Jul 22, 2026 · 11:05 PM
Subscribe
Home Crypto

Galaxy Digital bets $5 million that Bitcoin can be made quantum-proof before Q-Day arrives

Galaxy Digital committed up to $5 million on July 21, 2026 to fund post-quantum cryptographic defenses for Bitcoin, including developer grants, research, and an advisory council. Researchers estimate over $700 billion in BTC sits in quantum-vulnerable wallets, with Q-Day projected to arrive between 2028 and 2033.

Janet Harrison
· 5 min read · 536 reads
Galaxy Digital bets $5 million that Bitcoin can be made quantum-proof before Q-Day arrives

Galaxy Digital has put up $5 million for Bitcoin's post-quantum defenses, and the timing is the story. If the worst forecasts are even close, Bitcoin's upgrade clock has already started.

The clock is running. Project Eleven has put the exposed pool at about 6.9 million Bitcoin, roughly one-third of circulating supply, because the public keys behind those coins have already appeared on-chain. Coinbase's quantum advisory board cited the same firm in June when it estimated roughly 7 million Bitcoin were exposed to a future quantum attack. That isn't a password problem. It's a cryptography problem.

Galaxy Digital, the crypto financial services firm led by Mike Novogratz, announced the Galaxy Bitcoin Quantum Readiness Initiative on July 21, 2026. According to Galaxy's own announcement, the program commits up to $5 million in developer grants, sets up a Quantum Advisory Council, and expands Galaxy Research's work for Bitcoin developers and the investors and policymakers who need to understand what's coming. The grants are aimed at quantum-resistant transaction proposals, post-quantum signature schemes, wallet and custodian migration tools, and security audits.

That is the right target. You can't lobby a private key into safety. Bitcoin relies on elliptic curve cryptography, and a sufficiently powerful quantum computer running Shor's algorithm could derive a private key from an exposed public key. No such machine exists today. That doesn't make the risk fake.

Galaxy's advisory council includes Barry Sanders, Scientific Director of Quantum City at the University of Calgary, Damien Bérubé, an MIT Sea Grant Knauss Fellow, and Eran Tromer, a computer science professor at Boston University. As The Block reported on the announcement, Galaxy will start accepting grant applications immediately and make awards against milestones rather than simply handing out upfront checks.

That last detail matters. Bitcoin doesn't need another round of anxiety posts. It needs code, review, test vectors, wallet paths, and the dull work that keeps money from being lost when a protocol changes.

The exposed coins are not a theory

The vulnerable bucket comes mostly from old pay-to-public-key addresses and address reuse. In early Bitcoin formats, the public key was visible from the start. In later formats, it usually becomes visible when coins are spent. Once exposed, it stays exposed. Project Eleven's Bitcoin Risq List has counted about 6.9 million BTC in that condition, and its 2026 report puts its baseline Q-Day scenario in 2033, with faster and slower cases at 2030 and 2042.

Here's the thing: you don't have to wait for Q-Day to be hurt by it. The Federal Reserve published research in September 2025 on "harvest now, decrypt later" risk, where an attacker stores encrypted or cryptographically useful data today and waits for future hardware to break it. For Bitcoin, the harvested material is already public in many cases. The chain is the archive.

Recent research has tightened the conversation. A PRX Quantum paper accepted on July 6, 2026 by researchers from Google Quantum AI, Stanford, the Ethereum Foundation, and others estimated that breaking secp256k1 could be done with no more than 1,450 logical qubits and fewer than half a million physical qubits on certain fast-clock architectures. CoinMarketCap's write-up of the same work noted Justin Drake's estimate of at least a 10% probability that a quantum machine could recover a secp256k1 private key from an exposed public key by 2032.

Call that low if you want. It's still too high for a network securing hundreds of billions of dollars.

Bitcoin has to move before it agrees

The main proposal Galaxy's grants are likely to touch is BIP-360, a draft Bitcoin Improvement Proposal for Pay-to-Merkle-Root, or P2MR. The BIP proposes a soft fork that adds a new output type similar to Taproot but removes Taproot's key-path spend. That design gives users a way to reduce long public-key exposure while leaving room for future post-quantum signature work.

P2MR is not a cure by itself. The BIP documentation says exactly that. It helps with long-exposure attacks, but full quantum safety still depends on adopting post-quantum signature algorithms and getting wallets, custodians, exchanges, and users to migrate without confusion. That is slow work. Bitcoin is built to make consensus hard, and usually that's a virtue. In this case, it's also the bottleneck.

The rest of the internet is already moving. Cloudflare said in October 2025 that a majority of human-initiated traffic through its network was using post-quantum encryption against store-now, decrypt-later attacks. OpenSSH has offered post-quantum key exchange by default since version 9.0 in April 2022, and OpenSSH 10.0 made ML-KEM hybrid exchange the default in April 2025. Apple rolled out post-quantum protections with its 26 operating-system releases, according to Cloudflare's 2025 review.

Governments are moving too. The White House said President Trump signed an executive order on June 22, 2026 directing federal agencies to transition high-value assets to post-quantum cryptography by 2030 or 2031 depending on use case. The NSA's CNSA 2.0 guidance has already pushed national security systems toward quantum-resistant algorithms. Bitcoin has no agency head who can issue that memo. You either build consensus early, or you discover too late that your timeline was fantasy.

Five million dollars won't solve a $700 billion exposure. Galaxy knows that. The money is useful because it turns quantum readiness from a conference topic into funded engineering work, with named reviewers and a public grant process attached. Frankly, that is the minimum Bitcoin should expect from the institutions that built businesses on top of it.

The hard question is no longer whether quantum risk is real. The hard question is whether Bitcoin can prepare while preparation is still boring.

Also read: Abu Dhabi just gave tokenized gold the regulatory stamp it needed to go mainstreamAugustus raises $180 million to give the world's fintechs a direct line into the US dollarWhat is token vesting and how it differs from startup equity

TOPICS
Janet Harrison has over 16 years experience in the financial services industry giving her a vast understanding of how news affects the financial markets, and an early adopter of blockchain technology and digital currencies. Janet is an active holder and trader spending the majority of her time analyzing blockchain projects, reports and watching new and upcoming projects and other initiatives in the industry. She has a Masters Degree in Economics with previous roles counting Investment Banking.
Related Articles
More posts →
Loading next article…
You're all caught up