Citigroup researchers warn that advances in quantum computing could eventually break the elliptic‑curve cryptography protecting Bitcoin wallets, potentially exposing about 6.5–6.9 million BTC whose public keys are alr... These coins are particularly vulnerable because their public keys are already exposed on‑chain,...

Create a landscape editorial hero image for this Studio Global article: How does Citigroup argue that advances in quantum computing threaten Bitcoin, why are an estimated 6.5 to 6.9 million BTC especially vulnera. Article summary: Citigroup’s argument is that Bitcoin’s security model depends on elliptic-curve signatures that future fault-tolerant quantum computers could break, allowing an attacker to derive private keys from exposed public keys an. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "Bitcoin faces outsized quantum threat as computing breakthroughs accelerate, Citi says Crypto World Daily 7680 subscribers 2 views 18 May 2026 The bank said accelerating advances" source context "Bitcoin faces outsized quantum threat as computing breakthroughs accelerate, Citi says" Reference image 2: visual subj
Quantum computing is still an emerging technology, but some researchers and financial institutions are already examining how it could affect cryptocurrencies. A recent analysis highlighted by Citigroup argues that Bitcoin may face a unique long‑term security challenge: if sufficiently powerful quantum computers become practical, they could undermine the cryptographic signatures that protect Bitcoin wallets.
The concern is not immediate, but the migration to quantum‑safe cryptography could take years—meaning preparation would need to start long before such computers exist.
Bitcoin transactions rely on public‑key cryptography. Wallet owners sign transactions using a private key tied to a public key on the blockchain. Today this system is secure because deriving the private key from the public key is computationally infeasible for classical computers.
However, a powerful quantum computer running Shor’s algorithm could theoretically solve the mathematical problem behind elliptic‑curve cryptography much faster than traditional machines. If that happens, an attacker could calculate a private key from a known public key and use it to authorize fraudulent transactions.
Importantly, Bitcoin’s hashing functions are not considered immediately vulnerable. The primary risk comes from the digital signatures—currently based on elliptic‑curve schemes such as ECDSA and Schnorr—that protect wallet ownership.
Citigroup’s analysis highlights a subset of Bitcoin that could be particularly exposed in a quantum‑attack scenario.
Estimates suggest that about 6.5–6.9 million BTC—roughly one‑third of circulating supply—already have their public keys visible on the blockchain.
Those coins are easier targets because an attacker would not need to wait for the owner to broadcast a transaction to reveal the public key. Instead, the key is already recorded on‑chain and could be analyzed in advance.
Examples of exposed coins include:
Dormant coins pose a particular challenge. Some may belong to lost wallets, inactive users, or early holders who may never migrate them to safer address types, leaving large balances exposed indefinitely.
Even if quantum‑resistant cryptography exists, deploying it on Bitcoin is not simple.
Bitcoin’s governance model is intentionally conservative. Protocol upgrades require broad agreement among developers, miners, node operators, exchanges, custodians, and users. This slow consensus process is designed to protect stability—but it also makes large architectural changes difficult.
Citigroup analysts argue this could make Bitcoin slower to adopt post‑quantum protections compared with networks such as Ethereum, which historically have implemented coordinated upgrades more frequently.
A successful transition would likely require:
Because these steps involve both technical and social consensus, the timeline could stretch over many years.
Another concern highlighted in discussions about quantum security is the so‑called “harvest now, decrypt later” strategy.
In this scenario, attackers collect cryptographic data today—even if they cannot yet break it. Once sufficiently powerful quantum computers exist, that stored data could be decrypted retroactively.
Applied to Bitcoin, this means adversaries could already be cataloging addresses with exposed public keys. If quantum hardware eventually becomes capable of deriving private keys quickly enough, those coins could be targeted immediately.
Even before such attacks occur, the mere expectation of this risk could affect investor confidence or market pricing if the network appears slow to upgrade.
Developers have already begun discussing technical responses. Two notable proposals are BIP‑360 and BIP‑361, which outline ways to migrate Bitcoin to quantum‑resistant cryptography.
One controversial idea—outlined in BIP‑361—is a phased transition that would eventually sunset legacy signature schemes like ECDSA and Schnorr. Under some interpretations of the proposal, coins that remain in vulnerable address types after a migration deadline could become unspendable.
Supporters argue this would prevent quantum attackers from stealing funds tied to exposed public keys. Critics say it challenges Bitcoin’s long‑standing principle that coins remain spendable indefinitely if the private key exists.
The debate raises several risks:
Because of these trade‑offs, no single approach has universal support within the Bitcoin ecosystem.
For now, large‑scale quantum attacks remain hypothetical. No known quantum computer today can break Bitcoin keys at scale.
But the issue illustrates a broader challenge: cryptographic migration is slow, especially for decentralized systems with billions of dollars in assets. That means preparation often needs to begin years before the underlying threat becomes practical.
If quantum computing advances faster than expected, Bitcoin could face two difficult scenarios:
Either outcome would test the governance and resilience of the world’s largest cryptocurrency network.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Citigroup researchers warn that advances in quantum computing could eventually break the elliptic‑curve cryptography protecting Bitcoin wallets, potentially exposing about 6.5–6.9 million BTC whose public keys are alr...
Citigroup researchers warn that advances in quantum computing could eventually break the elliptic‑curve cryptography protecting Bitcoin wallets, potentially exposing about 6.5–6.9 million BTC whose public keys are alr... These coins are particularly vulnerable because their public keys are already exposed on‑chain, making it easier for a future quantum attacker to derive the private keys and move the funds.
Proposals such as BIP‑360 and BIP‑361 aim to migrate Bitcoin to quantum‑resistant signatures, but they raise difficult governance and property‑rights debates that could split the community or freeze some coins.