
On October 1, 2026, Europe’s three financial supervisory authorities — the EBA, EIOPA and ESMA — did something crypto has mostly managed to avoid: they put quantum computing on a formal risk agenda. In their Autumn 2026 risk assessment, they warned that advanced quantum machines “could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains,” and that such threats “could materialize earlier than any viable commercial application.”
The same week, the analytics firm Glassnode put a number on the exposure: roughly 6.04 million BTC — about 30.2% of supply, or some $469 billion at the time — sits in addresses whose public keys are already visible on-chain. Those are the coins a sufficiently powerful quantum computer could attack without their owners ever signing a transaction.
This article explains what the EU actually said, why exposed keys matter more than total holdings, how far Google’s research moved the bar, why serious analysts still call the threat distant, and why the hardest part of the problem is not engineering but governance.
Key takeaways
- EU supervisors (EBA, EIOPA, ESMA) flagged quantum risk in their Autumn 2026 assessment, warning of “harvest now, decrypt later” attacks.
- About 6.04 million BTC (~30.2% of supply) sits in addresses whose public keys are already exposed; CryptoQuant’s estimate was roughly 6.9 million BTC.
- Google Quantum AI reduced the estimated physical qubits needed for an elliptic-curve attack by roughly 20x — but no such machine exists today.
- The harder problem is governance: whether to freeze quantum-vulnerable legacy coins, and how to phase out current signature schemes.
- Timelines: EU post-quantum migration strategies by end-2026; Ethereum targets quantum resistance by December 2029; Q-Day estimates run from 2030–2032 and beyond.
What the EU actually said
The warning came from Europe’s three supervisory authorities — banking (EBA), insurance (EIOPA), and securities (ESMA) — acting jointly. Three elements matter:
- The threat is named, not hypothetical. The assessment says quantum machines could undermine cryptography “widely used to secure communications, transactions, databases and blockchains.”
- Timing is inverted. Threats “could materialize earlier than any viable commercial application” — meaning the risk is not when quantum computers become a business, but when they become good enough to break things.
- The attack model is “harvest now, decrypt later.” Data captured today can be decrypted later. For blockchains, the equivalent is already-stored, already-exposed public keys.
In parallel, the EU’s NIS Cooperation Group recommended that member states adopt post-quantum cryptography migration strategies by end-2026, with high-risk use cases protected by 2030. That pairing — a risk warning plus a migration deadline — is what turns quantum from a research topic into a compliance one.
Why exposed public keys matter
Bitcoin is protected by elliptic-curve cryptography (secp256k1). To spend a coin, you prove you hold the private key behind a public key — and the security rests on the assumption that recovering the private key from the public key is infeasible. A large enough quantum computer running Shor’s algorithm would break that assumption.
The subtlety is which public keys are visible. Bitcoin has several output types:
- Older pay-to-public-key (P2PK) outputs and reused addresses expose the public key directly on-chain. They are the most exposed, because an attacker does not need the owner to do anything.
- Modern pay-to-taproot (P2TR) outputs keep the public key hidden behind a hash until the coin is spent, so the key is not exposed in advance.
That distinction is why the exposure figure is smaller than “all Bitcoin,” and larger than most people expect. It is not about how much you hold; it is about whether your key is already public.
The scale of the exposure
Glassnode’s estimate — 6.04 million BTC, ~30.2% of supply, ~$469 billion — is the one European regulators cited. CryptoQuant’s figure was higher, at about 6.9 million BTC (~$586 billion). The gap reflects different measurement bases, not disagreement about the mechanism: both count coins whose public keys are already on-chain, which includes many long-dormant wallets from Bitcoin’s early years.

Google’s research and the falling bar
The reason the threat needs periodic re-pricing is that the engineering bar keeps moving. In 2026, Google Quantum AI published work representing roughly a 20-fold reduction in the physical qubits needed to run Shor’s algorithm against elliptic-curve cryptography. The circuits compiled to under 1,200 logical qubits, with an estimate of running on a superconducting machine with under 500,000 physical qubits in minutes.
Read this carefully. It does not mean a quantum computer can break Bitcoin. No such machine exists, and the error-correction that the estimate assumes remains the central unsolved problem. What it does mean is that the number that has to fall for the threat to become real fell by a factor of twenty — and it can fall again.
The counter-argument
Not everyone reads the trend as urgent. On October 1, Bitcoin Magazine argued there is “no basis” to expect a cryptographically meaningful quantum computer within ten years, pointing out that qubit stability and error rates remain unsolved, and that investment volume is not the same as technical maturity.
VanEck’s research chief, Matthew Sigel, took a middle position: quantum is a genuine long-term risk but not a reason to sell now, and he noted that AI data-center demand could simultaneously raise the value of miners through long-term power contracts. That is a useful reminder that the same forces driving quantum research — massive compute investment — are the forces repricing the mining industry.
The honest synthesis: the mechanism is real, the timeline is uncertain, and both “it’s already over” and “it’s impossible” are positions taken with more confidence than the evidence supports.
Why this is a governance problem
The moment you accept that some keys are exposed, the question stops being cryptographic and becomes political: what do you do about coins whose owners will not, or cannot, migrate to a post-quantum scheme?
That question is already circulating as a proposal. BIP-361 explores restricting quantum-vulnerable outputs, with a recovery mechanism for the coins involved. Separately, Bitcoin developers including Jameson Lopp and five co-authors proposed phasing out current signature schemes to make time for a migration. Ethereum, for its part, targets quantum resistance across its layers by December 2029, and several post-quantum signature schemes are under review — among them P2MR, P2TRv2, SHRINCS, SPHINCS, IBC and ML-DSA.
But proposals surface the hard edge immediately. If vulnerable coins are frozen to protect them, who holds the authority to freeze — and how does that authority avoid becoming the same censorship power that permissionless systems exist to resist? If they are not frozen, an attacker who cracks them keeps them. There is no version of this that is purely technical; every path encodes a decision about who gets to act on behalf of an absent owner.
How a Bitcoin migration would actually work
It helps to see why the technical path is the easy half. Bitcoin has migrated signature and script behavior before — SegWit in 2017, Taproot in 2021 — and both required years of coordination across wallets, exchanges, miners, and node operators. A post-quantum migration is larger in every dimension.
For one thing, post-quantum signature schemes are much bigger than elliptic-curve signatures. Larger signatures and public keys consume more block space, which raises the cost of every transaction that adopts the new scheme — a direct tension with Bitcoin’s block-space constraints. For another, funds would need to move from old, exposed outputs to new, quantum-resistant ones. That is voluntary for cooperative owners and impossible for the dormant ones, which is exactly where the governance fight lands.
So the practical sequence is: agree on a scheme, ship it in a way backward-compatible enough to be a soft fork, give holders years to migrate, and decide separately what to do about coins that never move. Every one of those steps is a coordination problem, and the last one is a values problem.
What this means for holders and builders
For ordinary holders, the guidance is undramatic: the threat is not actionable today, and there is no reason to sell into it. What is worth doing is understanding which of your own coins, if any, sit in old or reused addresses with exposed keys — because those are the ones with a migration deadline attached, whenever that deadline arrives. Modern address types that hide the public key are already a partial mitigation.
For builders, the signal is to plan for cryptographic agility: systems that can swap signature schemes without being rebuilt. That is easier to design in than to retrofit, and the projects that treated quantum as a 2030s problem will pay more to adapt than the ones that treated it as a parameter. The EU’s 2026 recommendation and 2030 high-risk deadline are the clearest external clock anyone has set.
What “quantum-resistant” means in practice
“Post-quantum” does not describe a single algorithm; it describes families of cryptographic schemes believed to resist both classical and quantum attacks. The main candidates fall into a few groups:
- Lattice-based schemes, such as ML-DSA and key-encapsulation schemes like Kyber, which are fast and compact enough for general use and have been standardized by NIST.
- Hash-based schemes, such as SPHINCS+ and the Bitcoin-oriented SHRINCS proposal, whose security rests on the durability of hash functions — a conservative bet, at the cost of larger signatures.
- Code- and multivariate-based schemes, older families that have seen recent refinement and remain under review.
The trade-off for a blockchain is structural. Elliptic-curve signatures are small; post-quantum signatures are orders of magnitude larger, and Bitcoin’s blocks are measured in megabytes. Adopting quantum resistance is therefore not a plug-in swap — it changes the cost of every transaction that uses the new scheme, which is why the choice of scheme is inseparable from the network’s capacity economics.
What to watch
- Whether the EU guidance becomes binding. A 2026 recommendation to adopt post-quantum migration strategies is soft; a rule with dates and audits is not.
- Whether a credible post-quantum signature scheme is adopted for Bitcoin. The technical path matters less than whether the network can agree to take it — a soft-fork coordination problem on a scale Bitcoin has rarely attempted.
- Whether “freeze or let them be” gets answered. How the industry handles the most exposed legacy coins will set the precedent for every future cryptographic migration.
FAQ
Can a quantum computer break Bitcoin today?
No. No quantum computer is close to the scale required to break elliptic-curve cryptography. The concern is about a future machine, and about coins whose public keys are already exposed and would need no action from their owner to be attacked.
What is “harvest now, decrypt later”?
It is the practice of capturing encrypted data today so it can be decrypted once quantum computers are powerful enough. For blockchains, the relevant version is simpler: public keys already stored on-chain cannot be un-published, so today’s exposure is tomorrow’s attack surface.
How much Bitcoin is exposed?
Glassnode estimated about 6.04 million BTC (~30.2% of supply) in addresses with public keys already visible on-chain; CryptoQuant’s figure was roughly 6.9 million BTC. Both count older and reused-address outputs where the key is not hash-protected.
Which coins are most at risk?
Older pay-to-public-key outputs and reused addresses, where the public key is already on-chain. Newer pay-to-taproot outputs keep the key hidden behind a hash until the coin is spent, so they are not exposed in advance.
Is this a Bitcoin-only problem?
No. Every blockchain that relies on elliptic-curve signatures shares the exposure, which is why the EU warning was addressed to “blockchains” generally and why Ethereum has set its own quantum-resistance targets. Bitcoin draws the most attention because of its size and its dormant early coins.
What would a fix look like?
Two layers. Technically, a post-quantum signature scheme (candidates include ML-DSA, SPHINCS, and Bitcoin-specific proposals) adopted through a coordinated upgrade. Governance-wise, a policy for coins whose owners do not migrate — the question BIP-361-style proposals are trying to answer.
Bottom line
The quantum threat to crypto is real in mechanism, uncertain in timing, and — the part most coverage skips — unsolved in governance. About 30% of Bitcoin’s supply sits in addresses whose keys are already exposed, and the engineering bar for an attack fell sharply in 2026. But no attack is possible today, and the harder problem is not building a post-quantum signature scheme; it is agreeing on what to do with the coins that cannot migrate on their own. Watch the EU’s guidance for teeth, Bitcoin’s developers for a signature plan, and the industry for the first real decision about freezing exposed legacy coins — because that decision, not the qubit count, is what will define how this plays out.
Sources
- CoinMarketCap / BSCN — Quantum threat to crypto gets fresh EU warning
- Gate News — EU regulators warn quantum computers could break crypto before commercial use
- KuCoin News — EU financial watchdogs warn quantum computing threatens blockchain encryption
- Digital Today — Quantum computers could neutralise bitcoin? No basis for it within 10 years
- Pluang — VanEck research chief: quantum risk is not a reason to sell Bitcoin






