
European financial regulators have warned that quantum computing could eventually weaken the cryptographic protections underpinning Bitcoin and other blockchain networks, with the risk potentially arriving before quantum technology has a viable commercial use.
The warning has added urgency to Bitcoin’s long-standing debate over coins held in legacy addresses where public keys are already visible onchain. If quantum computers eventually gain the ability to break Bitcoin’s cryptography, some of these holdings could become vulnerable to theft.
The Joint Committee of the European Supervisory Authorities (ESAs), comprising the European Banking Authority (EBA), European Securities and Markets Authority (ESMA) and European Insurance and Occupational Pensions Authority (EIOPA), raised the issue in its Autumn 2026 Risk and Vulnerabilities report.
The authorities said quantum-related threats could emerge before any commercially viable application becomes available. An advanced quantum computer, they warned, could undermine cryptographic systems widely relied upon for communications, transactions, databases and blockchain security.
CryptoQuant estimates that roughly 6.9 million BTC, worth about $586 billion, could be exposed if quantum computers eventually become capable of defeating Bitcoin’s cryptographic safeguards.
The regulators did not specify when quantum computing could reach that stage. IBM, however, recently estimated that quantum computing could be in use within four years or less.
Why Legacy Addresses Matter
Bitcoin held in older Satoshi-era addresses and reused addresses could carry greater quantum risk because their public keys may already be available on the blockchain. A sufficiently powerful quantum computer could theoretically use an exposed public key to calculate its associated private key and gain control of the coins.
Other dormant BTC is less exposed at present. Many unspent outputs conceal the public key through a cryptographic hash, meaning the underlying key is not directly visible until certain spending conditions are met.
Older pay-to-public-key outputs and reused addresses differ because their public keys have already been published onchain.
The EU warning does not indicate that such a quantum computer exists today. Instead, it highlights a potential future security problem that Bitcoin would need to address ahead of time.
Unlike a traditional financial institution, Bitcoin cannot simply implement a centralized security upgrade. Moving to quantum-resistant signatures would require network-wide consensus, while owners of vulnerable coins would need to transfer their holdings before quantum attacks become technically feasible.
Preparing for a Post-Quantum Threat
The European authorities also pointed to “harvest now, decrypt later” attacks, where encrypted information is collected in advance and stored until technology becomes capable of decrypting it.
The European Commission’s post-quantum roadmap calls on EU member states to begin transitioning to quantum-resistant systems by the end of 2026. High-risk use cases are targeted for protection by 2030.
For Bitcoin, the warning underscores the importance of addressing exposed public keys and developing quantum-resistant cryptography before quantum computers become capable of exploiting existing vulnerabilities.






