Marcus Webb Fintech Engineer · Crypto Researcher since 2017

Marcus spent nearly a decade building payment infrastructure at fintech companies. He writes plain-English explainers focused on accuracy and honest risk disclosure.

✓ Reviewed for accuracy · Full bio →

Key Takeaways

  • On July 23, 2026, nine institutions — including BlackRock, Coinbase, Fidelity, Block, and Strategy — launched the "Bitcoin Security Consortium," pledging $15 million over three years to Bitcoin's developers.
  • There is no shared pot of money. Each member writes its own checks to its own recipients, a design meant to prevent any single group from gaining leverage over Bitcoin's code.
  • The first stated priority is post-quantum cryptography research, after 2026 Google findings pulled quantum timelines forward.
  • The structure limits formal control but not informal influence — and individual amounts and recipients remain undisclosed.

Nobody Actually Works for "Bitcoin"

Here's a fact that surprises most people who own Bitcoin: there is no Bitcoin Inc. No headquarters, no payroll department, no CEO signing off on the software that secures roughly $1.3 trillion in value.

The software most of the network runs is called Bitcoin Core, maintained by a small group of independent contributors — roughly 41 active developers in recent counts. The protocol has no budget line for maintenance. Instead, developers are funded by an ad hoc patchwork of about 13 organizations: nonprofits like Brink, OpenSats, and Btrust; companies like Block (through its Spiral team), Blockstream, and Chaincode Labs; MIT's Digital Currency Initiative; and wealthy individual donors, including Arthur Hayes's Maelstrom fund.

To put the scale in perspective: Brink funds around eight full-time Core engineers on an estimated $1.5–2 million a year, and Chaincode Labs supports a similar number. For a network with trillion-dollar valuations and an entire ETF industry built on top of it, the maintenance budget is startlingly thin.

What the Bitcoin Security Consortium Actually Is

On July 23, 2026, that changed — at least in visibility. Nine of the largest institutional players in Bitcoin announced the Bitcoin Security Consortium: Anchorage Digital, ARK Invest, BlackRock, Block, Blockstream, Coinbase, Fidelity Digital Assets, Galaxy, and Strategy. Combined pledge: $15 million over three years.

The unusual part is the structure. There is no pooled fund and no grant committee. Each member independently decides which developers, researchers, or organizations get its money. Mike Schmidt, executive director of the nonprofit Brink, coordinates the day-to-day work — and does so in a volunteer capacity, not as a paid Consortium employee.

Think of it less like a joint venture and more like nine donors agreeing to show up to the same fundraiser and announce their gifts publicly, while still writing separate checks to charities of their own choosing. Coordinated visibility, no central treasury.

This isn't the first institutional money to reach core development. ETF issuers VanEck and Bitwise had already pledged portions of their fund profits to Brink — VanEck committed 5% of its spot Bitcoin ETF profits — and Jack Dorsey personally gave Brink $5 million. What's new is nine major firms doing it at once, in public, as a stated coalition.

Why Quantum Research Got the First Priority

The Consortium's declared first funding target is post-quantum cryptography — research into replacing the math that protects Bitcoin wallets with math a quantum computer couldn't unwind.

The urgency comes from a shifting timeline. Google research published in 2026 cut the estimated number of qubits needed to break Bitcoin-grade elliptic-curve cryptography by roughly 20x, moving some credible-threat estimates up to as early as 2029 from earlier assumptions measured in decades. We covered what that quantum threat actually means for holders in detail — the short version is that it's real, still years out, and being worked on.

The exposure is concentrated. Roughly 34% of circulating Bitcoin — about 6.5 to 6.9 million coins, including an estimated 1.7 million believed to be Satoshi-era — sits in addresses whose public keys are already visible on the blockchain. Those are the coins most at risk if quantum capability arrives before the network migrates. In April 2026, developers published BIP-361, "Post Quantum Migration and Legacy Signature Sunset," sketching an early roadmap. Ethereum's developers are running a parallel effort of their own.

The Firewall, and Whether It Holds

The Consortium explicitly renounces any role in protocol governance. It won't advocate for specific Bitcoin Improvement Proposals, won't pool funds, and claims no seat at the table when technical decisions get made.

That matters, because Bitcoin's rule changes don't work like corporate votes. As we walked through in our piece on how Bitcoin actually changes its own rules, upgrades require rough consensus across developers, miners, node operators, exchanges, and users. Money can't buy that outright.

But critics raise a subtler concern that deserves a fair hearing: if a handful of well-capitalized firms fund a large share of the developers working on one technical direction, that shapes which problems get attention — no vote required. The analysis at tftc.io framed the test bluntly: does any member ever publicly push a specific BIP, or condition its funding on one being adopted? If that happens, the firewall collapses.

What We Still Don't Know

Two honest gaps are worth naming.

First, disclosure. Individual contribution amounts and specific recipients haven't been published, so there's no way to verify how the $15 million is actually distributed — or whether it expands developer capacity beyond what Brink and Chaincode already fund. Spread across nine firms and three years, it works out to roughly $5 million a year: real money in this context, but not transformative.

Second, more money doesn't automatically buy better security. Bitcoin Core development had already rebounded sharply in 2025 without institutional coordination — activity up around 60%, with 135 contributors merging roughly 285,000 lines of code. That same year, Core received its first-ever public third-party security audit, by the firm Quarkslab, which found no critical vulnerabilities, only two low-severity issues, after 16 years of existence.

What This Means for You

Practically speaking, nothing changes in your wallet this week. No upgrade to install, no action to take.

What changes is your mental model. Bitcoin isn't maintained by a company and never has been. It's maintained by a few dozen people funded by donors who each decide independently whom to support — a fragile-sounding arrangement that has nonetheless produced software resilient enough to pass an outside audit clean.

The Consortium is a bet that this model can absorb institutional money without changing who holds the keys to decision-making. Whether that bet pays off is genuinely unresolved. The thing to watch isn't the dollar figure in the press release. It's whether, a year from now, any of those nine names is publicly arguing for a particular change to Bitcoin's code — and whether its checkbook is anywhere near the argument.