Crypto iconCryptoSep 17, 2026 ~7 min source read

Ledger CTO: Bitcoin faces a lengthy migration to post-quantum signatures, not an immediate breakage

Charles Guillemet says Bitcoin’s urgent problem is moving funds, wallets and backups safely to post-quantum schemes; SHRINCS raises new wallet-state and recovery risks.

Bitcoin quantum migration may take years, Ledger CTO says

Share this story

Send the public story page.

Useful takeaways from this story.

SHRINCS is a draft Bitcoin-specific post-quantum signature design that uses a smaller stateful signing path plus a larger stateless recovery path, changing wallet behavior and risk models.

Stateful signature use-once requirements introduce new wallet failure modes and recovery hazards for dormant coins and multi-device setups.

Protocol changes, hardware-wallet firmware, wallet software, backups and user adoption could take years to implement and reach network-wide coverage.

The useful part

Summary Ledger CTO Charles Guillemet says Bitcoin faces a migration challenge, not an immediate quantum crisis. SHRINCS combines stateful signatures with a stateless fallback while relying on SHA-256 for security today. Reusing one stateful signing slot can enable forged signatures, creating serious wallet-level fund theft risks.

How it works

  • Bitcoin BIPs 360 and 361 remain drafts, leaving post-quantum migration policy unresolved across the network.
  • Blockstream Research has argued that hash-based signatures offer conservative cryptographic assumptions and relatively cheap verification.
  • Its May research noted that standardized post-quantum signatures are much larger than Bitcoin's current 64-byte Schnorr signatures, creating pressure on block space and transaction throughput.
  • The Bitcoin specification remains research work requiring review and consensus before any network deployment.
  • Guillemet wrote that the attacker does not necessarily recover the entire private seed, but the affected user's funds can still become stealable.

What to take from it

The specification remains unfinished, carries no assigned BIP number and states that its formal "security proof is TODO." ⚛️ Bitcoin does not have a quantum computer problem today. The final problem includes coins whose owners may have lost their keys or have not moved funds for many years. Guillemet said migration cannot be judged solely by the cryptographic strength of a replacement scheme because wallets, hardware devices, backup systems and multi-device setups must implement it safely.

Example or evidence

  • Researchers Alex Pruden and Conor Deegan said the scheme transfers a security-critical state requirement into wallets and custodial systems, where backup restoration or state rollback could lead to reuse of...
  • Blockstream's research frames the tradeoff differently, arguing that SHRINCS verification is dominated by SHA-256 calculations and can therefore remain computationally manageable even when signatures...
  • BIP 360, called Pay-to-Merkle-Root, is a separate Draft proposal designed to remove Taproot's quantum-vulnerable key-path spend and protect users against long-exposure attacks.
  • Share Link copied Bitcoin's post-quantum migration debate has moved toward wallet security and dormant-coin handling after Ledger CTO Charles Guillemet argued that choosing a new signature scheme may prove...

Details worth keeping

Ledger CTO Charles Guillemet said in a technical analysis published by Ledger that "Bitcoin does not have a quantum computer problem today," while warning that migration research, software implementation, hardware-wallet changes and user adoption could take years. He said no cryptographically relevant quantum computer capable of breaking Bitcoin's current signatures is known to exist today, while the timing of such a machine remains uncertain. His review focuses on SHRINCS, a draft Bitcoin-specific post-quantum signature proposal that combines a smaller stateful signing mechanism with a larger stateless recovery path.

Related coverage

  • Cryptoslate: Coinbase's September workshop shows signature choices and operational migration must advance together across exchanges, wallets and key-management systems.
  • Fortune: The crypto industry has been preparing for 'Q-Day' for years says a Franklin Templeton crypto exec.
  • U: Ethereum's layer 1 fully resistant to quantum-computing attacks by December 2029.
  • Cryptopotato: Rushing early into post-quantum cryptography could create risks, including bugs or scams posing as wallet upgrades.
  • Crypto: An XRPL contributor outlined hybrid post-quantum testing for 2027 and a 2028 mainnet target, though no formal roadmap confirms it.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app