The Joint Committee of European Supervisory Authorities published on Wednesday, September 24, 2026, a report warning that future quantum computers could compromise the cryptography protecting blockchains. The stakes are significant: roughly 6.9 million bitcoins, worth close to $586 billion, are currently exposed to this risk because their public keys have already been revealed on-chain.
🔑 Key takeaways
- The Joint Committee of the ESAs (EBA, ESMA, EIOPA) issued a quantum warning in its Autumn 2026 report
- Roughly 6.9M BTC (~$586B) are vulnerable due to already-exposed public keys
- IBM estimates a viable quantum computer could emerge within 4 years or less
- The Ethereum Foundation targets a quantum-resistant network by December 2029
- Jameson Lopp proposed a post-quantum migration plan for Bitcoin in February 2026
The joint report from European supervisors
The document, titled Autumn 2026 Risk and Vulnerabilities Report, was issued by the Joint Committee of the European Supervisory Authorities (ESAs), a body that brings together three major regulators: the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA). The structure usually publishes analyses on financial stability, credit risk or banking liquidity. Including quantum risk for blockchains marks a turning point in how the European Union approaches the resilience of the crypto ecosystem.
Three authorities, one voice
The convergence of the three supervisors on this topic is notable. Each authority oversees a distinct segment of the financial system — banks, markets, insurers — and their joint front suggests the threat is viewed as cross-sector. The report explicitly cites blockchains among the infrastructures potentially affected, alongside communications systems, traditional banking transactions, and databases.
« Threats could materialize earlier than any viable commercial application. »
Autumn 2026 Report, Joint Committee of the ESAs
An alert qualified as systemic
The report does not merely raise a niche risk: it notes that a sufficiently advanced quantum computer could undermine « some cryptography systems widely used to secure communications, transactions, databases and blockchains. » No machine capable of executing such an attack exists today, but the authorities insist on the need for proactive preparation, arguing that the transition window will be shorter than sector participants currently anticipate.
Bitcoin: 6.9 million BTC exposed
According to data compiled by CryptoQuant and relayed by several outlets, approximately 6.9 million bitcoins are currently considered theoretically vulnerable to a quantum attack. At a reference price near $85,000, this represents roughly $586 billion, or close to one-third of the total BTC supply in circulation.
The vulnerability, however, is not uniform across the network. It concentrates on addresses whose public key has already been revealed on the blockchain — the case of legacy pay-to-public-key (P2PK) outputs or reused addresses. A quantum computer running Shor’s algorithm could, from that public key, derive the corresponding private key and seize the funds.
| Bitcoin address type | Public key exposed | Quantum risk level |
|---|---|---|
| Legacy P2PK (Satoshi-era) | Yes | High |
| Reused address (P2PKH) | Yes (after first spend) | High |
| Unreused P2PKH address | No (hidden behind hash) | Moderate |
| SegWit / Taproot (P2WPKH, P2TR) | No until spent | Low to moderate |
Many unspent outputs still hide their public key behind a cryptographic hash — notably SegWit and Taproot addresses that have never been spent — and therefore remain less exposed in the short term. This asymmetry explains why the risk is primarily concentrated in certain historical UTXOs, a portion of which is attributed to early miners and Satoshi Nakamoto himself.
Timeline: the preparation window narrows
The ESAs’ report does not provide a precise timeline for the commercial viability of quantum computing, but several converging elements point to a near-term horizon. IBM recently indicated, in a communication picked up by specialized media, that the technology could become operational within four years or less. In parallel, researchers at Google Quantum AI published in March 2026 a revised assessment estimating that the number of physical qubits required to break the cryptographic systems used by many cryptocurrencies could be divided by roughly twenty compared with previous estimates.
IBM and Google Quantum AI
While not definitive, these two contributions are enough to shift the debate. Specialists historically considered the deadline to be measured in decades. Numbers like « four years » change the equation dramatically for networks whose cryptographic migration requires years of coordination, testing and deployment. By way of comparison, Bitcoin’s move to SegWit took nearly two years from proposal to broad activation.
The « harvest now, decrypt later » scenario
The European authorities also highlight a risk described as harvest now, decrypt later. In this scenario, state or private actors collect large volumes of encrypted data today, waiting for the day they have the compute power to decrypt it. For blockchains, this means that the full transaction history — including associated encrypted off-chain communications — is already being archived by some actors, creating a potential retroactive vulnerability.
Technical responses: between roadmap and consensus
No solution is currently deployed at scale on major networks. The situation differs materially due to distinct governance mechanisms. For Bitcoin, any change to the cryptographic scheme — signature algorithm or address format — requires network-wide consensus, which is difficult to reach without a long transition period.
Jameson Lopp’s plan for Bitcoin
Developer Jameson Lopp, together with five other core developers, proposed in February 2026 a detailed plan to phase out the current signature method (ECDSA on the secp256k1 curve) and introduce a post-quantum scheme. The draft notably provides for restricting, five years after activation, the ability to spend funds whose UTXOs have not migrated to the new format. The proposal has not yet been adopted and, at this stage, no widely supported formal BIP has emerged.
The Ethereum Foundation’s roadmap
On the Ethereum side, the Ethereum Foundation has communicated a more structured timeline. The organization aims to make the entire network — execution layer, consensus layer, and data layer — quantum-resistant by December 2029. This roadmap builds on ETHResearch work around hash-based signatures (STARK, Lamport) and on NIST (National Institute of Standards and Technology) standardization tracks. Ethereum’s programmability and the relative flexibility of its hard-fork cycle constitute a clear advantage over Bitcoin on this specific front.
« No machine capable of executing such attacks exists today, but the technical timeline of a cryptographic migration far exceeds the political timeline of a decision. »
Crypto analyst, 2026 sector note
Conclusion
The European authorities’ warning should be read as a signal of institutional maturity: regulators no longer limit themselves to monitoring MiCA compliance or anti-money laundering efforts — they are now anticipating long-term structural risks. For Bitcoin, the issue is less technological than coordinative: the question is not whether a post-quantum migration is feasible, but whether it will be completed before the window of opportunity closes.
The most likely scenario over the next twelve to twenty-four months combines intensified research on hybrid signatures, increased regulatory pressure — notably through the European Commission’s post-quantum roadmap, which mandates a transition by the end of 2026 for high-risk use cases — and a gradual awakening among institutional holders of exposed bitcoins. The market remains little reactive for now, but the preparation window is now counted in years, not decades.
Sources
This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

