Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

Quantum Bitcoin Mining Would Require the Energy Output of a Star, New Research Finds

A paper published by BTQ Technologies calculates that using quantum computers to mine bitcoin at current difficulty would demand roughly 10 to the power of 25 watts — approaching stellar energy output — and argues the real quantum threat lies in cryptographic signatures, not mining.

By Tom Chen··3 min read
Quantum Bitcoin Mining Would Require the Energy Output of a Star, New Research Finds

Key Points

  • A paper published by BTQ Technologies calculates that using quantum computers to mine bitcoin at current difficulty would demand roughly 10 to the power of 25 watts — approaching stellar energy output — and argues the real quantum threat lies in cryptographic signatures, not mining.

A new academic paper has put hard numbers on the fantasy of quantum bitcoin mining — and the figures are, quite literally, astronomical.

Pierre-Luc Dallaire-Demers, a researcher at BTQ Technologies, published "Kardashev Scale Quantum Computing for Bitcoin Mining" on arXiv this week, delivering what appears to be the first end-to-end physical cost estimate for deploying quantum hardware against Bitcoin's proof-of-work algorithm. The conclusion: even under the most generous assumptions about future quantum hardware, competitive mining would require resources that make the exercise physically absurd.

The paper's title references the Kardashev Scale — a theoretical framework devised by Soviet astronomer Nikolai Kardashev in 1964 to classify civilisations by their total energy consumption. A Type I civilisation harnesses all energy available on its home planet; a Type II captures the full output of its star. The point of invoking it here is not rhetorical flourish. It's the scale at which quantum mining actually operates.

Advertisement

728×90

In the most favourable scenario the paper models — a partial-preimage attack against a simplified version of Bitcoin's hash function — a quantum miner would need roughly 10 to the power of 8 physical qubits and 10 to the power of 4 megawatts of power. That's already equivalent to a large national electricity grid dedicated to a single mining operation. At Bitcoin's actual mainnet difficulty, measured in January 2025, the requirements explode to approximately 10 to the power of 23 qubits and 10 to the power of 25 watts — a figure that approaches the luminosity of a mid-sized star.

"To push mining into non-trivial consensus effects, one must invoke astronomical quantum fleets operating at energy scales that lie far above present-day civilisation," Dallaire-Demers writes.

The underlying problem is Grover's algorithm, which provides a theoretical quadratic speedup for unstructured search problems — the kind of brute-force computation that underpins proof-of-work mining. In textbook form, that speedup sounds threatening. In practice, it collapses. The paper demonstrates that once you factor in the physical overhead of quantum error correction, the construction of the oracle circuits needed to evaluate SHA-256 hashes, and the logistics of running parallel quantum machines within Bitcoin's ten-minute block interval, the advantage evaporates entirely.

Bitcoin's difficulty adjustment is the critical constraint. The network recalibrates every 2,016 blocks to maintain a roughly ten-minute interval between blocks, which limits how much benefit a faster search algorithm can extract. A quantum attacker can't simply wait longer for a better result; they must compete within the same time window as every classical miner on the network. That forces parallelism — and parallel quantum machines multiply both hardware and energy costs linearly.

The paper's real contribution, however, may be in redirecting attention toward a threat it considers genuinely urgent. Public discussion of quantum risks to Bitcoin frequently conflates two very different problems: attacks on mining via Grover's algorithm, and attacks on Bitcoin's elliptic-curve digital signatures via Shor's algorithm. The latter — which could theoretically allow an attacker to derive private keys from public keys and steal funds — is a credible near-term concern that the Nobel physicist John Martinis warned about last week.

BTQ Technologies, a Nasdaq-listed quantum technology firm, has a commercial interest in the distinction; the company is developing Bitcoin Quantum, a post-quantum Bitcoin architecture designed around cryptographic primitives resistant to Shor's algorithm. But the paper's physics hold regardless of the company's product roadmap. The energy calculations rely on well-established models of superconducting qubit error rates and refrigeration costs, not speculative hardware improvements.

The practical takeaway for the Bitcoin community is straightforward. Mining is not the vulnerability. Signatures are. Circle's forthcoming Arc blockchain has already adopted quantum-resistant cryptography, and the pressure on Bitcoin's core developers to implement similar protections will only intensify as quantum hardware matures. The energy of a star is safe from Grover's algorithm. Private keys are not safe from Shor's.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Cardano Put Issuer Freeze Powers Into the Ledger Without a Hard Fork
Tech

The Cardano Foundation says CIP-0113 is live on mainnet after independent audits, letting issuers of stablecoins and tokenized funds build identity checks, sanctions screening and seizure into the asset itself. The controls reach only tokens whose issuers adopt the standard, not ADA.

·MiningPool Staff
Sepolia Forked to 200 Million Gas, a Limit Validators Can Decline
Tech

Prysm shipped the Sepolia gas schedule about 16 hours before the fork; without it, validators on older builds would have kept proposing at 60 million. The 200 million figure is a target proposers signal rather than a value the protocol enforces, and it applies to Sepolia alone.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Bitget Says Its Own Approval Process Released $351.6 Million
Tech

The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.

·MiningPool Staff
Only Agave Can Run Alpenglow as Solana Starts the Testnet Phase
Tech

Anza is targeting about 150 milliseconds to finality, down from the roughly 12.8 seconds it attributes to TowerBFT, but Firedancer and Frankendancer cannot run the code yet. No mainnet date has been announced, and September 28 is a feature-gate processing date rather than a confirmed Alpenglow launch.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.