If bitcoin remains invulnerable to them, then it is possible that the advent of quantum computers will even be useful for bitcoins in the sense that it will be possible to return to circulation over six million bitcoins that are now irretrievably lost.
1+ million Bitcoins, the other "lost" coins are QC resistant
You're talking about some kind of cyberpunk. It seems to me no one will dare to destroy the Bitcoin project, just think about what consequences it will end.
We want to make Bitcoin better and stronger.
LONG BEFORE before any actual Quantum Algorithm AND Quantum Computer exists that would allow someone to access the bitcoins secured by P2PKH, Bitcoin will already have moved to a quantum-resistant authorization algorithm.
"long before" implies you know when QC will be capable of breaking ECDSA. when will that be---and accordingly, when will bitcoin developers discuss which quantum resistant scheme to implement, and when to implement it?
We don't think that QC development will happen step by step. Our expectation is that someone will find a QC technology, that allows "far beyond expectations" numbers of qubits, that will allow this QC to get all private keys immediately.
We think that such a QC will surprise the Bitcoin community and only thereafter we will upgrade to a quantum resistant Bitcoin network. We hope that the user of such a QC to get the private keys, knows exactly how Bitcoin works and allows the owners to transfer their coins to the new QC resistant addresses. It would be a win-win game: the QC user would get the "lost" coins, the Bitcoin owners could transfer their coins to QC resistant addresses, the Bitcoin ecosystem wouldn't be affected, we would have a stronger Bitcoin network. How would a QC user act: starting with the oldest "lost" coins and moving them, so that the Bitcoin community can realize that someone is moving the "lost" coins (e.g. a special posting board here on bitcointalk) but gives the owners the possibility to transfer their coins to other addresses. In the meantime we will have a very quick "quantum resistance upgrade". And it will continue like DannyHamilton described it:
The coins that are still remaining in the weak transaction outputs once Quantum Technology becomes a realistic threat will be those coins that are effectively "lost". The QC owners will become the new owners of those coins, and Bitcoin will carry on as it always has.
but stronger