Cryptographers place $5,000 bet on whether quantum will ever break real-world crypto

April 9, 2026
Bitcoin and Ethereum coins on a digital circuitry background symbolizing blockchain technology.
Photo by Jonathan Borba on Pexels

The wager

Two well-known cryptographers have turned a technical disagreement into a literal wager. It has been reported that Filippo Valsorda and Matthew Green sketched out a $5,000 bet over whether a cryptographically relevant quantum computer (CRQC) will be able to recover a shared secret from ML-KEM-768, a recently approved quantum-resistant algorithm. The bet, allegedly drawn up by Green, pays out depending on whether that shared secret can be extracted from a public key within the agreed timeframe.

Why it matters

This isn’t poker for hobbyists. The question at stake is when — or if — quantum machines will collapse the superposition that currently defines the field of cryptography: both imminent doom and distant shrug. It has been reported that Google recently revised its estimates, claiming Shor’s algorithm would need about 20 times fewer physical qubits to tackle the elliptic-curve discrete logarithm problem (ECDLP-256) than previously thought. NIST’s timetable to phase out quantum-vulnerable algorithms by 2035 looms in the background, and vendors keep sounding the alarm.

The personalities and the point

The wager highlights a clash of temperaments as much as math. Peter Gutmann has been openly skeptical, arguing that error correction still blocks any near-term threat; Scott Aaronson and others urge caution. Valsorda says we should move faster on post-quantum transition; Green called that a reasonable precaution but said he’d personally bet heavy against a CRQC within the next decade. It’s lively, human, and a little theatrical — scholars arguing with spreadsheets, then putting skin in the game. Who says academics can’t have a little fun?

Stakes and the takeaway

So what does a $5,000 bet change? Not much in cash, but plenty in signal. It forces explicit definitions — what counts as “cryptographically relevant” and which algorithms really matter — and it dramatizes a policy problem that otherwise lives in standards documents and committee minutes. Whether you call it prudent insurance or alarmism, the wager underlines one truth: uncertainty has costs, and the community is now publicly hedging against them. Who wins the bet matters less than the conversation it kicked off.

Sources: The Register