Fidelity Digital Assets says future quantum computers could derive Bitcoin private keys from exposed public keys, threatening funds. A proposed hash-based signature system could strengthen security, although larger signatures would reduce transaction throughput and complicate wallet recovery.
Key Takeaways
- Quantum computers could eventually expose bitcoin private keys.
- SHRINCS combines compact signatures with a recovery mechanism.
- Quantum-resistant signatures would reduce Bitcoin’s throughput.
Fidelity Examines Bitcoin’s Quantum Vulnerability
Bitcoin’s private-key protections may eventually require replacement or supplementation, according to the Fidelity Digital Assets analysis published Sept. 1. Cryptographically relevant quantum computers, or CRQCs, do not currently exist, but sufficiently capable systems could undermine the mathematical assumptions securing transaction authorization and place funds at risk.
Fidelity Digital Assets Research identified transaction throughput as a central constraint for any future Bitcoin security upgrade:
“Minimizing key size to preserve Bitcoin’s transaction throughput remains a key concern, although the impact may be less pronounced considering the current state of a near-empty mempool.”
Private keys allow bitcoin owners to authorize transactions without relying on an intermediary. Wallets use a private key to produce a digital signature that proves control without disclosing the secret key. This relationship between private keys, public keys, and transaction signatures forms the foundation of Bitcoin ownership and self-custody.
Bitcoin’s Current Signatures Face a Future Threat
Most standard Bitcoin transactions use the Elliptic Curve Digital Signature Algorithm or Schnorr signatures. Schnorr signatures became available through Taproot, with Bitcoin Improvement Proposal 340 specifying Schnorr signatures and BIP 341 establishing Taproot’s spending rules. BIP 341 was assigned in January 2020 before the upgrade activated in 2021. Both schemes rely on the difficulty of solving the elliptic curve discrete logarithm problem with classical computers.
A sufficiently powerful quantum computer running Shor’s algorithm could solve that problem and derive private keys from corresponding public keys. Research has reduced some estimates for the resources needed to attack elliptic-curve cryptography, bringing the Bitcoin quantum-security debate into greater focus, although existing quantum systems remain far below cryptographically relevant capacity.
SHRINCS Combines Efficiency With a Recovery Path
Researchers are evaluating quantum-resistant signature systems that rely on hash functions rather than elliptic-curve cryptography. The SHRINCS draft specification combines a compact stateful signature path with a larger stateless fallback. Its current design specifies a 48-byte public key, stateful signatures ranging from 548 to 4,619 bytes, and a 5,777-byte stateless signature.
The stateful path requires signing devices to track which one-time signature keys have already been used. Lost or corrupted state prevents the wallet from safely continuing through that path, while SHRINCS’ fallback draws on algorithms from the National Institute of Standards and Technology’s SLH-DSA standard published Aug. 13, 2024. The stateless alternative preserves access but consumes substantially more block space.
Fidelity Digital Assets Research described how a future quantum-resistant Bitcoin upgrade could accommodate different security requirements:
“SHRINCS represents one potential path forward as a recently formalized BIP. However, Bitcoin’s technical constraints and the inefficiencies associated with larger quantum-resistant signatures suggest that a future solution may resemble Bitcoin’s current state.”
Larger Signatures Would Reduce Bitcoin’s Capacity
Bitcoin’s existing signatures remain far smaller than leading post-quantum alternatives, creating a direct trade-off between future security and network capacity. Larger signatures would consume more block space, raise transaction costs during periods of congestion, and limit how many transfers miners could confirm. Other assessments found that some quantum-safe signature systems could expand transaction data sharply.
Implementing SHRINCS or another quantum-resistant system would require new consensus rules, potentially through a backward-compatible soft fork. Wallet providers, miners, node operators, exchanges, and custodians would also need to support the transition. Fidelity joined eight other financial and crypto companies in July to fund a $15 million Bitcoin security initiative that includes quantum-resistance research.

By Bitcoin News | Created at 2026-09-03 03:00:18 | Updated at 2026-09-03 04:09:30
2 hours ago






