
The 35% Phantom: Quantum Fear, Bitcoin's Oldest Ghost, and What Adam Back's Silence Really Says
CryptoCred
The alert crossed my desk on a Tuesday, and it did what all good bearish alarms do in a bull market: it made my coffee taste like fear. Tom Lee, Fundstrat's eternal optimist, had a new number in his mouth. 35%. By 2028, he warned, quantum computers would break 35% of all Bitcoin. Not "test the network." Not "put pressure on exchanges." Break. Steal. Erase. The number was precise enough to be a headline and vague enough to be a prayer. I put down the mug and did what I always do when a clean number appears in a vacuum: I went hunting for the source.
There was none. No qubit count. No attack pathway. No fault-tolerant threshold. No timeline breakdown. Just the number, floating in conference-room air. The market didn't crash. The tweets didn't stop. But I noticed something strange: Adam Back, the man who has spent a decade as Bitcoin's intellectual bouncer, fired back almost before the echo settled. And in the silence between those two positions, I heard the real story. Finding the signal in the silence of the bear is a habit I have never been able to shake.
To understand why a 35% phantom can still vibrate through the price of Bitcoin, you have to understand the oldest ghost in the network's closet. Quantum computing has been hanging over this protocol since the earliest days. Shor's algorithm, if you ever met it in a math class and survived, can factor large integers and break discrete logarithms. That is exactly the mathematical spine of ECDSA, the signature scheme that secures a Bitcoin private key. If a fault-tolerant quantum computer ever reaches scale, any Bitcoin public key that is visible on the chain becomes a potential sitting duck.
But here is the catch that most scare stories miss: a Bitcoin address is not a public key. It is a hash. Most coins that have never been spent since they were mined are hidden behind layers of SHA-256 and RIPEMD-160, which is a much harder problem than the discrete log of an exposed public key. The coins that are truly exposed are the ones in P2PK outputs from the Satoshi era, where the public key is literally written on the blockchain, and the ones in reused P2PKH addresses that have already appeared in a spend transaction. Every time you spend from a reused address, you broadcast your public key to the world. If someone is recording all public keys today, they are building a victim list for tomorrow.
This is where Tom Lee's 35% becomes interesting. It is not necessarily wrong. It is just unproven. In my work examining early Bitcoin wallets and on-chain flows, I have spent more nights than I care to admit staring at UTXO snapshots. The old P2PK coins from 2009 through 2011 are the clearest canaries. Then there are the exchange behemoths, massive reused addresses that have spent thousands of times, their public keys flapping in the wind. The exact percentage of supply in such addresses is contested, but the direction is clear: a non-trivial slice of Bitcoin has already shown its hand. If Tom Lee's number is a rough proxy for that exposed supply, then it deserves more than a dismissive tweet. If it is just a fear-mongering heuristic, it is no more reliable than a horoscope with a haircut.
Let's run a mental audit, the kind I do before writing anything about cryptographic risk. Coins that have never moved remain in address-form, protected by a double hash. Coins that have moved exactly once from a fresh address leave their public key on the chain, but if the address is never reused, the exposure is contained to that single UTXO. Coins that sit in reused addresses are the true battlefield. A diligent attacker could have been archiving every P2PK and every spent public key for years. That archive becomes the attack surface. The 35% figure might well represent the share of Bitcoin in addresses with at least one prior spend. That is a plausible number, and I have seen similar estimates in research circles. But even so, the existence of an attack surface is not the same as the existence of an attack.
Adam Back knows this. He knows that Shor's algorithm is not a magic wand; it is a physics and engineering nightmare. To break a Bitcoin public key, you need roughly 2,500 logical qubits running error-free for a sustained period. To get those logical qubits, you need millions of physical qubits under an error-correction regime that does not yet exist in any lab. The current state of the art is a few hundred physical qubits with noise rates that would make a broke gambler wince. The timeline from here to there is not a straight line. It is a research graph with false starts, cooling failures, and billion-dollar funding rounds. The year 2028 is not entirely absurd as a date for some cryptographic milestone, but for Bitcoin specifically, it would require breakthroughs that no public roadmap supports.
So why did Adam Back bother? Because the number 35% is not just a technical claim; it is a referendum on the system. When he fires back, he is not only correcting the physics. He is defending the social contract. In a market that runs on memes, the physicist losing the argument to the storyteller is a daily tragedy. Back's rebuttal was short, almost dismissive, the kind of response a cypherpunk gives when an old ghost knocks on the door for the hundredth time. But I have learned to read the unspoken desires of the early adopters. They want certainty. They want the protocol to remain untouched, unmoved, unconquered. Every quantum scare threatens that sacred stillness.
Mapping the unspoken desires of the early adopters is a strange job, but it is mine. In 2022, during my Substack period, I tracked what I called "ghost narratives" — stories that refuse to die no matter how many times they are debunked. Quantum is the oldest ghost in the graveyard. It has all the ingredients the market loves: a hard deadline, a boogeyman made of math, and an outcome so catastrophic that it cannot be laughed off. Every few years the ghost gets a fresh coat of paint. First it was "quantum will kill Bitcoin." Then it was "quantum will kill Bitcoin in 10 years." Now it is "quantum will crack 35% of Bitcoin by 2028." The costume changes. The fear stays the same.
Listening to what the data refuses to say, I think, is the only way to stay sane in this industry. The data refuses to say whether 35% is a precise measurement or a rhetorical dart. The data refuses to say whether Adam Back's confidence is scientific or tribal. But the data does whisper a pattern: Bitcoin's price has historically been far more sensitive to narrative deadlines than to actual cryptographic upgrades. When the rumor of an ETF died in 2019, the market acted as though the product was impossible. When the ETF finally arrived in 2024, the market acted as though it had always been obvious. Deadlines are not technical objects. They are emotional objects. Tom Lee gave the market a new emotional object to hold. Adam Back tried to take it away. The market is still holding it.
Here is where I diverge from both camps. The real quantum threat was never the code. It was the story. Tom Lee's 35% warning, accurate or not, does something that a physical attack cannot: it plants a clock in the collective mind. Once you believe 2028 is a deadline, every decision starts to bend around that date. Institutions hesitate. Custodians start asking awkward questions about cold storage. Your pension fund whispers "quantum risk" before it whispers "Bitcoin." The FUD becomes a self-fulfilling prophecy not because the chain breaks, but because confidence fractures first. Adam Back is right to dismiss the timeline. But dismissing the narrative does not make it disappear. In a bull market, fear is the most underrated fuel.
I have seen this exact pattern before. In 2021, the "Bitcoin will be banned" narrative sent the market into a fever, even though no serious regulatory proposal had the votes to pass. The threat did not materialize, but the fear reshaped behavior. Exchanges changed their compliance teams. Retail investors moved coins to hardware wallets. The market is still navigating the consequences of that panic. Quantum is just the latest installment of the same story. The bogeyman changes, but the function remains: to introduce friction into the path of least resistance. When the story is compelling enough, capital flows away before the physics is proved.
Now, let me be clear about the distinction I am trying to draw. The question is not whether quantum is a real threat. It is. ECDSA is quantum-vulnerable. SHA-256 is not as vulnerable, but the signature layer is. There are honest engineers working on post-quantum signature schemes, and some of them are very good. The question is whether the 35% figure is a measurement or a mood. My reading of the situation is that it is a mood. Tom Lee is a strategist, not a cryptographer. He uses numbers the way a painter uses color. The number 35% is a shade of dread. It is not a coefficient in an attack model. That does not make it harmless. In a market that trades on mood, a shade of dread can move mountains.
Adam Back, on the other hand, represents the opposite failure mode: the belief that technical correctness will automatically win the narrative war. It will not. Bitcoin has survived the government ban narrative, the "death of crypto" narrative, and the "blockchain is just a database" narrative. It survived them because the market eventually moved on, not because the rebuttals were flawless. The quantum story will not be killed by a technical thread. It will be outlived by a better story. And the better story is already being written.
What would that better story look like? It would begin with an honest acknowledgment that Bitcoin's cryptography is old and may not be immortal. It would then pivot to the network's greatest asset: its ability to coordinate through consensus. If quantum risk ever becomes concrete, the social layer of Bitcoin can respond with a migration to quantum-resistant signatures. It will be ugly, it will take years, and it will be a coordination nightmare. But it is possible. The protocol has upgraded before, from P2PK to P2PKH, from P2PKH to SegWit, from SegWit to Taproot. Each upgrade was called impossible by someone. None of them were impossible.
The market should be watching not for a quantum computer in a lab, but for the early signs of migration. The first signal will be a serious conversation about address formats that support post-quantum signature schemes. The second signal will be a Bitcoin Improvement Proposal that treats quantum resistance as a feature, not a punchline. The third signal will be the day a major exchange announces that it has moved its hot wallet keys into a quantum-secure multisignature scheme. Those are the events that will actually change the risk profile. Quibit counts are noise. Migration narratives are signal.
There is a contrarian angle even to this. The quantum threat might not be a future event at all. It might be a current economic force that has been operating for years. Think about it: if the 35% figure is even close to accurate, then a meaningful portion of the supply is held in addresses that are one Shor's algorithm away from catastrophe. The threat does not need to be realized to depress valuation. It acts like a silent tax on every coin that sits in a reused address. The market, in its clumsy way, already senses this. That is why address hygiene has become a small industry. That is why hardware wallets advertise "never reuse addresses" as a security feature. The narrative is already doing its work.
I have sat through institutional meetings where the word "quantum" emptied the room. Not because the investors understood the physics, but because they understood risk. A tail risk that is impossible to price is a reason to not own an asset. Tom Lee's 35% gives that tail risk a frame. Adam Back's rebuttal gives it a challenge. But neither one gives the investor a clear path forward. The path forward is to stop treating quantum as a binary cliff and start treating it as a design constraint. Every coin moved to a fresh address is a coin that is harder to attack. Every coin moved to a multisig or a taproot output is a coin that is part of a more sophisticated lock. The market is quietly, imperfectly, making itself quantum-resistant one transaction at a time.
This is the insight I want to leave you with. The 35% phantom is not a lie. It is a map of our own exposure, drawn in fear. The question is not whether Tom Lee's date is real. The question is whether we are willing to do the dull, unglamorous work of moving into the future before the future moves into us. Bitcoin has always been a bet on the future. The quantum threat is just a reminder that the future is not patient.
The crash is just a chapter, not the end. The next chapter will be written by whoever controls the story of the quantum ghost. Tom Lee tried to write it with a headline. Adam Back tried to write it with a dismissal. But stories are not finished by authority. They are finished by adoption. Watch the addresses. Watch the migration. Watch the day when "quantum-safe Bitcoin" stops being an oxymoron and becomes a standard. On that day, the 35% phantom will look not like a prophecy, but like a calling card. Alchemy is just storytelling with better chemistry. Bitcoin has been turning digital gold into social alchemy for over a decade. The quantum scare is just another ingredient in that ancient recipe.