Europe's three financial supervisory authorities have added quantum computing to their list of emerging risks to the financial system, citing exposure within Bitcoin's own network as one of the clearest examples of what is at stake. The European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority made the assessment in their Joint Committee Update on Risks and Vulnerabilities, Autumn 2026.

The regulators point to estimates, drawn from data by CryptoQuant and Project Eleven, that around 6.9 million BTC, roughly 34% of circulating supply and worth about $586 billion at the exchange rate used in the study, sit in addresses where the public key has already been exposed on-chain. Of that total, about 1.7 million BTC remain in old Pay-to-Public-Key outputs, a legacy format that reveals the public key permanently.

Why some coins are more exposed than others

The vulnerability depends on transaction type. P2PK and Taproot's P2TR both display the public key on-chain at all times, whereas P2PKH and P2WPKH formats mask the public key until the coins are spent, offering a narrower window of exposure. Bitcoin relies on two signature schemes, ECDSA for older address formats and Schnorr for Taproot, but both are built on the same elliptic curve, secp256k1, meaning neither scheme would be inherently safer against a sufficiently capable quantum computer.

That theoretical threat moved closer in March 2026, when Google Quantum AI researchers lowered their estimate of the hardware required to break a 256-bit elliptic curve key of the kind Bitcoin uses. Under some technical assumptions, the researchers put the requirement at fewer than 1,200 logical qubits and fewer than 500,000 physical qubits, with the calculation itself, breaking the curve, taking only a few minutes once such a machine existed. No machine with those capabilities currently exists.

Bitcoin's own response

Developers have two draft proposals in circulation to address the risk. BIP-360 introduces a new output type called Pay-to-Merkle-Root, though it remains at draft stage and does not itself deploy post-quantum signature algorithms. BIP-361, authored by Jameson Lopp along with five co-authors, lays out a phased migration: an initial phase would limit the ability to send funds to vulnerable address formats, followed roughly two years later by tighter network-level conditions on spending bitcoin secured with ECDSA or Schnorr signatures. The proposal also includes recovery procedures for funds that are not migrated in time, relying on information unknown to a quantum attacker, such as data derived from deterministic wallets.

Outside Bitcoin, the US National Institute of Standards and Technology has already standardized three families of post-quantum algorithms and intends to phase classical, quantum-vulnerable signatures out of its standards by 2035.

The practical distance between today's hardware and a working attack was underlined by a bounty run by Project Eleven, which awarded a reward of 1 BTC to researcher Giancarlo Lelli after he broke an experimental elliptic curve key of just 15 bits. Bitcoin's actual keys use 256 bits, a gap that remains, for now, the main line of defence.