# Is $5M Enough to Quantum-Proof Bitcoin Before Q-Day?
Galaxy Digital (Nasdaq: GLXY) is committing up to **$5 million** to the Galaxy Bitcoin Quantum Readiness Initiative — developer grants, a dedicated research program, and a new advisory council — announced Tuesday, July 21, 2026. The move follows a March 2026 paper co-authored by [Google Quantum AI](https://quantumintel.tech/companies/google-quantum-ai), the Ethereum Foundation, and Stanford University estimating that breaking Bitcoin's secp256k1 elliptic curve cryptography may require roughly an order of magnitude fewer quantum resources than previously assumed. Under specific fast-clock superconducting hardware conditions modeled in that paper, a private key could theoretically be derived in approximately nine minutes — inside Bitcoin's ten-minute block confirmation window. Approximately **6.9 million bitcoin**, roughly one-third of circulating supply, already sit in wallets with permanently exposed public keys, according to the same paper. Of those, **1.7 million bitcoin** in early Pay-to-Public-Key addresses — including holdings attributed to Satoshi Nakamoto — have had public keys visible on-chain for over a decade. Galaxy's initiative is the most substantial single private-sector commitment to Bitcoin post-quantum cryptography to date, though whether $5 million is commensurate with the scope of the problem is a question the industry has not seriously answered.
---
## What Galaxy's Three-Pillar Initiative Actually Funds
The initiative operates across three defined areas, per Galaxy's announcement:
**Grant program:** Funding for quantum-resistant transaction proposals, post-quantum signature schemes, wallet and custodian migration tools, and security audits. Applications opened immediately on announcement day.
**Research program:** Galaxy Research will publish analysis targeting institutional investors, policymakers, and the developer community — explicitly framing quantum risk as an investor-legibility problem, not just a cryptography problem. Alex Thorn, Head of Firmwide Research at Galaxy, described the core challenge as a gap "between the quantum computing world, which is moving fast, and the Bitcoin development world, which is just beginning to engage with post-quantum cryptography in earnest."
**Quantum Advisory Council:** Initial members named are Barry Sanders, Professor and Scientific Director of Quantum City at the University of Calgary; Damien Bérubé, an MIT Sea Grant Knauss Fellow; and Eran Tromer, a Professor of Computer Science at Boston University. Sanders noted that quantum timelines continue to compress and that Bitcoin "should be no exception to the preparation underway across governments and industries."
Mike Novogratz, Galaxy's Founder and CEO, framed the initiative as an institutional responsibility: "As leaders in the digital assets space, we believe it's important that we help be part of the solution to any potential threat quantum computing poses to Bitcoin."
---
## Why Bitcoin's Exposure Is Structurally Different
Most encryption risk discussions focus on harvest-now-decrypt-later attacks: adversaries storing encrypted data today to decrypt once [fault-tolerant quantum computing](https://quantumintel.tech/glossary/fault-tolerant-quantum-computing) arrives. Bitcoin faces an additional, more acute problem.
The **on-spend attack** vector works differently. When a Bitcoin transaction is broadcast to the network, the public key becomes briefly visible before the transaction settles in a block. A sufficiently fast fault-tolerant quantum computer running Shor's algorithm could derive the private key within that window and broadcast a competing transaction with a higher fee, effectively front-running the original sender and draining the wallet in real time. No long-term data storage required — only speed.
The risk is not uniformly distributed across the Bitcoin ecosystem:
- Wallets using Pay-to-Public-Key-Hash (P2PKH) that have **never spent funds** keep their public keys hidden behind a hash — currently safer, but not immune to future protocol-level attacks.
- Wallets that have **previously spent funds** have exposed their public keys on-chain permanently. These are among the ~6.9 million bitcoin flagged in the March 2026 Google/Ethereum Foundation/Stanford paper.
- The **1.7 million bitcoin** in early P2PK addresses represent the highest-concentration exposure: public keys visible for over a decade, no mechanism to rotate them, and a blockchain that preserves every historical transaction permanently.
Unlike a financial institution that can issue new certificates and revoke old ones, Bitcoin's public ledger offers no key-rotation mechanism. Migration requires active user action and protocol-level upgrades — both of which move slowly. Bitcoin Improvement Proposals 360 and 361 have outlined migration paths, including BIP-360's proposed Pay-to-Merkle-Root address type that avoids exposing public keys, but neither has been activated.
---
## The Broader Industry Is Mobilizing — Unevenly
Galaxy's announcement lands inside a building wave of institutional quantum-security activity around Bitcoin specifically:
- **BitGo** has launched quantum risk management capabilities for institutional Bitcoin wallets, including a Quantum Risk Score and updated UTXO selection controls designed to reduce address-key exposure.
- **Blockstream** identified post-quantum cryptography as a major engineering priority in its Q2 2026 report.
- **Project Eleven** has placed Q-Day — the point at which a quantum computer can break Bitcoin's cryptography — at a baseline scenario of 2033, with a pessimistic bound of 2030, per the source material.
This is meaningful progress compared to 18 months ago, when institutional Bitcoin infrastructure vendors treated quantum risk as distant and theoretical. The March 2026 paper appears to have been a catalyst: the "order of magnitude fewer resources" finding forced a reassessment of previously comfortable timelines.
**Analysis:** Galaxy's $5 million positions it as a coordinator and funder of post-quantum Bitcoin work, not an executor. The grant program's value will depend heavily on whether it attracts serious protocol developers — a community that has historically been skeptical of corporate-funded initiatives and slow to integrate externally developed proposals. The advisory council's academic composition is credible, but notably lacks active Bitcoin Core contributors, which may limit the initiative's direct influence on protocol development. The research program targeting "institutional investors and policymakers" reads as the highest-probability near-term output: Galaxy is structurally better positioned to produce investor-facing analysis than to ship protocol code. Whether the full $5 million gets deployed, and on what timeline, remains unspecified in the announcement.
---
## Key Takeaways
- Galaxy Digital is committing up to **$5 million** to the Bitcoin Quantum Readiness Initiative, covering grants, research, and an advisory council.
- A March 2026 paper by [Google Quantum AI](https://quantumintel.tech/companies/google-quantum-ai), the Ethereum Foundation, and Stanford found breaking Bitcoin's secp256k1 curve may need roughly **an order of magnitude fewer quantum resources** than prior estimates.
- Under modeled fast-clock superconducting hardware conditions, a private key derivation could theoretically complete in approximately **nine minutes** — inside Bitcoin's block window.
- Approximately **6.9 million bitcoin** (~one-third of circulating supply) are in wallets with already-exposed public keys; **1.7 million bitcoin** in early P2PK addresses have been exposed for over a decade.
- The on-spend attack vector is structurally distinct from harvest-now-decrypt-later: it requires speed, not long-term data storage.
- BIPs 360 and 361 outline migration paths, but neither has been activated; protocol-level change in Bitcoin moves slowly.
- BitGo, Blockstream, and Project Eleven have all escalated post-quantum Bitcoin work in 2026.
- Galaxy's initiative is better positioned to produce investor-facing research than to directly accelerate protocol development, given the advisory council's academic (not developer) composition.
---
## Frequently Asked Questions
**What is the Galaxy Bitcoin Quantum Readiness Initiative?**
Galaxy Digital (Nasdaq: GLXY) announced on July 21, 2026 a commitment of up to $5 million across three areas: a developer grant program for quantum-resistant Bitcoin proposals and migration tools, an expanded research publication program through Galaxy Research, and a new Quantum Advisory Council. Applications for grants opened immediately.
**Why is Bitcoin specifically vulnerable to quantum computers?**
Bitcoin's security relies on elliptic curve cryptography (the secp256k1 curve). Shor's algorithm, run on a sufficiently powerful fault-tolerant quantum computer, can derive a private key from a public key. Bitcoin's on-spend attack vector is particularly acute: when a transaction is broadcast, the public key is briefly exposed. A fast enough quantum computer could derive the private key and broadcast a competing transaction within Bitcoin's roughly ten-minute block confirmation window.
**How many bitcoin are already at risk from quantum attacks?**
According to a March 2026 paper from Google Quantum AI, the Ethereum Foundation, and Stanford University cited in the source material, approximately 6.9 million bitcoin — roughly one-third of circulating supply — are in wallets with already-exposed public keys. Of those, 1.7 million bitcoin in early Pay-to-Public-Key addresses, including holdings attributed to Satoshi Nakamoto, have had public keys visible on-chain for over a decade.
**When could a quantum computer actually break Bitcoin?**
No quantum computer capable of this attack exists today. Project Eleven has placed Q-Day at a baseline scenario of 2033, with a pessimistic bound of 2030, according to the source. The March 2026 paper's hardware conditions that yielded the nine-minute estimate are theoretical — based on architecture that does not yet exist.
**What protocol changes are proposed to protect Bitcoin from quantum attacks?**
Bitcoin Improvement Proposals 360 and 361 have outlined migration paths. BIP-360 proposes a Pay-to-Merkle-Root address type that avoids exposing public keys on broadcast. Neither proposal has been activated. Migration also requires users to actively move funds to quantum-resistant addresses — a coordination problem that has no automated solution on a permissionless network.
BREAKING
Galaxy Commits $5M to Quantum-Proof Bitcoin
Published: July 21, 2026 at 14:46 EDTLast updated: July 22, 2026 at 03:57 EDTBy Jonas Vogel, Senior EditorLast reviewed by Jonas Vogel on July 22, 20268 min read
Galaxy Digital pledges $5M for Bitcoin quantum security research, developer grants, and an advisory council as Q-Day timelines compress.
post-quantum-cryptographybitcoingalaxy-digitalshor-algorithmelliptic-curvepqcfault-tolerant