can advance long before a relevant attacker exists.
What would prove it wrong?
Alarm tied to a specific machine should be rejected if no transparent resource estimate connects its logical capability to the relevant signature attack.
Largest uncertainty
No reliable date for a cryptographically relevant quantum computer exists. Resource estimates and defensive designs can change.

Source ledger

Evidence carrying this piece

Sources accessed 2026-09-06. Links point to the originating institution where available.
  1. NIST · First finalized PQC standardsStatus and purpose of the finalized standards
  2. NIST FIPS 204 · ML-DSAPrimary post-quantum digital-signature standard
  3. NIST · Migration to Post-Quantum Cryptography FAQCurrent standards and migration context
  4. Bitcoin developer guide · TransactionsBitcoin transaction and signature structure