Bitcoin’s Institutions Take On the Quantum Security Bill
July 23, 2026 — Nine institutions announced the Bitcoin Security Consortium: Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy, and Strategy. The members pledged an aggregate 15 million USD over three years to fund the developers and researchers working on Bitcoin’s long-term security, with post-quantum cryptography the headline item. There is no pooled fund; each member directs its own funding to the developers, researchers, and organizations it chooses. Mike Schmidt, executive director of the Bitcoin development nonprofit Brink, coordinates the group’s day-to-day work as a volunteer.
Two days earlier, on July 21, Galaxy had launched the Galaxy Bitcoin Quantum Readiness Initiative: up to 5 million USD in milestone-based developer grants, a research program under Galaxy Research, and a Quantum Advisory Council whose inaugural members include Barry Sanders of the University of Calgary, Eran Tromer of Boston University, and Damien Bérubé. The grant program’s stated priorities are implementation and review of quantum-resistant transaction proposals, post-quantum signature integration, wallet and custodian migration tooling, and formal security audits, with applications open immediately. Galaxy’s head of firmwide research, Alex Thorn, framed the initiative as closing the gap between a fast-moving quantum computing field and a Bitcoin development community only beginning to engage with post-quantum cryptography in earnest.
Bottom line: Bitcoin’s largest institutional holders and custodians have formally started paying for the quantum problem, and the week’s pledges, at most 20 million USD, are a small line item next to the value of the coins whose public keys already sit exposed on-chain.
The members drew a careful boundary in the launch text. The consortium “takes no position on specific protocol changes,” neither develops nor directs Bitcoin’s protocol, and does not claim to speak for Bitcoin or its developers. Its stated jobs are funding and communication: supporting existing open-source security work, and serving as a reference point for investors, media, and the public. The quantum framing is deliberately calm: no machine capable of threatening Bitcoin’s cryptography exists today, the members note, and they place that capability years away. Robert Mitchnick, BlackRock’s global head of digital assets, cast the pledge as additional funding for Bitcoin Core developers, and Strategy chief executive Phong Le tied it to the self-interest of long-term holders.
Neither announcement arrived alone. Coinbase established its Independent Advisory Board on Quantum Computing and Blockchain in January, and the board published its first position paper on April 21. On July 22, asset manager Strive announced a Bitcoin Stewardship Commitment with initial support routed through Brink. Custody firm BitGo had launched quantum risk scoring and exposed-address remediation for institutional Bitcoin wallets on July 9, and Blockstream co-founder Adam Back, quoted in that release, gave the month its thesis: start now, “while it’s calm and optional rather than urgent and forced.” Both the consortium’s coordination and Strive’s initial support run through Brink.
My Analysis
Full disclosure first: I advise Project Eleven, which works on post-quantum security for digital assets, and I covered its quantum threat report in May. I have a professional interest in this problem being taken seriously, so discount my enthusiasm accordingly.
The money is real and aimed at a real problem. Measure it against the exposure. CryptoQuant’s estimate, carried by CoinDesk, puts 6.9 million BTC at risk from a future quantum key-recovery attacker: coins whose public keys are already visible on-chain, in early pay-to-public-key outputs, reused addresses, and other scripts with visible keys. Coinbase’s advisory board and Project Eleven’s numbers converge on the same range. About 1.7 million of those are early P2PK outputs whose keys have been naked since the network’s first years, including the outputs attributed to Satoshi. Every one of those keys becomes a target the moment a cryptographically relevant quantum computer exists. That is a count of exposed keys, not a forecast of simultaneous theft.
At CoinDesk’s July 21 reference price of about 66,800 USD, those coins were worth roughly 461 billion USD, which prices the week’s pledges at about one dollar of defense for every 23,000 dollars they are meant to protect (and that is the generous reading: Galaxy sits inside the consortium too, neither announcement says whether its 5 million counts toward the 15, the pledges span three years, and the consortium’s money covers Bitcoin security broadly rather than quantum work alone).
The attack side of the ledger keeps shifting too. On July 20 I covered a preprint that cut the logical width of a secp256k1 attack circuit to 835 qubits, a record bought with a much larger gate count, and Google’s March study of the elliptic-curve discrete logarithm problem reset credible end-to-end estimates downward. The frontier moves in one direction; the individual metrics trade against each other along the way.
My stronger claim: the cryptography is the easy half of this problem. Post-quantum signature schemes exist; NIST standardized ML-DSA and SLH-DSA nearly two years ago. Getting Bitcoin to use one requires community consensus on a soft fork, new address types, migration of live coins, and a political answer for dormant coins whose owners will never move them, Satoshi’s included. I described the authentication version of this trap in Trust Now, Forge Later: keys that were safe when created become liabilities before their owners react.
The members know exactly where the line is, and they wrote the charter onto the safe side of it: fund the work, take no position on the protocol. Prudent, and also clarifying. Nine members can pay for reference implementations, test vectors, audits, and migration tooling. No consortium, however well funded, can vote a migration into existence.
That decision stays where it has always been, with a decentralized community whose most prominent institutional voice spent that same stretch arguing the opposite instinct: four days after the consortium launched, Michael Saylor wrote that Bitcoin’s core design is set in stone and that protocol changes “should be rare, conservative, and driven by necessity, not ambition.” A quantum migration would be the largest protocol change Bitcoin has ever attempted. Both instincts now live inside the same consortium. The charter’s silence on protocol questions is how they coexist.
Timeline check: Executive Order 14412, signed June 22, orders federal high-value assets and high-impact systems onto post-quantum key establishment by the end of 2030 and post-quantum digital signatures by December 31, 2031; I covered the full mandate in June. The order does not regulate Bitcoin, and it does not need to. Bitcoin is built on elliptic-curve signatures, exactly the class of cryptography those deadlines exist to replace, and the deadlines already forming around policy like this reach custody rules, listing standards, and insurance questionnaires long before any machine touches secp256k1. Bitcoin’s governance never signed up for that clock, but it runs on it anyway. The money arrived late. It arrived.