European financial watchdogs warned that quantum computers could eventually undermine cryptography protecting blockchains, putting about 6.9 million Bitcoin, worth roughly $586 billion, at risk. The authorities said the threat could emerge before quantum computing has a viable commercial application, but did not say such a computer exists today.
Why it matters
The risk is concentrated in older or reused Bitcoin addresses where public keys are already visible onchain. A sufficiently powerful quantum computer could use an exposed public key to derive its private key and take control of the coins. Many unspent outputs still conceal public keys behind a cryptographic hash and are less exposed for now.
The warning came from the Joint Committee of the European Supervisory Authorities, which includes the EBA, ESMA and EIOPA. It also points to the “harvest now, decrypt later” risk: information collected today could potentially be decrypted in the future. The European Commission has called for member states to begin post-quantum transitions by the end of 2026, with high-risk use cases protected by 2030.
Market impact
Bitcoin cannot change its security rules through a unilateral update. Moving to quantum-resistant signatures would require networkwide consensus, while holders of exposed coins would need to transfer them before a potential attack became possible. That makes coordination around legacy wallets a central challenge in any future upgrade.
The warning raises the urgency of Bitcoin’s post-quantum debate, but it is not evidence of an immediate ability to break the network’s cryptography. The key issues are the pace of quantum advances, how upgrades could be agreed, and what happens to exposed coins that are not moved.
Frequently asked questions
-
How much Bitcoin could be vulnerable to a future quantum attack?
The warning cites about 6.9 million BTC, worth roughly $586 billion, as potentially at risk.
-
Why are older or reused Bitcoin addresses more exposed?
Their public keys may already be visible onchain. A sufficiently powerful quantum computer could use an exposed public key to derive its private key.
-
Are all unspent Bitcoin outputs equally vulnerable?
No. Many unspent outputs still conceal public keys behind a cryptographic hash and are less exposed for now.
-
Does the warning mean quantum computers can break Bitcoin today?
No. The watchdogs warned about a possible future threat and did not say that a computer capable of breaking Bitcoin's cryptography exists today.
-
What would Bitcoin need to do to adopt quantum-resistant security?
A move to quantum-resistant signatures would require networkwide consensus, and holders of exposed coins would need to transfer them.
CoinDesk