A research note published by Citi analysts on May 18 reached a conclusion that should give every institutional bitcoin holder pause: the leading cryptocurrency faces significantly greater quantum risk than Ethereum, and the gap between them comes down not just to technology but to governance structure.

Market Context

The findings from Citi echo landmark research released in late March by Google Quantum AI in collaboration with Stanford University and the Ethereum Foundation. That paper found that the computing resources required to break bitcoin's foundational cryptography are approximately 20 times lower than previously estimated, dramatically shortening the timeline for practical quantum threats to digital assets.

Analysis

According to the joint research, a sufficiently advanced quantum computer operating with fewer than 500,000 physical qubits could derive a bitcoin private key from its public key in roughly nine minutes. That machine does not exist today, but the window to act responsibly is narrowing faster than most institutions realize, the paper noted.

Nic Carter, co-founder of Coin Metrics, has been sounding this alarm since October 2025, calling quantum computing 'the biggest long-term risk to bitcoin's core cryptography' and accusing developers of 'sleepwalking towards collapse.' Carter estimates a quantum computer could meaningfully break elliptic curve cryptography as early as 2028. Approximately 6.9 million BTC could be vulnerable at sufficient quantum scale, including legacy wallets and Taproot outputs, which already represented more than 21% of all bitcoin transactions in 2025.

The vulnerability stems from bitcoin's reliance on elliptic curve digital signature algorithms. When bitcoin is spent, the public key is briefly exposed on-chain. Under classical computing, reversing that to obtain a private key remains infeasible, but quantum computers running Shor's algorithm could theoretically accomplish this during the brief window a transaction is broadcast.

Key Numbers

- Approximately 20x lower computing resources needed to break bitcoin cryptography than previously estimated

- Fewer than 500,000 physical qubits required for a nine-minute private key derivation

- ~6.9 million BTC potentially vulnerable at sufficient quantum scale

- Taproot outputs represented more than 21% of all bitcoin transactions in 2025

- SegWit took approximately 8.5 years from conception to widespread adoption

- Taproot transition required roughly 7.5 years

What to Watch

Bitcoin's governance presents compounding risk. Current quantum proposals, BIP-360 and BIP-361, remain at draft or early testnet stage as of 2026. A full base-layer transition to post-quantum signatures would represent the most contentious change bitcoin has ever attempted.

Ethereum, by contrast, has already begun execution on a structured road map built on NIST post-quantum cryptography standards finalized in August 2024. The Pectra upgrade shipped on Ethereum mainnet in May 2025, introducing EIP-7702 as a critical stepping stone toward full account abstraction. Rather than requiring a single network-wide hard fork, Ethereum's architecture allows individual accounts to voluntarily switch to quantum-safe signatures.

The upcoming Hegotá hard fork, planned for the second half of 2026, is expected to embed post-quantum infrastructure further at the protocol level. The Ethereum Foundation has set structured milestones targeting completion of core post-quantum infrastructure by approximately 2029, with active interop devnets already running across multiple clients.

Regulatory pressure is intensifying. U.S. federal agencies faced an April 2026 deadline to submit post-quantum cryptography transition plans under National Security Memorandum 10. The EU has set a 2030 quantum-resistance target for critical infrastructure. The G7 Cyber Expert Group published a coordinated financial sector road map in January 2026, signals that compliance architecture will extend to digital asset treasury holdings.