Community Trust ScoreVerified
Galaxy Digital put $5 million on the table July 21, backing Bitcoin’s long-term security against quantum computing threats. It’s a big move, and the timing matters.
The pledge is meant to fund developers hitting key milestones, push forward quantum-resistance research, and stand up a dedicated Quantum Advisory Council. The money will flow toward reviewing quantum-resistant transaction proposals, integrating post-quantum signatures into the protocol stack, and running formal security audits. Software tooling and institutional migration tools are also on the list. Galaxy is pretty clear that it’s not trying to dictate Bitcoin’s final design or force a specific timeline — the goal is to get the research-to-practice pipeline moving faster, so the network isn’t scrambling when quantum hardware actually catches up.
Quantum computers can’t crack Bitcoin today. Not even close.
But the threat isn’t theoretical forever. The core concern is Shor’s algorithm, which could eventually pull private keys straight out of elliptic-curve public keys — basically forging valid signatures without ever touching the actual private key. That would be catastrophic for any output where the public key is exposed on-chain. Draft BIP 360 maps out exactly where Bitcoin is vulnerable: pay-to-public-key outputs, bare multisignature setups, and Taproot outputs all make the list. The proposal floats a new output format called Pay-to-Merkle-Root, or P2MR, to cut long-term exposure. But P2MR is still a draft. It handles initial exposure vulnerabilities and nothing more — there’s no finalized post-quantum signature scheme attached to it yet.
Two Draft Proposals, Years of Work Ahead
BIP 361 is the companion piece. It sketches out a potential five-year, two-phase transition that would kick off after activation, walking the network from its current cryptographic setup to post-quantum signatures. Two phases, five years, and it’s still a draft with no locked-in signature plan. That gap between “we know we need this” and “here’s exactly what we’re deploying” is basically the whole problem Galaxy’s funding is trying to close.
The decentralized structure of Bitcoin makes all of this harder than it sounds. Developers, miners, node operators, wallets, exchanges, custodians, and regular users all need to be on board. Galaxy’s own assessment is that designing, testing, and deploying an upgraded system could take years — plural. There’s no shortcut through that process. Community consensus isn’t optional; it’s the mechanism.
Address reuse makes the exposure worse. When a Bitcoin address gets reused, the public key sits on-chain longer, giving a future quantum attacker a bigger window. It’s one of those practices that’s been flagged for years on security grounds and now has a sharper edge to it.
NIST Standards and Federal Mandates Already Moving
The broader cryptographic world isn’t waiting around. In August 2024, NIST finalized three post-quantum cryptographic standards and pushed for early adoption across the industry. Executive Order 14412 goes further — it requires specified federal systems to integrate post-quantum signatures by the end of 2031. Those mandates only cover government systems and don’t say anything about when quantum hardware will actually be dangerous. But the direction is clear, and the urgency is real.
Bitcoin’s path is different from a federal IT rollout, obviously. There’s no central authority that can push a mandate. The whole thing runs on rough consensus and working code, which means Galaxy’s funding is essentially buying time and resources for the community to get its act together before the pressure becomes acute.
Other parts of the crypto ecosystem are moving too. Ethereum and Tron have their own quantum-mitigation work in progress. The awareness is spreading. Nobody wants to be the network that got caught flat-footed when a sufficiently powerful quantum machine comes online.
Galaxy’s involvement is early, and that’s probably the point. Getting a reviewed signature design in place, building community consensus around it, and leaving enough runway for funds to migrate into secure outputs — that sequence requires years of lead time. The funding won’t make the technical decisions for Bitcoin’s developers. It won’t force any particular BIP through the process. What it can do is make sure the people doing the work have the resources to do it properly, and that the audit and tooling infrastructure exists when the community is ready to move.
The five-year window BIP 361 floats isn’t arbitrary. A phased transition gives wallets, exchanges, and institutional custodians time to rebuild their systems around new security protocols without everything breaking at once. Institutions especially need migration tooling that doesn’t exist yet — that’s one of the explicit targets for the $5 million.
Unclear whether the Quantum Advisory Council will have any formal role in Bitcoin’s governance process or operate purely in an advisory capacity. No details on membership yet.
What’s not murky is the scale of the coordination problem. Upgrading Bitcoin’s cryptographic foundation is probably the most complex technical operation the network has ever attempted. The design work, the testing cycles, the community signaling process, the actual deployment — each step has its own failure modes. Galaxy’s $5 million is a start. BIP 360 and BIP 361 both remain drafts without finalized signature schemes.
Frequently Asked Questions
What is Galaxy Digital’s $5 million quantum fund targeting?
Galaxy Digital’s pledge funds developer milestones, formal security audits, post-quantum signature research, and the creation of a Quantum Advisory Council to advance Bitcoin’s quantum preparedness.
What are BIP 360 and BIP 361 proposing for Bitcoin?
BIP 360 identifies vulnerable output types and proposes a new Pay-to-Merkle-Root format, while BIP 361 outlines a potential five-year, two-phase transition to post-quantum signatures — both remain drafts without finalized signature plans.
