Mark RadarMARK RADAR
About
EN
Sign in

Bitcoin Faces Outsized Security Threat as Quantum Computing Breakthroughs Accelerate, Citi Says

2 reports · First detected 2026-05-18 · Last active 2026-05-21

Quantum computers capable of using Shor’s algorithm to break elliptic-curve cryptography could put Bitcoin holdings with exposed public keys at risk of theft. The threat could also extend to internet and financial infrastructure. Citi said Bitcoin’s conservative governance and the need for community consensus on upgrades could leave its migration to quantum-resistant technology trailing Ethereum’s.

Citi issued a digital-assets research report on May 18, 2026, warning that quantum computing breakthroughs are shortening the timeline for a practical attack. The report estimated that the public keys of about 6.5 million to 6.9 million Bitcoin, roughly one-third of the circulating supply, had already been exposed on-chain. Those holdings were worth about $450 billion at prices prevailing at the time.

All Coverage

2 original reports

The Backstory

The history behind this event
Coinbase Warns 7 Million Bitcoin Are Exposed to Quantum Attack Risk2026-06-14 · 1 reports · similarity 0.81

Bitcoin transactions use elliptic-curve digital signatures to protect assets. Once an address reveals its public key, a sufficiently powerful quantum computer could eventually derive the private key and steal the funds. The threat is not exploitable today, but the permanent public record of blockchain data means exchanges and long-term holders must plan ahead to migrate to quantum-secure addresses.

Coinbase’s independent advisory board on quantum computing and blockchain released a report on June 11, 2026, estimating that the public keys for about 7 million BTC have been exposed. About 1.7 million BTC are held in early P2PK addresses, while roughly 5 million BTC are exposed through address reuse and largely consist of active funds such as exchange cold wallets. Attackers can collect the data now and attempt to crack it later.

Quantum Computing Threatens Bitcoin Security as Bit Digital Shifts to Ethereum2026-06-11 · 1 reports · similarity 0.87

Bitcoin transactions use elliptic-curve digital signatures to secure assets. A quantum computer running Shor’s algorithm could potentially derive private keys from public keys, putting older wallets and transaction security at risk. Ethereum, by contrast, has planned a mechanism allowing accounts to adopt quantum-resistant signatures, bringing corporate crypto treasury strategies and onchain governance capabilities into focus.

Google Quantum AI and other institutions published research on March 30, 2026, estimating that fewer than 500,000 physical qubits could crack a key in about nine minutes. Citi warned on May 18 that the potential attack timeline had shortened. Bit Digital had already announced on July 7, 2025, that it would sell about 280 Bitcoin and, alongside a $172 million fundraising, increase its holdings to 100,603 Ethereum.

Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security2026-05-30 · 1 reports · similarity 0.84

Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.

Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.

Glassnode Says Nearly 10% of Bitcoin Supply Faces Structural Risk From Quantum Breakthrough2026-05-20 · 1 reports · similarity 0.84

Bitcoin uses secp256k1 elliptic-curve signatures to secure control of assets. If a large, fault-tolerant quantum computer could use Shor's algorithm to derive private keys from exposed public keys, attackers might be able to forge transactions. Blockchain analytics firm Glassnode said early P2PK, legacy P2MS and modern P2TR outputs all directly expose public keys, potentially making long-dormant assets from the Satoshi era targets.

On May 20, 2026, Glassnode published an analysis classifying 1.92 million BTC, or 9.6% of the supply, as “structurally unsafe,” including P2PK, P2MS and P2TR outputs. The report recommended adopting BIP-360, proposed in December 2024, which uses P2MR to remove Taproot's vulnerable key path. However, the proposal has yet to incorporate post-quantum digital signatures.

Google Research Finds Quantum Threat to Bitcoin Lower Than Expected2026-04-18 · 14 reports · similarity 0.80

Bitcoin and Ethereum rely on elliptic-curve cryptography to safeguard assets. A quantum computer capable of deriving a private key from a public key could potentially steal funds. Bitcoin activated Taproot on November 14, 2021, and because some transactions expose public keys in advance, the potential window for attack has widened.

The latest research from Google Quantum AI estimates that about 500,000 error-corrected physical qubits could be enough to crack a key within Bitcoin’s roughly nine-minute transaction confirmation window, far below previous estimates of several million qubits. No funds have been reported stolen through such an attack, but the researchers are urging the community to begin planning a migration to post-quantum cryptography.

Adam Back Urges Bitcoin to Prepare for Quantum Computing Threat2026-04-17 · 4 reports · similarity 0.83

Bitcoin currently relies on ECDSA and Schnorr signatures to secure asset ownership. A sufficiently powerful quantum computer could eventually use Shor’s algorithm to derive private keys from exposed public keys. Although the threat remains confined to laboratory experiments, migrating the network’s wallets, software and users would take considerable time, making early development of quantum-resistant safeguards critical to asset security.

Speaking at Paris Blockchain Week on April 16, 2026, Blockstream CEO Adam Back advocated introducing an optional upgrade first and giving users 10 years to move funds to quantum-resistant addresses. He estimated that a real threat remains at least 20 years away. Blockstream’s research division proposed a hash-based signature scheme in December 2025. The migration could also clarify whether the roughly 500,000 to 1 million Bitcoin attributed to Satoshi Nakamoto can still be moved.

Wall Street Broker Bernstein Warns of Quantum Threat to Bitcoin but Says Risk Is Manageable2026-04-14 · 6 reports · similarity 0.84

Bitcoin uses elliptic-curve digital signatures to prove asset ownership. If a large-scale quantum computer could use Shor's algorithm to derive private keys, older addresses whose public keys have been exposed could be vulnerable to theft. Wall Street research and brokerage firm Bernstein said the risk is concentrated in Satoshi-era wallets holding about 1.7 million BTC, rather than posing an immediate threat to mining or the entire network.

Bernstein said on April 8, 2026, that Google had cut its estimate of the number of qubits needed to break the cryptography by about 20-fold to fewer than 500,000, but Bitcoin still had three to five years to upgrade. On April 13, the firm said BTC's nearly 50% retreat from its October 2025 peak of $126,198 had already priced in most of the quantum risk. The real challenge, it said, lies in securing community consensus and migrating wallets.

Michael Saylor Says Quantum Threat to Bitcoin Is at Least 10 Years Away2026-04-09 · 2 reports · similarity 0.81

Quantum computers capable of breaking public-key cryptography could threaten Bitcoin signatures and asset ownership, making the technology a long-term market risk. Strategy, formerly MicroStrategy, co-founder and Executive Chairman Michael Saylor said banks, the internet and crypto assets all face the same pressure to upgrade, while Bitcoin could adopt quantum-resistant cryptography through updates to its nodes, wallets and protocol.

Saylor told Natalie Brunell’s “Coin Stories” on Feb. 23, 2026, that any quantum breakthrough posing a material threat was at least 10 years away. At a Mizuho event on April 8, he again said the risk was overstated and could be addressed through upgrades. He also said Bitcoin had likely bottomed at about $60,000 in early February; its price was around $71,200 when the report was published on April 9.

Nobel Physics Laureate Warns of Bitcoin Quantum Threat, Urges Swift Post-Quantum Planning2026-04-07 · 1 reports · similarity 0.84

Bitcoin uses public- and private-key cryptography to verify asset ownership and transactions. If powerful quantum computers become capable of deriving private keys from public keys, assets held at some addresses could be stolen. John Martinis, a Nobel physics laureate and former head of quantum hardware at Google, said the risk now raises questions about Bitcoin’s long-term security and its capacity for decentralized governance.

Martinis recently warned that quantum computers could become capable of breaking Bitcoin’s public-key cryptography within the next 5 to 10 years, and that the community should not wait for an attack before responding. He called for early planning on post-quantum cryptography, software upgrades and asset-migration mechanisms. The reports did not provide an exact publication date, the value of assets at risk or the scale of quantum computer that could break Bitcoin in practice.

Galaxy Digital Says Bitcoin Faces a Real Quantum Threat, but Not Yet an Existential Crisis2026-03-19 · 2 reports · similarity 0.81

Quantum computers could theoretically derive private keys from public keys exposed on-chain, allowing attackers to forge signatures and steal assets. Cybersecurity organization Project Eleven estimates that about 7 million Bitcoin may face long-term exposure, worth roughly $470 billion at recent prices. Most wallets whose public keys have not been revealed are currently unaffected, however, meaning the risk does not extend across the entire network.

Galaxy Digital research head Alex Thorn said on March 19, 2026, that the quantum threat was real but did not yet pose an existential crisis for Bitcoin. Research analyst Will Owens added on March 20 that related proposals had increased markedly since late 2025. Developers are advancing quantum-resistant addresses, BIP 360 and phased upgrade plans, while investors should currently view the issue as a long-term technical challenge.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)