Loading prices…
🩸BEARISH

Citi: Bitcoin faces 20x greater quantum risk than Ethereum

A May 18 Citi note and a Google Quantum AI paper converge on the same conclusion: bitcoin's governance moves too slowly to outrun a Shor's algorithm attack that could derive a private key in under 10…

Citi: Bitcoin faces 20x greater quantum risk than Ethereum
Citi: Bitcoin faces 20x greater quantum risk than Ethereum
Citi: Bitcoin faces 20x greater quantum risk than Ethereum
Citi: Bitcoin faces 20x greater quantum risk than Ethereum

Citi analysts warned on May 18 that quantum computing advances have shortened the timeline for practical attacks on digital assets, concluding that bitcoin faces significantly greater quantum risk than Ethereum. The finding echoes a Google Quantum AI paper produced with Stanford and the Ethereum Foundation, which estimated the computing resources required to break bitcoin's elliptic-curve cryptography are roughly 20 times lower than previously thought — a machine with fewer than 500,000 physical qubits could derive a bitcoin private key from its public key in roughly nine minutes.

Why it matters

The gap between the two assets is technological but, more decisively, structural. Bitcoin's consensus-driven governance has taken roughly 8.5 years to ship SegWit and 7.5 years to ship Taproot; the current quantum proposals BIP-360 and BIP-361 remain in draft or early testnet in 2026. Ethereum, by contrast, moved EIP-7702 — a stepping stone toward account abstraction and voluntary per-account signature migration — live in the May 2025 Pectra upgrade, and has structured milestones targeting core post-quantum infrastructure by approximately 2029. Nic Carter of Coin Metrics estimates a quantum computer could meaningfully break elliptic-curve cryptography as early as 2028, putting roughly 6.9 million BTC — including legacy wallets and the Taproot outputs that already represented more than 21% of 2025 transactions — in the at-risk bucket.

Market impact

The compliance architecture is already taking shape around these timelines. US federal agencies faced an April 2026 deadline to file post-quantum transition plans under National Security Memorandum 10; the EU has set a 2030 quantum-resistance target for critical infrastructure; the G7 Cyber Expert Group published a coordinated financial-sector road map in January. Treasury desks and sovereign wealth allocators now have a Citi-confirmed, Google-quantified risk differential between two of the largest digital assets — one with a structured, executable upgrade path and one whose base-layer transition would be the most contentious change in its history.

Related tokens
$BTC $ETH

Frequently asked questions

  1. What did Citi's May 18 quantum note actually say about bitcoin vs Ethereum?

    Citi analysts concluded that bitcoin faces significantly greater quantum risk than Ethereum, citing both the underlying cryptography and the governance speed needed to upgrade it. The note built on a Google Quantum AI paper produced with Stanford and the Ethereum Foundation.

  2. How real is the quantum threat to bitcoin right now?

    A machine capable of breaking bitcoin's elliptic-curve cryptography does not exist today. Google and Stanford estimated that a computer with fewer than 500,000 physical qubits could derive a bitcoin private key from its public key in roughly nine minutes; Nic Carter of Coin Metrics estimates a meaningful break could…

  3. How much bitcoin could actually be at risk in a quantum attack?

    Roughly 6.9 million BTC, including legacy wallets and Taproot outputs. Taproot outputs alone already represented more than 21% of all bitcoin transactions in 2025.

  4. Why is Ethereum considered more quantum-ready than bitcoin?

    Ethereum shipped EIP-7702 in the Pectra upgrade on May 2025 mainnet, letting accounts opt into different signature verification. The Hegotá hard fork planned for H2 2026 embeds this further, and the Ethereum Foundation targets core post-quantum infrastructure by approximately 2029, built on the NIST standards…

  5. Why can't bitcoin just upgrade its cryptography like Ethereum?

    It can in theory, but bitcoin's consensus-driven governance is slow. SegWit took roughly 8.5 years from conception to widespread adoption, Taproot about 7.5 years, and the current quantum proposals BIP-360 and BIP-361 are still in draft or early testnet in 2026 — leaving little margin before a possible 2028 quantum…

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 45d ago
Open original →