Europe warns of quantum computing risks to Bitcoin and urges early preparations
European financial regulators are stepping up their scrutiny of the potential impact of quantum computing on digital finance, warning that advances in the technology could eventually undermine encryption systems used to protect financial transactions, communications, databases and blockchain networks.
The warning was issued by the Joint Committee of the European Supervisory Authorities, which brings together the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority. In a risk update published on September 23, the authorities highlighted quantum computing as a technology that could bring major opportunities to financial services while also creating new cybersecurity challenges.
The regulators stressed that current quantum computers are not capable of breaking the cryptographic protections used by major blockchain networks such as Bitcoin. The concern is instead focused on the possibility that future machines could become powerful enough to attack cryptographic algorithms that are widely used today, making early preparation important because replacing cryptographic infrastructure across the financial system could take years.
Quantum computing is expected to have potentially useful applications in finance. More powerful quantum systems could eventually assist with complex calculations, portfolio modelling, pricing, fraud detection and compliance processes. However, the same technological advances could create risks if sufficiently capable quantum machines become available before financial institutions and digital-asset networks have completed the transition to quantum-resistant security.
One of the main concerns involves public-key cryptography. In a technical analysis published by ESMA in May, the regulator examined the potential use of Shor’s algorithm to attack cryptographic systems such as RSA and elliptic-curve cryptography. These technologies underpin a wide range of digital security applications and are also relevant to the cryptographic mechanisms used by cryptocurrencies.
Bitcoin relies on digital signatures to demonstrate control over funds and authorize transactions. Its ecosystem uses elliptic-curve cryptography, including ECDSA and Schnorr signatures, although the public key is not always exposed in the same way for every type of Bitcoin output. In several common address formats, a cryptographic hash provides an additional layer between the address and the public key until the funds are spent.
This distinction has become central to discussions about Bitcoin’s theoretical quantum exposure. Some older transaction formats reveal public keys directly, while practices such as address reuse can expose public-key information that was previously hidden. If a future quantum computer could derive a private key from a known public key quickly enough, an attacker could potentially attempt to move funds without the owner’s authorization.
Estimates of the amount of Bitcoin that could be theoretically exposed vary considerably because researchers use different methodologies to classify addresses, transaction outputs and previously revealed public keys. CryptoQuant founder Ki Young Ju estimated in February that approximately 6.89 million BTC could be vulnerable under his methodology, including coins associated with directly exposed public keys and other historical patterns of use.
Glassnode published a different assessment in May, estimating that about 6.04 million BTC had some form of public-key exposure while remaining dormant. The company estimated that approximately 1.92 million BTC fell into a category of structural exposure, including older Pay-to-Public-Key outputs and other transaction structures in which public-key information is available.
These figures should not be interpreted as an estimate of Bitcoin that could be stolen today. They describe theoretical exposure under a future scenario in which quantum computers reach a level capable of defeating current cryptographic protections. The timing of a potential attack would also be critical because an attacker would need to obtain the necessary information and derive a private key quickly enough to exploit it.
Bitcoin developers and researchers have therefore been examining possible approaches to reducing long-term quantum risks. Among the proposals is BIP-360, a draft Bitcoin Improvement Proposal that explores Pay-to-Merkle-Root outputs as a way of reducing some risks associated with long-term exposure of elliptic-curve public keys.
Another proposal, BIP-361, focuses more directly on the transition process. It outlines a possible framework for gradually restricting the movement of coins associated with cryptographic outputs considered vulnerable before introducing stricter measures affecting older ECDSA- and Schnorr-based signatures.
Neither BIP-360 nor BIP-361 is currently an active consensus rule on the Bitcoin network. Both remain proposals under discussion, meaning their technical specifications and any eventual transition mechanism could still change. A future migration to post-quantum signatures would also require broad coordination among developers, miners, exchanges, wallet providers, custodians and users.
The wider financial sector faces a similar challenge. Banks, insurers, payment companies and other institutions operate large infrastructures based on cryptographic standards that cannot be replaced instantly. The European regulators’ warning therefore reflects a broader debate over post-quantum cryptography and the need to identify vulnerable systems before quantum technology reaches a stage where attacks become practically feasible.
For Bitcoin, the issue is consequently less about an immediate security breach than about technological preparedness. The network has been designed to evolve through changes in its software and transaction standards, but any major cryptographic transition would have to balance security requirements with compatibility, user protection and the continuity of a global decentralized system.
Quantum computing remains at an early stage, and there is no established timetable for machines capable of breaking Bitcoin’s current cryptographic safeguards. Nevertheless, European regulators argue that the long lead time required to modernize critical digital infrastructure makes preparation a present-day issue, rather than a problem that can safely be addressed only once a quantum threat becomes operational.
-
21:00
-
20:35
-
20:15
-
19:58
-
19:41
-
19:25
-
19:10
-
18:47
-
18:32
-
18:15
-
18:00
-
17:42
-
17:25
-
17:10
-
16:47
-
16:31
-
16:15
-
16:00
-
15:42
-
15:27
-
15:21
-
15:05
-
14:45
-
14:30
-
14:14
-
13:58
-
13:41
-
13:25
-
13:10
-
12:47
-
12:32
-
12:15
-
12:00
-
11:42
-
11:25
-
11:11
-
10:47
-
10:32
-
10:15
-
10:00
-
09:42
-
09:21
-
09:05
-
08:45
-
08:30
-
08:14