Google's Quantum AI team estimates a future fault-tolerant quantum computer could derive a Bitcoin private key from its public key in approximately nine minutes — inside Bitcoin's ten-minute block time. Citi's digital asset research desk flagged May 18 that 4.5–6.7 million BTC, worth $350–500 bil...
"The window to prepare is narrowing. We are not talking about a hypothetical — the question is when, not if." — Scott Aaronson, UT Austin Computer Science, Coinbase Quantum Advisory Council
Google's Quantum AI team estimates a future fault-tolerant quantum computer could derive a Bitcoin private key from its public key in approximately nine minutes — inside Bitcoin's ten-minute block time. Citi's digital asset research desk flagged May 18 that 4.5–6.7 million BTC, worth $350–500 billion at current prices, already sit in wallets with exposed public keys. On April 24, Italian researcher Giancarlo Lelli broke a 15-bit elliptic curve key on publicly accessible quantum hardware, winning Project Eleven's Q-Day Prize — a 512-fold improvement over the first public quantum ECC attack nine months earlier.
The market response has been immediate. The quantum-resistant token category hit a $12.9 billion market cap as of late April, up 15.9% in a single day. On May 21, the broader privacy coin sector — led by Zcash, which surged 15.3% in 24 hours after the SEC closed its multi-year investigation without enforcement — approached $63 billion in total market capitalization on $4.7 billion in daily volume. Behind the price action: a convergence of academic research, institutional warnings, and protocol-level engineering that marks the quantum threat's transition from theoretical curiosity to operational timeline.
On March 31, 2026, Google's Quantum AI division published research demonstrating a refined version of Shor's Algorithm that requires 20 times fewer resources to crack the Elliptic Curve Digital Signature Algorithm (ECDSA) securing Bitcoin and Ethereum wallets. The paper estimates that a sufficiently powerful quantum machine could derive a private key from a public key in approximately nine minutes.
Bitcoin's average block time is ten minutes. The implication: an attacker with a fault-tolerant quantum computer and access to an exposed public key could potentially hijack a transaction before network confirmation.
Google's current Willow chip operates at 105 qubits — several orders of magnitude below the estimated 500,000-qubit threshold for a full 256-bit ECDSA attack. However, the paper's significance lies in the resource reduction, not the current hardware. Previous estimates placed the requirement at 10 million+ qubits. Google cut that by a factor of 20. A subsequent paper from Caltech and Oratomic suggested a neutral-atom architecture could lower the figure further to approximately 10,000 qubits.
Google's researchers pointed to 2029 as a critical deadline for blockchain migration planning.
Not all blockchain wallets face equal quantum risk. The vulnerability centers on public key exposure.
Pay-to-Public-Key (P2PK) addresses — Bitcoin's earliest format — store the public key directly on-chain. Approximately 1.7 million BTC reside in these addresses, including coins widely attributed to Satoshi Nakamoto. These wallets are vulnerable to "quantum at-rest" attacks — no transaction broadcast required.
Address-reuse wallets compound the problem. Any address that has broadcast a spending transaction has revealed its public key. According to Citi's May 18 research note, 4.5–6.7 million BTC already have exposed public keys on-chain. At current prices, that represents $350–500 billion in quantum-exposed value.
Ethereum faces a structurally different risk profile. According to the same Citi report, proof-of-stake networks upgrade protocols more frequently. Ethereum's account-abstraction roadmap (EIP-8141) allows individual wallets to migrate to post-quantum signature schemes without waiting for a full protocol-level change. Bitcoin's consensus-driven governance model makes equivalent upgrades slower.
The issue extends beyond individual wallets. Citi estimates a quantum-enabled attack on a major U.S. bank's infrastructure could put $2–3.3 trillion of GDP at risk, framing blockchain quantum vulnerability as a subset of a broader financial system threat.
On April 24, 2026, Project Eleven awarded its Q-Day Prize — 1 BTC, worth approximately $78,000 — to independent Italian researcher Giancarlo Lelli. Lelli derived a private key from its public key across a 15-bit search space (32,767 possibilities) using a variant of Shor's algorithm running on publicly accessible quantum hardware.
The benchmark matters for scale. In September 2025, Steve Tippeconnic demonstrated a 6-bit ECC break on quantum hardware — the first public demonstration. Lelli's result extends the attack surface by a factor of 512 in nine months.
Bitcoin's ECDSA uses 256-bit keys. The gap between 15 bits and 256 bits remains enormous. But the trajectory — from 6 bits to 15 bits in under a year, accomplished on cloud-accessible hardware without classified or proprietary equipment — is what cryptographers track. The rate of progress, not the absolute level, determines timeline estimates.
Two institutions issued major quantum-risk assessments in 2026.
Citi published a multi-part analysis. Its January 2026 Citi Institute report estimated the total quantum cybersecurity threat at a multi-trillion-dollar scale. The May 18 digital asset research note from analyst Alex Saunders specifically warned that accelerating quantum computing advances are shortening the timeline for risks to Bitcoin, revising practical attack estimates to between 2030 and 2032.
Coinbase established an independent Quantum Advisory Council in January 2026, comprising Scott Aaronson (UT Austin), Dan Boneh (Stanford), Justin Drake (Ethereum Foundation), Sreeram Kannan (Eigen Labs/University of Washington), Yehuda Lindell (Coinbase/Bar-Ilan University), and Dahlia Malkhi (UC Santa Barbara). The council's 50-page position paper, published April 2026, concluded that while current blockchains remain secure today, preparation "must begin now."
The advisory board noted that NIST recommends completing migration to quantum-resistant cryptography by 2035 — a timeline the paper characterized as potentially optimistic.
Three parallel engineering tracks are addressing the quantum threat at the protocol level.
Bitcoin: BIP-360 and BIP-361. Developer Agustin Cruz's Quantum-Resistant Address Migration Protocol (QRAMP) proposes a mandatory migration window: all Bitcoin holders would need to move funds from legacy ECDSA-secured addresses to quantum-resistant addresses by a set deadline. Coins remaining in vulnerable wallets after the deadline would become unspendable. BIP-361, titled "Post Quantum Migration and Legacy Signature Sunset," was updated in Bitcoin's proposal repository in April 2026 and would phase out vulnerable address types over several years. Both proposals remain in draft form without community consensus.
The trade-offs are material. Post-quantum signatures — such as NIST-approved CRYSTALS-Dilithium (ML-DSA) or Falcon-1024 — are tens to hundreds of times larger than current ECDSA signatures. For Bitcoin, this means increased block space consumption, higher storage requirements, increased bandwidth, and elevated transaction fees.
Ethereum: Strawmap. Vitalik Buterin published a four-year quantum resistance roadmap in February 2026, identifying four components requiring upgrades: consensus-layer BLS signatures, KZG-based data availability, ECDSA account signatures, and zero-knowledge proofs. The Ethereum Foundation launched a dedicated post-quantum security hub in March 2026 with more than 10 client teams. EIP-8141, targeted for the Hegotá fork in the second half of 2026, would enable per-account signature scheme migration via account abstraction. STARKs, already used by several rollups, are inherently quantum-resistant because they rely on hash functions rather than elliptic curves. The Foundation targets completion of core post-quantum infrastructure by approximately 2029.
NIST Standards. NIST finalized its first round of post-quantum cryptography standardization in August 2024, certifying three algorithms: ML-KEM (public-key encryption), ML-DSA (digital signatures, formerly CRYSTALS-Dilithium), and SLH-DSA (hash-based signatures, formerly SPHINCS+). Algorand was the first major blockchain to execute a mainnet transaction using NIST-approved Falcon-1024 in November 2025.
The quantum narrative has produced measurable capital rotation.
Quantum-resistant tokens collectively reached a $12.9 billion market capitalization in late April 2026, with a 15.9% single-day increase and $1.2 billion in 24-hour trading volume. Key names in the category include Algorand ($2.1 billion market cap, Falcon-1024 live on mainnet), QRL (Quantum Resistant Ledger, $81.6 million market cap, XMSS hash-based signatures since 2018), and QANplatform (NIST Dilithium-based, EVM-compatible).
Privacy coins saw a broader and larger capital inflow. On May 21, 2026, the privacy coin sector surged approximately 5%, with total market capitalization approaching $63 billion and 24-hour trading volume reaching $4.7 billion — a 24% volume increase.
Zcash (ZEC) led the sector, trading at $676.54 (+15.3% in 24 hours, +29.4% over seven days), with a market cap of $11.29 billion. Two catalysts converged: first, the SEC formally closed its multi-year investigation into the Zcash Foundation without recommending enforcement action, resolving a regulatory overhang that began with a subpoena in August 2023; second, ZEC's 17 million circulating supply and a technical golden crossover attracted momentum capital.
Dash (DASH) gained over 16%, crossing $50. Monero (XMR) traded at $396.43 with a $7.3 billion market cap.
The conflation of "privacy" and "quantum resistance" in market narratives is worth noting. Zcash's zk-SNARK technology and Monero's ring signatures address transaction privacy — a different problem than quantum-resistant key derivation. Only a subset of privacy coins implement post-quantum signature schemes. The market is pricing both narratives into a single trade, which may not reflect the underlying technical differentiation.
The Coinbase advisory paper and Citi reports converge on a key point: migration to post-quantum cryptography will be expensive and technically complex.
For Bitcoin, the primary costs include: signature size inflation (ML-DSA signatures are approximately 2,420 bytes versus 72 bytes for ECDSA — a 33x increase), which translates to reduced transaction throughput per block, higher fee pressure, and increased node storage and bandwidth requirements. If BIP-361 enforces migration deadlines, any unmigrated coins would be permanently frozen, potentially shrinking Bitcoin's effective supply by millions of coins.
For Ethereum, account abstraction provides a more flexible migration path, but each wallet must individually opt in. The Foundation's 2029 target assumes no acceleration in quantum hardware timelines — an assumption Citi's revised 2030–2032 estimate challenges.
The broader economic calculus: NIST's 2035 migration deadline applies to the entire U.S. government and critical infrastructure. If blockchain protocols cannot migrate before their underlying cryptographic assumptions are broken, the damage would be asymmetric — digital assets would face immediate, irreversible loss, while traditional financial systems could fall back on centralized patching mechanisms.
The quantum threat to blockchain has moved from academic speculation to institutional risk modeling. Google quantified the attack surface. Citi put a dollar figure on the exposure. Coinbase assembled a world-class advisory council and published a 50-page warning. Project Eleven demonstrated live ECC attacks on public hardware.
The engineering responses — BIP-361 for Bitcoin, Strawmap for Ethereum, NIST-approved algorithms deployed on Algorand — are real but early-stage. None have achieved production-scale deployment on a major network. Bitcoin's governance model makes rapid migration structurally difficult. Ethereum's account abstraction offers a faster path but requires per-user action.
The market is pricing the narrative before the technology. Privacy coins surging 15–29% in a week are not, in most cases, implementing post-quantum cryptography. The capital rotation reflects awareness of the problem, not necessarily the availability of solutions. Whether the current price action represents informed repricing or narrative-driven speculation will become clearer as protocol-level migration progresses through 2026 and 2027.
The data suggests the industry has approximately three to six years to complete a cryptographic overhaul affecting trillions of dollars in digital assets. The clock started when Google published its paper on March 31. It has not stopped.