EU Watchdogs Flag Quantum Risk to Blockchains in Sept. 23 Update

Illuminated server room with a glowing quantum computing component in the foreground, representing quantum threats to blockchain cryptography

European financial supervisors warned on Sept. 23 that sufficiently advanced quantum computers could undermine the cryptography securing blockchains, transactions, databases and communications, according to Crypto.news. The Joint Committee of the European Supervisory Authorities — made up of the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority — issued the warning in its Autumn 2026 risk update, which did not claim that a machine capable of breaking Bitcoin’s cryptography exists today.

The joint update said quantum computing could improve financial processes such as pricing, fraud detection and compliance monitoring, while the same technology could eventually weaken cryptography used across financial infrastructure. The authorities wrote that risks “could also materialise faster than any commercially viable application.” A separate ESMA technical analysis published in May said sufficiently advanced quantum computers could use Shor’s algorithm against public-key schemes including RSA and elliptic-curve cryptography, while stressing that such attacks remain beyond current noisy intermediate-scale quantum, or NISQ, machines.

Also read: Draper Urges Apple and Meta to Hold Bitcoin, Repeats $250K Target

Key facts

  • EU supervisors issued the quantum warning in their Sept. 23 Autumn 2026 risk update, focused on preparation rather than an existing threat.
  • CryptoQuant founder Ki Young Ju estimated in February that approximately 6.89 million BTC could face quantum exposure under his methodology.
  • Glassnode’s May research measured 6.04 million BTC, or 30.2% of issued supply, as having public-key exposure at rest, including 1.92 million BTC classified as structurally exposed.
  • IBM said in April that fault-tolerant quantum systems could begin approaching cryptographic relevance by the end of the decade.
  • BIP-360 and BIP-361, Bitcoin proposals covering quantum-resistant outputs and migration policy, remain drafts in the official repository and are not activated consensus rules.

Exposure estimates depend on methodology

How much Bitcoin is potentially exposed to a future quantum attacker remains disputed because researchers count address types and reused keys differently. Ki Young Ju’s February estimate of roughly 6.89 million BTC included about 1.91 million BTC with directly visible public keys and other coins whose keys may have been revealed through previous spending behavior, along with dormant holdings attributed to early Bitcoin users. Glassnode’s later framework placed 1.92 million BTC in its structural category, which includes early pay-to-public-key outputs, bare multisig outputs and Taproot outputs where the key is revealed by design. Operational exposure, per Glassnode, covers address reuse, partial spending or custody practices that make a key visible while coins remain associated with it.

Draft proposals leave migration unsettled

Bitcoin ownership depends on digital signatures, and several common address formats keep a public key hidden behind a hash until coins are spent — while other output types expose the key from creation. BIP-360, listed as a draft, proposes Pay-to-Merkle-Root outputs intended to reduce long-exposure attacks against elliptic-curve keys, but notes that protection against an attacker deriving a key while a transaction waits for confirmation may require a post-quantum signature scheme. BIP-361 addresses migration policy by eventually preventing new funds from being sent to quantum-vulnerable output types and later tightening spending rules for legacy ECDSA and Schnorr signatures. As Crypto.news detailed, developers continue debating how dormant or inaccessible coins should be handled if legacy signatures eventually become unsafe.

Also read: Bitcoin Closes Above 50-Week Moving Average for First Time Since 2025

Cointelegraph reported that Bitcoin developer Jameson Lopp and five co-developers in February proposed phasing out the network’s current signatures and restricting how unmigrated funds could be spent five years after the proposal’s activation — a proposal that has not been adopted. Cointelegraph also reported that the Ethereum Foundation aims to make Ethereum resistant to quantum attacks across its execution, consensus and data layers by December 2029, a target date that does not appear in the Crypto.news report. Separately, Cointelegraph noted that Google Quantum AI researchers estimated in March that breaking the cryptography used by many cryptocurrencies could require about 20 times fewer physical qubits than earlier estimates.

Why it matters

The warnings shift quantum computing from a theoretical concern to a planning item for institutions holding crypto and for the developers who maintain blockchain networks. Europe’s transition timetable already calls for all EU member states to begin moving toward post-quantum cryptography by the end of 2026, with high-risk use cases completing the transition no later than the end of 2030 — deadlines that now sit alongside an unresolved technical standard on Bitcoin. Because Bitcoin changes require consensus across developers, miners, businesses, wallet providers and node operators, the gap between regulatory deadlines and network readiness is the practical risk. Institutional custodians have begun preparing without waiting for Bitcoin to pick a final signature system; Crypto.news reported that Coinbase is designing post-quantum Bitcoin custody capable of supporting multiple potential signature schemes, with Chief Cryptographer Yehuda Lindell saying the company wants its custody architecture to remain usable regardless of which system a blockchain ultimately adopts.

What to watch

Whether BIP-360 and BIP-361 advance beyond draft status, and whether EU member states meet the end-of-2026 start of their post-quantum migration roadmap, are the two timelines that will indicate how quickly the preparation gap narrows. ESMA’s “harvest now, decrypt later” concern — attackers collecting encrypted data today to decrypt it with future machines — means the useful life of financial information, not the arrival date of a quantum computer, drives the schedule.

Jackson Lee

Written by

Jackson Lee

Jackson Lee covers Bitcoin and Ethereum markets at CryptoNewsInsights, tracking price movements, network developments, and ecosystem news.

Sources: crypto.news, Cointelegraph

Leave a Reply

Your email address will not be published. Required fields are marked *