Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,000▼ 0.04%ETH$2,690▲ 0.42%SOL$120.52▲ 3.43%TOTAL CRYPTO$2.89T▼ 2.30%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.60▼ 3.26%GOLD4,321.20▼ 7.95%WTI92.41▲ 12.20%BRENT97.44▲ 10.00%EUR/USD1.1400▼ 2.30%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

EU Regulators Put Quantum Risk on Bitcoin’s Doorstep

EU financial watchdogs warn quantum computers could break blockchain cryptography before the tech is commercially viable, exposing 6.9 million bitcoin.

Pexels – DS stories

European financial regulators say quantum computers could break the cryptography protecting blockchains before the technology has any commercial use, and roughly 6.9 million bitcoin, worth about $586 billion, sit in addresses most exposed to that scenario. The warning comes from the Joint Committee of the three European Supervisory Authorities, the bodies that oversee banking, securities and insurance across the EU, in their Autumn 2026 risk report released Wednesday.

The report does not claim such a machine exists today. What it does say is sharper than most previous regulatory language on the subject: threats “could materialize earlier than any viable commercial application,” and an advanced quantum computer “could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains.” That framing matters for finance ministries and bank risk officers, because it removes the comfortable assumption that regulation can wait until quantum hardware is actually on the market.

Why some bitcoin is more exposed than the rest

The vulnerability is not spread evenly across bitcoin’s 19.9 million coin supply. Modern address formats hash the public key, so a thief cannot see it on the blockchain until coins are spent. Older pay-to-public-key outputs and any reused address behave differently: the public key is already visible, and a sufficiently powerful quantum computer running Shor’s algorithm could derive the private key from it.

According to an analysis by Cryptoquant, about 6.9 million bitcoin fall into the exposed category. That figure includes coins mined in bitcoin’s early years, when pay-to-public-key was the default, and it presumably covers the estimated 1 million or so bitcoin attributed to Satoshi Nakamoto, which have never moved. Cryptoquant’s researchers have previously estimated that a quantum attack on exposed coins could become technically feasible before the network completes a migration, which is why the firm’s CEO has called for freezing vulnerable coins, a proposal that split the bitcoin community down the middle.

Not every dormant wallet is equally exposed. Many unspent outputs still hide the public key behind a hash, so they are harder to attack until the owner transacts. But the distinction is lost on headlines, and the aggregate number, $586 billion at current prices, is large enough that policymakers cannot file it under theoretical.

What the regulators actually said

The Joint Committee combines the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority. Its autumn risk update treats quantum computing as a live operational risk for financial infrastructure, not a distant research topic.

“Threats could materialize earlier than any viable commercial application. An advanced quantum computer could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains.”

The report also flagged “harvest now, decrypt later” attacks, in which encrypted data collected today is stored until a future quantum computer can break it. For blockchains the analogous problem is nastier in one respect: transaction data is public by design. Anyone recording exposed public keys today is collecting exactly the input a future attack would need, and there is no way to un-publish a public key.

On the policy side, the European Commission’s post-quantum roadmap already calls on member states to begin transitioning critical systems by the end of 2026, with high-risk use cases protected by 2030. The watchdogs’ report effectively extends that logic to crypto assets held by European institutions and to the infrastructure European banks use when they touch digital assets.

Bitcoin’s governance problem, not its engineering problem

Post-quantum signature schemes exist. The harder question is how bitcoin adopts them, because unlike a bank, the network cannot push a software update to every participant. Moving to quantum-resistant signatures requires broad consensus among developers, miners and node operators, and any change touches the most sensitive part of the protocol: how coins are owned.

Grayscale researchers argued in an April paper that bitcoin’s quantum problem is governance rather than engineering. The options on the table range from soft-fork migration paths that let holders move coins to quantum-safe addresses, to more drastic proposals that would eventually burn or freeze coins that never migrate. The freeze idea, floated publicly by Cryptoquant’s CEO, runs against a core norm that the protocol does not confiscate, and prominent developers have rejected it. But if a quantum computer ever does break exposed keys, the choice may not stay theoretical: do nothing and watch possibly millions of coins stolen, or intervene and set a precedent bitcoin has avoided for its entire life.

The timeline debate

How much time does the industry have? Estimates vary widely, and the EU report pointedly declines to give one. A recent IBM assessment said quantum computing would be in commercial use within four years or less, which is aggressive. Most cryptographers working on post-quantum migration assume more time, but few still argue the risk is zero within a decade.

Meanwhile, work on fixes is accelerating. In September, CoinDesk reported that crypto researchers cut their estimate for the cost of a single quantum-safe bitcoin transaction from $320 to $66 after a week of engineering, a sign that the overhead of post-quantum signatures is falling fast. A separate proposal known as PQLN adds post-quantum protection to the Lightning Network using standardized ML-DSA and ML-KEM schemes, with measured cryptographic overhead below a third of a millisecond. Ethereum researchers have run similar exercises for the account abstraction layer.

Actor Position or deadline Status
EU Joint Committee (EBA, ESMA, EIOPA) Quantum threat to blockchain cryptography flagged in autumn risk report Report published September 2026
European Commission Member states begin post-quantum transition by end of 2026; high-risk use cases protected by 2030 Roadmap in force
Bitcoin network No quantum-resistant signature scheme activated Discussion stage; governance unresolved
Cryptoquant estimate 6.9 million BTC, about $586 billion, in exposed address types Analysis, disputed in scale
IBM Commercial quantum use within four years or less Vendor assessment

What happens next

For exchanges, custodians and funds in the EU, the practical read is that quantum exposure is joining cybersecurity questionnaires. A fund holding bitcoin in reused addresses looks different on a risk register than one that has swept coins to fresh hashed addresses, and compliance teams will start being asked to show which they do.

For bitcoin itself, the report changes little immediately. No rule binds the network, and its developers answer to no regulator. But the cumulative pressure is real: a major regulatory bloc has now put a date, however soft, on when its financial system expects quantum readiness, and the largest pool of exposed wealth on any blockchain sits in bitcoin’s oldest addresses. The debate over what to do about Satoshi’s coins, frozen, migrated or left alone, is no longer confined to developer mailing lists. It now has a regulatory document attached to it.

SourcesEuropean Supervisory Authorities Joint Committee autumn 2026 risk report; CoinDesk; Cryptoquant analysis; IBM quantum computing assessment; European Commission post-quantum cryptography roadmap
Share: X