TechNewsReel
Live

Citi: One-Third of Bitcoin Supply Vulnerable to Future Quantum Attacks

Roughly 6.9 million BTC are at risk as quantum computing advances threaten the elliptic curve cryptography securing early wallets.

TechNewsReel Newsroom · September 13, 2026

A research note from Citi warns that approximately one-third of the total Bitcoin supply is vulnerable to future quantum computing attacks. The report highlights a systemic risk to the network's security that could jeopardize billions of dollars in assets.

According to the May 18, 2026, note authored by analyst Alex Saunders, between 6.5 and 6.9 million BTC—valued at roughly $450 billion—are held in wallets with public keys already exposed on-chain. This vulnerability primarily affects early 'Pay-to-Public-Key' (P2PK) addresses and any addresses where the user has reused the same address for multiple transactions. Technical projections suggest that a quantum computer equipped with fewer than 500,000 physical qubits could derive a private key from an exposed public key in approximately nine minutes.

The Quantum Vulnerability

Bitcoin relies on elliptic curve cryptography to secure its ledger. While modern Bitcoin addresses typically keep the public key hidden until a transaction is initiated, older P2PK addresses—including those used by Bitcoin's creator, Satoshi Nakamoto—expose the public key permanently. Quantum computers utilizing Shor's algorithm can exploit this exposure to reverse-engineer the private key, effectively bypassing the network's security. This threat is exacerbated by a 'harvest now, decrypt later' strategy, in which attackers collect encrypted on-chain data today with the intention of decrypting it once quantum hardware reaches the necessary maturity.

Market and Governance Risks

The potential for a sudden unlock of a massive portion of the supply, including the legendary Satoshi-era coins, could trigger extreme market volatility and a fundamental crisis of confidence in Bitcoin's security. Unlike more agile proof-of-stake networks, Bitcoin's decentralized nature makes implementing quantum-resistant upgrades, such as BIP-360 or BIP-361, a slow and arduous process. "Bitcoin’s conservative, decentralized governance makes protocol upgrades slow and difficult to coordinate," Saunders noted in the Citi report.

Global Response and Outlook

The threat has already reached the highest levels of international policy. On September 3, 2026, the G7 Cybersecurity Working Group issued a formal call to action regarding the urgent need for post-quantum cryptography. The industry now faces a critical race between the advancement of quantum hardware and the evolution of the Bitcoin protocol. Investors and developers are closely watching for a coordinated effort to migrate funds to quantum-secure addresses before the theoretical window of vulnerability closes.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.