Post-quantum cryptography in the blockchain context refers to the eventual replacement of today's elliptic curve signature schemes with algorithms that would remain secure even against a sufficiently powerful quantum computer, since a quantum computer running Shor's algorithm could in theory derive a private key from an exposed public key.
Where the actual vulnerability sits
Bitcoin and most other blockchains rely on elliptic curve cryptography to verify that a transaction was signed by the legitimate owner of a wallet. The mathematical problem this scheme depends on, the elliptic curve discrete logarithm problem, is effectively unsolvable for classical computers within any reasonable timeframe, but Shor's algorithm running on a large, fault-tolerant quantum computer could solve it in polynomial time, exposing the private key behind a known public key.
Why most bitcoin addresses are still safe for now
A standard Bitcoin address does not show your public key directly, it shows a hash of that public key, produced by running it through SHA-256 and then RIPEMD-160. Grover's algorithm, the main quantum threat to hash functions, only offers a quadratic speedup rather than the exponential break Shor's algorithm provides against elliptic curves, so a hashed public key remains reasonably secure even in a post-quantum world. The catch is that the moment you spend from an address, the transaction reveals the underlying public key on-chain, at which point that specific key would become vulnerable if a capable quantum computer existed at the time.
The road toward migration
Standards bodies including NIST have already finalized post-quantum signature algorithms such as ML-DSA, built on lattice-based mathematics that quantum algorithms cannot yet efficiently break. When quantum hardware eventually becomes advanced enough to pose a real threat, blockchain networks would need to coordinate a protocol upgrade to shift new transactions over to one of these quantum-resistant schemes. Most serious estimates put a cryptographically relevant quantum computer, one actually capable of this kind of attack, at somewhere between one and two decades away, which gives the ecosystem time to plan a transition rather than react to an emergency.
Practical steps for holders today
Avoiding address reuse is the simplest defense available right now: once you spend from an address and its public key is exposed on-chain, move any remaining funds to a fresh address rather than leaving a balance sitting behind an exposed key indefinitely. Keeping long-term holdings in modern address formats such as native SegWit or Taproot does not itself add quantum resistance, but it does encourage the kind of single-use address habits that limit how many exposed public keys sit on the network at any given time.