Former SEC official John Reed Stark is warning that the crypto industry faces a “ticking clock” as advances in quantum computing edge closer to threatening the cryptographic foundations that secure blockchain networks, including Bitcoin.
Stark pointed to two recent developments he says should worry “every financial professional”, not just Bitcoin holders: IBM CEO Arvind Krishna telling CNBC's Jim Cramer that within three to four years “we should all be rather paranoid” about quantum threats, and a Duke University paper by Lee Reiners arguing that financial regulators need contingency plans for quantum-vulnerable digital assets now, not later.
The Exposure Is Growing, Not Shrinking
Stark's core argument is about timing and integration rather than an imminent break. “The quantum-vulnerable blockchain infrastructure is being integrated deeper into the traditional financial system every month: spot ETFs, bank custody, stablecoin legislation,” he said, adding that “the trend line is hard to dismiss.” His concern lines up with recent research: a widely cited 2026 estimate cut the number of qubits believed necessary to break Bitcoin's signature scheme by a factor of 20, compressing what had looked like a decades-away risk into a much tighter window, even though the hardware needed to mount such an attack still doesn't exist. The actual weak point is ECDSA transaction signing rather than SHA-256 mining, meaning older, reused Bitcoin addresses carry more exposure than modern wallet setups.
Not Another Y2K, Stark Argues
Stark explicitly rejected comparisons to Y2K, noting that scare turned out fine specifically because regulators like the SEC ran aggressive enforcement campaigns in 1998 and 1999 to force compliance — the opposite, he argues, of the current regulatory posture. He was pointed about current SEC leadership, describing Chair Paul Atkins as “the industry's own man, installed in the regulator's chair” and questioning his credentials as an effective watchdog given prior industry ties.
The Industry Isn't Standing Still
Some preparation is already underway. NIST finalized its post-quantum cryptography standards in 2024 and has floated deprecating RSA-2048 and ECC-256 by 2030, while separate U.S. national-security rules require quantum-safe systems by January 2027. Bitcoin's own developer community has floated BIP-360, a proposed quantum-resistant address format, and firms including Galaxy Digital and Blockstream have launched initiatives specifically focused on quantum-readiness — efforts that echo the kind of proactive hardening seen elsewhere in crypto security, such as the hardware-wallet industry's response after Coldcard hack victims reported losses topping $111 million.
Related: Coldcard Hack Victims Report Median 1 BTC Loss as Theft Tops $111M