European financial authorities have warned that advances in quantum computing could eventually threaten the cryptographic systems that protect Bitcoin and other blockchains, potentially creating a security challenge before quantum technology reaches commercial maturity.
The warning has renewed debate over Bitcoin held in legacy wallets where public keys are already exposed onchain. If quantum computers become capable of breaking the network’s cryptography, questions could arise over whether vulnerable BTC should be moved, frozen or otherwise protected.
The Joint Committee of the European Supervisory Authorities (ESAs), which includes the European Banking Authority (EBA), European Securities and Markets Authority (ESMA) and European Insurance and Occupational Pensions Authority (EIOPA), highlighted the risk in its Autumn 2026 Risk and Vulnerabilities report.
The regulators said the threat could appear before quantum computing has a viable commercial application. According to the report, a sufficiently advanced quantum computer could weaken cryptographic systems currently used to protect communications, transactions, databases and blockchain networks.
CryptoQuant estimates that approximately 6.9 million BTC, valued at about $586 billion, could be vulnerable if quantum technology eventually becomes capable of breaking Bitcoin’s cryptographic defenses.
The European authorities did not give a timeline for when quantum computers might reach that level of capability. A recent IBM report, however, suggested quantum computing could enter practical use within four years or less.
Older Bitcoin Addresses Could Be More Vulnerable
Coins associated with Satoshi-era wallets and reused Bitcoin addresses could face greater exposure because their public keys may already be visible on the blockchain. A sufficiently powerful quantum computer could potentially use those public keys to derive the corresponding private keys and take control of the funds.
Dormant Bitcoin holdings do not all face the same level of exposure. Many unspent outputs continue to conceal public keys behind cryptographic hashes, meaning they remain less vulnerable under current conditions.
Older pay-to-public-key outputs and reused addresses present a different situation because their public keys have already been published onchain.
The EU regulators did not suggest that a quantum computer capable of compromising Bitcoin exists today. Instead, the warning highlights the need to prepare for a potential future scenario.
Bitcoin’s decentralized structure also makes a cryptographic upgrade more complex than a conventional security update at a bank. Introducing quantum-resistant signatures would require broad consensus across the network, while holders of exposed BTC would need to move their coins before quantum computing reaches the required capability.
EU Pushes for Post-Quantum Protection
The regulators also highlighted the “harvest now, decrypt later” threat, in which attackers collect encrypted information today and attempt to decode it once more powerful technology becomes available.
The European Commission’s post-quantum roadmap calls for EU member states to start transitioning to quantum-resistant systems by the end of 2026. High-risk applications are expected to have appropriate protections in place by 2030.
For Bitcoin, the challenge is therefore largely about preparation: the network would need to address potentially exposed keys and adopt stronger cryptographic protections before quantum computers become capable of exploiting them.





