Bitcoin Does Not Use RSA — And the Quantum Machine That Would Attack It Does Not Exist

2026-04-10 · 3,378 words · Singular Grit Substack · View on Substack

Bitcoin uses a digital signature algorithm. It encrypts nothing. The quantum threat to it is built on a computer that has never been built, using a logical qubit that has never existed.

The Fraud Begins With a False Object

Bitcoin does not use RSA, and the persistence of that mistake is not an innocent technical slip but the opening move in a larger fraud. Bitcoin does not encrypt transactions, does not conceal balances, and does not operate as though secrecy were the foundation of its security model. Bitcoin uses a digital signature system. The ledger is public, the transaction graph is public, and the relevant security question is not whether ciphertext can be decrypted but whether a private signing key can be derived from a public key quickly enough to forge authorisation. That distinction matters because the entire public discussion of quantum risk has been corrupted by people who repeat slogans instead of examining mechanisms. Once the RSA fiction is removed, one sees the second fraud more clearly: the quantum computer that is supposed to threaten Bitcoin does not exist, has never existed, and has not produced the single logical qubit required before any of the advertised attack scenarios can be treated as engineering reality rather than mathematical theatre.

Fraud is the correct word here, and it ought not be softened for the comfort of institutions that have spent years laundering speculation into inevitability. This is not merely hype, because hype still allows the possibility that the underlying object exists in some immature but real form. Here the object itself is absent. A functioning, stable, working logical qubit does not exist. The field has nevertheless built an industry, a media language, a funding pipeline, and a policy apparatus around the assumption that the absent object is sufficiently near at hand that it may be invoked as though it were already part of the world. That is not caution. That is not foresight. That is not sober extrapolation. That is fraud: real mathematics attached to a non-existent machine and then sold to the public as practical inevitability.

Bitcoin Uses Signatures, Not Encryption

One has to begin with the primitive itself, because almost every public article on the subject begins with the wrong one. Bitcoin does not use encryption to protect coins in the manner of a locked safe. Bitcoin uses digital signatures to prove the right to spend. The Elliptic Curve Digital Signature Algorithm on secp256k1 does not hide a transaction, does not obscure the amount, and does not render the ledger unreadable. It provides evidence that the spender controls the private key associated with the relevant public key or public-key hash. The chain is public because Bitcoin is a public ledger. Its integrity depends on verifiable authorisation, not hidden information.

This is why the phrase “quantum computers will decrypt Bitcoin” is the sort of sentence that should disqualify its speaker from serious participation in the discussion. There is nothing to decrypt. The attacker is not opening a locked box. The attacker, in the hypothetical world where the required machine existed, is recovering a private key from a public key and then generating a valid signature. That is signature forgery, not decryption. One cannot even frame the threat correctly until one has the discipline to state the correct primitive. The fact that so much commentary refuses to do so is not a minor embarrassment. It is evidence that the discourse is built to persuade and alarm rather than to describe.

Shor’s Algorithm Is Real; the Machine Is Fraud

There is no need to deny mathematics in order to call the public quantum narrative fraudulent. Shor’s algorithm is real. The theorem stands. Given a sufficiently powerful fault-tolerant quantum computer, elliptic-curve discrete logarithms could in principle be solved efficiently. The problem is not the algorithm. The problem is the illicit conversion of theorem into machine by rhetorical force. In public discussion, the conditional clause is always smuggled out of the room. What should be said is, “if a cryptographically relevant fault-tolerant quantum computer with real logical qubits existed.” What is actually said is, “quantum computers will break Bitcoin.” The first is mathematics bounded by engineering. The second is fraud.

That fraudulent conversion is the entire business model of the field as publicly sold. A theorem is treated as though it were a prototype. A resource estimate is treated as though it were a build sheet. A paper model is treated as though it were an industrial plan. The audience is invited to believe that because the asymptotic mathematics is elegant, the machine is effectively inevitable. This is the kind of reasoning that would be laughed out of any mature engineering discipline. No one would accept a bridge justified by a proof that a bridge of some kind could exist under ideal conditions while conceding that no materials, assembly method, or stable load-bearing structure had yet been demonstrated. Yet quantum computing enjoys this absurd privilege. The field is allowed to speak of future capacity as though the core physical unit had already entered the world. It has not.

The Logical Qubit Does Not Exist

Everything in the attack story depends on a logical qubit, and that object does not exist. Not in the strict sense that matters. Not as a stable, working computational unit that survives noise, corrects errors, and carries sustained computation without depending on discarded failures, postselection, or carefully curated reporting. The field has endless encodings, endless demonstrations, endless papers about partial behaviours under narrow conditions, but none of this yields the object that would justify treating the rest as practical engineering. A logical qubit worthy of the name must be more than a codeword written across several physical qubits. It must persist as a reliable unit under computation. It must do work. It must survive.

This absence is not a detail. It is not one engineering challenge among many. It is the foundation. Without the logical qubit, every sentence about thousands of logical qubits is decorative nonsense. One cannot stack a thousand absent things and call them a roadmap. One cannot cite algorithms requiring 2,330 logical qubits, or 20,000 logical qubits, or any other number, as though the first instance had already been made real and the remaining problem were merely multiplication. Zero is not the first rung of a ladder to a million. Zero is the absence of the ladder. The field’s refusal to speak plainly about this is why fraud is the right word. It is not merely optimistic. It is structurally dishonest.

The Lower Threshold for Bitcoin Makes the Fraud More Dangerous, Not Less

The repeated public habit of talking about RSA rather than Bitcoin’s actual signature system has one especially perverse effect. It allows commentators to say that since quantum hardware is nowhere near breaking RSA, Bitcoin is safe. This is a childish argument dressed in technical vocabulary. The relevant algorithmic estimates for attacking secp256k1 require fewer logical qubits than the headline estimates for RSA-2048, which means that the common slogan “we are nowhere near the RSA threshold” does not automatically imply anything reassuring about Bitcoin. It merely demonstrates that most of the people repeating the claim have borrowed a talking point instead of doing the arithmetic.

That arithmetic is not comforting. Breaking Bitcoin’s elliptic-curve signature system has been estimated at roughly 2,330 logical qubits and approximately 126 billion Toffoli gates. The older widely quoted RSA-2048 estimate requires about 20,000 logical qubits, while later optimisations reduce logical qubit requirements for RSA at the cost of runtime. The important point is not that one number is larger and one smaller, as though this were a quiz show for people addicted to tables. The important point is that Bitcoin’s threshold in logical qubits is lower. In principle, a machine incapable of attacking RSA-2048 under one cost profile might still be relevant to secp256k1. In practice, however, this remains trapped in the world of paper arithmetic, because the machine required for either target is fraudulent in the public sense: announced in implication, absent in reality.

Physical Qubit Estimates Reveal the Chasm

Once logical qubits are translated into physical resource requirements, the entire public story becomes grotesque. Under the attack windows cited in your draft, a ten-minute attack against Bitcoin transactions in flight requires on the order of 1.9 billion physical qubits. A one-hour attack requires roughly 317 million. A one-day attack on already exposed keys still requires roughly 13 million physical qubits. Those are not numbers one cites lightly if one is interested in honesty. Those are numbers that should stop the conversation cold and force everyone to admit that the machine under discussion is not “difficult but coming soon,” but absent in a way that makes most public commentary look ridiculous.

These numbers matter because they convert mathematical possibility into engineering absurdity. Bitcoin’s average block interval is about ten minutes. So when people speak grandly of intercepting transactions in the mempool, they are speaking of a machine with nearly two billion physical qubits, operating fault-tolerantly, decoding errors in real time, sustaining a vast gate budget, and delivering results inside a window shorter than the average confirmation time. That is not a plausible near-term risk. It is not even a plausible medium-term risk on any demonstrated hardware path. It is a civilisation-scale machine conjured into conversation by people who want the prestige of mathematics without the discipline of physics.

The Exposure Is Real Even Though the Machine Is Fraud

The paradox that serious writing must preserve is that the machine is fraudulent while the exposure classes are real. A large portion of Bitcoin is structurally exposed if such a machine ever existed. That is the point that lazy optimists prefer to suppress. One cannot dismiss the issue simply by saying that no quantum computer exists today. Some Bitcoin output types are already in a posture where the only thing protecting them is the non-existence of the required hardware. That is not the same as cryptographic security in the ordinary sense. It is contingency.

This is where one must distinguish cleanly among output classes. Bitcoin is not uniformly situated. Some outputs reveal their public keys permanently on-chain. Others remain protected by hashes until the moment they are spent. These are radically different conditions. Public discourse likes universals because universals are easy to scream. The truth is stratified, conditional, and inconvenient. Roughly six to seven million BTC, under the estimates you supplied, already have no meaningful time-window protection once the machine exists. Roughly thirteen million BTC remain hash-protected until spend, after which they enter a short race window. The machine is fraud, but the exposure map is not. That is precisely why precision is required.

P2PK Outputs Are Permanently Exposed

Pay-to-Public-Key outputs are the clearest case, and they ought to terrify anyone who is not intoxicated by slogans. In P2PK, the public key is already on-chain in the locking script. It is not hidden behind a hash. It has been visible from the moment the output was created. That means there is no race against the mempool, no need to wait for spending activity, and no reliance on timing. If the machine existed, the attacker could harvest those public keys at leisure, derive the private keys, and spend the outputs. The only barrier is the non-existence of the machine.

This is what makes early Bitcoin holdings, including the famous stock of coins associated with Satoshi-era P2PK outputs, so politically explosive. They are not “safe until moved.” They are simply sitting there behind public keys. The fact that the machine required to exploit them does not exist is what prevents action, not any remaining concealment in the script. That distinction should change the entire tone of the debate, because it means that a meaningful portion of supply is already in a condition where a future cryptographically relevant machine would create no timing problem at all. The attack would be slow, selective, and methodical, not cinematic.

Address Reuse Converts Hash Protection Into Permanent Exposure

The next class of vulnerability is not a design necessity but a civilisational embarrassment. When P2PKH or P2WPKH addresses are spent from, the corresponding public key becomes visible in the unlocking data. If the owner later reuses that address and receives funds to it again, those later funds sit behind an already revealed public key. At that point the output is, for quantum purposes, effectively exposed in the same way as P2PK. The user has voluntarily downgraded from hashed concealment to permanent public-key exposure.

This is more than poor hygiene. It is the transformation of a theoretically better security posture into a worse one through repeated human laziness. Estimates cited in your draft place this reused-address exposure at roughly four to five million BTC, with some analyses pushing the figure higher when combined with P2PK exposure. That is an immense stock of value. It means that the system’s quantum vulnerability is not merely a question of abstract future hardware. It is also a record of human indiscipline embedded in the chain itself. The rhetoric of sovereignty is always splendid until one notices how many people exercise their sovereignty by behaving like fools.

Clean Hashed Outputs Are Protected Only Until Spend

The largest stock of Bitcoin remains in outputs whose public keys have not yet been revealed. Here, at least, the system has a genuine protective layer. So long as the public key remains concealed behind SHA-256 and RIPEMD-160, Shor’s algorithm cannot directly attack it, because there is no public key yet exposed to attack. This is the source of the familiar phrase that Bitcoin is “safe until spent.” The phrase is not wholly false, but it is so incomplete that in public use it becomes misleading.

Once such an output is spent, the public key appears in the transaction input and is visible to the network before confirmation. At that point the attacker’s problem becomes one of speed. Under the model cited in your draft, completing the attack inside the ten-minute block interval would require about 1.9 billion physical qubits. That makes the scenario, under present and projected hardware realities, fraudulent as a near-term threat claim. But one must not allow the absurdity of the machine to obscure the conditional vulnerability of the script type. The right statement is neither that Bitcoin is safe nor that Bitcoin is doomed. The right statement is that hash-protected outputs are conditionally protected until spend, and that the public story becomes dishonest the moment it forgets either half of that sentence.

Hashes Matter, and Grover Is Not the Saviour of Panic Merchants

People who know just enough quantum computing to frighten journalists often throw Grover’s algorithm into these discussions, as though every mention of a second algorithm adds another trumpet to the apocalypse. In context, the effect is usually to generate heat without light. SHA-256 reduced by Grover still presents an effective security level of 128 bits, which is fantastically beyond any practical attack scenario anyone can responsibly discuss. RIPEMD-160 under Grover is less generous, but even there the real-world implications are constrained by the sequential nature of the algorithm and by the fact that the machine needed to run it at meaningful scale does not exist.

The practical consequence is straightforward. For outputs whose public keys remain hidden, the relevant quantum concern is not some imminent generic collapse of hashing, but the moment of public-key revelation when a signature attack becomes conceivable in principle. Public commentary collapses all these categories because panic is easier to market than taxonomy. The result is that people are frightened about the wrong things in the wrong order for the wrong reasons. Fraud need not consist in inventing a false theorem. It is enough to arrange true premises so badly that the resulting picture becomes false.

The Economics Turn “Quantum Doom” Into Theatre

The economics of the attack models are perhaps the most humiliating part of the story for those who prefer apocalyptic simplicity. A one-day attack model involving around 13 million physical qubits and roughly 10 watts per qubit implies on the order of 130 megawatts of continuous power draw, before one has even touched capital expenditure, cooling overhead, fabrication, maintenance, or error-control infrastructure. A day of operation alone runs into immense energy costs. A ten-minute interception model at 1.9 billion qubits would require something so vast that the phrase “commercial deployment” becomes a joke.

This matters because public fear narratives often speak as though the arrival of a quantum-capable attacker would mean effortless, universal theft. That is fantasy. Even if such a machine existed, which it does not, the economics would favour highly selective targeting rather than indiscriminate plunder. Exposed outputs with large balances would matter more than small ones. Dormant early addresses would matter more than ordinary retail activity. Strategic, state-scale targets would matter more than casual opportunism. None of this makes the threat unreal in principle. It makes the hysteria dishonest in practice. The machine is sold as universal destiny because universal destiny raises more money than selective strategic capability.

The Governance Trap Around Satoshi’s Coins

The greatest irony is that the most famous coins in the system crystallise the political problem most brutally. If the early P2PK outputs associated with Satoshi are indeed permanently exposed through already revealed public keys, then a future cryptographically relevant machine would place those coins in a uniquely awkward position. Their owner cannot be expected to migrate them. If the owner is absent, dead, silent, or simply unwilling to move, then every migration proposal runs into a moral and legal contradiction. Either the network leaves those outputs spendable, in which case a future attacker who derives the keys may take them, or the network freezes or burns them by consensus, in which case the network itself arrogates power over dormant property.

This is not a technical inconvenience. It is a constitutional problem. Bitcoin’s mythology rests heavily on the claim that the network does not discriminate among UTXOs and does not adjudicate private property according to collective sentiment. Yet any protocol change that invalidates permanently exposed outputs after a deadline would do exactly that. The community would be choosing which property remains legitimate and which does not. The rhetoric of neutrality cannot survive that choice unmodified. This is another reason the quantum discussion is so often conducted dishonestly. Once one follows the implications all the way through, one discovers not merely an engineering fantasy but a governance crisis waiting behind it.

Quantum Computing as Publicly Sold Is Fraud

The cleanest summary is also the harshest. Quantum computing as publicly sold is fraud. That statement does not deny mathematics. It does not insult every individual physicist. It does not require pretending that no interesting laboratory work is being done. What it does is refuse the central deception by which the field is marketed. The public is told, implicitly or explicitly, that the machine is effectively underway, that the gap from theory to hardware is narrowing in some smooth and intelligible fashion, and that cryptographically relevant capability is an engineering problem with a credible horizon. None of that has been shown. The core computational unit, the logical qubit, does not exist in the sense required to make the rest of the story real.

The field survives by converting absence into rhetoric. Error-detection results become “steps to fault tolerance.” Fragile demonstrations become “milestones.” Resource estimates become “roadmaps.” The audience is trained never to ask the vulgar but necessary question: where is the working logical qubit? Because if that question is allowed to dominate, the scenery collapses. Bitcoin then reappears in its true posture: not under immediate assault by an inevitable machine, but partly exposed to a threat that exists in mathematics and not in hardware. That is a much less cinematic story, which is precisely why institutions prefer the fraudulent one.

The Honest Conclusion

The honest conclusion is severe because reality is severe. Bitcoin does not use RSA. Bitcoin uses ECDSA over secp256k1. The relevant quantum attack is signature forgery through key recovery, not decryption. Another substantial portion remains protected only until spend. The mathematics for the attack is real. The machine is not. No logical qubit has been built. The public story that treats quantum attacks on Bitcoin as an approaching engineering inevitability is therefore fraudulent in its essential structure.

That is the position in full. The exposure is real. The machine is fraud. The discourse that suppresses either half of that truth is itself dishonest.


← Back to Substack Archive