Cardano founder Charles Hoskinson has warned that quantum computing could eventually threaten Bitcoin’s position as the world’s largest cryptocurrency if the network cannot coordinate the upgrades needed to protect vulnerable coins.
Hoskinson framed the issue less as an immediate cryptographic emergency and more as a test of Bitcoin’s governance model. Bitcoin has survived exchange failures, regulatory pressure, internal disputes and the disappearance of its pseudonymous creator, Satoshi Nakamoto. A sufficiently powerful quantum computer, he argued, would present a different kind of challenge because responding could require a contentious change to the protocol and the migration of existing funds.
“The issue with Bitcoin is it’s frozen in time. It’s very difficult to change anything,” Hoskinson said.
He argued that this resistance to change, often treated as one of Bitcoin’s strongest qualities, could become a liability if developers, miners, businesses and users fail to agree on a response before quantum computing becomes a practical threat.
Hoskinson said Bitcoin could lose its top position if its governance structure makes meaningful progress impossible or if the changes needed to address quantum computing undermine the characteristics that make people use the network.
His comments do not mean that existing quantum computers can currently steal Bitcoin. The threat centers on whether a future cryptographically relevant quantum computer could derive private keys from exposed public keys by breaking the elliptic-curve cryptography used to authorize Bitcoin transactions.
Current machines are not known to possess that capability. The timeline for such a breakthrough remains deeply uncertain.
Still, the broader technology sector is no longer treating post-quantum security as distant science fiction. The US National Institute of Standards and Technology finalized its first post-quantum cryptography standards in 2024 and urged organizations to begin preparing for migration. The standards are designed to resist attacks from both conventional and quantum computers.
For Bitcoin, the technical concern is unevenly distributed.
Coins held in addresses whose public keys have never been revealed may receive some protection because the blockchain initially exposes only a hash of the public key. Once a user spends from many common address types, however, the public key becomes visible. Older output formats and reused addresses may already expose public keys directly.
Researchers and Bitcoin developers have debated estimates suggesting that millions of BTC could potentially become vulnerable under certain quantum-attack scenarios. One review summarized by Bitcoin Optech estimated that between 4 million and 10 million BTC may be exposed to potential quantum theft, depending on which outputs and attack assumptions are included.
That range includes another political landmine: coins believed to belong to early miners, including addresses commonly associated with Bitcoin’s earliest years.
A future migration could require owners to move funds into quantum-resistant addresses before a deadline. But what happens to coins that do not move?
Leaving them spendable could allow a quantum attacker to take them.
Freezing them could amount to making valid coins permanently unspendable through a protocol change.
Either option would force the Bitcoin community into an argument that cannot be solved by cryptography alone.
Hoskinson contrasted that uncertainty with Cardano’s formal onchain governance system.
Cardano completed its transition to decentralized onchain governance through the Chang and Plomin upgrades. ADA holders can participate directly or delegate voting power to delegated representatives, known as DReps. Governance actions can cover protocol updates, treasury withdrawals and future hard forks.
“With Cardano, we’re going to have to make some decisions about what to do with quantum-vulnerable infrastructure,” Hoskinson said. “And if there needs to be a migration, we can have a vote, and then there could be an onchain function to do that.”
His argument is that Cardano has a visible process for making difficult decisions, while Bitcoin relies on rough social consensus among developers, node operators, miners, exchanges, custodians and users.
Bitcoin does not have token-weighted onchain voting or a central authority capable of ordering an upgrade. Protocol changes are proposed publicly, reviewed over long periods and adopted only when participants voluntarily run compatible software.
That system intentionally makes sweeping changes difficult.
Supporters say the friction protects Bitcoin from capture. A wealthy group cannot simply buy voting power and rewrite monetary policy. A foundation cannot compel nodes to accept a new rule. Developers cannot unilaterally alter the 21 million BTC supply limit.
Critics see the same structure as institutional paralysis.
Hoskinson belongs firmly in the second camp.
He described Cardano as a “spiritual successor” to Bitcoin, arguing that it preserves parts of Bitcoin’s original philosophy while correcting problems that Satoshi lacked the time or expertise to solve.
“Cardano is, in many ways, a spiritual successor,” he said. “It reflects correcting a lot of things that I think that Satoshi couldn’t get around to because of expertise or time but was directionally moving there.”
Hoskinson entered the cryptocurrency sector through Bitcoin roughly 15 years ago and later became one of Ethereum’s original co-founders alongside Vitalik Buterin. He subsequently left Ethereum and co-founded Cardano, which uses proof of stake rather than Bitcoin’s proof-of-work consensus system.
Cardano attempts to sit between Bitcoin’s emphasis on monetary rules and Ethereum’s focus on programmable applications. Its ADA token has a market capitalization of more than $6 billion, placing it among the 20 largest crypto assets.
Hoskinson also said Cardano is preparing for what he described as the network’s biggest upgrade to date, claiming the changes could make it 60 times faster.
He did not provide full technical detail in the remarks, but Cardano has been developing scaling improvements intended to increase throughput without abandoning its extended unspent transaction output accounting model.
The quantum argument, however, is not settled simply because Cardano has formal voting.
Onchain governance can make decisions more explicit, but it does not automatically make those decisions correct. Voting participation can remain low. Delegated power can become concentrated. Large holders may gain disproportionate influence. Technical upgrades can still take years to design, test and deploy.
Bitcoin’s slower system has also shown that it can change.
Segregated Witness altered transaction structure and expanded effective capacity. Taproot introduced Schnorr signatures and new scripting capabilities. Both were major consensus upgrades, even though reaching activation was slow and politically difficult.
Bitcoin developers are also actively discussing quantum-resistant address formats, migration plans and alternative signature systems. A draft proposal for a quantum-safe address format appeared in 2024, while later discussions explored phased soft forks that could first introduce post-quantum outputs and eventually restrict spending from vulnerable addresses.
That weakens the claim that Bitcoin is technically frozen.
It does not eliminate Hoskinson’s deeper point.
Designing a quantum-resistant signature scheme may prove easier than persuading the entire Bitcoin economy to adopt it, move old funds and decide what to do with coins that remain behind.
The danger is not that Bitcoin developers have no ideas.
They have several.
The danger is that every available path creates winners, losers and uncomfortable questions about ownership.
Hoskinson Is Right About Bitcoin’s Governance Problem but Wrong to Call the Race
Quantum computers are not stealing Bitcoin today.
Let’s get that out of the way before this turns into another crypto panic cycle.
There is no machine sitting in a lab quietly cracking Bitcoin wallets while traders argue over candles. Nobody has demonstrated a quantum computer capable of breaking Bitcoin’s elliptic-curve signatures at the speed and scale needed to raid the network.
So no, BTC is not about to get nuked tomorrow morning.
Hoskinson’s warning still matters.
Not because quantum computing is close enough to justify panic. Because it exposes the one problem Bitcoiners hate discussing: what happens when doing nothing becomes riskier than changing the protocol?
Bitcoin’s resistance to change is usually a feature.
I’d argue it is probably the main feature.
Anyone can propose a new rule. Nobody can force the network to accept it. Developers write code, but node operators choose what to run. Miners order transactions, but they do not own the consensus rules. Exchanges can influence markets, yet they cannot rewrite your node from across the internet.
Messy.
Slow.
Painful when everyone disagrees.
That friction is why nobody has casually raised the 21 million limit or pushed through a foundation-controlled rescue package.
But quantum migration would not be casual.
It could force Bitcoin into the ugliest governance fight in its history.
The cryptography is only the first layer. Assume developers agree on a post-quantum signature system. Great. Now convince wallets, exchanges, miners, custodians, payment companies, institutional investors and millions of individual holders to support it.
Then ask everyone to move vulnerable coins.
Simple, right?
Not even close.
Some owners are dead. Some lost their keys. Some do not follow technical debates. Some funds sit in cold storage specifically because their owners do not want to touch them for years. Some outputs may belong to Satoshi. Others come from hacks, abandoned wallets or early mining.
A migration clock starts ticking.
A massive chunk of supply does not move.
Now what?
Keep those coins spendable, and a sufficiently capable quantum attacker may eventually sweep them.
Disable vulnerable spending, and developers are accused of confiscating coins that remain valid under the original rules.
That is the real grenade.
I’ve watched Bitcoin governance fights over changes far smaller than this. Block-size arguments split communities, companies and chains. Taproot activation produced months of debate despite broad technical support. Imagine the mood when the proposal can be summarized as: move your coins or risk losing them, and after a deadline we may freeze whatever remains.
Good luck keeping that civil.
Hoskinson sees this and points at Cardano’s voting machinery.
His pitch is clean: Cardano can put the question onchain, let representatives and stakeholders vote, approve a migration and execute it through defined governance procedures.
There is real value in that.
You know who can propose an action.
You know who votes.
You know the approval thresholds.
You know how treasury money can be allocated.
You know how a hard fork moves from proposal to implementation.
Bitcoin is far fuzzier. Its governance is spread across mailing lists, developer meetings, GitHub repositories, miners, economic nodes, wallet providers and social consensus.
Nobody is officially in charge.
Which is comforting until you need somebody to coordinate the fire drill.
Hoskinson wins that part of the argument.
Cardano has a clearer decision process. Bitcoin has a clearer refusal process.
Those are not the same thing.
Still, I don’t buy his jump from “Bitcoin governance is slow” to “Bitcoin may lose the number one position.”
Lose it to what?
That part gets hand-wavy.
Bitcoin is not number one because it processes more transactions than Cardano. It does not.
It is not number one because it has richer smart-contract tooling than Ethereum. It does not.
It is number one because the market treats BTC as the crypto asset with the hardest monetary identity, the deepest liquidity, the broadest institutional recognition and the lowest perceived risk of arbitrary rule changes.
The slowness Hoskinson attacks is tied directly to that premium.
You cannot remove the friction without changing the product.
Cardano can vote faster because Cardano is designed to vote. Bitcoin moves slowly because its users do not want token holders governing money through weighted ballots.
That distinction matters.
Onchain governance sounds democratic until whales, custodians and organized voting blocs show up. A protocol vote does not magically reveal the objectively correct technical answer. It records which coalition gathered enough power under a predefined system.
Sometimes that is better than chaos.
Sometimes it is governance theater with a ledger attached.
I would not assume ADA holders will calmly approve the perfect quantum migration while Bitcoiners melt down. Cardano would face the same brutal questions around legacy funds, inactive wallets, exchange custody and incompatible software. Voting makes the decision visible. It does not make the trade-offs disappear.
There is another problem with the “Bitcoin is frozen” line.
It isn’t true.
Bitcoin changes deliberately. SegWit happened. Taproot happened. Developers are already working through quantum-safe output types, hash-based signatures, lattice-based approaches and staged migration plans.
That is not a network asleep at the wheel.
It is a network arguing about where to steer before there is a wall directly in front of it.
And honestly, that is reasonable.
Post-quantum signatures can be bulky. Some schemes create larger transaction data. Others carry implementation risks or complicated state-management requirements. Pick too early and Bitcoin could lock itself into a weak or inefficient standard. Wait too long and migration becomes a panic instead of a plan.
There is no clean timing.
NIST telling organizations to begin migrating does raise the pressure. The wider security industry has already moved from “quantum someday” to formal standards and transition planning.
Bitcoin cannot ignore that forever.
But banking systems can rotate certificates under centralized authority. Technology companies can push software updates. Governments can mandate deadlines.
Bitcoin has no administrator password.
That is the headache.
My gut says the network will eventually adopt a post-quantum path, probably long before a machine can raid exposed keys in real time. It may begin as an optional output type. Wallets will start supporting it. Exchanges will gradually require safer withdrawal formats. Old address types will become socially discouraged. Only later will the community confront restrictions on vulnerable spending.
Slow migration rather than emergency surgery.
That is the least insane route.
The market may even reward Bitcoin for handling it cautiously. A successful migration would prove that the network can defend itself without giving a foundation or a voting cartel control over the rules.
Hoskinson’s challenge is useful because it forces Bitcoiners to stop treating immutability like magic.
Bitcoin is not immutable.
Its transaction history is extraordinarily difficult to rewrite. Its consensus rules are hard to change. Those are different claims.
Quantum computing could force a rule change precisely to preserve the thing users thought was immutable: their ownership.
There is the paradox.
Refuse to change, and old coins may become stealable.
Change too aggressively, and the network may compromise property rights or fracture into competing versions.
No slogan fixes that.
Cardano’s governance gives it more procedural tools, but Hoskinson is also talking his own book. He is comparing Bitcoin’s weakest-looking feature with one of Cardano’s central selling points.
Fair game.
Just don’t mistake it for detached analysis.
The 60-times-faster claim deserves the same skepticism. Huge throughput numbers sound great during interviews. Then engineering shows up with trade-offs involving validation, storage, bandwidth, node requirements and application demand.
Speed without usage is empty block space.
Speed without decentralization is a database.
Speed without stable software is a future incident report.
Cardano needs to deliver the upgrade under real conditions before the multiplier means much.
That does not make the work fake. It means the number is marketing until the network proves it.
Hoskinson has identified the right stress point but is overselling Cardano as the obvious answer.
Bitcoin’s quantum problem is governance.
Cardano’s governance problem is legitimacy and concentration.
One network struggles to decide.
The other can decide, but still has to prove that its decision-making system cannot be captured, ignored or turned into whale politics.
What would I watch?
Not quantum-computing headlines. Most will be clickbait.
Watch whether Bitcoin wallets begin supporting post-quantum commitments or new address formats. Watch whether exchanges discuss migration standards. Watch whether developers converge on a signature family. Watch what they propose for lost, inactive and early coins.
That last part decides whether this stays a technical upgrade or becomes a civil war.
And Cardano?
Watch whether its governance can push through the coming performance upgrade without confusion, voter apathy or a small group effectively deciding the result. That would make Hoskinson’s argument stronger than another interview ever could.
I’m not betting on Bitcoin losing the top spot because of quantum computing.
Not yet.
But I would not laugh off the threat either.
The code can probably be fixed.
Getting humans to agree on who absorbs the cost is the part that could break everything.
