I don't think the "quantum risk" is FUD. It's a real threat to take into account. But this article is FUD. It omits deliberately all the effort Bitcoin developers (including Blockstream) have already dedicated to find a reasonable path to quantum resistance (SHRINCS, SHRIMPS, Tadge Dryja's recovery mechanism ...).
The nice thing is: Everybody can be reasonably safe for years if he simply stops to re-use addresses.
And then there is this sentence which is almost a caricature:
He estimates a quantum computer could meaningfully break elliptic curve cryptography as early as 2028. Approximately 6.9 million BTC could be vulnerable at a sufficient quantum scale, including legacy wallets and Taproot outputs, which already represented more than 21% of all bitcoin transactions in 2025.
First, the "2028" date the article cites is NOT for a quantum computer that can break Bitcoin's ECC in 10 minutes. It's for a quantum computer which would be able to break a elliptic cryptography key, but probably would take years, or only be able to break small keys like the cryptographic puzzles. I have read no sources for such an early date for a full Bitcoin key. These QCs still need thousands of logical qubits and that's still quite far away.
Second, the Taproot outputs are almost all "d*ckb*tt" transactions (as PepeLapiu likes to call them, i.e. memecoins and NFTs based on Ordinals) and the resulting outputs are too small to be a real incentive for a quantum hacker.
P2PK and above all re-used addresses are the biggest targets. Both can be migrated now to a safe address.
Now the horror scenario the author paints is that in a few years quantum computers could exist that crack a key in 10 minutes. You would be trapped, right? Would never be able to move your precious coins, because they are on that olde ECDSA address!
Incorrect ... a simple softfork could provide a
recovery mechanism for all coins on addresses where never a public key has been exposed. It's still better if people are able to migrate earlier to post-quantum cryptography. But even if Shor-capable QCs arrive before Bitcoin has post-quantum cryptography: between "a QC that cracked an old key in a year" and "a QC that cracked a key on the fly while transacting" there will be probably years of time to do that.