Grover's algorithm cuts hash strength in half. As I understand it, the whole point of 256 bit crypto is to survive the advent of quantum computers, when it degrades to 128 bits. Yes, a quantum computer shouldn't break SHA256, but quantum computers would almost immediately account for the vast majority of the hashing power, centralizing control of the currency.* Once everyone has quantum computers, it would work again (with a replacement public key system), but given such a disruption, I don't see much point to salvaging the old currency, rather than starting over.
* I think a gigahertz quantum computer would have the hashing power of the current bitcoin network.
I think a gigahertz quantum computer would have the hashing power of the current bitcoin network.
My math agrees with you. Looks like I was underestimating the effect of quantum computers.
Difficulty is currently growing at 30-40% per month. That won't last forever, obviously, but we can expect it to keep going up for a while, at least. (https://blockchain.info/charts/hash-rate) Still, it looks like you'd need an unrealistic amount of ASICs to match the output of just 1000 quantum computers.
Given that, there'll probably be a large financial incentive to m...