Wall Street Broker Bernstein Warns of Quantum Threat to Bitcoin but Says Risk Is Manageable
Bitcoin uses elliptic-curve digital signatures to prove asset ownership. If a large-scale quantum computer could use Shor's algorithm to derive private keys, older addresses whose public keys have been exposed could be vulnerable to theft. Wall Street research and brokerage firm Bernstein said the risk is concentrated in Satoshi-era wallets holding about 1.7 million BTC, rather than posing an immediate threat to mining or the entire network.
Bernstein said on April 8, 2026, that Google had cut its estimate of the number of qubits needed to break the cryptography by about 20-fold to fewer than 500,000, but Bitcoin still had three to five years to upgrade. On April 13, the firm said BTC's nearly 50% retreat from its October 2025 peak of $126,198 had already priced in most of the quantum risk. The real challenge, it said, lies in securing community consensus and migrating wallets.
All Coverage
6 original reportsThe Backstory
The history behind this eventCoinbase Warns 7 Million Bitcoin Are Exposed to Quantum Attack Risk
Bitcoin transactions use elliptic-curve digital signatures to protect assets. Once an address reveals its public key, a sufficiently powerful quantum computer could eventually derive the private key and steal the funds. The threat is not exploitable today, but the permanent public record of blockchain data means exchanges and long-term holders must plan ahead to migrate to quantum-secure addresses.
Coinbase’s independent advisory board on quantum computing and blockchain released a report on June 11, 2026, estimating that the public keys for about 7 million BTC have been exposed. About 1.7 million BTC are held in early P2PK addresses, while roughly 5 million BTC are exposed through address reuse and largely consist of active funds such as exchange cold wallets. Attackers can collect the data now and attempt to crack it later.
Quantum Computing Threatens $440 Billion in Bitcoin, Including Satoshi's Million-Coin Stash
Bitcoin transactions rely on elliptic-curve digital signatures. A sufficiently powerful quantum computer could use Shor's algorithm to derive a private key from a public key, leaving older addresses whose keys have already been exposed at greatest risk. A February 2026 estimate put nearly 7 million BTC at risk, including about 1 million attributed to Satoshi Nakamoto, with a combined value of about $440 billion. The issue has implications for holders' property rights and consensus across the network.
On June 13, 2026, an independent quantum computing advisory board convened by Coinbase said quantum computers could not yet break Bitcoin but urged immediate planning for quantum-resistant signatures. It estimated that about 6.7 million BTC was at risk but did not endorse freezing or restricting older coins. A May 6 report from Project Eleven set 2033 as its baseline year for Q-Day, with 2030 as the earliest scenario.
Quantum Computing Threatens Bitcoin Security as Bit Digital Shifts to Ethereum
Bitcoin transactions use elliptic-curve digital signatures to secure assets. A quantum computer running Shor’s algorithm could potentially derive private keys from public keys, putting older wallets and transaction security at risk. Ethereum, by contrast, has planned a mechanism allowing accounts to adopt quantum-resistant signatures, bringing corporate crypto treasury strategies and onchain governance capabilities into focus.
Google Quantum AI and other institutions published research on March 30, 2026, estimating that fewer than 500,000 physical qubits could crack a key in about nine minutes. Citi warned on May 18 that the potential attack timeline had shortened. Bit Digital had already announced on July 7, 2025, that it would sell about 280 Bitcoin and, alongside a $172 million fundraising, increase its holdings to 100,603 Ethereum.
Experts Warn ‘Harvest Now, Decrypt Later’ Attacks Threaten Bitcoin Security
Bitcoin uses elliptic-curve cryptography to protect assets and communications, but sufficiently powerful quantum computers could eventually break its current encryption. Experts say the more immediate danger is a “harvest now, decrypt later” strategy, in which attackers intercept and store large volumes of encrypted communications today, then recover sensitive historical data once the technology matures. The threat extends beyond wallet private keys.
Security experts and an early-stage venture investor have recently warned that historical communications and infrastructure data across the Bitcoin ecosystem may already be targets for quantum attacks. Ethereum has begun work on a post-quantum migration, but as of this report, neither Bitcoin nor related companies had publicly committed to specific safeguards, disclosed investment amounts or set completion dates. The upgrade timetable and division of responsibility therefore remain unclear.
Bitcoin Faces Outsized Security Threat as Quantum Computing Breakthroughs Accelerate, Citi Says
Quantum computers capable of using Shor’s algorithm to break elliptic-curve cryptography could put Bitcoin holdings with exposed public keys at risk of theft. The threat could also extend to internet and financial infrastructure. Citi said Bitcoin’s conservative governance and the need for community consensus on upgrades could leave its migration to quantum-resistant technology trailing Ethereum’s.
Citi issued a digital-assets research report on May 18, 2026, warning that quantum computing breakthroughs are shortening the timeline for a practical attack. The report estimated that the public keys of about 6.5 million to 6.9 million Bitcoin, roughly one-third of the circulating supply, had already been exposed on-chain. Those holdings were worth about $450 billion at prices prevailing at the time.
Google Research Finds Quantum Threat to Bitcoin Lower Than Expected
Bitcoin and Ethereum rely on elliptic-curve cryptography to safeguard assets. A quantum computer capable of deriving a private key from a public key could potentially steal funds. Bitcoin activated Taproot on November 14, 2021, and because some transactions expose public keys in advance, the potential window for attack has widened.
The latest research from Google Quantum AI estimates that about 500,000 error-corrected physical qubits could be enough to crack a key within Bitcoin’s roughly nine-minute transaction confirmation window, far below previous estimates of several million qubits. No funds have been reported stolen through such an attack, but the researchers are urging the community to begin planning a migration to post-quantum cryptography.
Michael Saylor Says Quantum Threat to Bitcoin Is at Least 10 Years Away
Quantum computers capable of breaking public-key cryptography could threaten Bitcoin signatures and asset ownership, making the technology a long-term market risk. Strategy, formerly MicroStrategy, co-founder and Executive Chairman Michael Saylor said banks, the internet and crypto assets all face the same pressure to upgrade, while Bitcoin could adopt quantum-resistant cryptography through updates to its nodes, wallets and protocol.
Saylor told Natalie Brunell’s “Coin Stories” on Feb. 23, 2026, that any quantum breakthrough posing a material threat was at least 10 years away. At a Mizuho event on April 8, he again said the risk was overstated and could be addressed through upgrades. He also said Bitcoin had likely bottomed at about $60,000 in early February; its price was around $71,200 when the report was published on April 9.
Nobel Physics Laureate Warns of Bitcoin Quantum Threat, Urges Swift Post-Quantum Planning
Bitcoin uses public- and private-key cryptography to verify asset ownership and transactions. If powerful quantum computers become capable of deriving private keys from public keys, assets held at some addresses could be stolen. John Martinis, a Nobel physics laureate and former head of quantum hardware at Google, said the risk now raises questions about Bitcoin’s long-term security and its capacity for decentralized governance.
Martinis recently warned that quantum computers could become capable of breaking Bitcoin’s public-key cryptography within the next 5 to 10 years, and that the community should not wait for an attack before responding. He called for early planning on post-quantum cryptography, software upgrades and asset-migration mechanisms. The reports did not provide an exact publication date, the value of assets at risk or the scale of quantum computer that could break Bitcoin in practice.
Galaxy Digital Says Bitcoin Faces a Real Quantum Threat, but Not Yet an Existential Crisis
Quantum computers could theoretically derive private keys from public keys exposed on-chain, allowing attackers to forge signatures and steal assets. Cybersecurity organization Project Eleven estimates that about 7 million Bitcoin may face long-term exposure, worth roughly $470 billion at recent prices. Most wallets whose public keys have not been revealed are currently unaffected, however, meaning the risk does not extend across the entire network.
Galaxy Digital research head Alex Thorn said on March 19, 2026, that the quantum threat was real but did not yet pose an existential crisis for Bitcoin. Research analyst Will Owens added on March 20 that related proposals had increased markedly since late 2025. Developers are advancing quantum-resistant addresses, BIP 360 and phased upgrade plans, while investors should currently view the issue as a long-term technical challenge.
Bitcoin's Quantum Computing Fears Will Fade as Technology Advances, Analyst Says
Quantum computers capable of breaking Bitcoin's current elliptic-curve digital signatures could potentially steal assets from older addresses whose public keys have been exposed, including holdings attributed to Satoshi Nakamoto. The threat is therefore seen as existential. Martin Gaspar, senior crypto market strategist at FalconX, compared the issue with the 2021 controversy over the energy use and climate impact of Bitcoin's proof-of-work system, which also weighed on investor confidence.
In an analysis published by CoinDesk on March 4, 2026, Gaspar noted that Strategy announced a quantum-security initiative on February 5 as Bitcoin plunged toward $60,000. Coinbase also established a quantum computing and blockchain working group, while Project Eleven and BTQ Technologies are developing post-quantum technology. Gaspar said quantum concerns would recede like the earlier climate panic as the industry provides data, protection recommendations and migration plans.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.