TL;DR
- European financial authorities warned that quantum computers could break the cryptography protecting blockchains before having any viable commercial use.
- According to Cryptoquant, approximately 6.9 million bitcoin valued at around $586 billion will be exposed if the technology advances far enough.
- The European Commission’s post-quantum roadmap requires member states to begin the transition before the end of 2026 and protect high-risk cases by 2030.
The Joint Committee of the European Supervisory Authorities (ESAs), which brings together the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA), published this week its Autumn 2026 Risks and Vulnerabilities report.
The report issues a stark warning: quantum computers could undermine the cryptographic systems protecting communications, transactions, and blockchains before the technology even has a viable commercial application. “The threats could materialize before any viable commercial application,” the document states.
The document does not specify concrete timelines for the commercial adoption of quantum computing, but a recent report by IBM estimates it will be in use in four years or less.
That horizon brings to the forefront the debate over what to do with bitcoin stored in legacy addresses, where the public key is already visible on the blockchain. A sufficiently powerful system could use that information to derive the private key and take control of the funds.
The Real Risk of Quantum Computers
Not all inactive wallets share the same level of exposure. Unspent outputs that still conceal the public key behind a cryptographic hash currently carry lower vulnerability. In contrast, pay-to-public-key outputs and reused addresses present a higher risk because their keys are already visible on the blockchain. According to Cryptoquant, around 6.9 million BTC —valued at approximately $586 billion— are in that situation.
The report does not claim that a computer capable of breaking Bitcoin’s cryptography exists today, but it does warn about “harvest now, decrypt later” attacks, in which information captured today could be decrypted in the future.
Network-Level Consensus Is Needed
Bitcoin cannot update its security with the same agility as a bank: migrating to quantum-resistant signatures would require network-level consensus, and users holding exposed coins would need to move them before an attack of this kind becomes feasible.
The European Commission’s post-quantum roadmap establishes that member states must begin that transition before the end of 2026, with the highest-risk cases protected by 2030.







