Ly Gravity

The 35% Illusion: Tom Lee, Quantum Fear, and the Missing Attack Model

IvyFox NFT

Tom Lee handed the market a number this week: 35% of Bitcoin's supply will be “cracked” by quantum computers by 2028. He did not publish a qubit count. He did not specify an attack surface. He did not define what “cracked” means in an ECDSA context. The market did what markets do—it repriced fear. Volume without velocity is just noise in a vacuum, and this was noise with a timestamp.

Tom Lee is not a cryptographer. He is the co-founder of Fundstrat Global Advisors, an equity strategist who converts macro data into price targets. His Bitcoin calls have often been aggressive—$25,000 by 2022, $150,000 by the end of 2024—and they have been right often enough that his name still triggers headlines. But a price target does not require a cryptographic proof. A claim about Shor's algorithm does.

Adam Back is the opposite pole. The inventor of Hashcash, the proof-of-work precursor cited directly in the Bitcoin whitepaper, and the co-founder of Blockstream, he has spent thirty years thinking about consensus and cryptography. When Back says the 2028 warning is wrong, he brings institutional memory to the table. The reported exchange, however, was never a technical debate. It was a hype cycle compressing into a quote. Neither side, according to the source material, brought a model.

The original coverage contained exactly two data points: a warning and a rebuttal. No paper. No benchmark. No UTXO analysis. No methodology. As a risk consultant, I have learned to treat that shape as a red flag. A precise number without a falsifiable process is not an insight; it is a marketing artifact. The rest of this article is a forensic teardown of that artifact.

What 35% Could Possibly Mean

Let me do what forensic analysis demands: strip the narrative and look at the raw claim. If Lee meant that there is a 35% probability of a quantum break by 2028, then he is making a probabilistic forecast without a probability distribution. That is not analysis; it is rhetoric. If he meant that 35% of Bitcoin's supply will become vulnerable, he needs to identify which coins, how their public keys are exposed, and what attack scenario links a theoretical computer to a supply metric. We were given neither. The ambiguity is not a minor omission. It is the tell.

When I receive a strange number, I ask three questions. Where did the number come from? What equation produced it? What does it predict that can be falsified? Lee's number fails all three. It has no input, no process, and no output except fear. That makes it indistinguishable from a meme.

The 35% Illusion: Tom Lee, Quantum Fear, and the Missing Attack Model

I learned this lesson in the 2021 ICO audit detour. I spent four weeks auditing EthoX, a staking protocol promising 400% APY. The whitepaper described a sustainable reward engine. The contract had a reentrancy bug and an oracle manipulation path. I flagged it to the team; they ignored it for three days; the exploit drained $12 million. The lesson was not that all high-yield projects are frauds. The lesson is that risk lives in the specific mechanism, not in the fear-level of the community. Quantum panic is the same. The mechanism—key exposure, qubit count, migration timeline—determines the actual risk. Everything else is sentiment.

The Quantum Threat Model: Public Key, Not Address

The quantum threat to Bitcoin is real, but it is also narrow. Bitcoin uses ECDSA for legacy addresses and Schnorr signatures for Taproot. Both rely on the elliptic curve discrete logarithm problem. A fault-tolerant quantum computer running Shor's algorithm could theoretically derive a private key from a public key in polynomial time. But theory is not a timestamp.

A Bitcoin address is not a public key. For a P2PKH output that has never been spent, the public key exists only as a hash. To exploit Shor, an attacker must first recover the public key from the hash, which requires inverting SHA-256 and RIPEMD-160. That is an additional preimage problem that current quantum algorithms cannot solve efficiently. The set of coins actually exposed is the set of addresses whose public keys are already public: old P2PK outputs, spent change outputs, and any address that has sent at least one transaction.

That set is not automatically 35% of supply. Early P2PK coins from the Satoshi era contain roughly a few million BTC, and many of those are considered inert. Spent change outputs add more volume, but no one has done the public accounting. A credible warning would begin with a UTXO snapshot and then compute the economically active vulnerable share. A number like 35% without that snapshot is not data. It is a construction.

The 35% Illusion: Tom Lee, Quantum Fear, and the Missing Attack Model

I saw the same construction in the 2023 NFT wash trading exposé. When I mapped clustered wallet addresses on a CryptoPunks derivatives marketplace, I found that 40% of reported volume was wash trading. The number 40% sounded like a data point. It was actually a fabrication enforced by one entity. The lesson: percentages become real only when the methodology is transparent. Lee gave no methodology, so his 35% belongs in the same category as my 40%—a number that tells you more about the narrator than about the system.

The 35% Illusion: Tom Lee, Quantum Fear, and the Missing Attack Model

The Missing Qubit Count

Quantum computing is progressing, but not at the rate the panic implies. IBM's Condor reached 1,121 physical qubits in 2023, a milestone in hardware engineering. Yet those are noisy qubits. Error correction consumes thousands of physical qubits for every logical qubit. Public estimates for breaking secp256k1 require thousands of logical qubits and billions of Toffoli gates. That translates to millions of physical qubits. No published roadmap, from IBM, Google, or any academic lab, puts that capability on a timetable ending in 2028.

I am not saying the roadmap is impossible. I am saying the roadmap is absent from Lee's claim. In my 2024 ETF custody audit, I saw how dangerous it is to rely on the absence of proof. Two of the top three Bitcoin ETF issuers depended on third-party custodians with insufficient private-key insurance. The regulatory wrappers made the custody arrangement look safe. The actual insurance coverage was thin. The same pattern appears in the quantum debate: the absence of an immediate exploit is treated as proof that no exploit is coming.

Authenticity cannot be hashed; it must be proven. The same applies to risk forecasts. A claim about quantum risk is not authentic because it comes from a famous strategist. It must be proven with an attack model, a supply analysis, and a timeline. Lee provided none of those. Adam Back's rebuttal, while technically sound in the narrow sense, also stopped short. “Bitcoin can be upgraded” is not the same as “Bitcoin will be upgraded in time.”

The Real Vulnerability: Coordination, Not Cryptography

Here is the contrarian angle. The bulls who dismiss quantum risk entirely have a blind spot. The upgrade path is not merely a code change; it is a social contract. Moving Bitcoin to a post-quantum signature scheme would require a consensus change, likely a soft fork. BIPs take years to reach activation. Miners must signal. Exchanges must update. Hardware wallets must ship new firmware. Cold-storage users must physically find old devices and move funds.

SegWit took years. Taproot took years. In an actual quantum emergency, the timeline would compress into months, perhaps weeks. The owner of a vulnerable wallet would need to wake up, generate a new key, and broadcast a transaction before an attacker's Shor pipeline completes. That is not a protocol problem. It is an operations problem. And operations are where I have seen every system fail.

When Terra and Luna collapsed in May 2022, I did not panic. I built a correlation matrix between UST's minting velocity and LUNA's burn rate. The data showed the loop was unsustainable before the final death spiral. My report, “The Algorithmic Trust Deficit,” was cited by multiple financial outlets. I bring this up not for vanity but to state my method: I will not score a claim until I have an input, a process, and an output. Lee gave us only a number. Back gave us only a rejection.

The market should reject the number too. But watch how markets price this kind of event: volatility futures jump, options skew flips, and retail headlines multiply. In a bull market, a quantum scare is a liquidity event, not a risk signal. Institutional investors will buy the volatility. Retail will sell into the next dip. The actual cryptographic risk has not changed by one hash.

Patterns emerge when you stop looking for winners. I have been writing and auditing since before the ICO bubble. The pattern here is familiar: a high-status name, a scary date, a clean percentage, and zero technical traceability. It is the same shape as every Ponzi forecast I have seen. The only difference is the asset class.

So let me steelman the panic. Tom Lee may be wrong about 2028, but he is right about one thing: there will be a window where quantum computers create a real, if partial, threat. That window will likely come later than 2028, but it will come. If you wait until the first announced exploit, you are not early; you are last. The bull case that says “we have plenty of time” is as dangerous as the bear case that says “the end is 2028.” Both ignore the system's weakest point: human latency.

The deeper issue is governance. Bitcoin can adopt a hash-based signature scheme like SPHINCS+ or Lamport, and Bitcoin Core can add a new key type. But activation is not a commit message. It is a global referendum. No one is publicly coordinating that referendum with the same urgency as a token launch. That gap is the true 35%: the portion of Bitcoin's value currently dependent on the assumption that the social layer will move faster than the hardware layer.

Gravity always wins against leverage. The leverage here is fear. The gravity is the slow, unglamorous work of cryptographic migration. Market participants who understand this will not buy or sell on the 35% number. They will audit their own custody, check whether their addresses expose public keys, and begin thinking about post-quantum address formats today. That is the only trade that survives both timelines.

We do not fear the hack; we fear the ignorance. The 2028 quantum warning is a test of that principle. It should fail. But the lesson it reveals should not be discarded. The next time a high-profile forecaster offers a percentage for a cryptographic apocalypse, do not ask whether it is bullish or bearish. Ask for the model. Show me the circuit depth, the key exposure ledger, and the migration plan. If none exists, the correct trade is to do nothing.

Volume without velocity is just noise in a vacuum. And in this market, the only thing more expensive than FOMO is fear marketed as precision. The 35% number is noise. The vulnerability it gestures toward is real. The difference between the two is the entire discipline of risk management.

One final question remains. If a major exchange moved 35% of its Bitcoin to a quantum-resistant address tomorrow, would you know whether it was preparing for the threat or for a bank run? Probably not. And that, more than any 2028 forecast, is the risk that deserves your attention.

Market Prices

BTC Bitcoin
$63,166.1 -0.42%
ETH Ethereum
$1,886.02 +0.26%
SOL Solana
$75.62 -0.11%
BNB BNB Chain
$606.6 -0.33%
XRP XRP Ledger
$1.01 +0.17%
DOGE Dogecoin
$0.0700 +0.03%
ADA Cardano
$0.1803 -0.72%
AVAX Avalanche
$6.45 +0.81%
DOT Polkadot
$0.7656 -0.43%
LINK Chainlink
$8.88 +1.81%

Fear & Greed

29

Fear

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,166.1
1
Ethereum ETH
$1,886.02
1
Solana SOL
$75.62
1
BNB Chain BNB
$606.6
1
XRP Ledger XRP
$1.01
1
Dogecoin DOGE
$0.0700
1
Cardano ADA
$0.1803
1
Avalanche AVAX
$6.45
1
Polkadot DOT
$0.7656
1
Chainlink LINK
$8.88

🐋 Whale Tracker

🔴
0xfc57...aedc
12h ago
Out
6,367 SOL
🟢
0x762c...3ba5
3h ago
In
4,039,343 USDT
🔵
0x9d3a...e347
2m ago
Stake
7,618,665 DOGE

💡 Smart Money

0xc54f...b4e0
Arbitrage Bot
+$2.3M
65%
0x997d...c42b
Top DeFi Miner
+$2.1M
78%
0xa3fe...c403
Top DeFi Miner
+$4.5M
66%

Tools

All →