The Joint Committee of the European Supervisory Authorities, which brings together the European Banking Authority, European Securities and Markets Authority and European Insurance and Occupational Pensions Authority, identified quantum computing as an emerging risk in its Autumn 2026 assessment of the European financial system.
“Threats could materialize earlier than any viable commercial application,” the authorities said. A sufficiently advanced quantum computer “could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains.”
The warning does not mean computers capable of breaking Bitcoin’s cryptography exist today. The concern is that migration to quantum-resistant systems can take years, while progress in quantum hardware and algorithms could shorten the time available to prepare.
The European Commission has already called on EU member states to begin transitioning toward post-quantum cryptography by the end of 2026, with high-risk use cases expected to receive protection by 2030.
Why Are 6.9 Million Bitcoin More Exposed?
The risk is not distributed evenly across Bitcoin. An estimated 6.9 million BTC sit in addresses where public keys are already exposed, potentially making those coins more vulnerable if a cryptographically capable quantum computer emerges.
Bitcoin relies on public-key cryptography to prove that the holder of a private key has authority to spend coins. With many newer unspent outputs, the public key remains hidden behind a cryptographic hash until the bitcoin is spent. That provides an additional layer an attacker would first need to overcome.
Older pay-to-public-key outputs and addresses that have already been reused are different. Their public keys can already be visible onchain. A powerful enough quantum computer running an algorithm capable of attacking elliptic-curve cryptography could theoretically calculate the corresponding private key and spend the funds.
That makes Satoshi-era wallets particularly important. Some of Bitcoin’s oldest holdings have remained untouched for more than a decade, creating a difficult question over what should happen if their owners do not migrate before quantum attacks become practical.
Investor Takeaway
Quantum computing is not an immediate Bitcoin-breaking event. The market risk is the migration problem: millions of BTC may need protection before an attack becomes technically possible, while the network still has to agree on what happens to vulnerable coins that never move.
Should Bitcoin Freeze Vulnerable Coins?
That question has turned quantum security from an engineering problem into a governance dispute. Bitcoin developers could introduce quantum-resistant signature methods, but holders would still need a way to migrate existing coins into safer addresses.
The harder issue concerns coins that remain behind. One approach would prevent vulnerable legacy outputs from being spent after a transition period, effectively protecting them from a quantum attacker but also freezing coins belonging to legitimate holders who failed to migrate.
The debate has already produced proposals such as BIP-361, which explores restrictions on quantum-vulnerable Bitcoin while attempting to create a recovery mechanism for legitimate owners.
The issue becomes especially sensitive around Satoshi Nakamoto’s dormant holdings. Freezing them could be viewed as necessary protection against theft, while leaving them spendable could eventually allow whoever develops sufficient quantum capacity first to claim coins that may have been untouched since Bitcoin’s earliest years. The possibility has already divided Bitcoin investors and developers over whether vulnerable Satoshi-era coins should ever be frozen.
For now, the threat is about preparation rather than an imminent attack. Bitcoin’s network is still functioning under its existing cryptographic assumptions, and the European authorities did not claim that current quantum systems can break Bitcoin keys.
The longer-term risk is that the network waits too long to agree on migration rules. Unlike a bank or technology company that can centrally replace an encryption system, Bitcoin requires developers, miners, businesses, exchanges and users to coordinate around protocol changes.
Research is already examining ways to reduce that migration burden, including post-quantum wallet designs intended to protect existing address structures. None removes the need for broad agreement over how Bitcoin should treat older exposed coins.
That makes quantum progress relevant to BTC investors well before anyone can use a quantum computer to steal bitcoin. Hardware milestones, post-quantum Bitcoin proposals and the treatment of legacy addresses could increasingly influence expectations over how much of Bitcoin’s supply remains securely spendable in a post-quantum world.