Oxford lecturer argues quantum memory will break Bitcoin and power quantum money

Stefano Gogioso argues that portable quantum memory is inevitable and will both break Bitcoin's security and enable quantum money as a replacement.

04/09/2026 17:4221 min read

Cryptography's most significant device has not been built yet. According to an Oxford lecturer, quantum memory will determine if Bitcoin (BTC) is broken or superseded by a superior alternative.

On Tuesday, Stefano Gogioso published this argument. He states that the future of quantum cryptography depends on constructing one specific piece of hardware.

“The development of portable long-term quantum memory will be one of the most consequential milestones of quantum technology. These devices will power an entirely new class of applications, such as quantum money, the ultimate incarnation of a digital store of value.”

Gogioso, who lectures on quantum computing at the University of Oxford and co-founded the quantum security company Spooqy, shared this with BeInCrypto.

The Bottleneck Quantum Money Never Cleared

A previous report from the BeInCrypto Experts Council concluded with an unresolved issue. Quantum money is unforgeable since quantum states cannot be duplicated.

However, no one can maintain those states for extended periods. Even the best laboratory systems can only keep a quantum state alive for seconds, a limitation that has kept the case for quantum money theoretical.

Gogioso's post outlines the requirements for a practical device. Stability lasting months, or preferably indefinitely. Portability, starting with a shipping crate and eventually a pocket. Capacity for billions of individual states.

He furthermore dismisses the concept of quantum RAM. His design does not require random access or in-place editing. States are retrieved sequentially and used only once.

The gap between seconds and months encapsulates the entire challenge.

Why Gogioso Calls Quantum Memory Inevitable

His response comes in two parts, with the first being absolute.

A fault-tolerant quantum computer must preserve delicate states at scale, resisting noise, for the duration of a computation. That condition defines fault tolerance.

Take away the computing, Gogioso contends, and what is left is a quantum memory device. Therefore, rejecting one implies rejecting the other.

This reframing has commercial significance. Billions of dollars have already been allocated to fault-tolerant machines. The memory is embedded in those roadmaps as an inevitable phase.

The second step addresses portability. Machines operating at cryogenic temperatures will maintain their states inside a refrigerator for many years.

Atom-based approaches differ. They encode information in properties that nature isolates on its own. This transforms the challenge into a difficult engineering problem rather than a physics one.

Gogioso also relaxes the requirement in a manner largely overlooked by the discussion. A memory need not last for decades. A sealed, single-use cartridge, loaded at a facility and consumed state by state, would suffice for all the applications he outlines.

The Same Machine Breaks Bitcoin and Builds Its Replacement

Applying that argument to cryptocurrency yields an uncomfortable symmetry.

In March, Google Quantum AI collaborated with the Ethereum Foundation and Stanford to estimate the cost of attacking Bitcoin. They determined the requirement to be less than 500,000 physical qubits.

Such a machine is only functional if it is fault tolerant. And fault tolerance, according to Gogioso's definition, is quantum memory.

The implication is awkward for both sides. The hardware that would reveal Bitcoin's signatures would also power quantum money.

Consequently, every dollar spent on fault tolerance simultaneously finances both futures. No scenario exists where quantum computers break Bitcoin while the alternative remains unattainable.

Gogioso and Daniela Herrmann, chief executive of quantum firm Dynex, articulated the broader argument.

Why a Stolen Shipment Would Not Matter

The security model underlying all this reverses an old assumption.

Classical key material is risky during transport. Anyone who copies it possesses it, leaving no evidence of the copying.

An entangled pair holds no information while in storage. The randomness that forms a key emerges only upon measurement.

Thus, a crate that is intercepted would cost a supplier its inventory, not its secrets. Gogioso notes that the worst a dishonest supplier could provide is a tank of inert gas.

A second implication is more peculiar. These resources are consumed. A key uses up entangled pairs, and a banknote is spent through its own verifications.

Gogioso terms this effect 'cryptography by combustion.' Money constructed in this manner would come with a fuel gauge.

Q-Day Has a Calendar. Quantum Money Does Not.

The two parts of this narrative progress at vastly different paces.

The attack timeline is filled with dates. IBM expects quantum computing to move its earnings by 2028 or 2029. Hong Kong has given its banks a quantum readiness deadline of 2030.

The National Institute of Standards and Technology intends to phase out current elliptic-curve signatures by 2030. It would prohibit them entirely by 2035.

The replacement side has no timetable at all. Gogioso refuses to provide one. His post argues that the resource is inevitable, not that a product is imminent.

He was more forward-looking, suggesting applications that are provably impossible within five to seven years. That estimate covered quantum resources broadly, not a memory compact enough for a wallet.

Herrmann set the same limit during the discussion.

“Quantum money is the vision, once this all plays out. Right now, quantum money as such isn't available yet. But as soon as the chips advance, these things have to be handled with real responsibility.”

What the Argument Leaves Open

Two questions remain unresolved.

Someone still needs to fill the memories. That places an issuer within a system marketed as having no custodian.

A bearer instrument without a ledger also lacks recovery. A note that is lost, stolen, or simply allowed to decay takes its value along with it.

The industry is constructing the machine regardless. It has not yet chosen which of the two outcomes it prefers.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles