Key Takeaways
A new whitepaper from Google Quantum AI researchers, together with contributors from the Ethereum Foundation and Stanford University, is putting hard numbers on how much cryptocurrency could eventually be exposed to quantum attacks.
The paper says future cryptographically relevant quantum computers could break the elliptic-curve cryptography behind many blockchain signatures in minutes, giving the industry a clearer view of which major networks face the biggest exposure.
The researchers estimate that breaking 256-bit elliptic-curve keys could take about 9 minutes on average under one of their fast-clock quantum computing scenarios.
They also stress that these machines do not exist yet.
In a separate post, Google said it is moving its own post-quantum cryptography migration timeline to 2029 as hardware, error correction and cryptanalysis continue to improve.
Bitcoin carries the clearest headline number in the paper.
The researchers estimate that about 6.7 million BTC sit in vulnerable addresses.
This is largely because of exposed public keys and key reuse across older address types and legacy outputs.
At current prices, that stock is worth about $451.3 billion.
The paper also explains why Bitcoin remains central to the debate.
If a public key becomes exposed on-chain or during transaction propagation, a sufficiently powerful quantum attacker can derive the private key and redirect funds.
Citi reached a similar conclusion in its January quantum-threat report, estimating that 4.5 million to 6.7 million BTC are potentially quantum-exposed.
Ethereum’s exposure is spread across several parts of the network.
The paper points to risks tied to user accounts, smart-contract administration, validator cryptography and data-availability design.
It estimates:
The researchers also flagged about $200 billion in stablecoins and tokenized real-world assets that could be affected through smart-contract admin risk.
The study treats these as separate categories and does not say they are mutually exclusive, so any combined total should be viewed cautiously.
It also says the 1,000 highest-value Ethereum accounts held about 20.5 million ETH at the time of analysis and could be cracked in less than nine days under the model’s assumptions.
The paper also flags other major chains with persistent account models, including Solana, Rootstock, Algorand, TRON and XRP Ledger.
Its core argument is that these designs leave public keys easier to identify than in UTXO systems that keep keys hashed until spent.
However, public-key exposure can still emerge in Bitcoin once users spend funds or reuse keys, the paper notes.
The study does not provide comparable network-wide token-at-risk totals for SOL, XRP, TRX or ALGO.
That leaves Bitcoin and Ethereum as the two largest networks with publicly quantified exposure.
Google’s research maps the other large chains qualitatively rather than scoring them with a simple token total.
The paper lands as several major ecosystems are already discussing or testing post-quantum responses.
On March 31, Ethereum Foundation researcher Will Corcoran said he had presented Ethereum’s post-quantum security strategy in New York and announced a new hub for Ethereum’s roadmap, protocol-level impacts and open research.
The launch builds on Vitalik Buterin’s February warning that four major parts of Ethereum remain exposed to future quantum threats.
Outside Ethereum, Algorand says its State Proofs already use Falcon-based post-quantum signatures.
Solana developers have published a Winternitz-based quantum-resistant vault design, and XRP Ledger contributors have been discussing support for next-generation post-quantum signature schemes.
The paper’s short-term recommendations are practical: reduce public-key exposure, avoid address reuse and use transaction designs that narrow the window for interception, including private mempools and commit-reveal schemes where relevant.
Over the longer term, the fix is migration to post-quantum cryptography.
That broader migration is already underway outside crypto.
NIST finalized its first three post-quantum encryption standards in August 2024 and says organizations should begin transitioning immediately. Google, for its part, says it is targeting 2029 for its own post-quantum migration planning.
For the market, the message is clear. Today’s quantum machines are nowhere near draining major blockchains.
But the paper argues that if cryptographically relevant quantum hardware arrives before networks complete the shift to post-quantum security, Bitcoin and Ethereum carry the largest publicly quantified exposure, with several other top chains facing the same underlying weakness.