Citi has warned in a new report that progress in quantum computing is compressing the timeline for security risks facing cryptocurrencies, with Bitcoin identified as one of the most exposed assets. The bank estimates that roughly 6.5 million to 6.9 million BTC are currently at quantum risk because their public keys have already been exposed. That amounts to about one-third of Bitcoin’s circulating supply, valued at roughly $450 billion at current prices.
Why Citi sees Bitcoin as unusually exposed
According to Citi analyst Alex Saunders, large-scale quantum attacks remain a medium-term concern, but the pace of technological progress is reducing the time available to prepare. The core issue is that a sufficiently powerful quantum computer could break the cryptographic systems protecting wallets and blockchains, especially the ECDSA digital signature scheme widely used by Bitcoin and Ethereum. If attackers can derive private keys from exposed public keys, they could forge transactions and steal funds.
The report describes Bitcoin as facing an “outsized threat” for two main reasons. First, its governance process is conservative, which can slow protocol upgrades. Second, the chain contains a large number of dormant wallets with exposed public keys, including early P2PK addresses. Citi also noted the widely held belief that wallets associated with Satoshi Nakamoto may fall into this category.
“Harvest now, decrypt later” is part of the risk
Citi also pointed to a separate attack path: “harvest now, decrypt later.” In that model, attackers collect and store encrypted data today, then wait until quantum systems become capable enough to crack it. The threat does not depend on immediate decryption. Data exposed now could still become valuable to attackers later.
Ethereum may adapt faster, but it is not immune
In comparing major networks, the report said proof-of-stake systems such as Ethereum may be in a better position because they can implement protocol changes more frequently and with greater flexibility. Even so, Ethereum is not outside the threat model. If quantum systems become advanced enough, validator keys could also be compromised and network operations could be disrupted.
Citi added that the industry is actively working on post-quantum cryptography. Within the Bitcoin community, proposed upgrades including BIP-360 and BIP-361 are being watched as possible paths for strengthening defenses against future quantum attacks.

