Key Points
- Citi warns quantum computing advances could threaten Bitcoin and Ethereum by 2030–2032.
- Ethereum’s governance model may enable faster quantum-resistant upgrades than Bitcoin.
A recent Citi research note stated that accelerating progress in quantum computing could compress the timeline for breaking current blockchain cryptography to between 2030 and 2032.
The report identifies Bitcoin as more exposed than Ethereum, not solely due to technical design but because of differences in governance flexibility.
Google researchers have estimated that a sufficiently advanced 500,000-qubit quantum machine could break elliptic-curve encryption within minutes, with some projections pointing to a potential “Q-Day” around 2032.
While such hardware does not yet exist, the pace of development has narrowed the assumed security window around existing cryptographic standards.
Shor’s Algorithm and ECDSA Risks
Both Bitcoin (BTC) and Ethereum (ETH) rely on the Elliptic Curve Digital Signature Algorithm (ECDSA) to secure transactions.
ECDSA’s security depends on the difficulty of solving the discrete logarithm problem using classical computers, a task currently considered computationally infeasible.
However, a sufficiently powerful quantum computer running Shor’s algorithm could theoretically solve this problem in polynomial time, allowing private keys to be derived from public keys.
Public keys are exposed when transactions are broadcast, and wallets with previously revealed public keys may face higher risk if quantum capabilities reach the required threshold.
Citi estimates that between 6.7 and 7 million BTC reside in wallets with exposed public keys, including early address formats associated with Bitcoin’s early mining period.
If a cryptographically relevant quantum computer surpasses the error-correction and qubit thresholds needed to attack 256-bit elliptic curves, current ECDSA-based protections would be rendered ineffective.
Governance and Upgrade Capacity
Citi’s analysis emphasizes governance structure as a key differentiator between Ethereum and Bitcoin.
Although Ethereum also uses ECDSA and is theoretically vulnerable, its developer community has demonstrated the ability to coordinate major protocol upgrades.
The 2022 Merge shifted Ethereum from proof-of-work to proof-of-stake, while other upgrades such as EIP-1559 and Dencun were implemented through established governance processes.
Ethereum co-founder Vitalik Buterin has stated that the network would likely have advance notice before quantum systems become capable of breaking ECDSA, allowing time for a hard fork to quantum-resistant signature schemes.
Researchers have discussed migration paths involving account abstraction and ERC-4337-compatible wallets, enabling hybrid models that combine existing ECDSA keys with post-quantum cryptography.
NIST’s selection of CRYSTALS-Dilithium as a lattice-based signature standard has provided a recognized candidate algorithm for potential migration planning.
In contrast, Bitcoin’s conservative consensus model makes rapid protocol changes more complex, and proposals such as BIP-360 and BIP-361 have not reached consensus consideration.
Industry participants have described Bitcoin’s quantum challenge primarily as a coordination issue, reflecting the need for broad social and technical agreement before implementing cryptographic transitions.



