EU Supervisors Flag Quantum Risk to Blockchains in Autumn Report

Europe's three financial supervisors put quantum computing in their autumn risk report on Wednesday, and blockchains are named in the sentence that matters. An advanced quantum computer, the document says, "could undermine some cryptography systems widely used to secure communications, transactions, databases and blockchains." No machine capable of that exists today. The committee's argument is about timing: the danger could arrive before quantum computing becomes commercially useful for anything else.
What the document is
It is JC 2026 29, the Joint Committee update on risks and vulnerabilities in the EU financial system, autumn 2026 edition. The joint committee is the European Banking Authority, ESMA and the European Insurance and Occupational Pensions Authority acting as one body. The PDF carries 23 September. Cointelegraph wrote it up at 12:22 UTC that day, CoinDesk and crypto.news on Thursday morning, and the filing dates across the three do not line up, so the date on the document is the one worth holding to.
The mechanism is narrow and well understood. A sufficiently advanced machine could derive a private key from a public key that has already been exposed onchain, then sign transactions with it. The report pairs that with what cryptographers call harvest now, decrypt later: "Currently-gathered information could be decrypted in the future." It also gives quantum computing a second column, listing pricing, simulation and fraud detection as medium-term benefits to the sector.
Nobody agrees how much bitcoin is exposed
CoinDesk puts it at 6.9 million BTC and around $586 billion, naming no dashboard for either figure. crypto.news carries a different set: 6.89 million BTC from CryptoQuant founder Ki Young Ju in February, of which 1.91 million sit in addresses with directly visible public keys, against Glassnode's May count of 6.04 million exposed at rest and 1.92 million structurally exposed. The totals are close, the classifications are not, and the two accounts do not reconcile. Only crypto.news itemises anything, and the dollar value rests on CoinDesk alone.
The clock Brussels has already started
The report notes that the EU NIS Cooperation Group told member states to adopt a post-quantum migration strategy by the end of 2026, with high-risk uses expected to finish by 2030. It also points at DORA, the EU's operational resilience rulebook, which obliges supervised firms to keep cryptography current against new threats. Neither instrument sets a date for crypto-asset service providers specifically. The estimates that set the pace keep moving, and Google Quantum AI's March finding that the attack needs about 20 times fewer qubits than previously thought is the reason this has climbed the agenda at all.
Chains cannot be told to migrate
A regulator can set a deadline for a bank. A permissionless network has to agree with itself. Changing Bitcoin's signature scheme takes network-wide consensus, and holders sitting on exposed keys would have to move their coins before any of it helps. Jameson Lopp and five co-authors proposed in February phasing out today's signatures, with a five-year restriction on funds left unmigrated after activation; it has not been adopted. Ethereum's developers are working to a December 2029 target across execution, consensus and data layers, the thread that produced a draft allowing 8,192-byte validator keys.
The same report flags frontier AI models that "can find and exploit software weaknesses very quickly and easily," alongside ENISA's count of more than 48,000 new vulnerabilities in 2025, up 22% on the year. What it does not do is name the Bitcoin proposal, set an inventory deadline for exposed cryptography, or say what supervisors will ask firms for first.
Read also: Ripple Sets Out a Four-Stage Path to a Quantum-Safe XRP Ledger