Earlier essays looked at the problem of detecting attacks against digital assets involving quantum computers, focusing on the difficulty of attribution. There is an unstated assumption there— and more generally, discussions of quantum risk: an adversary in possession of a so-called “cryptographically relevant quantum computer” or QCRC will have no qualms about using it to steal every last penny of vulnerable funds they can locate on-chain. That simplified picture is worth challenging. Even a profit-motivated threat actor realizes there are limits to profiting from stolen goods. Stealing cryptocurrency is one thing, being able to fence/liquidate those assets at anything close to their fair-market value is an entirely different problem. In fact major thefts on blockchains often result in temporary dips in the price; they can even result in dips on completely unrelated chains1 as in the case of the Bybit incident from 2025. An attack using QCRC introduces an entirely new dimension to this tendency of thefts to devaluing the very assets the perpetrator walked away with. Once word gets out that the core principle underlying blockchain assets— person with the private key controls the funds— is no longer true in the presence of quantum-computers, it is no longer a matter of taking a small “haircut” to unload stolen assets: the market value of that asset can go to zero immediately.
To untangle the conflicting incentives and understand how quantum-attacks are likely to play out in the wild, it helps to clarify the threat-actors objectives. Roughly speaking there are three possibilities:
- Profit-motivated, effectively going long on the asset. The perpetrator plans to profit by selling the stolen assets. Interestingly there is alignment here between the interests of the attacker and the broader ecosystem— although obviously not with the interests of the specific victim targeted. In order to ensure getting highest price for their ill-gotten goods, the attacker wants to steer clear of driving prices to zero or destroying the entire ecosystem.
- Profit-motivated, going short. An entirely different way to profit from theft involves capitalizing on the second-order effects, such as widespread market panic. This is monetizable by betting against the asset, for example by buying put options on one of the bitcoin or ethereum ETFs.2 Flipping the script on the first persona, here the adversary does not care about the overall health of the ecosystem. Shaking investor confidence is the whole point, to the extent that loss of confidence can be exploited in a trading strategy.
- The state strikes back: not economically motivated, but ideologically driven to undermine confidence in a particular blockchain. For example a central bank threatened by the rise of non-sovereign monetary systems may want to reassert control by sabotaging bitcoin. The attacker objectives are similar to the previous example but they are no longer constrained by any trading strategy. Suppose a QC attack against Ethereum would cost a billion dollars but the available liquidity for shorting Ethereum ETFs only permits a half billion upside under best-case assumptions—namely, the price of ETH goes to zero. This is not a “useful” attack for the profit motivated adversary; the juice is not worth the squeeze. But it may well be worth it for a central banker nursing a grudge against ethereum or stablecoins.
Given this background, consider how each type of threat actor is likely to proceed.
Profit-motivated, long
This is at once the most straightforward motivation— old-fashioned greed— and also the most tricky category for monetization. Cryptocurrency theft is self-defeating at scale: public awareness of a major heist will both tank prices and increase the odds that various players in the ecosystem will overcome inertia to coordinate a response. For example they can reach consensus to treat the stolen funds as “tainted” and refuse to accept them for payment, or seize them if ever transferred into their custody as part of an attempt to cash-out into a different currency. In the worst-case scenario where the amount stolen is a substantial fraction of circulating balance or belongs to a systematically important project— witness the DAO breach of 2016— it may be enough to warrant a hard-fork, the blockchain equivalent of historical revisionism: undoing the theft by rewriting the past. To invert the old saying about credits dynamics for banks:
“If you steal a thousand dollars worth of cryptocurrency, it is the owner’s problem. If you steal a million dollars, it is your problem”
Stolen amounts aside, an attacker armed with a quantum computer faces an extreme version of the price impact: if word gets out that quantum-attacks have left the realm of academic speculation and executed successfully in the wild, the price can go directly to zero. Because it means that the only notion of “ownership” recognized on chain— control over private keys— has become meaningless; property rights have been superseded by a quantum-computing version of might-makes-right.
Here the attacker gets a lucky break: it is very difficult to provide attribution for security breaches, much less prove that a particular avenue of attack was involved. By the public nature of blockchains, everyone can observe that funds moved on-chain and based on protestations from the owner, that this movement was not authorized. Beyond that everything is open to dispute: was the root cause a ground-breaking quantum computer in the hands of the defenders or bush-league hardware wallet with bad entropy in the hands of the defenders? With the exception of addresses deliberately constructed as quantum canaries or tripwires, a quantum attack will not leave a tell-tale signature that can be used as proof beyond doubt that the Rubicon has been crossed. If anything, public opinion and Occam’s Razor will favor the more mundane explanation: garden variety human-error, supply-chain attack, disgruntled employee, infiltration by North Korean IT workers. Any one of these is a priori more plausible than having witnessed a historical first: nation states armed with quantum-computers, putting their exotic machinery to the task of making a quick buck. Also recall that victims have an incentive to exaggerate attacker capabilities: every company putting out a press release in the aftermath of an embarrassing incident refers to “sophisticated attackers” and “advanced techniques;” no one wants to admit their third-rate enterprise IT was owned by a bunch of script-kiddies. All the while more reason for public skepticism against any claim that some attack must have involved a quantum computer. About the only time that possibility would be entertained is if the target happens to be one of a handful of the largest institutional custodians. For example the highest-balance BTC address today belongs to the exchange Binance, at a staggering 250K bitcoin. Suppose those funds vanished tomorrow and the Binance security team swears on a stash of pre-IPO shares that they have found no evidence of a traditional breach of their custody system. In that scenario at least some observers may give Binance benefit of the doubt and classify the episode as the first likely use of quantum attacks in the wild. But this scenario is unlikely for reasons pointed out earlier: for a profit-motivated attacker, going after the highest balance address—and draining 100% of it in one shot— is a Pyrrhic victory.
What does an optimal strategy look like from an attacker perspective?
- Target small balances for each heist. Large balances are harder to launder and may increase the risk of a coordinated ecosystem response to quarantine or otherwise freeze funds before they can even get to the laundering stage. In the worst case scenario,
- Avoid wallets belonging to well-known figures or projects associated with security initiatives. Similar to the first concern, with a twist: some of these players may have sufficient clout in the eyes of blockchain users that their claims of the attack originating with a quantum-computer may have a modicum of credibility.
- Resort to the offensive analog of parallel reconstruction: assuming the wallet owner can be identified, orchestrate a traditional infrastructure breach of the same target as a diversion from the quantum attack. For example, deface the website, dump databases containing customer PII or otherwise create an overt, undeniable security incident to undermine market confidence in the security of that organization. A blockchain theft by quantum computer coinciding with such a traditional breach is more likely to be interpreted publicly as part of a single event— despite protestations to the contrary by the organization insisting their cold-wallets are completely air-gapped from the compromised infrastructure. In that scenario, it would be difficult for the defenders or neutral observers to argue that some shadowy organization with unprecedented quantum capabilities is behind the attack.
Profit-motivated, short
The observation that headline-making blockchain thefts result in panic selling and price dip suggests another intriguing possibility for profiting from a quantum computer. One can carry out the heist but instead of attempting to liquidate the stolen assets, instead profit indirectly from the downward price movement. A “socially-responsible criminal” could even return the funds once their position is closed, alleging that it was all part of an emergency white-hat hacker rescue of vulnerable assets.
This approach runs into several, closely related limitations:
- Compared to selling a stolen asset with a haircut, the upside from betting on a marginal price decline is limited. It would require building a substantial position to generate the same returns as laundering what is essentially free money taken from another blockchain address. Unless of course the expectation is that the asset value will go all the way to zero, in which case see point #5.
- Short-selling or buying put options on that scale requires locating massive liquidity in thinly-traded markets to take the opposite side. In theory short interest in asset can exceeds its market cap—as the GameStop debacle demonstrated— but this is not the case for most cryptocurrencies.
- Building up these positions will require upfront investment of capital. Put options are not free. A short position has collateral requirements proportional to risk. (Perpetual futures may offer one way out of this problem.)
- It creates exposure to counter-parties and trading venues. Exchanges that allow margin trading and perpetual futures actively monitor open positions, and may close out even profitable positions to avoid getting into a state where the counter-parties on the other side exceed risk tolerances. Alternatively the venue itself may go under, converting an otherwise winning bearish bet into a loss before the position can be closed.
- In the extreme case, if the theft is convincingly attributed to a quantum computer, it would completely destroy confidence in not only the security model of that particular blockchain but virtually every digital currency. Even if the original theft occurred on say Bitcoin, the contagion would spread to wipe out Ethereum, Solana and every other layer-one dependent on the same vulnerable cryptography. In that case it becomes unclear if realized paper profits can be captured. Trading would likely be halted and some option contracts may not be fully settled. There would be a total, correlated crash of the market.
- A massive, well-timed short-position right before a major price decline attracts attention. An exchange with a robust market integrity program could investigate further or notify regulators of what looks like potential insider trading. (It is insider trading in one sense— the customer was privy to material non-public information, namely that they were about to commit a heist that would result in a sharp price decline.) Threat actors are more likely to get away with this on smaller, less-scrutinized venues or on-chain decentralized exchanges, but then the liquidity problem is worse.
All of this also assumes that the theft in question will trigger a price crash at the right time. Depending on exactly how the event plays out, it may even have the opposite effect. For example if the stolen funds were “burned” either explicitly by the perpetrator moving them to a blackhole address or by consensus among the community to treat those funds as blacklisted— due to say OFAC sanctioning the address— the net effect is a reduction in the money supply. For a deflationary system like bitcoin where the supply is capped, that should theoretically increase the value of every other bitcoin held.
For all these reasons, betting on a temporary price dip does not look any more profitable than old-fashioned theft.
Undermining cryptocurrencies
While a precision strike to profit from temporary price shocks are tricky to engineer, quantum-armed attackers will have an easier time arrange for what might be called the “nuclear option:” drive the price of almost every digital asset to zero, by proving that the notion of ownership as recognized cryptographically on blockchains is meaningless. It is not even necessary for a single penny to be “stolen” on-chain in the traditional sense. Simply proving that the capability exists— for example, by recovering a private-key for a deterministically generated, so-called “nothing up my sleeve” or NUMS public key that controls exactly zero value on chain— would send the same message just as convincingly.
That nuclear option however carries a strategic cost: the attacker is forced to tip their hand and provide proof that a particular attack was carried out using a quantum computer. This is the inverse problem of the attacker trying to fence stolen assets without inducing market panic. Recall that monetizing a quantum theft requires going to great lengths to disguise an extremely sophisticated attack as a garden-variety security breach. A government hell-bent on destroying bitcoin has the opposite problem: they must prove beyond doubt that a QC capability exists and this capability can target any exposed public-key.
The intelligence downside of such a disclosure would be enormous. As long as everyone believes that quantum computers are hypothetical risks belonging to the distant future, complacency reigns. There is no rush to replace classical algorithms with quantum-safe counterparts. At least some potential targets of interest will continue to use vulnerable systems. That is a win from the intelligence perspective: more encrypted traffic that unbeknownst to the enemy can be intercepted and decrypted, more vulnerable authentication systems that can be bypassed. Disclosure of QC capabilities in the wild would serve as a wake-up call, alerting potential adversaries to the exposure. There is historical precedent for cryptographic breakthroughs being protected at great cost, by deliberately not acting on all intelligence obtained from successful decryption. Occasionally letting the enemy get away with known movements in some minor skirmish was deemed preferable to revealing a capability that can change the course of the conflict.
That creates a dilemma for a nation state threatened by the existence of non-sovereign money. No matter how much disdain central bankers may harbor for bitcoin, states’ willingness to wipe out the entire cryptocurrency ecosystem must be balanced against the intelligence value of keeping the existence of QC capabilities secret. As a weapon, cryptographic capabilities have an inverse logic compared to nuclear weapons: states crossing the threshold of nuclear capability rush to announce their new-found prowess with a mushroom cloud, in order to put their adversaries on notice and reshuffle the balance of power. A state that builds a quantum-computer capable of breaking widely deployed algorithms has great, vested interest in keeping that breakthrough a closely guarded secret, in order to lull adversaries into a false of security about continuing to use those algorithms.
What this suggests is that a nation-state may redirect their QC capability into economic objectives— such as systematically trying to undermine all cryptocurrencies— only when disclosure of that capability is already imminent and can not be prevented.
CP
1 This is not completely irrational investor psychology, even as some critics pile on cryptocurrency investors as exhibit A for irrationality: stolen Ethereum is often converted to other assets by bridging or trading for wrapped-equivalents on decentralized exchanges. So attackers’ end-game may well involve a market-crashing fire-sale of a different asset than what they originally stole.
2 It is also possible to bet against assets using DeFi lending pools but it is unclear how well any of those mechanisms would operate in the event of widespread chaos.