Market Context
On May 19, 2026, Bitcoin dropped below the $79,000 psychological support level, trading around $78,500, amid mounting concerns over cryptocurrency structural fragility. Simultaneously, Citigroup released its latest quantum computing risk report, warning that approximately 690,000 BTC—currently worth approximately $54 billion—stored in legacy P2PK (Pay-to-Public-Key) addresses are vulnerable to quantum attacks using Shor's algorithm. These addresses were used primarily during 2009-2013 by early miners including Satoshi Nakamoto, and their public keys are fully exposed on the blockchain, making them prime targets for quantum decryption.
Core Perspectives
The Citigroup report distinguishes between two attack vectors: Near-term threats against P2PK addresses where public keys are permanently exposed, and long-term threats against P2PKH addresses where public key exposure only occurs at the moment of spending. Quantum computers running Shor's algorithm could derive private keys from exposed public keys within hours of targeted computation. While current quantum computers lack sufficient qubit stability to execute such attacks, the cryptographic community estimates quantum threat timelines are compressing from "decade-scale" to "5-7 years" given recent advances in error correction and qubit coherence. The BIS and IMF have both begun incorporating post-quantum cryptography readiness into their digital asset regulatory frameworks.
Risk Advice
Investors holding BTC in legacy addresses from the 2009-2013 era should consider migrating to modern P2PKH or Taproot addresses as a precautionary measure. Post-quantum cryptographic standards (CRYSTALS-Kyber, CRYSTALS-Dilithium) are being actively integrated into wallet infrastructure by Coinbase, Ledger and Trezor. While the immediate threat remains theoretical, the irreversibility of blockchain transactions means that once quantum computing reaches the threshold, exposed addresses have zero recovery options.








