EU watchdogs warn quantum computers could hit blockchains
European financial watchdogs have warned on Sept. 23 that sufficiently advanced quantum computers could undermine cryptography securing blockchains, while CryptoQuant founder Ki Young Ju estimates 6.89 million BTC may have public-key exposure relevant to a future quantum attack.
- EU financial watchdogs warn quantum computing could undermine cryptography securing blockchains, transactions, databases and communications.
- CryptoQuant founder Ki Young Ju estimates 6.89 million BTC may face future quantum exposure risks.
- ESMA says practical quantum attacks remain beyond current NISQ devices despite rising long-term security concerns.
- EU states should begin post-quantum migration by 2026, protecting high-risk uses no later than 2030.
- Bitcoin developers have proposed quantum-resistant migration paths, but consensus and legacy coin handling remain unresolved.
The Joint Committee of the European Supervisory Authorities, comprising the European Banking Authority, European Insurance and Occupational Pensions Authority and European Securities and Markets Authority, warned that quantum computing could create major risks for cryptographic systems protecting transactions, communications, databases and blockchains.
The Sept. 23 Autumn 2026 risk update did not say a machine capable of breaking Bitcoin cryptography exists today. Its warning focused on preparation, noting that quantum-related security risks could emerge before commercially useful quantum applications become practical.
EU watchdogs say cryptographic risks could emerge early
In its risk update, the Joint Committee said quantum computing could improve financial processes, pricing, fraud detection and compliance monitoring. The same technology could eventually weaken cryptography used throughout financial infrastructure. The authorities wrote that “risks posed could also materialise faster than any commercially viable application.”
A separate ESMA technical analysis published in May examined the mechanics in more detail. It said sufficiently advanced quantum computers could use Shor’s algorithm against public-key schemes including RSA and elliptic-curve cryptography, or ECC. Bitcoin relies on elliptic-curve signatures for ownership and transaction authorization.
ESMA stressed that such attacks remain beyond current noisy intermediate-scale quantum, or NISQ, machines. Its report said systems capable of threatening existing cryptography are not expected immediately, but long migration periods make early preparation necessary.
IBM has taken a similar position on timing. The company said in April that fault-tolerant quantum systems could begin approaching cryptographic relevance by the end of the decade. IBM has not said a Bitcoin-breaking quantum computer exists now.
Bitcoin quantum exposure estimates depend on methodology
The amount of Bitcoin potentially exposed to a future quantum attacker remains disputed because researchers count address types and reused keys differently.
CryptoQuant founder Ki Young Ju estimated in February that approximately 6.89 million BTC could face quantum exposure under his methodology. His figure included roughly 1.91 million BTC associated with directly visible public keys and other coins whose keys may have been revealed through previous spending behavior. The estimate included dormant holdings attributed to early Bitcoin users.
— Ki Young Ju (@ki_young_ju) February 18, 2026
Glassnode later produced a different calculation. Its May research measured 6.04 million BTC, or 30.2% of issued supply, as having public-key exposure at rest. Within that total, Glassnode classified 1.92 million BTC as structurally exposed because the output type reveals the key by design.
The Glassnode framework includes early pay-to-public-key outputs, bare multisig outputs and Taproot outputs in the structural category. Operational exposure covers situations where address reuse, partial spending or custody practices make a key visible while coins remain associated with it.
As crypto.news reported in its coverage of Bitcoin quantum exposure measured by Glassnode, the firm’s narrower structural measure put 1.92 million BTC directly in the category where public keys are revealed by design.
Exposed public keys create the Bitcoin-specific risk
Bitcoin ownership depends on digital signatures. For several common address formats, a public key may remain hidden behind a hash until coins are spent. Other output types expose the public key from creation, while address reuse can leave previously hidden keys visible onchain.
BIP-360, currently listed as a draft in the official Bitcoin Improvement Proposal repository, proposes Pay-to-Merkle-Root outputs designed to reduce long-exposure attacks against elliptic-curve keys. Its specification identifies P2PK, reused outputs and Taproot outputs among categories with long-exposure risk.
The proposal does not claim to solve every quantum attack path. BIP-360 notes that protection against an attacker deriving a key while a transaction waits for confirmation may require a post-quantum signature scheme.
BIP-361 addresses migration policy. The draft would eventually prevent new funds from being sent to quantum-vulnerable output types and later tighten spending rules for legacy ECDSA and Schnorr signatures. Its timetable begins only after a post-quantum output type is implemented and activated.
As crypto.news detailed in its Bitcoin BIP-360 and BIP-361 migration coverage, developers continue debating how dormant or inaccessible coins should be handled if legacy signatures eventually become unsafe.
Neither BIP is an activated Bitcoin consensus rule. The official BIP repository lists BIP-360 and BIP-361 as drafts, leaving the technical standard and migration policy unsettled.
Europe wants post-quantum migration to start in 2026
The European Commission already has a transition timetable covering public institutions and critical infrastructure. Its post-quantum roadmap calls for all EU member states to begin moving toward post-quantum cryptography by the end of 2026. High-risk use cases should complete the transition no later than the end of 2030.
The roadmap grew out of a Commission recommendation issued in 2024 and a coordinated implementation plan adopted in June 2025. A Sept. 2, 2026 consultation update said respondents favored clear deadlines, risk-based prioritization, hybrid cryptographic approaches and crypto-agility.
ESMA’s May paper set out another concern known as “harvest now, decrypt later.” Attackers can collect encrypted information today and store it until future computers become capable of decrypting it. The regulator said the long useful life of some financial information makes migration planning a multi-year security task.
For blockchains, migration involves an extra problem because existing assets and keys may need to move before older signature systems become unsafe. Bitcoin changes require consensus across developers, miners, businesses, wallet providers and node operators before new consensus rules can become active.
Institutional custodians have begun preparing without waiting for Bitcoin to choose a final signature system. In related coverage, crypto.news reported that Coinbase is designing post-quantum Bitcoin custody capable of supporting multiple potential signature schemes. Coinbase Chief Cryptographer Yehuda Lindell said the company wants its custody architecture to remain usable regardless of which system a blockchain ultimately adopts.
Ledger CTO Charles Guillemet has separately argued that migration may take years because changing wallets, custody systems and existing holdings can be harder than selecting a post-quantum algorithm. Crypto.news reported that Bitcoin’s quantum migration remains a wallet and coordination challenge while BIP-360 and BIP-361 remain drafts.