Submitted:
18 August 2026
Posted:
18 August 2026
You are already at the latest version
Abstract
Published assessments of Bitcoin’s exposure to a cryptographically relevant quantum computer convert resource estimates into risk figures by substituting a point estimate of the key-derivation time into an exponential tail. We show that this procedure is systematically optimistic. Because the exponential tail is strictly convex, its expectation over any non-degenerate break-time distribution exceeds its value at the mean, so every such figure is a provable lower bound on the true risk: at an unchanged nine-minute mean, exponential dispersion moves Bitcoin’s on-spend theft probability from 41% to 53%. We develop the distributional model this requires, a race between a Poisson block-arrival process and a random time-to-key embedded in a Nakamoto reorganization contest and a replace-by-fee bidding game, and obtain closed forms for the theft probability, for the commit–reveal delay attaining a given security target, and for the coin value an owner retains in the fee war. Replacing the zero-delay catch-up bound with a delay-aware one raises the required delay by a factor of 1.2 to 20.4, a correction driven almost entirely by the adversary’s pre-mining lead rather than by propagation delay. Reconciling our results with a concurrent round-based analysis shows that an apparent threefold disagreement in the literature is a difference in security target, not in substance. Finally, we test the block-arrival assumption against 40,320 block headers: the exponential marginal law holds, but a conditional-uniformity test detects within-epoch rate drift invisible to a Kolmogorov–Smirnov test, an effect worth under a third of a percentage point and again conservative.
Keywords:
blockchain security
; Bitcoin
; quantum computing
; post-quantum migration
; Nakamoto consensus
; stochastic modeling
; commit–delay–reveal
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.