
Loading summary
Nick Carter
I think the assumption inherent in what Saylor is saying and what others have said is we will have a very clear notice period before Q Day comes. That's the assumption. It's. Well, you know, the technology will progress gradually and we will know. We'll be able to do the extrapolations and we'll know. All right, it's going to hit in 2041 or whatever, so all we have to do is target that day. But it's not like Y2K. Right. Nobody knows the day or the hour. Right. It will just happen one day.
David
Nick Carter, welcome to Banklist once again.
Nick Carter
Hello, gentlemen. Thank you for having me. Is this the seventh or eighth time? I don't know.
Sam
We're approaching double digits. Yeah. But I think this might be the longest gap since we've had you on. I heard you had a decently long podcast hiatus.
Nick Carter
No, I mean, I've been retired from podcasts. Yeah. But, you know, I heard someone was coming for my record on this show, so.
David
Yeah, I think it's a good time to have you on because I've. I've heard you're bullish on the eth. Bitcoin ratio, actually. Yeah.
Nick Carter
I mean, I'm already in trouble with the bitcoiners, so, you know. Yeah. I think if nothing changes in Bitcoin eth, BTC could look pretty interesting here. I agree.
Sam
Do you think that there is a window of possibility where Bitcoin really fails this challenge? Ethereum succeeds in overcoming this challenge, and then Ethereum takes the number one spot.
David
Wow, David.
Nick Carter
Yeah, I think that's possible. I don't want that to happen, but.
Sam
You don't want that to happen, but it's possible?
Nick Carter
Yeah. I mean, the complacency I'm seeing on the bitcoin side is really disconcerting and only matched by the Ethereum Foundation's proactiveness, proactivity. I mean, there's a deadline, right, to transition on 2029. Is that what they're saying?
David
Yeah, that's what the Google paper seems to say. We'll talk about this. So I guess maybe the theme of this episod to Saving Bitcoin, we're going to figure out how to save it today.
Nick Carter
Yeah, I. You know, that's not my base case. That's not my base case. I mean, I think things could go right, but the reason I'm getting in so much trouble and fighting so much is because I want things to go right. And it's going to take a lot of work for that to happen.
Sam
If you're already holding soul, here's something you may want to pay attention to. Galaxy One just launched Solana Staking and you can earn up to an estimated 6.5% in variable staking rewards on your soul with no platform commission fee charged throughout December 31, 2026. While many other platforms charge up to 35% commission fees on staking rewards, Galaxy One offers you 0% platform commission through December 31. Other fees may apply. You should see the terms. This is powered by Galaxy Digital's own validator infrastructure, one of the largest salon of validator operations in the world and now available to individual investors directly within the Galaxy One platform. Once you stake, rewards accrue and compound automatically, no active management needed. You can track everything in one place, including balances, rewards and tax reporting through taxbit. Getting started is straightforward. You can buy sold directly in the app or transfer it in. If you want to put your soul to work, you can now start staking on Galaxy 1 today. Click the link in the show notes to learn more and get started. Not investment advice Bankless isn't just a name, it's a genuine belief that you shouldn't need permission from an institution to use your money. Metamask has been around since the beginning of Ethereum and they carry the same DNA we do. MetaMask was my first wallet and well if you haven't opened up the app recently, let me tell you, they've been shipping creating the One app to finally replace your bank and exchange. You can trade just about everything right from within Metamask, leverage perps via hyper liquid prediction markets to polymarket tokenized stocks like Nvidia. And you can swap tokens gaseously and across networks and even spend your crypto with your Metamask card at real merchants all around the world. It's better than institution services, but from a self custodial wallet. And this is what we've been talking about for years. Money that's open and it's happening. So give Metamask trading features a look at the link below. The reason why you're getting into trouble is that the status quo for Bitcoin is something bad happens. And Bitcoin really likes the status quo. Like the the small blockers were the status quo. They won. Bitcoin always defaults to the status quo. And this is the one instance that we know in Bitcoin history where the status quo does not work and you're the one who's like pulling the alarm bells being like hey guys, the status quo is actually the failure scenario Here.
Nick Carter
That's precisely correct. Bitcoin governance is spectacularly unsuited to a threat that is of an uncertain timeline and requires total mobilization. It's not clear if bitcoin governance can accommodate that. Actually, nobody knows how it works. We're not even sure if it's possible to make a change to bitcoin, let alone a sweeping set of numerous changes that need to occur. So bitcoin works great when nothing has to change, that's, you know, its strength. But when there is something existential that requires a core infrastructural change, we've actually never dealt with that before, not in the whole history of bitcoin, ever.
Sam
Yeah.
Nick Carter
So this is the first time.
David
Yeah.
Sam
And that is, it's been the practice of bitcoin culture to create that reality. And that has been bitcoin's strength, to the detriment of all the other crypto assets, is that it has become incredibly hard to make changes to bitcoin. And this is the first time where that actually is its weakness, not its strength.
Nick Carter
Yeah, and one weird dynamic is, you know, bitcoin is this like, evolutionary environment where bitcoin selects for people that are, you know, relentlessly optimistic and, and are willing to ignore fuds, you know, for lack of a better word. And so now everybody that's sold because they're worried about something or other, the only people that are left are the people that ignored every successive wave of fud, whether it's energy or bcash, big blocks, or double spend attacks, or all the various fuds over the years. So now you have this ecosystem of people that just are optimistic 100% of the time and are totally happy with the status quo. But that's very ill suited for the predicament we find ourselves in.
David
You know what's so funny is what you're describing sounds like it's an immune system response, right? And maybe what you're saying is bitcoin has an overactive immune system because part of the immune system has been to fight fud. So David and I just did a recording yesterday with Michael Saylor, and this was post the Google Quantum paper coming out. We asked him about it. We were just like, hey, Michael, here's the situation. They say 2029, the SHOR's algorithm enhancements have got 20x faster. You know, like, is this something we should be worried about? And you have Satoshi's supply, you know, 2.3 million Bitcoin, according to the paper. Seems like a decision will have to be made if Quantum happens right and his response, which I think bankless listeners can, can go listen to it for themselves, was, was very much like, hey, there's two types of people in the world. There's optimists and there's pessimists, and you have to choose which one you want to be. I'm an optimist. Everybody else who is worried about this is an alarmist. That doesn't mean we shouldn't be prepared. But the core devs will figure it out. We always do. We'll come to contain anything otherwise and
Sam
we'll find a solution.
David
And so it's kind of the panic and take like it was just like, there's a bunch of Chicken Littles going around. You know, he compared this to kind of like other scares in the past, global warming, other things that haven't come to pass. Why should this time be any different? And maybe that's just part of the default immune system response. Maybe Michael is kind of representing the immune system at some level, kind of the cultural trait that many bitcoiners share.
Nick Carter
Yeah, there's panic ins and there's process trusters. And I'm a process truster, actually, generally speaking, you know, with regards to politics, I trust the process. With regards to this issue, I'm a panikin, which is embarrassing to admit because you never want to be a panikin, but I just think the data is actually pretty, pretty clear and trusting. The process is great when it's peacetime, but it's not peacetime, it's wartime. And the process in Bitcoin, it's very unclear as to how a change might even be effectuated, how consensus could occur. And I hear the same exact thing from the bitcoin developers, and I've been hearing from them a lot over the last couple days, and they told me the exact same thing. They say, you know, when it's time to make a change, we'll just go with what the community wants, the general will. And it's this kind of like incredibly vague concept. It's like, well, how are you going to solicit that input from the people? What's the mechanism to get this input from my seat, I'm the one providing that feedback. But they're not hearing the feedback right. So what happens If Coinbase and BlackRock and et cetera, et cetera, go to the developers and say, hey, we need to fix this? That will be perceived as an attack. So the mechanism that they say leads to success is something that they're also attuned to ignore. So it's very unclear to me how this problem would spontaneously solve itself, how they would even measure what the community wants. So we're actually in a kind of a huge pickle.
Sam
Fortunately for us, we actually were given some solutions by the writers, the authors of the paper that came out on Monday. We'll get to that, I think, further on in this conversation. But let's talk about these two papers that got revealed, released on Monday of this week. One was from Google, one was from another organization called Oratomic, another set of academia authors. Nick, can you just kind of like summarize the significance of these papers? What do we need to know about them as it relates to quantum and bitcoin and crypto?
Nick Carter
Yeah. So I'll start by being very, very explicitly clear. These are not academics that are saying they have broken elliptic curves. They're not claiming that they've built a scaled quantum computer that can do it. The hardware has not been built, right? No, hardware doesn't exist. The hardware that exists today is like miniature tiny versions of this stuff that can't do anything. Both of these papers pertain to resource estimates for what it would take to run a circuit, to run Shor's algorithm, to crack ECC256, which is the core cryptographic algorithm that powers most Bitcoin parts of Ethereum. So that's what it is. These are improved resource estimates. So they're trying to estimate how many logical qubits do you need, how many physical qubits, how many to Foley gates? Actually, I don't know how to pronounce that. I've only ever read the word. I've never heard anyone say it. So if is it toffely gates or toffoli gates, whatever that just means how many operations need to occur to run the circuit. And from that you can back out how long it would take in terms of wall clock time. So you devise an algorithm that are on shores to break ECC and then you make estimates as to what the requirements would be. Based on that, we can kind of look out into the future and say, well, we seem to be improving, you know, the logical qubit count by this much per year on this modality, you know, because they actually one was for superconducting qubits, one was for neutral atoms, different architectures. So, you know, based on these now lowered thresholds, we can look and say, well, we think actually might be easier than we thought to break ECC256. The Google Dan Benet, Justin Drake paper was pretty notable in that they didn't actually publish the circuit. They published a ZK proof of the circuit because they didn't want to tip their hand to some black hat. So I can go into much more detail, but that's at a high level what the papers are all about.
David
Let's talk about that last piece for a minute. So they didn't publish published the circuit. Instead they published a ZK proof that they had the ability to improve these algorithms in the, in the way that they were stating. Because this is kind of both methods are an improvement, a software improvement basically in Shor's algorithm, the ability to potentially attack and break ECC256. Do you think that this is a mark of these types of breakthroughs no longer being public? There's, there's something to the fact that this was a secret such that they couldn't tell people how they actually did it, or else they would inform black hat or adversaries or maybe nation states outside of the the United States. Have we also entered an era where some of these breakthroughs may not be so public? I mean there's almost like if we want to get tinfoil hats on, right? There's like kind of like if we know about this, what about what might we not know that nation states with cryptographers are actually executing on run with that. What do you think it means that they didn't actually publish the algorithms and how they did this?
Nick Carter
Yeah, I like to compare this to the race for a nuclear fission device, aka an atomic bomb. So what happened was in 1938 or 1939, someone theoretically proved that fission was possible with uranium isotopes. For the next year or so, all these physicists started self censoring because they didn't want to tip off their colleagues in Germany that were also working on the same idea. Then the Manhattan Project began and there was an official censorship regime. So then it was a total blackout. We are in the equivalent time, it's the equivalent stakes, frankly. And we're in the equivalent of 1940, where basically since 2024, since the Google Willow result, we have known that this was theoretically possible. There were no new physics discoveries that needed to occur. Now we're at the point where we just have to do the engineering. And so you do get scientists that are self censoring because they don't want China or North Korea or whomever to get this technology. And eventually we'll enter a hard censorship regime too. So then we'll just be in the dark. Yeah, I think it's actually a really. I'm glad they did it frankly, I can tell you these papers are published in consultation with the US government. So NIST and the NSA are fully aware of this and were aware, you know, well before the publication of the papers. And so this was done with government approval. But yeah, it doesn't surprise me that they censored the exact architecture, although it may not actually inhibit that much progress because they are, they're still demonstrating this is possible. So anybody independently working on it, that might be enough information for them.
Sam
I mean, if I was China, I would be like, thank you for informing me that you guys know something. I am now going to send all of my operatives to try and figure out what that thing is.
David
And I have names on the paper too, so thanks for that.
Nick Carter
Yeah. And it might be easier to hack these labs than actually do the physics work yourself, Right.
David
This comparison to kind of the fission bomb in 1940. I think I saw Scott Aronson make this comparison as well. So it's not just kind of a Nick Carter drawing these parallels, right?
Nick Carter
Yeah, I mean it's similar to that in some respects. It's also similar to the discussion around AI superintelligence, especially with regards to hard takeoff versus soft takeoff. Right. So that's a huge parallel, which is if it is the case that AI becomes recursively self improving really quickly, that's sort of maybe a very bad outcome. If it is the case that we do not get any kind of gradual Runway lead in to a CRQC cryptographically relevant quantum computer, if it's the case that it's more of a jump, a sudden break, that's also a very bad outcome. So what we're arguing about here, actually the crux of the debate is what is the first derivative? Actually even the second derivative look like of growth here. If it's abrupt, then we're in huge trouble. And one thing they said in the paper, in the Google paper is we think it's going to be abrupt.
David
And why did they say that they think it's going to be abrupt?
Nick Carter
Because of the engineering of quantum computers, which is once you sort of solve error correction at scale, you can just kind of add a bunch of logical qubit or physical qubits effectively and there's a net amount of noise reduction in the system. And you can go very quickly from a computer that can break 5 or 10 bits to 256 bits. So it scales, I think it's polylogarithmic is the scaling model. So that was actually the thing that I read on Monday whenever it came out that scared me the most was they are explicitly and these are the best subject matter experts in the world on their respective fields. Dan Benet, Justin Drake and the Google Quantum AI team. Craig Gidney on the Google team has written the two prior state of the art papers on this for rsa. He's the guy on this. They are saying collectively we should assume that it will be a threshold model and that we will not get significant prior notice before a CRQC exists.
David
We will not get significant prior notice, it'll just happen.
Nick Carter
So this is the notice, actually this paper is the notice.
Sam
This is our last warning shot. And then the next thing that will happen will be after actual real in production attacks in.
David
So this difference between a fast takeoff, a slow takeoff or a fast takeoff and a slow takeoff really is kind of this engineering problem of kind of scaling the physical and logical qubits. And what I was trying to ascertain was is this an engineering problem like the engineering problem of fusion, which is it's always like 10 to 15 years out, we can't seem to figure it out and it's still hypothetical, you know, may take many more decades for us to do. Or is this more like the engineering problem of like scaling up transformer architecture and AIs which is kind of a known thing, which is like you just add a whole bunch of hardware and compute and you get smarter AI. And it seems to be more maybe in the AI scaling side than fusion, which is like it's hypothetical. We may never get quantum computers. Is that your take?
Nick Carter
Yeah, it's kind of a little bit like both and then also not like either one. So like fusion, we sort of need new physics breakthroughs to get to a fusion reaction that produces energy on net, which is actually kind of similar in some ways to scaling up quantum computer so that the amount of net error reduction is negative as opposed to positive. Because there's this problem with quantum computers where you put a bunch of qubits together, it introduces error on net. But that fusion breakthrough type thing, the Willow Google processor in 2024 demonstrated that in my opinion, the way it is not like the AI scaling model is that what the transformer architecture showed us in I think 2017 was that you can hold some variables, fix and scale up some other variables, like the amount of data for pre training and you just get a better loss function mathematically out of that. We don't have that level of certainty yet where you can hold a bunch of variables, fix you, you increase one initial variable and you get a Better output? Well, we don't have that yet in quantum computing because there's like 30 different variables that you. You. All these different levers that you're pulling. And there's also six different major modalities, like types like what these things are made of, you know, so the two papers actually exemplify this. You have superconduction qubits. This is a Google paper. Those are just atoms that are super cooled to like 0.000 kelvin.01 kelvin or whatever. The challenge with scaling that up is you have to cool these atoms to incredibly, like, literally colder than outer space. Right. So that's why it looks like this big chandelier thing. All of that is cooling, refrigeration, and so it's really hard to scale that up and keep it super cold. Right. The other paper, the oratomic Caltech paper, they have a neutral atom modality. So it's a totally different architecture, doesn't have the same cooling requirements, but the clock speed is much slower, so way slower computation. So all of. And there's like five other modalities. There's photonics, and there's trapped ions. There's all kinds of stuff. So for each of these modalities, there's a different lab or a dozen or so labs working on it. So what we don't have is this equation where more X yields more Y. Because there's so many variables, these modalities,
David
I'm just kind of beginning to understand it. But the difference between the Google quantum paper and the oratomic paper was a difference in kind of a fast clock versus a slow clock. That's kind of what you're saying, and some of the implications. So for the Google paper, there was like a. A 20x reduction or improvement in Shor's algorithm for a fast clock type of attack. And that would literally mean if you're trying to crack an ECDSA key, it would take like nine minutes. This would also, they said in the paper, give you the ability to intercept transactions before they confirm. Right. Because you can do it in nine minutes. So if I'm sending Bitcoin, this is what I took it to mean. If I'm sending Bitcoin from myself to you, Nick, a quantum computer running this with enough logical and physical qubits could actually intercept that message. That's the fast attack. The other modality was kind of the slow attack. It would take longer to crack a key. Like a few days maybe to crack a key. You couldn't do that intercept transaction type of maneuver. But that's another whole path that can be pursued. And you're saying there's even more than these two paths? There might be like close to half a dozen of these paths, almost like mini transformer type architectures that could be pursued. Is that somewhat of the picture here?
Nick Carter
Yeah, that's why quantum computing is so hard to analyze is it's actually not just one thing. There's so many different approaches to the problem and they're actually proliferating. So like the superconducting qubit thing, that's like what most of the big labs do. That's what Google does, that's what IBM does. That's what you think of when you think of a quantum computer. But in recent years we've discovered better ways to get high fidelity, less noisy qubits. But that, yeah, they introduce different trade offs. So yeah, what you, what you're talking about, the on spend attack is what they call it in the paper. I call it a short range attack. This was actually the thing when I read the paper I'm like oh my God. I didn't expect that this would be the case. This whole time I've been studying quantum computing and its relevance to blockchains. I thought on spend attacks would not be possible, right? I thought the first attack, and this is based on modeling that Project 11 has done, for instance. I thought that the first attacks we would see on ECC would take 200 days. So like really long range attacks or maybe you know, month, a few weeks at least. I'd never ever seen a result with a low amount of logical qubits. Like the Google paper where they're saying no, this could be done in nine minutes. So it completely changes the threat model, right? My threat model going into this was we have to worry about the long range attacks and the coins that are published on the blockchain that we can't unpublish. So the satoshi coins. But this model now threatens all transactions. Because when you spend bitcoin, only on Bitcoin by the way, not Ethereum or Solana, when you spend Bitcoin you publish your public key to the world and you give the attacker a window of time to take the public key, reverse engineer the private key, broadcast a different high fee transaction and steal the coins.
David
This onspend attack, this short range attack that is basically like an ender of bitcoin transactions.
Nick Carter
It means that you have to fully transition the whole network into a post quantum exclusive regime before that computer is built. Because so we have less time than we thought.
Sam
It doesn't because it draws for the draw the example of like we're in a post quantum world. Bitcoin hasn't made the transition and I'm just a normal guy making a normal bitcoin transaction. And there's a motivated attacker who's got a quantum computer.
David
If you try to send it, your bitcoin gets yoinked.
Nick Carter
So you can kind of protect yourself from a quantum computer just by practicing Google Wallet Hydra hygiene.
David
Right.
Nick Carter
Like you use one of the newer types and you don't reuse addresses so you don't want to expose your public key. But that becomes irrelevant in the world of on spend attacks. So the whole system has to be 100% fully post quantum if you are to protect against short range attacks. Otherwise, you know, even if I'm spending out of a protected hashed address, I'm still exposed for the 10 minutes or 20 minutes it takes for that to confirm.
David
One other difference worth highlighting between these two papers. And again, they represent two modalities of quantum that can each be pursued and probably will be pursued in parallel. Right. So we had the fast clock from Google and the slow clock from or atomic. The fast clock method, the Google method. They both use Shor's algorithm, but the Google method was a 20x reduction in qubits. I believe from what was perceived before. The oratomic approach was a 50x reduction and improvement in the efficiency of Shor's algorithm. So was I reading that correct? And by the way, I didn't read the oratomic paper. This is. Claude helped me read this. Okay. Because it was out of my def. Okay, but like that even has a lower threshold in terms of the amount of logical qubits required to actually go crack some of our cryptography. Was I reading that correctly?
Nick Carter
Yeah, I mean as someone that is primarily concerned about long range attacks because that's the easier threshold to get to. Right. So I'm worried about what does the first attack look like and when does that happen. Right. And what does the quantum computer look like that that attack is possible on the oratomic. Caltech paper is the more concerning of the two because they, because neutral atom systems, the biggest neutral atom array that exists already is 6,000 physical qubits. Right.
David
Does that collapse down with kind of air correction like 50 or something logical?
Nick Carter
Yeah. So it's 6000, 6000 physical. Unclear what the exchange rate is. Logical. That's like the source of uncertainty. This oratomic paper doesn't actually talk about logical at all. It just says ECC could be cracked with between 10k and 26k. Physical, physical qubits. The prior estimates we had state of the art was half a million physical qubits, millions of physical qubits. So this is a vast fast reduction and it's with the neutral atom, which in my circles is considered the most promising approach actually.
David
Why is this? Because we don't need refrigeration like refrigeration kind of like, you know, zero kelvin temperatures and such.
Nick Carter
Because they're more stable. Yeah. And they have a lower noise ratio. So it seems based on the oratomic paper that you're getting a really good exchange rate between physical and logical. And so you could get to as few, they say as few as 10k physical, which is basically in the kind of range that we're in state of the art today. And I'm not saying this is going to be broken next week at all by the way. I know people think I'm an alarmist, but I mean you just have to read the papers and then compare them to what exists. It is quite frightening.
Sam
So to summarize things as I understand it and correct me if I'm wrong, we have two attack vectors that we need to account for. We have the long range attacks, which is all exposed wallets that are exposed as of today, notably the satoshi coins. But there's also a very large supply of otherwise dormant coins that have some chunk of them that are very likely to be lost and therefore are not going to move in the face of a quantum computer. These are the long range attacks. The, the operator of said computer has infinite amounts of time to crack these wallets and so we just assume that they're going to get cracked. That's one problem. That's the long range problem. That's going to be the, you know, perceived to be the first problem that we run into. And then there's the short range attacks is eventually once quantum computers scale up so incredibly powerful, powerfully, like no one is safe because your address which you have to reveal to make a bitcoin transaction gets revealed and then a quantum computer starts racing to crack your private key before your transaction lands. Is that these are the complete set of problems. Is there anything else?
Nick Carter
Yeah, I mean those are some big problems though.
Sam
The big problems. But I just want to make sure that we have them.
David
You know what something that's nice though. David. Some good news is my reading of the Google paper, there was no problem with proof of work. So I remember a few years ago there was some speculation that quantum computers could kind of like Nerf through like Grover's algorithm could kind of like Nerf bitcoin mining and hashing. And that doesn't seem to be a near term horizon problem.
Nick Carter
Yeah, I mean it is true that Grover's is a more efficient way to search for the pre image of a hash, but it's only quadratic at best. So take the square root of bitcoin mining and you have a slightly better bitcoin miner. No one that has an insanely good quantum computer would waste it on bitcoin mining. Yeah, that'd be terrible misuse of resources.
David
Okay, because they can proof works fine, whatever.
Sam
So we're down to these ver two two low number of each respectively, very large problems. I'll also say even though it's not the best outcome, the long range attacks, the satoshi coins, at least it doesn't break the whole blockchain. Like the blockchain still runs. Then with a short range attacks, then we start getting into the conversation of like, okay, is bitcoin. I can't even store my value on bitcoin if there's a short range attack all the time, right?
Nick Carter
Yeah, I mean it breaks the core assumption underpinning bitcoin, which is that the person with knowledge of the key is the owner of the coins. And that's pretty key, you know.
Sam
Okay, so Nick, it's April 2026 right now, the Google paper, two weeks before Google released the paper, they released a statement saying, hey, we are accelerating our quantum transition plans from where I think it was at 2032-2029. So they have moved up their own standard of when they are transitioning all of their systems to be post quantum. Do you think that that also means bitcoin needs to become post quantum by that same timeline? Or is bitcoin on a different timeline? What timeline do you think bitcoin is on?
Nick Carter
Yeah, I mean undoubtedly it'll be slower. I think it would be a little embarrassing if Bitcoin is trailing Google and Cloudflare has already migrated by the way.
Sam
Probably.
Nick Carter
This like Internet infrastructure that we're using right now is post quantum. The US government has this window of 2030, 2035 critical functions. By 2030, you know every CSO on the planet, every bank, and this is something Bitcoiners say, oh, quantum breaks everything. No, dude, everyone else is aware of this and actively mitigating it. Apple is on it. Cloudflare has already done it. Google has set themselves this incredibly near. That's 2.7 years away for the biggest Internet company on the planet. So I think it would be quite embarrassing if bitcoin was much later, because we like to think we're the state of the art, cutting edge guys, but we're actually going to be the laggards. And the problem is this transition for Bitcoin is there's a chain code paper about it. They said a reasonable time horizon is seven years, and they said maybe you can rush it and do it in two years. But there's so many parts of this that are slow. We have to agree that we're going to do it. We haven't even agreed. We have to pick some kind of cryptographic function. We have to determine how we're going to make the change. And we don't have any consensus on how changes get made in Bitcoin anymore. The last three soft forks all happen different ways, different activation pathways. Then everyone has to migrate their coins. Every single address on Bitcoin has to turn over every single one. That's 50 million addresses. That'll take three months if blocks are full the whole time. And then you want to give people time to migrate before deprecating their old coins, which you don't want to commit theft. Right. And then we also have to debate and deliberate and decide what we're going to do about these satoshi coins that can't migrate. That's a huge debate on its own. That's a fundamental debate. How long do you think all that would take? 5 years? 10 years? So yeah, I mean, I don't see it happening for Bitcoin before 2030.
David
Can I just add another problem to that list just to make sure we're cataloging it or I'm understanding it, which is it seems like some of the post quantum hashing algorithms that Bitcoin might need to adopt are radically less efficient than the cryptography it's adopting right now. So Justin Drake came on the podcast and said, by way of estimate, if Bitcoin's doing three transactions per second or something, if we use lattice space or something, that could drop it under one second, right? Bitcoin transactions per second could be 0.3. And so there's also the challenge of can we actually find performant cryptography for a blockchain based system? At least I think that's a problem. Google mentioned it in the paper, at least.
Nick Carter
Yeah, no, you're right. I mean the nist, the government body that standards standardizes things, they've helpfully provided with us three post quantum algorithms. There's lattice based cryptography. MLDSA is a variant of that there is hash based cryptography which Bitcoiners like and I actually think the Ethereum people like as well, as far as I can tell, because it introduces no additional new assumption. We already trust hashes, right? So lattices, we don't trust them. We think that probably they're hard to break, but it's actually the same model as elliptic curves. We don't really have a proof that elliptic curves can't be reverse engineered, but we just trust them because they've been around for a while. Lattices are the same, so it's kind of an unknown. Lattices are smaller, much smaller, but much bigger than elliptic curve. Elliptic curve signatures are tiny, like less than 100 bytes. So you're going to deal with a minimum 10x deterioration or increase in signature sizes and byte terms all the way up to maybe a thousand X. So obviously work is being done on this. But if you use hash based signatures like Sphinx, you know, you might, you might be dealing with 100-1000x additional resource requirements. Of course, if this happens, there would be an offsetting block size increase, so. Because that's not going to be controversial anymore because we're already changing so much, right? So okay, there wouldn't be another block
David
war you think, if there was a block size increase?
Nick Carter
No, because the fight around what we're going to do with Quantum is a much more contentious thing. If we agree we're going to fix Quantum, then it's just understood that there would be a block size increase. That's like a tiny detail, it's a footnote. But yeah, this is going to be a problem for actually every blockchain and it's a problem for Bitcoin, but relatively speaking it's actually more of a problem for the super high performance blockchains that are hyper optimized around tiny signatures and specific variants. So I mean, not to like name names, but Solana is going to have to rebuild everything from scratch and they've already massively optimized hardware around these signatures which they're going to have to rip out and replace. So if you're a very performant blockchain, it's actually a big problem because now you have these slow, ugly, clunky signatures.
Sam
So the deadline for Bitcoin to get over these hurdles, to solve these problems is Q day. Q day is defined, loosely defined as the day that a quantum computer becomes sufficiently capable that it can actually do these sum of attacks. But it's not actually a particular day, there's not a date in the future It's a pre. It's a prediction of when Q day actually does arrive. But, like, we do know that there is something out there. It's going to be called Q Day, and it's when these attacks start to like, come online. So, Nick, do you have, do you have like a sort of just predictive deadline, just an arbitrary date, that you kind of think it would be in the best interest of Bitcoin, of hitting that date, of becoming post quantum?
Nick Carter
Yeah, I mean, we don't know when qday is. Of course we do know that. It just got a lot closer. Everyone agrees. Everyone. We don't know when it is. We can only rely on what these companies building quantum computers expect. So their own internal published roadmaps. So we can look at what they're saying. So they're saying they expect to get to a scaled functional quantum computer for the most part. They all say around the early 2000s. So if you ask IBM or you ask Google or Microsoft or Quantinuum or Queira or SiteQuantum, generally late 2000s, early 2000s. But maybe they're biased because they're selling a product or they're raising money. You look at what the U.S. government and frankly most other governments, or they're putting the window in the early 2000 and 30s. Google's now put their deadline in 2029, which is very aggressive. So one nuance there though is you might want to upgrade long before you think Q day will happen. Right. Because if you're the US government, what China could do is just monitor your communications, read or store all your encrypted data, and then later decrypt it. So what you might want to do is just make sure that the encryption that protects that data is post quantum long before QDay comes. So the US government saying they want to upgrade between 2030 and 2035 doesn't necessarily mean they think QDay is falling in that range. But if I had to guess, I believe they will revise this forward, actually. So I think it's going to change to become earlier. But yeah, to answer your question, based on my analysis and the modeling I've done, which is primitive, I think it'll happen in between 2030 and 2035 based on extrapolating progress rates, because you're looking at two curves, the declining resource requirement curve and then the increasing hardware curve. So if you plot those, you get an intersection in the early 2000 and 30s.
David
Remind listeners 2030 is only four years away, so not a lot of time. You guys are both talking about Q day as if there's an inevitability about that day. Like it's going to happen, like quantum computers are going to happen. There have been some that are pushing back on that. And so Anatoly, founder of Solana I saw him saying, look, it's still hypothetical. We haven't really solved that engineering problem of us being able to scale up qubits in kind of meat space. And therefore it's kind of a hypothetical. The same way AI doomers will talk about hey, like what's your P doom? You know, you know, is AI going to kill us all or not? It's like something that can't really be known at this stage. What's your reaction to that? Like, I mean, is there some probability in your mind, Nick, that quantum computers will never happen or not in your lifetime? It could still be decades out. We'll find something. There's some reason on the engineering side that we won't be able to scale this out in the physical space.
Nick Carter
Yeah, that's certainly possible. That's definitely possible. The consensus of experts appears to be that it probably will happen. But of course there might be a fat right tail on when it happens. I mean Scott Aronson is a guy that I trust on this. He's a very well known professor of quantum computing and other disciplines. And he said in recent months, look, it's just an engineering challenge. There's no sort of fundamental physics things that need to be discovered.
David
And that's notable for him because he's been basically a skeptic of any kind of real world quantum scaling up to this point 100%.
Nick Carter
And he's really dramatically changed his tone in recent events, including reaction to this new paper. So yeah, I mean I think it's certainly possible, but why would we as bitcoiners? So we're meant to have a pretty paranoid outlook, right? Why would we want to be extremely lackadaisical about something that every other organization is preparing for? We look lazy. By contrast, if the US government has a mandate that all cryptography running through its veins be post quantum, if Google is doing it and Cloudflare, why would Bitcoin, this software project that defines money as a valid cryptographic signature exclusively, why would we not transition when everyone else is. We look terrible.
Sam
And something about like being paranoid about paranoia, like it's like it's self terminating, whereas as like they are Bitcoin culture is paranoid and then they are pointing paranoia at people being paranoid about quantum, like there's something self referential about that.
Nick Carter
Yeah, there's a conspiratorial tone inherent in Bitcoin culture, which is unfortunate. But yeah, I mean I find it to actually really bizarre. You know, Bitcoin Core used to be the most paranoid organization on the planet. You know they would write their own implementations of. I think they wrote their own implementation of ECDSA because they didn't trust anyone else, they didn't want any dependency and the whole thing is just architect of this intensely paranoid approach. Yet when it comes to the whole notion of the, you know, all of the underlying cryptography being undermined, there is a real laissez faire attitude to it. It's very puzzling.
Sam
What if you could trade gold, Forex and global markets with the same tools and speed that you use for crypto? That's exactly what Bitget TR Tradfi unlocks. After strong beta demand, including over $100 million in single day gold trading volume, Bitget Tradfi is now live for all users. Inside of your existing Bitget account, you can trade 79 instruments across forex, precious metals, indices and commodities all settled directly in usdt. No platform switching and no fiat conversions. This is Bitget's universal exchange vision in action. Crypto and traditional finance side by side. You get deep liquidity, low slippage and leverage up to 500x letting you apply crypto strategies and to macro markets. New to Tradfi Start with gold. The Gold USD pair is liquid macro driven and a familiar natural bridge between crypto and traditional markets. Try trading gold on bitget now@bitget.com click the link in the show notes for more information. This is not financial advice.
David
Some exciting news. We are launching a new podcast to help people figure out the crypto cycle. How to navigate it. The best crypto cycle investor I know, his name is Michael NATO. He runs the Defi Report. This is the guy that sent me a sell alert before the 10:10 price drop happened. His cycle analysis has been absolutely on point. I've been following him for years and this year we started recording weekly podcast episodes. Each one we get into his portfolio, what he's holding, the market structure, entry targets, fair market value of bitcoin and ether and where we are in the cycle, there's new episodes that are released every Wednesday. They're 30 minutes, they're short, they're punchy. I think this crypto cycle is harder to navigate than most. So let's do it together. Go to subscribe to this podcast Search the Defi Report wherever you get your podcasts YouTube, Apple Spotify or find a link in the show notes. There's a new episode waiting for you now. What's your answer to that? Same question of why wouldn't they treat this more seriously? Why are they not more paranoid?
Nick Carter
Why? Institutional incentives is my answer. I've been really wondering about this. I mean, now I'm at odds with the whole bitcoin community again, for some reason. I don't know why this keeps happening. I think as far as core developers are concerned, they don't want to take responsibility for the protocol. They don't want to be seen as the leaders. That has caused them a huge amount of problems, legal harassment, you know, like right now there's the BIP110 people that are harassing the core devs. So the reaction of the core devs is to disclaim responsibility, say, don't target me. I'm not in control. I'm not the guy in charge. The same with Craig Wright, legally harassing the devs. A lot of them retired or semi retired in response to this, their reaction to the legal threats was to be like, I am not in control. I have no responsibility. So you end up with this enormous power vacuum. And this is reflected in the lack of updates to Bitcoin. There's been two changes in the last decade, right? So the system is now in a state of total stasis with people that are influential and they matter, but no one will admit that they have real influence over what gets implemented in Bitcoin. So that's one issue. And also there's this culture of like, well, if you want to change something, do it yourself. You know, you write the code. I think it's like an absurd thing. It's like, really the only way to contribute to Bitcoin is to write a bip. Like, that's a waste of time. Nobody ever. They wouldn't look at my bip, right? So they're incapable of, like, taking feedback from the market. It's really weird. Then the incentive of individual holders, including the largest holders in the world, is to deny that there's a problem because they don't want to admit that there's anything that could undermine Bitcoin because to them, like, bitcoin is ontologically perfect inherently. It's a perfect money. There could never be any problem with it. So they're insulted that someone might say, hey, this whole thing has a huge tail risk attached to it. They don't want to convey any weakness to the market because a lot of these people's jobs is to basically sell Bitcoin to third parties. So I think that's why there's been this reaction.
David
Something else we heard from Michael Saylor was in addition to don't worry about the alarmists and the fudsters and the pannikins was this idea that the cure could be worse than the disease and so we shouldn't rush anything. And I've heard this from Bitcoin developers as well. Just like, hey, we're looking at it now. Sure, quantum computers could happen at some point in the future. Maybe they will, maybe they won't. But there's no real need to rush things. Let's take this slowly and look, we're upgrading all of the cryptography here. Let's make sure we do the right thing before we commit to something.
Nick Carter
Yeah, I mean, the cure is not going to be pleasant, as you guys know. Like, if you've seen the Ethereum roadmap, it's not like a fun exercise to go through. The new signatures are more annoying and harder to work with than the old signatures. But I think the assumption inherent in what Saylor is saying and what others have said is we will have a very clear notice period before Q day comes. That's the assumption. It's. Well, you know, the technology will progress gradually and we will know. We'll be able to do the extrapolations and we'll know, all right, it's going to hit in 2041 or whatever. So all we have to do is target that date. But it's not like Y2K, right? Nobody knows the day or the hour. Right. It will just happen one day. So unfortunately, we have to make a decision under conditions of uncertainty, a very costly decision. Right. Because it's going to be very hard to do this. But the problem is this is the crux of it. There is no one with the executive ability in Bitcoin to coordinate this. Not like Ethereum. There's a foundation, there's a guy who makes the decisions. Not just one guy, of course, but there's more order in terms of the governance. In Bitcoin, the governance is deliberately people disclaim responsibility by choice. If you talk to any individual core developer and I have, they will all say, I'm not in charge. We're going to let the community decide. So the whole structure is leaderless, enormously leaderless. I mean, the whole. The thing's running on autopilot, basically. And so that's the problem. We have something where someone needs to step up to the plate and say, we have to make this costly decision today. And the system can't accommodate that structurally.
Sam
Let's talk about what we actually have to do. Once we get consensus that we have to do something, what do we actually have to do? So we are at A, we need to be at B by 2030, 2032, sometime around then. What is actually A to B? What are the things that we actually need to get done?
Nick Carter
Yeah, people keep asking me for my roadmap. It's like, I, I don't know man. I feel like I can just be the guy that like pulls the fire alarm and doesn't do anything else. But if I have to give one, we need to settle on a signature scheme and it could be more than one. Actually there's no reason why we couldn't have two signature schemes. So what I think it will actually look like in practice is a period where you can sign a transaction with traditional signature plus maybe a hash based signature or a lattice based signature. And those live in parallel for a time. And maybe after X years of that, enough people have moved over to the new signature scheme and you can deprecate elliptic curves entirely in parallel. We also need to decide what the fate of the satoshi coins is going to be. And that's going to be a huge fight. So that's going to take years. So you know, eventually then you would just turn off the legacy signatures and retain exclusively the new signatures. I mean that's like broadly what it's going to have to look like, but it's going to be a mess.
David
Of course at some level the, the technical challenges of upgrading the cryptography are less scary to me than kind of the social issues of what to do with the satoshi coins. And let's talk about what that is. So this is from the Google paper again. It was nice of them to quantify all this for us too. Like it was a great paper. I was shocked at how much they knew about our crypto like systems. Right. This is coming from Google. Did not expect this level of debt.
Nick Carter
Well, I think that's why they brought in Justin.
David
Yeah, I wonder if that's part of the intel here. But their numbers were 6.9 million bitcoin that would be vulnerable to this, which is one third of all supply. But of course those could be transitioned to different addresses. But there might be 2.3 million bitcoin that are kind of the satoshi keys, the loss keys. You cannot be moved and I don't know, that's like 10%, 10 to 15% of all Bitcoin supply. And to the question for the bitcoin community to somehow find consensus is what do we do with the satoshi coins and these lost coins? They gave four options. The do nothing option, the burn option, which is you just take the satoshi coins, you just like burn them forever. You make them permanently unspendable. The do nothing option is obviously you just wait for the first quantum attack to go get the booty and, you know, they win the treasure. Congratulations. They also had two other approaches, one called an hourglass, where it's kind of like a. You just slow down the dormant coins that slow down the speed at which they can be sent. You just avoid the quick confiscation. And then they had another approach they called bad sidechain. This is like you take the satoshi supply, you put it in some pegged sidechain, and then if an owner shows up later, they can prove ownership somehow cryptographically and like unlock their coins. So these were the, the four options. Which of those is best to you? Are there more than those four options? How do you think this gets resolved?
Nick Carter
Yeah, I mean, I think this is actually the question, like, I think basically in a few months from now, everybody in bitcoin is going to agree with me and we'll all understand that there's important. We need to transition to pq. So I think that'll happen, but this is the thing that'll be outstanding. It's like the immensely tricky question of, like, how do you save bitcoin from this without undermining bitcoin's core values? Because you would be. If you burn the satoshi coins, we've now arbitrarily changed bitcoin supply from 21 million to 19 point something million. That's an enormous change. The whole point of bitcoin is no one's meddling with the money supply. Right? That's a huge, huge issue. I think what is likely to happen is that I think once the institutions get involved, they'll just say, okay, we're burning the coins. We will only support a fork where the coins are burned, so that will canonically become bitcoin. I think that's likely to.
David
Okay, so what would that look like? You say, the institutions coming together. So I'm imagining like Brian Armstrong this morning tweeted, hey, this is something we're going to have to look into. I'm personally looking into this. He was talking about the quantum issue we had Michael Saylor on earlier. He didn't really have a comment on this piece other than, you know, it's kind of like fud But I'm sure BlackRock will have a perspective. I'm sure all of the major exchanges will have a perspective. CZ yesterday tweeted out, well, one thing we could do is maybe just burn the supply. He just threw that out as a floater on Twitter. What does that practically look like when you say the institutions will all come together and likely want to like burn this supply?
Nick Carter
Yeah, I mean, it's really unprecedented times, truly. But I think you'll have. I think it'll happen actually. And I don't have any private knowledge of conversations behind the scenes, but my guess is that the 10, 15, 20 most important custodians of bitcoin on the planet will sign a letter saying, we will only honor a fork where the satoshi coins are burned, period. That will be btc bitcoin ticker. Bitcoin. That will be bitcoin. The other thing will be something else. And you can, you can go buy that one, but we're not going to support it. It's not going to be on exchange. The etf. The thing that the ETF holds is going to be this new bitcoin thing that's going to canonically be bitcoin, is
Sam
that the institution is kind of just like strong arming the whole rest of the ecosystem.
Nick Carter
Well, someone's going to have to do it. These times call for a dictator. I'm sorry, we can't have this passive. Oh, I'm not in charge. Maybe he's in charge now. I'm not in charge. Like that's not going to work. Right. And I'm not saying, I'm not advocating for this. I'm not saying I want to be the dictator. I'm not telling anyone to do this. I'm just saying I think this is how it's going to play out.
David
Why? Because the incentives line there, that's good for everyone. I suppose at some level, if you can coordinate, then you have over 19 million and everyone gets positive, whatever the opposite of dilution is.
Nick Carter
Positive reverse dilution. Yeah, yeah, no, that's a real thing. I mean, yeah, I mean, of course, like, of course you would prefer that there be fewer bitcoins, but. Yeah, I mean, this is what people don't understand. These custodians, exchanges, et cetera, especially custodians, they are fiduciaries. They have a responsibility for their clients coins and they can't accept a situation where, you know, China or whoever steals 1.7 million bitcoins and market sells them a situation that's a foreseeable total wipeout, loss of value. That's catastrophic for these companies. So they are forced into one of two choices, right? They can delist bitcoin and not support it. They can just end their bitcoin business completely. Probably that will happen too. Or they can go to the bitcoin community and say, hey, look man, my hands are tied. I can only do this. So there's only two things they can do. Delist bitcoin or insist that the coins be burned. Those are their options.
David
Do the miners have a role in this or are they weaker powers here?
Nick Carter
Yeah, I mean the miners are price takers. You know, they're basically irrelevant today.
Sam
In the absence of the bitcoin community being proactive and coming up with a solution ahead of institutions, strong arming, I actually do feel some level of comfort that it seems like these institutions will provide a solid backstop of, you know, Q days around the corner. We haven't come up with solution, therefore, you know, we're, we're, we're in charge here and we're gonna strong arm you guys. It seems like, it seems like there could at least be space for, you know, Blackrock, Anchorage, all the custodians to say to like give space for bitcoiners to come up with their own organic solution. But if they don't, then they pull the fire alarm and like, okay, this is what we're doing now.
Nick Carter
Yeah, that's what's happening right now. Every single bitcoin institution on the planet has a perspective on this already. So they're watching and they're waiting and they're hoping that the devs get it under control. But if they don't, why is that so bad?
David
So the burn. The burn option, let's say so everyone gets reverse diluted. You know, there's a world where maybe bitcoin holders are excited about that. If you have bitcoin, you have greater percent of the network after that. Why is this a bad thing? What are the cons to this?
Nick Carter
The con is that we permanently ruin the thing that we said we were doing, which is maintaining an absolutely immaculate supply schedule. Remember the amount of crap that Ethereum people got for the DAO hack remediation? You guys remember, right? This is like that times a trillion. Yeah, this is much worse.
Sam
But this is the self referential part about that is bitcoiners talking to the Ethereum community and the Ethereum community talking back to the bitcoiners. And that was in 2016. And yes, Bitcoiners have elevated the role of property Rights and the story of bitcoin's immaculate conception and the 20, all this espousing of the cool things about bitcoin. And now we're in 2026 and now we got BlackRock and then the ETF, we got Michael Saylor and maybe the market. The world just doesn't give a fuck nearly as much as bitcoiners think that they do. Like, we're in the world, we're in
Nick Carter
the real world now.
Sam
We're out of the imagination. Like, if we go from 21 million units to 18.5 million units, everyone actually has a larger share of the network. People are profit motivated, people are pragmatic. Who cares about the property rights being violated the one time that we have.
David
The one time.
Sam
It's only the one time with like, promise, a very valid reason. Like, fuck it, like, we're, we're doing the thing. And all the bitcoiner intellectual masturbation about, like, for strong property rights can stay inside of that silo. But we're in the world of like pragmatism. Like, I don't see.
Nick Carter
I would care. I would care.
Sam
Okay, so, all right.
Nick Carter
I mean, I'm not like falling in on one side or the other, but I think it's. It basically ruins bitcoin as this true ideological project. I think it's over at that point. It's become something that's effectively captured and any feature of the system can be changed arbitrarily. And it would be the greatest theft in human history that would be on our conscience. It's mean to satoshi.
David
Is it captured in the right direction? Which is. It's not captured in a way that's inflationary to some unaccountable third party. I guess maybe in a way it is sort of. Right.
Nick Carter
Because it's no different from existing holders. Yeah, it's no different from some socialist, you know, being elected and saying we're just going to steal all of Jeff Bezos's wealth. And like, yeah, okay.
Sam
It is different though, because this assumption, the presumption is that satoshi doesn't actually have those coins.
Nick Carter
They are satoshi's coins, no matter what, or his estate.
Sam
I think satoshi needs to wake up and say that in order for that to be valid.
David
Satoshi's not waking up though, which is why it's okay.
Nick Carter
It would be really great if satoshi came back right about now. I think I know who it is and I don't think they are. But yeah, unfortunately, I think that this is how it's going to be. And that'll be the end of the bitcoin project, in my opinion.
David
What about this other approach then, the sidechain type approach where you don't confiscate it forever, you just take that supply, you shove it somewhere else. And if a holder of satoshi comes back and provides the cryptographic proof, then Satoshi gets coins back.
Nick Carter
Yeah, I mean, that's, that's what should happen, actually, in a more legalistic and less cryptographic way. So I wrote a short story about this called Trillion Dollar Salvage. I recommend you guys read it.
David
But I have read it. It's fantastic. I, I, I feel like I should read it to my kids. A little bedtime story.
Nick Carter
I put a lot of work into it. I think what should actually happen is what happens to ship. Like the Titanic is a good example. The Titanic, there's this legal doctrine called salvo in possession, where one company was granted basically the right to salvage and protect the wreck. And, you know, they, they're not granted ownership of it. So it's like the, the stuff in there is not theirs, but they're the custodians of it. So something similar could play out. And this is actually how a lot of shipwrecks end up is like, basically you as the person doing the salvage, you get a finder's fee, like 10%. But the, you know, the gold or the doubloons still belongs to whoever the original owner was. And this it can trace over hundreds of years, by the way. And so what I think should happen is the government should effectively appoint someone or some lab to salvage the coins, hold them in trust for satoshi or Satoshi's estate, and the person doing the salvage entity should get 10% or 15% or whatever. And then if satoshi does come back, then they can claim their coins. And if not, they get escheated, I think is the word. And actually the government gets them. So I think that would be a much more neat solution that does not involve ruining bitcoin at the protocol level.
David
So with salvage law, how is it governed internationally in kind of the law of the jungle that we find ourselves in, which is who gets to make the rules from an international perspective?
Nick Carter
Yeah, I mean, there's a very well established international law on this, actually. So there was this big famous shipwreck that this guy in the 80s found had $500 million worth of gold from a Spanish ship from 200 years earlier. Spain got all that gold, actually, because Spain was considered to be the unbroken owner that had not, even though it was the empire of Spain. And then it became Spain, just like the empire.
David
Who found it? Like, what nationality found it?
Nick Carter
This Floridian guy.
David
Okay, so an American found it.
Nick Carter
Tommy Thompson was his name.
Sam
Sounds like a fake name, actually.
Nick Carter
Sorry, I might be mixing up two cases, but. Yeah, sorry. I'm thinking about the Nuestra Senora. This was sunk in 1804. 500 million was recovered. In 2007, Spain declared sovereign immunity. They said they had an unbroken ownership claim over the ship and all of that gold went back to Spain. So this is the thing. The courts generally, they have an extremely high bar for what's considered abandonment. They actually need the owner to come out and say, I have abandoned this. And no one ever says that. So unless Satoshi says that the new owner, I don't think would get everything.
David
If I recall in your story, it was like the. The ones who were able to salvage it was actually like US domiciled. So it was a US based company. And ultimately kind of the US government got it. And I can see the scenario you're talking about with international law, working among allies. Right? And then your scenario, by the way, had a nice happy ending, I think. Right? Which was.
Nick Carter
Well, it was kind of dark in a way, but yeah, yeah, the US
David
government got a portion of it. Bitcoin, kind of like dipped in price for a time. Then everyone realized, oh, the US government has it and there's the strategic bitcoin reserve. And, you know, things resumed on the ascent. However, what happens if an adversary, you know, gets it? So what we're talking about is not necessarily kind of Western alliance type companies. I mean, Russia could crack the, the Q Day stuff, or it could be China or something. And are they going to respect salvage laws? Isn't this like an international race? I guess. And it's more akin to kind of the law of the jungle. Unless the US unilaterally is able to marshal the tech to. To make this happen.
Nick Carter
Yeah, I mean, hell, you know, Europe may not like, honor our laws after what we've done to them recently, but yeah, I mean, in the story, actually, the reason the government authorizes the theft is because they know that China is just right around the corner. And this is actually what's happening in the quantum race in the real world. You know, we are racing against China to get it the same way we were racing for AGI. So quantum is much more important than just bitcoin, of course. It's the ability to spy on your enemies completely, you know, with impunity and the ability to make these Amazing breakthroughs in physics and material science and chemistry and stuff. So we are actively racing them. They're spending tens of billions of dollars a year on this stuff.
Sam
Do you know who's spending more, us or them?
Nick Carter
It's about the same, but it's mostly private sector in the US and it's mostly public sector in China. So there's a race. And does China really care about bitcoin? I don't think so. I think they actually dislike bitcoin. So people always say to me, like, well, who would rationally steal the bitcoin? They won't be able to sell it. China doesn't care about that. They're no, you know, they might just want to embarrass us. You know, if bitcoin is perceived to be a very American thing, so you can't trust that the first entity who gets a quantum computer is altruistic or benevolent. So, you know, if they get there first, we're in, in trouble.
Sam
So let's say that at the end of all of this, the bitcoin, the satoshi coins, all the dormant coins, the ones that are exploitable by a quantum computer, they do get exploited and they either end up inside of the bitcoin strategic reserve in America or they end up getting markets sold by China. Add those two properties together, probabilities together, what is the total probability of either of these two outcomes happening?
Nick Carter
My modal outcome is that we freeze the coins. So I think it would actually be pretty unlikely that we don't. But I mean, I'm totally guessing your
David
modal outcome is the institutions come together and they opt for the burn option. Freeze.
Nick Carter
I don't think the bitcoinist will do that spontaneously.
David
This will cause a fork. We get freeze and burn. This will cause a fork. There will be some bitcoin classic out there, will there not?
Nick Carter
Yeah, but nobody will support it, right?
David
Right.
Nick Carter
It'll be worse. It will be a fork, but it'll
David
be like Ethereum supported. Nick, you'll be out there.
Nick Carter
Look, I supported Ethereum Classic. It didn't go well for me.
Sam
You might ideologically support Ethereum Classic, but you're going to also hold the bitcoins that are having the market value, which is going to be.
Nick Carter
Yeah, I'll go with ticker, Bitcoin, ticker, btc, whatever that is.
David
You said at the beginning of the episode, Nick, that Ethereum, you saw the EF is positioning things better. It's funny because on the Ethereum side, I think it's a pastime to complain about the EF or it has become so lately I've seen that.
Nick Carter
Yeah.
David
All right, what are you seeing from the outside that Ethereum is doing right and maybe the EF is doing right on this issue.
Nick Carter
Whenever I talk to anyone in Ethereum they're like, oh, Ethereum is so messed up. They're making us sign this woke pledge to like be trans or something. I don't know what it is. Like it's completely indecipherable from where I sit, by the way. But I did see a very cool website called pqethereum.org or whatever. And the fact that Justin is on this paper is also quite telling. I mean it's in Night and Day. You know, Ethereum is basically in Bitcoin. It's just me worrying about this and a half dozen other people in Ethereum. That's already been decided the transition is going to occur. And the roadmap is. I was reading the blog on the pq, Ethereum side, I'm like, I could have written this. I completely agree with every word written on here. And I think Ethereum is also beneficiary in the sense that it has not gone for this relentless optimization route. So like some of those like high bandwidth or high throughput blockchains have because they're going to suffer from this. As I said, the transition is more complex for Ethereum though. It's multi layered as you know. It's not just the address layer, it's also, you know, the consensus layer and the roll up layer. I think the push towards account abstraction is actually really helpful though. That means it's easier to kind of like hot swap out underlying algorithms whilst, you know, having one address that's consistent. So yeah, I was very impressed by the roadmap. I hope you guys can do it by 2029. I mean it's going to be very painful because we're, we're still standardizing these cryptographic functions. We haven't picked the good ones yet. So that's the, that's the hardest part is you want to rush, but you also want to wait for the functions to get better.
David
Nick, there's kind of a final question I think, to wrap all this up and it's sort of the question of like, like, does bitcoin? Do you think bitcoin survives this? And I want you to put maybe your investor cap on, right? I've heard Ray Dalio talking about Bitcoin. Whenever he's asked, he's like, I prefer gold because it can't be hacked. Part of what he might mean is kind of quantum hacked. Do you think bitcoin survives this and what's like the investment case?
Sam
Right.
David
Is there a case in your investor mind to just like maybe not be bullish on crypto until there's demonstrated capability that our chains will upgrade to quantum? Maybe you hedge to gold for a period of time until this is resolved. Round this out for us and tell us what you think this means for investors.
Nick Carter
Yeah, I mean I'm all in on crypto obviously. My career, my fund, everything. I'm not a panic at the core. I have the confidence we'll be able to surmount this and I think it's actually very helpful that Ethereum has shown what a roadmap looks like. I think as eth BTC rallies that's like a dagger into the heart of the bitcoin process. Trusters and eventually bitcoin will come around purely through price signals. It'll have to happen. And I. You know the scary thing is what has to happen in bitcoin is unprecedented. It basically will be commandeered by corporate interests, I think so I think bitcoin can and will survive but it'll be changed in the process and it won't be the same way it was before. The ideology will probably have to be compromised. But yeah, as an investor this is the number one question I get now from big investors. And I think it is ultimately an opportunity for blockchains to show that yeah, we can be very rigid and antifragile and not change very much, but also we can adapt when it is necessary. We've seen that Ethereum and to a lesser degree Solana are willing to adapt. We haven't seen the willingness from bitcoin. It is the thing that has scared long time bitcoiners the most for sure. A lot of the people I talk to, their faith is being shaken but luckily there's still time to react. So I hope that the devs come around.
David
Well, thanks for sending the smoke signals Nick and for your tireless work fighting for this issue. We appreciate you stopping by.
Nick Carter
Yeah, thanks guys.
David
Bankless nation. Gotta let you know of course crypto is risky. You could lose what you put in. Hopefully not to a quantum computer. We are headed west. This is the frontier. It's not for everyone. But we're glad you're with us on the Bankless journey. Thanks a lot. Sam.
Bankless Podcast Summary
Episode Title: Bitcoin Has 3 Years to Survive | Nic Carter on Bitcoin’s Quantum Vulnerability
Release Date: April 6, 2026
Guests: Nic Carter
Hosts: David, Sam
This episode dives into the existential threat posed to Bitcoin (and broader crypto) by advances in quantum computing, specifically following new breakthrough papers by Google and Oratomic. With the shocking new resource requirements for breaking elliptic curve cryptography, Nic Carter sounds the alarm: Bitcoin’s legendary status-quo governance is now its greatest liability, and the clock might be ticking faster than anyone realized. The conversation grapples with technical, social, and governance challenges, the fate of “Satoshi’s coins,” potential catastrophic scenarios, and whether Bitcoin can— or will— adapt in time.
Google and Oratomic Papers Released (09:22–11:47):
Fast Takeoff vs. Gradual Transition (15:08–17:19):
Types of Attacks (28:11–29:16, 24:07–25:19):
Miners and Proof-of-Work:
Picking New Cryptography:
The Satoshi Coins Dilemma:
Solutions Proposed (52:50–55:49):
Institutions v. Ideology: Who Decides?
On Quantum’s Suddenness:
On Bitcoin’s Immune System:
On Governance:
On the Institutional Dilemma:
On Ideological Costs:
On Ethereum’s Preparation:
Nic Carter delivers a sobering, urgent analysis: Quantum advances have moved the finish line much closer. Bitcoin’s traditional strengths—decentralized, ossified governance; reluctant-to-change culture; ideological purity—are now its chief vulnerabilities. Unless a radical, painful transition is marshaled, likely with the heavy hand of institutional custodians, Bitcoin’s future as a “perfect money” faces an existential crisis. Ethereum, meanwhile, is lauded for being agile and realistic in the face of quantum threats. With only a few years before quantum’s potential arrival, "the die is cast"—whether Bitcoin can adapt or will be forced to compromise its ideals is now a race against time.