European financial regulators have raised alarms about the potential risks posed by quantum computing to the cryptographic security of blockchain technology. They caution that advanced quantum computers could compromise the encryption safeguarding about 6.9 million Bitcoins, valued at approximately $586 billion.

This warning, issued by the Joint Committee of the European Supervisory Authorities (ESAs) — which encompasses the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA) — emphasizes the immediate need for Bitcoin to address the vulnerabilities of older addresses. These legacy addresses may have their public keys exposed on the blockchain, making them susceptible to attacks from sufficiently powerful quantum computers.

According to the authorities, "Threats could materialize earlier than any viable commercial application," as noted in their Autumn 2026 Risk and Vulnerabilities report released on Wednesday. The report states that advanced quantum computing capabilities could undermine various cryptographic systems that are critical for securing communications, transactions, databases, and blockchain networks.

While the report does not specify when quantum computing might become commercially viable, a recent IBM study predicts that it could happen within the next four years. The risk is particularly acute for Bitcoin held in older or reused addresses, where public keys might already be visible on the blockchain. A sufficiently advanced quantum computer could potentially derive private keys from these public keys, thereby allowing unauthorized access to the coins.

However, not all dormant wallets face the same level of exposure. Many unspent Bitcoin outputs still obscure their public keys behind cryptographic hashes, which offers some protection for now. In contrast, older outputs, such as pay-to-public-key transactions and reused addresses, have made their public keys available on-chain.

The EU's warning does not imply that a capable quantum computer currently exists. Unlike traditional banking systems, Bitcoin cannot simply update its security protocols. Transitioning to quantum-resistant signatures would necessitate consensus across the entire network, and users of exposed wallets would need to transfer their coins before a quantum attack could be executed.

Additionally, the regulators noted that data collected today could later be decrypted in so-called "harvest now, decrypt later" attacks. The European Commission's roadmap for post-quantum cryptography urges member states to initiate transitions by the end of 2026, with high-risk applications expected to be safeguarded by 2030.