1

Galaxy Pledges $5M to Help Bitcoin Prep for a Quantum Future (Before the T-Rex Shows Up)

What Galaxy is funding (short version)

On July 21, Galaxy Digital committed up to $5 million to jump-start Bitcoin’s preparations for a future where quantum computers are strong enough to matter. The money is meant to fund developers who hit concrete milestones, support research, and help set up a Quantum Advisory Council — basically a nerdy SWAT team for cryptography.

The cash can push proposals from whiteboards and papers into reviewed code, audits, and migration tools. But funding can’t wave a magic wand over Bitcoin’s decentralized process: upgrades still need buy-in from developers, miners, node operators, wallets, exchanges, custodians and everyday users. That coordination can take years.

Why Bitcoin needs a quantum plan (and how the fix might look)

Short answer: quantum computers aren’t a present-day free-for-all, but they could be someday. A big enough quantum machine running Shor’s algorithm could recover a private key from an exposed elliptic-curve public key and forge signatures. That means keys that are visible on the blockchain or revealed while a transaction sits in the mempool are potential targets.

There are two key exposure windows to worry about. First, some output types reveal a public key on-chain for a long time — things like pay-to-public-key, bare multisig, and the Taproot key-path (plus address reuse and certain wallet descriptors). Second, even outputs that hide keys until spending still expose a public key briefly when the transaction is broadcast and sits in the mempool, which opens a shorter attack window.

One draft proposal (BIP 360) suggests a soft fork introducing a Pay-to-Merkle-Root (P2MR) output. The idea is to drop the long-term key-path exposure that Taproot allows so keys stay hidden until they absolutely must be revealed, keeping options open for stronger signature schemes later. That proposal handles the long-exposure problem but doesn’t solve the mempool/rebroadcast exposure — post-quantum signatures are likely needed there.

Another draft, BIP 361, sketches an operational plan: it depends on an actual post-quantum signature standard (still to be decided) and imagines a roughly five-year, two-phase transition after activation. That timetable is a scenario, not a contract — once a design is chosen there would still be proposal reviews, security audits, wallet and node releases, institutional upgrades, and time for users to migrate funds into protected outputs.

National cryptography programs are already on multi-year schedules. In August 2024, standards bodies finalized a few post-quantum algorithms, including signature schemes, and some government directives (an executive order) are pushing federal systems toward post-quantum signatures by the end of 2031. Those moves don’t mean quantum computers will arrive on that exact timeline, but they underline why starting early makes sense.

At the end of the day, Galaxy’s funding is a push to speed research, audits, and tooling — the boring but essential plumbing work. Money can accelerate development, testing, and tooling, but it can’t force a unified upgrade. The trickiest risk may not be exotic math; it’s making sure exchanges, custodians, wallets and ordinary users can actually move funds safely without creating chaos. In short: the cryptography is one thing, coordination and migration are another — and both take time.