EU financial watchdogs warn quantum computing poses imminent threat to blockchain encryption
The warning brings renewed urgency to the debate over how bitcoin should deal with legacy addresses whose public keys are already exposed onchain.
European financial authorities warned that an advanced quantum computer could undermine cryptography used to secure blockchains, saying the threat could emerge before the technology has a viable commercial application.
The warning from the Joint Committee of the European Supervisory Authorities (ESAs), which includes the European Banking Authority (EBA), European Securities and Markets Authority (ESMA) and European Insurance and Occupational Pensions Authority (EIOPA), brings fresh urgency to a long-running question for bitcoin of whether to freeze or not freeze the BTC in legacy wallets. In the event that quantum computers one day do become capable of breaking bitcoin’s cryptography, roughly 6.9 million bitcoin, worth roughly $586 billion, are currently vulnerable, according to Cryptoquant.
“Threats could materialize earlier than any viable commercial application,” the authorities said in their Autumn 2026 Risk and Vulnerabilities report released Wednesday. An advanced quantum computer “could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains,” according to the report..
Although the report does not mention timelines for quantum computing becoming commercially viable, a recent IBM report says it will be in use in four years or less.
The Satoshi-era bitcoin held in older, legacy addresses or reused addresses could face greater risk if quantum computing advances. In those cases, the public key may already be visible on the blockchain. A sufficiently powerful quantum computer could use it to derive the private key and take control of the coins.
That does not apply equally to every dormant wallet. Many unspent bitcoin outputs still hide the public key behind a cryptographic hash, leaving them less exposed for now. Older pay-to-public-key outputs and reused addresses are different because their public keys are already onchain.
The European Union (EU) warning does not say that a quantum computer capable of breaking bitcoin’s cryptography exists today. But bitcoin cannot simply update its security in the same way a bank does. Moving to quantum-resistant signatures would require network-wide consensus, and holders of exposed coins would need to move them before such an attack becomes possible.
The European financial watchdogs said information gathered today could be decrypted later in so-called “harvest now, decrypt later” attacks. The European Commission’s (EC) post-quantum roadmap calls on member states to begin transitioning by the end of 2026, with high-risk use cases to be protected by 2030.
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Asanat Analysis — Why it matters
EU financial regulators flagging quantum computing as an 'imminent' threat signals a shift from theoretical concern to active policy consideration. This matters because it legitimizes work already underway in cryptography circles—particularly post-quantum signature schemes and address migration pathways—but creates pressure for timeline acceleration. The specificity of EU regulatory bodies raising the alarm suggests formal risk assessments are underway, which typically precede formal guidance or compliance requirements.
Bitcoin's exposure of public keys through legacy address reuse is the concrete vulnerability at stake. Once quantum computers reach sufficient scale (still years away, but timelines are uncertain), they could theoretically derive private keys from exposed public keys onchain. This isn't a Bitcoin-only problem—it affects Ethereum and most blockchains using ECDSA. The debate over 'how bitcoin should deal with' this reveals the core tension: introducing quantum-resistant signatures requires protocol changes that may face adoption friction, yet inaction leaves accumulated value exposed to future extraction.
The regulatory angle is significant. EU action typically presages broader institutional pressure on digital asset custody, exchange listing standards, and potentially reserve requirements. Regulated entities holding Bitcoin may soon face questions about quantum-readiness from compliance teams, creating market incentives for migration solutions before regulatory mandates arrive.