
Unexplained wallet thefts, not a Satoshi hack, will signal Q-day, Quantus founder Christopher Smith said, with forecasts split between 2028 and the early 2030s.
The first sign that quantum computing has broken modern cryptography probably won't be a splashy theft of Satoshi Nakamoto's dormant Bitcoin. It could be a stretch of unrelated crypto wallet breaches with no trace of how the attacker got in, according to Christopher Smith, founder and CEO of blockchain startup Quantus Network.
"When someone cracks your key, you don't get a memo saying how they did it," Smith told Cointelegraph. A quantum computer powerful enough to pull a private key from the public keys exposed onchain could move funds without ever compromising a wallet or an exchange's internal systems.
Q-day, the moment quantum machines become strong enough to break standard public-key cryptography, is unusually hard to pin down. In a theft at a highly secure organization, "the only forensic evidence would be that there was no breach," Smith said.
His warning lands as advances in quantum algorithms have cut the estimated computing resources needed to attack the elliptic-curve cryptography major blockchains rely on. In March, Google moved its post-quantum migration timeline forward to 2029 after an AI-assisted breakthrough showed elliptic curve cryptography can be cracked with far fewer physical qubits than earlier forecasts suggested.
Much of crypto's Q-day fear centers on what happens if a quantum computer breaks the keys to Satoshi's estimated Bitcoin holdings, worth $63 billion at the time of writing, and floods the market with them. Smith thinks the first targets would be military systems and state secrets, and that crypto attackers would aim for keys worth more than the creator's wallets.
"If I'm focusing on blockchain, what's the single most valuable key? It's probably Tether's minting key," Smith said. A quantum attacker could mint tokens from an administrative wallet and dump them before the issuer could respond, he added. USDT is a multi-chain stablecoin, and some of the networks it runs on are already working on post-quantum migration.
A quieter opening move is another scenario. Sean Cheetham, a security researcher at Blockchain Capital, said an attacker would more likely hit exchange hot wallets "that aren't going to ring alarm bells rather than stealing Satoshi's coins." Smith said a quantum theft could be dressed up as an ordinary compromise.
"There's an alternative scenario where they... have these plausible, deniable [explanations]: 'Oh, somebody just lost their keys somehow,'" he said.
Exchanges run the hot wallets Cheetham expects attackers to test first, and stablecoin issuers hold minting keys that can create supply out of nothing. On the infrastructure side, Blackstone said blockchains have started migrating to post-quantum signatures rather than waiting for the threat to arrive.
On timing, the builders disagree. Smith, whose company is building a blockchain network meant to be quantum-resistant from launch, put a "50-50" chance on a capable machine by 2028. He argued that AI-assisted improvements in quantum algorithms and hardware research are making past forecasts unreliable.
Cheetham called the early 2030s "definitely is almost a certainty" and described an earlier arrival as "more of a trailing probability."
Michael Coates, chief information security officer at the Solana Foundation, declined to give an estimate in an earlier interview. "There's no way to know," he said. "If you talk to people in the industry, it is always five years away, and it's been that way for 10 years or more now. Perhaps today people say it's four years away."
The uncertainty is not a reason to delay, Coates added. Roy Blackstone, CEO of hardware wallet maker NGRAVE, said earlier quantum forecasts failed to account for the parallel development of AI.
"Thankfully, blockchains aren't waiting and have started migrating to post-quantum signatures," Blackstone said. "The damage would be catastrophic if they didn't."
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.