The crypto industry is waking up to a threat that cannot be patched with a weekend hotfix. In February 2026, Citi published a landmark report estimating that quantum computing could expose trillions of dollars in financial assets — with roughly $440 billion in Bitcoin alone sitting in quantum-vul...
"Freezing old Satoshi-era addresses would violate immutability and property rights — but so would allowing a quantum adversary to steal them." — Roya Mahboob, CEO, Digital Citizen Fund
The crypto industry is waking up to a threat that cannot be patched with a weekend hotfix. In February 2026, Citi published a landmark report estimating that quantum computing could expose trillions of dollars in financial assets — with roughly $440 billion in Bitcoin alone sitting in quantum-vulnerable address formats. The same month, Bitcoin developers merged BIP-360 into the official Bitcoin repository, Ethereum's foundation formed a dedicated post-quantum security team, and Iceberg Quantum demonstrated that breaking RSA-2048 may require just 100,000 physical qubits — a tenfold reduction from previous estimates.
The question is no longer whether quantum computers will threaten blockchain cryptography, but whether the industry can migrate fast enough. CoinShares argues the risk is "manageable." Citi warns it is systemic. And caught in the crossfire is a philosophical debate that strikes at Bitcoin's core identity: should Satoshi Nakamoto's estimated 1 million BTC — held in the oldest, most vulnerable address format — be frozen before Q-Day arrives?
This report examines the converging technical, economic, and governance dimensions of crypto's quantum reckoning, and why the next 24 months may define whether blockchain networks survive the post-quantum transition intact.
"Q-Day" — the moment a quantum computer can reliably break the elliptic curve cryptography (ECDSA) underpinning Bitcoin, Ethereum, and virtually every blockchain — remains a moving target, but it is moving faster than many anticipated.
Citi's January 2026 report assigns a 19–34% probability that quantum computers will break widely used public-key encryption by 2034, rising to 60–82% by 2044. These are not fringe estimates; they come from one of the world's largest financial institutions, which warns that a single-day disruption to a top-five U.S. bank's Fedwire access could trigger $2–3.3 trillion in losses — equivalent to a 10–17% decline in annual GDP.
On the hardware side, the timeline is compressing. Google's 105-qubit Willow chip demonstrated exponential error reduction in late 2024, and in February 2026, Iceberg Quantum unveiled its Pinnacle Architecture, showing that RSA-2048 could be broken with fewer than 100,000 physical qubits using quantum LDPC codes — down from previous estimates exceeding one million. The startup, backed by LocalGlobe, Blackbird, and DCVC with $6 million in seed funding, is partnering with PsiQuantum, Diraq, and IonQ to commercialize the approach.
Yet CoinShares, in a February 2026 research note, argues that breaking Bitcoin's ECDSA signatures would require fault-tolerant quantum computers roughly 100,000 times more powerful than today's machines. Blockstream CEO Adam Back has maintained the timeline is 20–40 years. The gap between optimistic and pessimistic projections remains enormous — but the direction of travel is unambiguous.
What is already underway is "harvest now, decrypt later" — a strategy where adversaries collect encrypted traffic and exposed public keys today, storing them for decryption once quantum capability matures. Citi explicitly names this as an active threat vector, suggesting nation-state actors are already stockpiling blockchain data.
Not all crypto is equally vulnerable. The risk concentrates around address formats that expose public keys on-chain before funds are spent.
Bitcoin exposure estimates vary significantly by methodology:
| Source | Vulnerable BTC | % of Supply | Estimated Value | |--------|---------------|-------------|-----------------| | CoinDesk / Deloitte | ~7 million BTC | ~33% | ~$440B | | Citi Institute | 4.5–6.7 million BTC | ~25% | $500–600B | | CoinShares | ~1.6 million BTC | ~8% | ~$100B |
The discrepancy hinges on what counts as "vulnerable." CoinShares takes the narrowest view, counting only legacy Pay-to-Public-Key (P2PK) addresses where public keys are permanently exposed on-chain. The broader estimates include addresses where public keys were revealed through at least one outgoing transaction, which encompasses Pay-to-Public-Key-Hash (P2PKH) addresses that have been used.
CoinShares further narrows the economically relevant risk: of the ~1.6 million BTC in P2PK addresses, only around 10,200 BTC is concentrated enough that its theft "could cause appreciable market disruption." The remaining coins sit in 32,607 individual ~50 BTC UTXOs that would take millennia to unlock, even under optimistic quantum projections.
Ethereum's exposure is structurally worse. Approximately 65% of all ETH is quantum-exposed because the network's account model reveals public keys with every outgoing transaction. Solana and most modern chains face similar architectural exposure. The longer a blockchain has operated, and the more transactions its users have executed, the larger its quantum attack surface.
Bitcoin's defense strategy centers on BIP-360, a proposal for a new output type called Pay-to-Merkle-Root (P2MR), co-authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke. In early 2026, BIP-360 was merged into the official Bitcoin repository — the first concrete step toward quantum-resistant addresses in the protocol's history.
P2MR functions similarly to Taproot (P2TR) but removes the quantum-vulnerable keypath spend. Public keys are hidden behind a Merkle tree structure until the owner spends funds, eliminating the window during which a quantum attacker could derive private keys from exposed public keys.
The complementary Quantum-Resistant Address Migration Protocol (QRAMP) proposes a two-phase mandatory migration:
QRAMP is where the debate gets heated. A mandatory migration with a hard deadline would force every Bitcoin holder to move funds to quantum-safe addresses or lose access permanently. For active users, this is an inconvenience. For lost coins, Satoshi's stash, and dormant wallets, it is an irreversible economic event.
Ethereum is taking a different approach — one that leverages its more flexible governance model. In January 2026, the Ethereum Foundation formed a dedicated Post-Quantum Security team led by Thomas Coratger, with a $2 million research prize pool. The team is building on leanVM, a cryptographic execution environment designed for quantum-resistant operations.
On February 26, 2026, Vitalik Buterin outlined Ethereum's quantum resistance strategy through the foundation's "Strawmap" — a four-year roadmap targeting seven hard forks through 2029. Buterin identified four critical vulnerability surfaces:
The plan proposes replacing these with hash-based and lattice-based quantum-resistant alternatives, supported by recursive STARK aggregation. For user wallets, native account abstraction under EIP-8141 would allow adoption of post-quantum signature schemes once efficient implementations exist.
A biweekly breakout call focused on post-quantum transactions launched in March 2026 as part of Ethereum's All Core Developers process, with a devnet test running in February and full activation targeted for a later fork.
The contrast with Bitcoin's approach is instructive. Ethereum's foundation-driven governance allows for coordinated, top-down planning across a defined timeline. Bitcoin's decentralized, consensus-driven model makes every upgrade a political negotiation — which is precisely why the Satoshi coins debate has become a proxy war over the network's identity.
The quantum threat forces Bitcoin into its hardest social consensus test: what happens to coins that cannot migrate?
An estimated 1 million BTC attributed to Satoshi Nakamoto sits in P2PK addresses — the most vulnerable format. If QRAMP's Phase B deadline passes and these coins remain in legacy addresses, they would be permanently frozen. If no migration deadline is set, a quantum-capable adversary could eventually drain them, flooding markets with hundreds of billions in previously dormant supply.
The community is fracturing along predictable lines:
Pro-freeze advocates argue that protecting network integrity is paramount. A defensive soft fork that renders vulnerable outputs unspendable unless migrated to quantum-resistant addresses preserves the network's security while giving active holders time to act.
Anti-freeze advocates see any intervention as a violation of Bitcoin's core promise. Paolo Ardoino, CEO of Tether, has suggested that allowing old coins to reenter circulation — even through quantum breakthroughs — may be preferable to altering consensus rules. The argument: if Bitcoin can selectively freeze addresses, what stops it from freezing addresses for political reasons?
A March 2026 debate on the Bitcoin-dev mailing list surfaced a third option: a "slow migration" approach where legacy addresses are gradually disincentivized through higher fees rather than hard deadlines, buying time without forcing a binary choice.
The quantum threat is not just a technical problem — it is an economic value redistribution event. Applying the economic-value-first framework reveals several layers of impact:
Direct exposure: $100B–$600B in quantum-vulnerable BTC (depending on methodology), plus an unknown but likely larger amount in ETH and other chains where public key exposure is structurally higher.
Infrastructure investment: The quantum-safe migration will require upgrades across every layer of the blockchain stack — wallets, exchanges, custodians, Layer 2 networks, bridges, and smart contracts. BTQ Technologies has demonstrated the first quantum-resistant Bitcoin implementation using NIST-standardized ML-DSA signatures, but enterprise-grade deployment remains years away.
Competitive repositioning: Chains that achieve quantum resistance first gain a structural advantage for institutional capital. Ethereum's coordinated roadmap may attract risk-averse allocators before Bitcoin's more contentious governance process reaches resolution.
Quantum-safe premium: A new category of "quantum-verified" addresses and assets may emerge, commanding premium pricing from institutional holders who require cryptographic assurance beyond current standards. The Quantum Resistant Ledger (QRL) surged 20% in early March 2026, suggesting markets are already pricing this dynamic.
Citi estimates a 19–34% chance quantum computers break public-key encryption by 2034, with active "harvest now, decrypt later" attacks already underway.
$100B–$600B in Bitcoin sits in quantum-vulnerable addresses, with Satoshi's estimated 1 million BTC at the center of a governance crisis.
BIP-360 has been merged into Bitcoin's official repository, introducing quantum-resistant P2MR addresses — but mandatory migration timelines remain contentious.
Ethereum has formed a dedicated post-quantum team and outlined a seven-fork roadmap through 2029, leveraging its governance flexibility for faster adaptation.
Iceberg Quantum's Pinnacle Architecture reduced the qubit threshold for breaking RSA-2048 by 10x, compressing timelines that the industry assumed were decades away.
The Satoshi coins debate is a proxy for Bitcoin's deepest governance question: can immutability survive an existential security threat?
The quantum threat to crypto is real but not imminent — a paradox that makes it exceptionally dangerous. History shows that security migrations succeed only when they begin years before the threat materializes. The crypto industry has a narrow window — likely 5 to 15 years — to execute the most complex cryptographic upgrade in the history of decentralized systems.
Bitcoin's BIP-360 merge and Ethereum's Strawmap represent genuine progress, but the hardest work lies ahead: achieving social consensus on migration deadlines, upgrading billions of dollars in infrastructure, and resolving the Satoshi coins dilemma without fracturing communities.
The chains that navigate this transition will emerge as the institutional-grade infrastructure of the post-quantum era. Those that delay may find their security assumptions — and the trillions in value built on top of them — obsolete overnight.