Quantum Money Explained: The Quantum-Safe Future of Digital Currency

Quantum money is a banknote that carries a sequence of quantum states alongside its serial number, and physics forbids anyone from copying those states perfectly. Stephen Wiesner proposed it around 1969–70. It was published in 1983, and it has never been built or used as real currency.

Ordinary banknotes rely on making copying difficult, using holograms, special inks and microprinting. A well-funded forger can eventually match all of them.

Wiesner’s idea was different in kind. He wanted a note whose security comes from nature itself, so that no amount of money or skill could produce a perfect copy. Treat what follows as an idea worth understanding, not a product on its way.

The no-cloning theorem 

You cannot make a perfect copy of an unknown quantum state. This is not a matter of copying being expensive or hard. It is impossible, and that single fact is what would make a quantum banknote unforgeable.

A qubit is the quantum version of a bit. You can read it in more than one way, and each way is called a measurement basis. Think of the basis as the question you ask the qubit.

If you ask the question it was prepared for, you get its stored value back. If you ask the other question, you get a random answer. Worse, the qubit is overwritten to match that random answer. Nothing warns you that this happened, and the result looks perfectly plausible.

 Analogy: imagine a photocopier that, whenever it guesses the page’s layout wrong, silently scrambles both the copy and the original. You walk away with two ruined pages and no idea anything went wrong.

The theorem was proved in 1982 by Wootters and Zurek in Nature. To copy something, you must read it, and reading an unknown quantum state disturbs it.

How Wiesner’s quantum money scheme actually works

The bank prints a note with a serial number and a row of qubits, and it secretly records how each qubit was prepared. Only the bank can check the note. A forger fails because every wrong guess leaves damage behind.

Quantum money is fifty years old and still theoretical, but the ideas underneath it, including no-cloning and quantum key distribution, are the working vocabulary of quantum information today. If you want to learn them properly rather than in headlines, look at the 

Certification in Applied Quantum Computing and AI with IIT Delhi: 6.5 months, live online with recorded sessions, and one of India’s first applied quantum programmes.

What the bank prints

Each note gets an ordinary, readable serial number and a hidden row of qubits. The bank keeps a private record of exactly how each qubit was prepared.

In Wiesner’s era, the natural qubit was a photon’s polarisation. You can ask a photon either “upright or sideways?” or “diagonal left or diagonal right?” A genuine note is assembled from three ingredients:

  • A classical serial number that anyone can read, like the number on a rupee note today.
  • A row of qubits. For each one, the bank randomly picks one of the two bases and a value (0 or 1), then prepares the qubit accordingly.
  • A private table stored at the bank that maps each serial number to the list of bases and values used. This table is the whole secret.

How the bank verifies a note

The bank looks up the serial number, asks each qubit the exact question it was prepared with, and checks the answers. A genuine note passes every time.

Because the bank knows the right question for every position, its check never disturbs a genuine note. Verification runs in three steps:

  1. Read the serial number and retrieve the matching row from the private table.
  2. Measure each qubit in the basis the table records.
  3. Accept the note only if every result matches the recorded value.

Why a counterfeiter fails

A forger must read the note to copy it but doesn’t know which question to ask each qubit. Every wrong guess scrambles a state. Over many states, the chance of getting away with it becomes negligible.

At each position, the forger guesses the basis right half the time and copies that qubit perfectly. When they guess wrong, they get a random value, and their copy still passes that position only half the time. So each position survives with roughly a three-in-four chance, and those chances multiply along the note.

The table below shows how fast the odds collapse as the bank adds qubits. It uses the simple guess-and-copy strategy described above.

Qubits on the noteChance a forger’s copy passes
175%
20about 0.3%
100about 3 in 10 trillion

Cleverer strategies don’t help. In 2012, Molina, Vidick and Watrous proved at the TQC conference that no attack does better at producing two passing notes from one.

how quantum money prevents counterfeiting infographic

The security hole in the original scheme

Wiesner’s scheme is secure against a forger working alone. It is not secure against a forger who can keep submitting notes to the bank and watching which ones pass, because that feedback leaks the secret bases.

In 2010, Andrew Lutomirski of MIT posted “An online attack against Wiesner’s quantum money” on arXiv. He showed that if the bank hands back notes it has rejected, an attacker can break the scheme in time that grows only linearly with the note’s length.

The intuition is simple. Tamper with one qubit, submit the note, and read the verdict. Each accept-or-reject answer tells you something about one position, like a lock that clicks when you find each pin.

In 2012, Scott Aaronson and Paul Christiano described a way to “patch a major security hole in Wiesner’s scheme.” Their private-key construction allows unlimited verifications. It stays unconditionally secure even when the counterfeiter interacts adaptively with the bank. The work appeared at ACM STOC 2012, with the journal version in Theory of Computing 9(9), 2013.

Public-key quantum money: anyone can check it

Public-key quantum money lets anyone, such as a shopkeeper, verify a note, not just the bank that printed it. The price is that security now rests on maths problems believed to be hard, rather than on physics alone.

The problem with needing the bank

Wiesner’s note can only be checked by its issuer, because only the issuer knows the bases. A currency you must post to a central authority before accepting it is not really a currency.

Publishing the bases would let everyone verify notes, but it would also let everyone copy them. Researchers have shown that publicly verifiable banknotes cannot rely on no-cloning alone. They also need computational assumptions: problems that are hard to solve, not impossible.

Quantum money from hidden subspaces

Aaronson and Christiano’s 2012 scheme was the first public-key quantum money with a security proof resting on a classical hardness assumption. The core idea is a quantum state hidden inside a secret mathematical “shape.”

Each note is a quantum state spread evenly across a secret subspace, a structured set of bit-strings. The bank publishes a disguised description of that subspace as the solutions of random multivariate polynomials. Anyone can use it to test a note, but nobody can use it to rebuild the note.

Verification needs only two tests, one in each of two complementary bases, which echoes Wiesner’s original intuition. In an idealised “black-box” version, the authors proved the scheme unconditionally secure.

Citation: Aaronson & Christiano, “Quantum Money from Hidden Subspaces,” STOC 2012; Theory of Computing 9(9), pp. 349–401, 2013.

What happened next

Researchers have kept proposing public-key schemes, and cryptanalysts have kept breaking some of them. That back-and-forth is normal for young cryptography, but it means no public-key scheme is yet considered settled.

The table below shows the main milestones. Note that the attacks on Aaronson–Christiano target its concrete polynomial versions, not the idealised black-box version.

Scheme or resultAuthors, venue, yearStatus
Quantum money from knotsFarhi, Gosset, Hassidim, Lutomirski & Shor, ITCS 2012Proposed; security rests on conjectures about knot invariants
Attack on the noise-free Aaronson–Christiano schemeConde Pena, Faugère & Perret, PKC 2015Algebraic cryptanalysis of the concrete scheme
Attack on the noisy Aaronson–Christiano schemeConde Pena, Durán Díaz, Faugère, Hernández Encinas & Perret, IET Information Security13(4), 2019Classical polynomial-time attack over prime fields other than F₂; partial attack over F₂ for some noise ranges
Lattice-based approachesLiu, Montgomery & Zhandry, EUROCRYPT 2023Showed how several lattice-based attempts fail
Quantum money from abelian group actionsZhandry, ITCS 2024Newer proposal; research ongoing

Why quantum money still does not exist

Nobody can store a quantum state for years in a wallet. One of the longest single-qubit memories ever reported holds its state for roughly an hour and a half, and it works only inside a vacuum chamber surrounded by lasers.

Quantum states constantly leak information into their surroundings through heat, stray fields and vibration. This process is called decoherence, and a quantum memory is any device that holds it off for as long as possible.

In January 2021, a team reported in Nature Communications an estimated coherence time of about 5,500 seconds for a single trapped ytterbium-ion qubit. They extrapolated that figure from measurements up to 960 seconds.

A banknote needs years in circulation. One year is roughly 5,700 times longer than that record, and the note would have to survive at room temperature, in a pocket, not in a laboratory trap.

Laboratory demonstrations do exist, but they are not prototypes. In 2018, Bozzio and colleagues reported in npj Quantum Information a quantum “credit card” variant with classical verification, built from weak laser pulses. The states went straight to the card reader without being stored in any quantum memory. The authors themselves describe current storage technology as too immature for a real card.

To be clear, quantum money has never been deployed, and no central bank has announced one. The physics works in the lab, but the hardware to put it in a pocket does not exist.

Does quantum money have anything to do with quantum computers breaking Bitcoin?

No. Quantum money uses quantum physics to stop counterfeiting. The Bitcoin worry is about quantum computers breaking the classical maths that secures transactions. They are two problems with two toolkits, sharing one adjective.

A cryptocurrency such as Bitcoin is ordinary digital data. Ownership is proved with elliptic-curve digital signatures. In 1994, Peter Shor published a quantum algorithm that, on a large enough error-corrected quantum computer, could in principle recover the private keys behind those signatures. That is the threat behind “quantum-safe” headlines.

The defence is post-quantum cryptography. These are classical algorithms that run on normal computers and rely on maths problems that quantum computers are not known to solve efficiently. No qubits are involved anywhere.

Quantum money sits on the opposite side of the line. It needs quantum hardware inside every note and targets forgery, not codebreaking. It does not protect Bitcoin, bank accounts or any other asset from quantum computers.

The confusion is understandable: “quantum” plus “money” reads like a crypto story. But the work on protecting digital payments from quantum attacks happens in NIST’s post-quantum cryptography project. NIST published its first finalised post-quantum standards in 2024, and that is the place to follow the topic.

What quantum money teaches you about quantum information

Wiesner’s idea failed as money but succeeded as cryptography. The same “measurement disturbs the state” trick became BB84 quantum key distribution, which runs on real fibre links today.

In 1984, one year after “Conjugate Coding” finally appeared, Charles Bennett and Gilles Brassard presented BB84 at the IEEE International Conference on Computers, Systems and Signal Processing in Bangalore. The protocol uses the same two-basis encoding. If an eavesdropper measures a photon in the wrong basis, they leave detectable damage.

The crucial difference is timing. A quantum key only has to survive a trip down a fibre, which lasts a tiny fraction of a second. A banknote has to survive for years.

The lesson worth remembering is that in quantum information, the property that makes one scheme impossible to build is often the same property that makes another scheme secure. Fragility killed the banknote, and the same fragility makes eavesdropping visible. That is why Wiesner’s idea is still taught more than fifty years later.

The timeline below shows how the idea moved from rejected manuscript to modern research. The gap between the first two dates is part of the story.

development of quantum money

Frequently asked questions

1. How does a quantum banknote prevent someone from spending a counterfeit copy?

A quantum banknote contains quantum states that cannot be perfectly duplicated. When a counterfeiter attempts to measure these states without knowing how they were prepared, the measurement can disturb them. The bank checks the states against its private records to identify forged notes.

2. What happens if someone measures a quantum banknote using the wrong basis?

Measuring a qubit in the wrong basis produces a random result and changes its state. This means the altered qubit may no longer pass the bank’s verification test. The disturbance makes unauthorised copying detectable.

3. Why does the bank need a private database to verify quantum money?

In Wiesner’s original scheme, the bank stores a secret record linking each note’s serial number to the quantum states used to create it. During verification, the bank uses this record to measure the qubits correctly and determine whether the note is genuine.

4. Can quantum money be verified without contacting the issuing bank?

Yes, in principle. Public-key quantum money is designed to let anyone verify a note using publicly available information. However, these schemes require additional mathematical security assumptions, and practical, widely accepted public-key quantum money remains undeveloped.

5. What is the difference between private-key and public-key quantum money?

Private-key quantum money can be verified only by an authority that holds the secret preparation information. Public-key quantum money aims to let anyone verify a note using public information. The challenge is making public verification possible without allowing counterfeiters to reproduce valid quantum states.

6. Why is quantum memory essential for making quantum money practical?

Quantum memory must preserve a note’s quantum states until they can be verified. If those states lose their information through decoherence, the note may become unusable. Current quantum memories cannot preserve states under everyday conditions for the years that physical currency needs to remain in circulation.

7. Could quantum money work alongside ordinary banknotes and digital payments?

In principle, quantum money could be designed as a different form of physical currency, while ordinary banknotes and digital payment systems continue to operate. However, quantum money would require specialised quantum-state preparation, storage, and verification hardware that is not currently practical for everyday currency.

8. How can repeated bank verification attempts create a security risk?

If a bank returns rejected notes and reveals whether each submission passed, an attacker may use that feedback to learn information about the note’s hidden quantum states. Research showed that this kind of interaction can weaken Wiesner’s original scheme, making verification protocols an important part of quantum-money security.

9. How did quantum money contribute to the development of quantum cryptography?

Stephen Wiesner’s quantum-money proposal helped establish the idea that measuring unknown quantum states can reveal tampering. This principle later influenced BB84, a quantum key distribution protocol that allows two parties to detect potential eavesdropping while establishing a shared key.

10. What are the biggest challenges preventing quantum money from becoming real currency?

The main challenges include preserving quantum states for long periods, building practical quantum memories, preventing attacks during verification, and developing secure schemes that can be used at scale. Until these problems are addressed, quantum money remains a research concept rather than a deployable currency.

IIT Delhi

Continuing Education Programme

Certification in Applied Quantum Computing and AI

One of India's first applied quantum programmes — built for the quantum decade.

Duration

6.5 Months

Format

Live Online + Recorded

Batch

Weekend

Application open now

6.5 Months

Weekend batch

4+1 Projects

Incl. capstone

STEM Eligible

B.Tech / BE / BSc

Varsity

×

Quantum Computing