Why Bitcoin Is Going to Zero
OIJ (#32) Explaining How Quantum Computing Could Obliterate Bitcoin
Welcome back dear fellow đ§ââď¸ Hermits đ
đ§ââď¸ First time here? â This 3-Minute Crash Course Will Save You Hours
đ§ââď¸ Weâre obsessed w/ research â Come Take a Peek at Finland Through Our Eyes
âż New to Blockchain? â Get You Up to Speed Fast
This article leans a bit more into the technical side, but it lays out a compelling case for why Bitcoin may go to zero. This is not a doomsday article, but rather an examination of a high-probability event and its ramifications.
It baffles us that no oneâs talking about this.
If terms like proof, ciphers, forks, or keys feel unfamiliar, we recommend starting with our primer on crypto protocols. It'll give you the foundation to follow along confidently.
The Quantum Blade
Not with a bang but with a bit-flip.
â T.S. Eliot (had he owned a Ledger Nano S)
Thousands of hours.
Billions of dollars.
An entire culture of âHODLâ memes, laser eyes, and Michael Saylor sermons.
And yet, what if it all crumbles... not because of regulation, not because of ESG, but because a quiet little lab in Zurich or Hangzhou boots up a cold, humming monster and cracks the entire thing open like a walnut?
This is a post about math, physics, and code-breaking. And it might explain why the SHA-256 cryptographic hash function (the foundation of Bitcoinâs security) could one day be as obsolete as a MySpace welcome page.
âď¸ The Blade That Cuts Through Time
Bitcoin is built on a beautiful illusion: that certain functions are âone-way.â You can take data (a block), run it through the SHA-256 function, and get a hash. But you canât go backward. You canât look at a hash and know what data produced it. Thatâs called a pre-image resistance property. And it's sacred in crypto.
But what if you could go backward?
Letâs introduce our assassin: the quantum computer.
Not a laptop. Not a cluster of new gen Nvidia GPUs. Something much⌠stranger.
Quantum computers process information using qubits, which exist not in a state of 0 or 1, but in superposition, like SchrĂśdingerâs cat flipping a coin.
The threat to Bitcoin arises from Groverâs Algorithm, a quantum technique that essentially halves the effective security of hash functions.
SHA-256 has a 256-bit output, and a classical brute-force attack would need ~2^256 operations to find a collision (a matching input). With Groverâs, that drops to 2^128. Still big... really big
More alarming? Shorâs Algorithm, which doesnât apply directly to hashing but destroys RSA and ECC, used in Bitcoin's digital signatures
your private key â public key â signature
Ballpark Comparison Example
Hereâs a little pause for added contextâŚ
Letâs imagine you want to search a database of 2âśâ° entries:
A classical computer must try up to 2âśâ° â 1.15 quintillion possibilities. That, even at 1 billion operations/sec, is 36 years of computing.
A quantum computer using Groverâs only needs ~2Âłâ° = 1 billion operations. That means you can finish the same problem in about 1 second.
Speedup factor: â 1,000,000,000Ă
In Bitcoin:
You generate a private key.
From that, you derive a public key.
You sign transactions with your private key.
Everyone verifies it with the public key.
But if your public key is exposed (as it is every time you send BTC), a quantum computer with Shorâs could one day derive your private key.
It doesnât matter whether your storage is hot or cold. If youâve ever performed a transaction (sent counts, received does not), then thereâs a record of your key is out there.
In other words, your wallet could be⌠toast. đ
đŞ Why Every Transaction Is a Liability
Over 89% of BTC in circulation has public keys already exposed.
Those addresses are quantum vulnerable. Thatâs not a our hot-take, thatâs a fact.
Satoshi's original wallet?
Exposed.
Mt. Gox reserves?
Exposed.
Every time someone spends BTC, the public key is visible on-chain, forever. Quantum computers donât need to work today. They just need to work before you cash out.
We're not talking about some live man-in-the-middle attack. Weâre talking about a retroactive apocalypse, a time-bomb where historical transactions become reverse-engineerable.
If the money is still in the system, the person controlling the red button can move it all around at will.
đ§ So... How Real Is This Threat?
Letâs get a few things straight.
First, the quantum threat to Bitcoin at first would not be about SHA-256, at least not yet. Itâs about ECDSA, the signature algorithm used every time you send BTC.
Thatâs the weak link.
And specifically, itâs about exposed public keys, which are visible every time a user spends from their wallet. If a quantum computer can reverse-engineer your private key from that public key, your coins are no longer yours.
Please note that not all BTC addresses are equally vulnerable.
Old-school addresses from the early P2PK era (2009â2011) expose public keys before a transaction is made⌠meaning theyâve been quantum-exploitable from day one. These make up a non-trivial chunk of the dormant Bitcoin supply, including potentially Satoshiâs original coins.
Newer Bitcoin addresses, such as P2PKH (Pay-to-PubKey-Hash) or Bech32/Taproot types, donât expose the public key until the coins are spent. As long as the coins havenât moved, those addresses remain cryptographically opaque and quantum-safe for now.
Between 30â37 % of the total BTC supply sits in old or reused outputs whose public keys are already on-chain. These are immediate targets once a working machine exists.
Some argue that this makes the issue moot. As a buddy of mine put it:
Sure, someone might crack a founder's P2PK wallet⌠but theyâd never be able to spend it without the whole chain knowing.
Every blockchain hawk would be watching those coins.
And thatâs⌠partially true.
Yes, Bitcoin is radically transparent. Any movement from dormant founder wallets would light up every block explorer on earth.
But transparency doesnât stop theft, it just makes it visible.
If a quantum actor gains the keys to an old address, they donât need to launder or hide; they just need to move the coins before a fork or blacklist kicks in. And by the time anyone reacts, the BTC might be sitting in 15 layers of wrapped synthetic tokens, or (more likely) swapped into fiat.
And what if the movement isnât theft? What if itâs a prank, as some believe Roger Ver may have played by moving legacy coins into a non-P2PK format? Or worse, what if it's a test? A proof-of-concept run using cracked keys from addresses with weak entropy or poor randomness?
Thatâs a credible scenario.
In either case, the loss of confidence alone could trigger a market panic, especially if mainstream headlines scream: âSatoshi Wallet Breached by Quantum Computerâ. It wouldnât matter if it was true or if the coins never moved again. The mere signal could crash the trust layer.
đ From Immutable to Broken
Imagine itâs 2028.
IBM, Google, Alibaba, Microsoft (or some less desirable state actor) announces a 4,096-qubit, error-corrected monster. A production-grade, post-NSA-grade machine.
Within weeks:
Signatures begin to fail verification.
Coins are moved from dormant wallets.
"Unspendable" funds suddenly⌠disappear.
Forks are proposed. None agreed upon.
Bitcoin Core developers panic. Tether breaks. Coinbase halts withdrawals. Twitter/X spaces turn into all-night funerals.
The market doesnât wait for explanations.
And⌠the price collapses.
Why? Because the very feature that made it so appealing, the inability to change the rules conceived in the initial white paper, is now its greatest weakness.
When quantum computers arrive, Bitcoin may not adapt to post-quantum security⌠and that rigidity is a death sentence.
FYI, IBMâs Condor chip (2025) hits 1,121 physical qubits; its roadmap shows a 4,158-qubit multi-chip system by 2026, still physical, not logical.
For the uninitated⌠Logical â Physical. Weâre probably a decade+ away from enough logical qubits if error-correction scales as hoped.
The math is as follows:
A rough estimate puts the break-point at â1,500 logical qubits, about 10šš gatesâŚÂ
⌠but weâd need 10â20 million physical qubits with todayâs error-correction to actually deliver.
đŹ âBut Weâll Just Fork to a Post-Quantum Chainâ
Will you though?
Because if trust dies, Bitcoin dies.
And trust in a âpost-quantum hard forkâ after a catastrophic security breach is like trusting a parachute that failed once already.
Besides, a hard fork means invalidating all existing signatures and moving to quantum-resistant cryptography. But that breaks the entire history. You canât just tack on SPHINCS+ and pretend the Mona Lisa of crypto didnât melt.
There will be no patch or rebirthâŚ
Unlike the mythical phoenix, Bitcoin is not designed to rise from its ashes.
Itâs built to never change.
đ So Why Not Just Upgrade Bitcoin?
Yes, quantum-resistant cryptography exists. Lamport, SPHINCS+, XMSS, weâve got some tools. But the upgrade path is messy.
Bitcoin has no CEO. No emergency hotline. No kill switch.
To protect the network, youâd need:
A majority of economic actors (wallets, exchanges, custodians) to adopt new key formats
A migration of every spendable coin to new, quantum-hardened addresses
A hard cutoff date for old, vulnerable outputs
Coordination across millions of holders, many of whom are long gone
This isnât exactly a software patch. Itâs pretty much the equivalent of a contract overhaul. And history tells us that even optional upgrades like SegWit took over 6 years to reach 90% adoption.
So yes, maybe Bitcoin can survive quantum.
But the window to act shrinks every year, and the cost of inaction could be fatal.
Because when you build something to be immutable, you better be damn sure it was designed to survive the future.
đĄď¸ What the Bitcoin-Core Crowd Is (and Isnât) Doing
Ongoing Research
Drafts for Lamport, XMSS and SPHINCS+ output types exist (hereâs a GitHub link), but nothing has reached BIP-final status.Soft-Fork First Mentality
Developers favour an opt-in soft fork so economic nodes can begin using PQ signatures without invalidating old UTXOs.The Hard-Fork Fallback
If a live break happens, a flag-day hard fork that âsunsetsâ vulnerable outputs is the nuclear option. Every coin that fails to move before cut-off becomes unspendable collateral.Big Unknowns
Lost coins (Satoshiâs, Mt. Gox, etc.) may never move â permanent supply shock.
Legal & custody rails must re-tool in parallel; banks can patch overnight, but self-custody wallets depend on users acting.
đ§ââď¸ On Faith, Fungibility, and Finality
There are three ways to kill a currency:
Debase it (ask Argentina).
Displace it (ask the denarii).
Break its code (ask Bitcoin, maybe).
As with all coins, Bitcoin is wrapped in belief. Sure, itâs mathematically induced belief, but itâs a trust system nonetheless. The second that math becomes reversible, itâs not a currency anymore.
So no, I donât know when Bitcoin goes to zero.
But I do know this:
Every qubit added to a quantum processor is one step closer to the moment Satoshiâs coins collapses and the spell breaks.
When that happens?
The Hermit will be long gone. Holding oil, farmland, or maybe even (if need be) a goat.
Just not BTC.
đ§ââď¸
PS: If youâve made it this far and are screaming profanities into your keyboard, feel free to drop a rebuttal in the comments. We welcome it. Debate is healthy. And the Hermits read everything.
If you want to dig deeper into the quantum-vs-crypto war, here are some links:
Want more of this?
⌠like â¤ď¸ and comment so that more people can discover and enjoy this Substack đ













Eh, if quantum computers steal all my bitcoins from me itâs also going to steal my bank accounts and everything digital tied to me. It will destroy the entire digital economy. I think the BTC might be the least of my worries at that point. Iâd be more worried about my rifle and ammo stockpile.
Great Read! I must say I have to agree, and I own 10+ BTC. My favorite part of your article is when you put a spot light on the Achilles heel of BTC. The same thing that built the faith in BTC is the same thing that will destroy it. Itâs Unchangeable. This really alters my outlook on a lot of things.
Quantum computing wonât affect banking because banking can pivot. Fiat can pivot. BTC canât pivot. Sure it works now. But it literally cannot work at some point in the future , we donât know when. But we know that for sure.