Oxford’s Stefano Gogioso Ties Bitcoin (BTC) Quantum Break Risk to Fewer Than 500,000 Qubits

Oxford’s Stefano Gogioso says portable quantum memory will decide whether Bitcoin (BTC) breaks or is replaced; Google estimates fewer than 500,000 qubits.

(07:01 PM UTC)
4 min read
AI SummaryAI
  • Stefano Gogioso ties Bitcoin's (BTC) quantum fate to portable long-term quantum memory.
  • Google Quantum AI and Stanford estimate fewer than 500,000 physical qubits to attack Bitcoin.
  • NIST plans to retire current elliptic-curve signatures by 2030 and disallow them by 2035.
  • Hong Kong set its banks a quantum-readiness deadline of 2030.
k7rq2fdm

Gogioso’s Quantum Memory Thesis

The hardware that could decide the fate of Bitcoin (BTC) does not exist yet — and the same device, one Oxford researcher argues, would also build its successor. Stefano Gogioso, a quantum computing lecturer at the University of Oxford and co-founder of quantum security firm Spooqy, laid out the case in a post published on his company’s blog on Tuesday. Portable, long-term quantum memory, he writes, will be one of the most consequential milestones in the field, because it unlocks quantum money — the ultimate digital store of value. The idea has stayed theoretical for a simple reason: quantum states cannot be copied, so quantum banknotes cannot be forged, yet nobody can hold those states for long. The best laboratory systems keep one alive for seconds. A usable device would need stability measured in months or ideally forever, portability first inside a shipping crate and later in a pocket, and capacity running to billions of separate states. Gogioso rules out quantum RAM, since his design needs no random access — states are drawn in order and spent once. A sealed single-use cartridge, filled at a facility and spent state by state, would already suffice. His inevitability argument runs in two steps: a fault-tolerant quantum computer must keep fragile states alive at scale for as long as a calculation runs, so strip away the computing and a quantum memory device is what remains. The security model inverts an old assumption — classical key material is dangerous in transit because whoever copies it owns it, while an entangled pair carries no information in storage. A hijacked crate would cost a supplier its stock, not its secrets; the worst a corrupt supplier can deliver, Gogioso writes, is a tank of useless gas. He labels the effect cryptography by combustion: money built this way would ship with a fuel gauge.

Fewer Than 500,000 Qubits to Break BTC

The attack side of the ledger already carries a price tag. In March, Google Quantum AI worked with the Ethereum Foundation and Stanford University on the cost of attacking Bitcoin (BTC), disclosing the vulnerability estimate at fewer than 500,000 physical qubits. That figure only holds for a fault-tolerant machine — and fault tolerance, by Gogioso’s own definition, is quantum memory. The hardware that would expose Bitcoin’s signatures would, in other words, fuel quantum money too. Dates cluster on the attack side: the National Institute of Standards and Technology plans to retire current elliptic-curve signatures by 2030 and disallow them outright by 2035, Hong Kong has set its banks a quantum-readiness deadline of 2030, and IBM expects quantum computing to move its earnings by 2028 or 2029. The replacement side has no calendar — Gogioso declines to give one for quantum money itself, arguing for the inevitability of the resource rather than the imminence of a product. On portability, his second step, cryogenic machines will keep their states at the bottom of a refrigerator for years; atom-based designs differ, storing information in properties nature already keeps isolated, which turns the problem into hard engineering rather than physics. Daniela Herrmann, chief executive of quantum firm Dynex, drew the same boundary in a recent panel discussion: quantum money is the vision once the technology plays out, it is not available yet, and advancing chips must be handled with real responsibility. Google framed its work as responsible disclosure of vulnerabilities, not a forecast of a working machine. Readers tracking the market in real time can follow live spot and futures prices on Bybit.

One Roadmap, Two Futures

COINOTAG’s read: the awkward symmetry is the story. Every dollar chasing fault tolerance funds both futures at once — there is no version where quantum computers break the network while the alternative stays impossible. Gogioso’s own post leaves two questions open. Somebody still has to fill the memories, which keeps an issuer inside a system advertised as custodian-free; and a bearer instrument with no ledger offers no recovery, so a lost or decayed note takes its value with it. For a market built on proof-of-work scarcity and long-horizon HODL conviction — including treasuries run as a strategic bitcoin reserve — the thesis lands hardest on bitcoin maximalism. The industry is building the machine regardless; it has not yet decided which of the two things it wants. Follow our Bitcoin security coverage as the timelines firm up.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.