← All stories
🔐

EU and crypto stakeholders preparing for quantum risks

European supervisors — the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority — warned in a joint autumn risk update that advances in quantum computing could weaken the cryptography securing transactions, communications, databases and blockchains. They highlighted the “harvest now, decrypt later” threat, urging preparation because encrypted material gathered today might be decipherable in the future. The EU’s recommendation calls for member states to begin post‑quantum migration by the end of 2026 and to protect high‑risk uses no later than the end of 2030.

The warnings referenced technical work from Google Quantum AI, which estimated that breaking much of the cryptography used by cryptocurrencies could require roughly 20 times fewer physical qubits than older estimates. At the same time, authorities and industry observers stressed that no machine capable of such an attack exists today and that practical quantum attacks remain beyond current NISQ devices. IBM has similarly suggested that fault‑tolerant systems could approach cryptographic relevance by the end of the decade, but has not claimed a present‑day breaking machine.

For blockchain assets, exposure is already measurable and depends on methodology. CryptoQuant founder Ki Young Ju estimated about 6.89 million BTC face potential quantum exposure under his approach. Glassnode produced a different calculation in May, measuring 6.04 million BTC, or 30.2% of issued supply, as having public‑key exposure at rest; within that total it identified 1.92 million BTC as structurally exposed because certain output types reveal public keys by design. That Bitcoin‑specific risk arises because some address formats, reused addresses or early output types expose public keys onchain, allowing a future quantum attacker to attempt key derivation without an additional transaction.

Developers have proposed technical and policy responses but have not reached consensus. BIP‑360 (Pay‑to‑Merkle‑Root outputs) and BIP‑361 (migration policy) are listed as drafts in the official Bitcoin Improvement Proposal repository and would limit long‑exposure outputs and eventually tighten rules on ECDSA and Schnorr signatures, but neither is activated. The reports note that migration involves not only choosing post‑quantum algorithms but coordinating node operators, miners, wallets, custodians and exchanges. Institutional custodians have begun preparing: Coinbase is designing post‑quantum Bitcoin custody able to support multiple potential signature schemes, and Ledger’s CTO has warned migration may take years because changing wallets, custody systems and existing holdings is operationally complex.

This summary is composed by the cFlash AI editor from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources