EU financial watchdogs warn quantum computers threaten blockchain security
European Union financial regulators have warned that advanced quantum computers could eventually crack the cryptography protecting blockchains, with roughly 6.9 million bitcoin worth about $586 billion currently exposed. The warning adds regulatory weight to a debate Bitcoin has long avoided: whether to freeze coins in old, vulnerable wallets before a quantum attack becomes possible.
- The ESAs’ Joint Committee released its Autumn 2026 Risk and Vulnerabilities report on Wednesday.
- Roughly 6.9 million bitcoin, worth about $586 billion, sit in wallet types considered vulnerable, according to CryptoQuant data.
- The European Commission wants member states to begin post-quantum transitions by the end of 2026, with high-risk systems covered by 2030.
- 6.9M BTC bitcoin holdings regulators flag as quantum-exposed
- $586B dollar value of that exposed bitcoin supply
- 4 years IBM’s estimate for commercially viable quantum computing
- 2030 EU deadline to secure high-risk cryptographic use cases
European financial watchdogs have warned that a sufficiently powerful quantum computer could undermine the cryptography that secures blockchains, and that the danger could arrive before quantum computing has any viable commercial use. The warning comes from the Joint Committee of the European Supervisory Authorities, which groups the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority. It appears in their Autumn 2026 Risk and Vulnerabilities report, released Wednesday, according to reporting by CoinDesk.
“Threats could materialize earlier than any viable commercial application,” the authorities wrote in the report.
6.9 million Bitcoin sit exposed, cryptoQuant data shows
According to CryptoQuant figures cited in CoinDesk’s reporting, roughly 6.9 million bitcoin, worth about $586 billion, would be at risk if a quantum computer capable of breaking Bitcoin’s cryptography were built. That figure equals close to a third of Bitcoin’s eventual 21 million coin supply cap, underscoring how much of the network’s value sits in wallet formats regulators consider fragile.
The EU report does not claim such a machine exists today. IBM has previously estimated commercially viable quantum computing could arrive within four years, though the ESAs report itself sets no timeline, saying only that risks could emerge ahead of any practical quantum application.
The gap between those two claims, no working machine yet versus a possible four-year horizon, is the crux of the urgency regulators are trying to convey.
Old Bitcoin addresses carry the real exposure
Not every dormant bitcoin wallet faces equal risk. Many unspent outputs still hide their public key behind a cryptographic hash, leaving the underlying key concealed unless the coins are spent, which limits exposure for now.
Older pay-to-public-key outputs and reused addresses are different, because their public keys are already visible on the blockchain. A sufficiently powerful quantum computer could use an exposed public key to derive the matching private key and take control of the coins, a risk concentrated in Satoshi-era holdings and addresses that have been reused. The ESAs flagged a related danger they call “harvest now, decrypt later,” in which encrypted data or exposed keys are collected today for decryption once quantum capability catches up.
Brussels sets a 2026-to-2030 migration deadline
The European Commission’s post-quantum cryptography roadmap traces back to an April 2024 Recommendation urging member states to build coordinated national PQC strategies. A NIS Cooperation Group work stream, co-chaired by Germany, France and the Netherlands, translated that into the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, adopted in June 2025.
That roadmap sets the timeline the ESAs report now echoes for finance specifically: member states should start transitioning to post-quantum cryptography by the end of 2026, with high-risk use cases protected no later than the end of 2030. Between August 11 and September 29, 2025, the NIS Cooperation Group ran a stakeholder survey on the roadmap and has since published an FAQ document covering risk estimation, milestones and hybrid cryptographic schemes, though it leaves unresolved how quickly financial infrastructure specifically, as opposed to general public-sector systems, must comply.
Bitcoin itself has no equivalent deadline. Moving to quantum-resistant signatures would require network-wide consensus among miners and node operators, plus voluntary migration by holders of exposed coins before any attack becomes feasible.
The BlockWest read. The pressure here falls less on Bitcoin’s protocol, which cannot be forced to upgrade on Brussels’ timetable, and more on custodians, exchanges and institutional holders sitting on Satoshi-era or reused-address balances. Expect compliance teams at regulated EU custodians to start auditing address exposure and planning coin migrations well before the 2030 high-risk deadline, regardless of whether Bitcoin’s own governance ever reaches consensus on a network-level fix.
The next concrete marker is the NIS Cooperation Group’s promised second deliverable supplementing the EU’s post-quantum roadmap, which will spell out further detail beyond the 2026 and 2030 milestones already set. Whether Bitcoin’s developer community responds with its own quantum-resistant proposal, or leaves the roughly $586 billion in exposed coins to individual holders to secure, remains an open question the ESAs report does not answer.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
