Bitcoin enters Europe’s quantum debate
Quantum risk is no longer just a discussion among cryptographers. It was already among the pressure factors observed around Bitcoin in recent months. This time, three European financial supervisory authorities have officially classified it as an emerging vulnerability.
The Joint Committee of the European Supervisory Authorities brings together the European Banking Authority, ESMA and EIOPA. Its report explains that quantum computers could one day compromise certain cryptographic systems currently used to secure communications, transactions and blockchains. Above all, the authorities add an important point: the risks could materialize even before commercially viable quantum applications emerge.
This does not mean that a machine capable of stealing bitcoins currently exists. A report published by ESMA in May instead notes that quantum hardware remains limited and that the technology is still at an early stage. Nevertheless, the authority considers that a sufficiently powerful computer would pose a significant risk to current cryptographic protocols.
Europe therefore does not want to wait until the attack becomes feasible.
Why 6.9 million BTC are raising greater concerns
Not all bitcoins face exactly the same level of exposure.
To spend BTC, its owner uses a digital signature proving ownership of the corresponding private key. A sufficiently advanced quantum computer could theoretically use Shor’s algorithm against certain public-key cryptography systems and attempt to reconstruct a private key from a known public key.
This is where older Bitcoin outputs and address reuse become sensitive.
With some modern types of Bitcoin addresses, the public key remains hidden behind a hash until the bitcoins are spent. It is revealed only when the transaction takes place. With certain older pay-to-public-key outputs, or when an address has already been used to spend funds and then reused, the public key may already be recorded on the blockchain.
CoinDesk consequently reports a CryptoQuant estimate of around 6.9 million BTC potentially more exposed, equivalent to approximately $586 billion at current prices. This figure does not mean that 6.9 million BTC can be stolen today or that they will automatically be stolen when a quantum machine appears. Rather, it measures a group of bitcoins whose migration would be more urgent.
The issue also ties into broader cybersecurity challenges linked to quantum computing: infrastructure must be modified before the cryptography it uses becomes genuinely vulnerable.
Europe wants to begin the migration in 2026
The European Union has already set its timetable.
Its roadmap for post-quantum cryptography calls on member states to begin their transition before the end of 2026. Uses considered to carry the highest risks must be protected by post-quantum mechanisms by the end of 2030 at the latest.
Post-quantum cryptography itself does not require a quantum computer. It consists of algorithms designed to run on current machines while resisting attacks from a future quantum adversary.
For Bitcoin, the transition is more complicated than a simple software update. Changing the network’s signature system requires broad consensus among developers, node operators, companies and users. It will also be necessary to determine what should happen to bitcoins whose owners never migrate their funds.
That is why the debate already focuses on old coins: should they one day be frozen, left exposed or made recoverable through a dedicated mechanism? Each option directly affects the ownership principles underpinning Bitcoin.
This preparation is also accelerating outside Europe. The United States has already begun its own post-quantum migration, with several deadlines planned for sensitive federal systems.
The European signal should therefore be read without panic and without complacency. No known quantum computer currently threatens Bitcoin wallets. Nevertheless, the authorities consider that the time required to modify such complex financial infrastructure justifies starting before the threat becomes operational.
For Bitcoin, waiting for the first successful quantum attack would obviously be the worst way to discover that the migration began too late.
In brief
- The EBA, ESMA and EIOPA have classified quantum risk among finance’s emerging vulnerabilities.
- A sufficiently powerful computer could weaken certain cryptographic signatures used by blockchains.
- CoinDesk cites CryptoQuant, which estimates that around 6.9 million BTC are more exposed because their public keys are already visible.
- No known quantum computer can currently break Bitcoin in this way.
- The European Union is asking member states to begin their post-quantum migration before the end of 2026.
- High-risk uses must be protected by the end of 2030 at the latest.