Policy

The 2029 Deadline Is a Story. The Exposed Public Key Is the Problem.

CryptoSam

Here is the error: a technical brief circulating this week describes BIP-361 as a "staged migration from ECDSA to Schnorr signatures" and files it under the heading of quantum resistance. That sentence is wrong in a way that matters. Schnorr signatures on Bitcoin are computed over secp256k1 — the same elliptic curve that ECDSA uses. Shor's algorithm does not distinguish between them. It breaks the curve. Swapping one signing scheme for another on the same curve is a UX improvement, a privacy improvement, and a verification-efficiency improvement. It is not a single qubit of post-quantum defense.

Tracing the gas leak where logic bled into code: this is where most readers will absorb a false comfort and move on. I want to stop there, because the mistake is not isolated. It sits inside a larger narrative — one the US government just spent real money to accelerate, and one that Ethereum has attached a hard date to. On September 10, the US Commerce Department took equity stakes in three quantum hardware firms through the CHIPS Act framework. The number most outlets repeated was roughly $300 million. The names were Rigetti, D-Wave, and Quantinuum. Within hours, timelines began collapsing in the discourse: 2029, Q-Day 2030, a window that is closing.

Context first.

Post-quantum cryptography (PQC) migration is not a performance upgrade. It is a replacement of the mathematical assumption the entire settlement layer rests on. Today, Bitcoin and Ethereum both derive address security from the hardness of the elliptic curve discrete logarithm problem. A sufficiently large fault-tolerant quantum computer running Shor's algorithm solves that problem in polynomial time. The replacement candidates — lattice-based schemes like those in the NIST standardization pipeline, and hash-based constructions — rest on different hardness assumptions, none of which have been broken by a quantum algorithm to date.

The engineering distance between "we have a proposal" and "the network has migrated" is where this entire story lives. Bitcoin's relevant proposals, BIP-360 and BIP-361, are in discussion. They are not activated. Ethereum has done something structurally different: the Foundation stood up a dedicated post-quantum team and set a self-imposed deadline of December 2029 for migration completion. That asymmetry — one chain with a coordinator and a calendar, one chain with a mailing list and a disagreement — is the real content of the news, not the $300 million.

Now the part nobody is pricing correctly.

The quantum threat does not attack addresses. It attacks exposed public keys. This distinction is the whole ballgame, and it is routinely flattened. In the UTXO model, an unspent P2PKH output that has never been signed is protected by a hash, not by the curve. Hashing is not what Shor's algorithm breaks. Those coins are, relatively speaking, safe. But the moment that output is spent — or in the older P2PK format, which committed the public key directly to the script — the public key sits on-chain forever. From that point, a quantum adversary derives the private key and takes the coins.

I spent part of last year modeling the aged-UTXO set against this rule, and the result is uncomfortable. The highest-risk category is not active coins. It is early P2PK outputs, including the roughly one million BTC attributed to Satoshi-era addresses, whose public keys have been visible since the genesis era. In the silence of the block, the exploit screams — it has been screaming for sixteen years, and no one could hear it because no machine could act on it.

So when I look at the three companies the US government just bought into, I look at their architectures, not their tickers. D-Wave builds quantum annealers. Annealing is a specific computational paradigm optimized for optimization problems. It does not run Shor's algorithm. It does not factor integers. Its relevance to breaking ECC is, at best, indirect and probably nonexistent. The genuinely threatening architectures are gate-based, fault-tolerant, general-purpose machines — the category Rigetti and Quantinuum are working in, alongside IBM and Google. Reviewing the announced funding allocation, roughly a third of the capital went to a company whose hardware cannot, by design, threaten the curve. That is not a scandal. It is a data point about how the narrative is being constructed versus how the technology actually works.

The headcount figures being cited — IBM's trajectory toward a "Starling" system by 2029, Google's sub-1200 logical-qubit estimates — are projections and design targets, not measurements. As of the last published hardware milestones I reviewed, no gate-based system is close to the millions of physical qubits required for fault-tolerant Shor execution at cryptographic key sizes. The practical attack horizon is not 2029. It is later, and "later" is doing an enormous amount of undisclosed work in every timeline you have read this week.

This is where I part ways with both the panic and the complacency.

The most overestimated risk is an imminent quantum break. The most underestimated risk is coordination failure. The cryptography is the easy part. Lattice schemes exist. They have been studied for two decades. The hard part is moving three hundred million wallet holders, thousands of DeFi contracts, every exchange custodian, every hardware wallet firmware, and every indexer off one signing scheme and onto another without losing funds, bricking assets, or splitting the network. Based on my audit experience with cross-layer signature migrations, the application layer is always the bottleneck — and on Ethereum, signature verification logic is embedded inside immutable contracts that were never designed to be upgraded.

Ethereum's 2029 deadline is a coordination device, not a technical guarantee. It exists because someone at the Foundation understood that a decentralized system will never migrate without a forcing function. That is a rational move. It is also, structurally, a centralized decision imposed on a system whose value proposition is that it has no central authority. Governance is just code with a social layer, and the social layer just published a calendar.

Bitcoin cannot do this. BIP-361 contains a provision that would, after a transition window, restrict or deprecate old-style signatures. Read that carefully. It means coins that never migrate can, in principle, become unspendable. For active holders, this is a nudge. For the Satoshi-era P2PK outputs, whose keys may be lost or whose owner may be gone, it is closer to a functional seizure decided by whoever ships the consensus change.

That is the powder keg nobody is discussing. Bitcoin's entire cultural identity is built on absolute property rights and credible immutability. A proposal that renders some coins unspendable by policy is, in the strictest sense, a redistribution of rights justified by a threat that has not materialized. Optics are fragile; state transitions are absolute. If this provision survives into activation, I expect a legitimate fight — and a legitimate fight on Bitcoin has historically resolved as a chain split. The 2017 block size war is the reference implementation.

Here is my contrarian read for this cycle. In a sideways market where everyone is hunting for asymmetric setups, the quantum narrative is being traded in the wrong instrument. The durable beneficiaries are not BTC and ETH spot — those are slow variables whose price barely registered the funding news. The beneficiaries are the PQC tooling and migration-services layer, and, selectively, the gate-based hardware names. The narrative also seeds a category of new L1s that will market native quantum resistance as a differentiator. Some of those will be real engineering. Most will be slide decks wearing a lattice-shaped logo. Watch for the pattern: a whitepaper that cites NIST standards by number but never publishes a testnet signature.

On regulation, note what the equity stakes actually encode. When a state acquires ownership in the companies capable of breaking public-key cryptography, the relationship between that state and cryptographic networks stops being a technology race and becomes a governance question. Whose standardization process defines "quantum-safe"? Whose export controls decide who gets the migration libraries? NIST's PQC process is the de facto global standard, which means every chain that migrates is adopting a US-curated assumption set. That dependency is not written into any BIP, and it should be examined as carefully as the algorithms themselves.

The relevant signal to watch is not a hardware keynote. It is the first signature from a long-dormant early address — whether migration or compromise, the market will not know the difference for hours, and that ambiguity is the actual tail risk. Second signal: whether the restrictive clause in BIP-361 survives technical review or gets stripped. Third: whether Ethereum's PQC team ships a working devnet signature scheme before the deadline, because that is the first real proof that coordinated migration is possible at all.

The 2029 date is a story we are telling ourselves to create urgency. The exposed public keys are the problem we actually have. One of these is a calendar. The other is mathematics, and mathematics does not negotiate its deadline.