Forbes ran a quantum-threat piece this week. Six sources. Five sell quantum-resistance products, one sells gold.
The exposure is real. The sourcing gradient is the story.
Three things the piece gets soft:
Justin Drake's "10% by 2032" is presented as an outside read on Google's March 30 paper. He coauthored it. That's one source counted twice.
The 15-bit key break is real and it's a toy — a 512x headline that is nine bits. The remaining distance to 256 is 2^241.
And no runtime. One architecture needs 264 days to run the attack. That machine cannot take a coin out of the mempool. It can only take a coin that has been sitting still for a decade.
Which points at the actual near-term exposure, and it isn't the hardware.
BIP-361 would retire legacy signatures and render Satoshi-era coins permanently unspendable. That is a contentious-fork fight, a confiscation narrative, and a volatility event — and none of it requires a working quantum computer. The physics clock reads 2032. The governance clock reads now.
Watching qubit counts is watching the wrong clock.