European financial regulators have raised concerns that advances in quantum computing could eventually compromise the cryptographic protections used by Bitcoin and other blockchains, potentially before the technology becomes commercially practical.
The warning has also revived questions around Bitcoin held in older wallets where public keys are already exposed onchain, including whether such coins may eventually need to be frozen or moved to safer addresses.
The Joint Committee of the European Supervisory Authorities (ESAs), made up of the European Banking Authority (EBA), European Securities and Markets Authority (ESMA) and European Insurance and Occupational Pensions Authority (EIOPA), issued the warning in its Autumn 2026 Risk and Vulnerabilities report.
The authorities said the risk could emerge before quantum computing has a viable commercial application. An advanced quantum computer could potentially weaken cryptographic systems used across communications, financial transactions, databases and blockchain networks.
CryptoQuant estimates that around 6.9 million BTC, worth approximately $586 billion, could be vulnerable if quantum computers eventually become capable of breaking Bitcoin’s cryptography.
The report did not specify when such technology might become commercially available. However, IBM said in a recent report that quantum computing could be in use within four years or less.
Legacy Bitcoin Addresses Face Greater Exposure
Bitcoin stored in older Satoshi-era wallets and reused addresses could be particularly vulnerable because their public keys may already be visible on the blockchain. If quantum computers become powerful enough, attackers could potentially derive private keys from those exposed public keys and gain access to the associated BTC.
Not every dormant Bitcoin address carries the same level of risk. Many unspent outputs still conceal their public keys behind cryptographic hashes, providing an additional layer of protection for now.
Older pay-to-public-key outputs and addresses that have been reused are more exposed because their public keys are already recorded directly onchain.
The European regulators did not claim that a quantum computer capable of breaking Bitcoin’s cryptography currently exists. Instead, the warning focuses on preparing for a potential future threat.
Upgrading Bitcoin to quantum-resistant cryptographic signatures would also present challenges that differ from those faced by traditional financial institutions. Such a change would require broad agreement across the Bitcoin network, while owners of exposed coins would need to transfer them to addresses using stronger cryptographic protection before a quantum attack becomes feasible.
Post-Quantum Preparation
The European authorities also pointed to the risk of “harvest now, decrypt later” attacks, where encrypted information is collected today with the expectation that advances in quantum computing will eventually make it possible to decrypt.
The European Commission’s post-quantum roadmap calls on EU member states to begin transitioning toward quantum-resistant systems by the end of 2026. It also sets a target of 2030 for protecting high-risk use cases.
For Bitcoin, the issue is therefore not an immediate attack but the potential need to upgrade cryptographic infrastructure well before quantum computers become capable of exploiting currently exposed keys.
































