The Joint Committee of the European Supervisory Authorities (ESAs) — comprising the European Banking Authority, the European Securities and Markets Authority and the European Insurance and Occupational Pensions Authority — has placed quantum computing among the technological risks financial supervisors should be monitoring closely, according to its Autumn 2026 Risk and Vulnerabilities Report, published on Wednesday, September 23.

The report's central warning is one of timing. According to the ESAs, the threat posed by quantum computing to widely used cryptographic systems could materialise even before quantum machines reach viable commercial application, a conclusion that complicates the usual assumption that such risks remain safely distant.

Bitcoin is named specifically as an exposed system. Coins linked to old or reused addresses may have their public keys visible on-chain, a condition that could, in principle, allow a sufficiently powerful quantum machine to derive the corresponding private keys. Once a private key is recovered, control over the associated funds follows.

Scale of the exposure

Research firm Project Eleven has estimated that approximately 6.9 million BTC, worth around USD 586,000 million at current terms, sit in this potentially vulnerable position. That figure represents a substantial share of circulating supply and underlines why the issue has moved from theoretical speculation to a matter regulators are prepared to put in writing.

Addressing the exposure is not simply a matter of software patching. A migration to quantum-resistant signature schemes on the Bitcoin network would require changes accepted collectively by network participants, a coordination challenge that has historically proven slow and contentious in Bitcoin's governance history.

Brussels sets a timeline

The warning from the ESAs lands alongside a broader European Commission digital strategy roadmap on post-quantum cryptography, which urges member states to begin their transition before the end of 2026, with the goal of protecting the highest-risk use cases by 2030. The roadmap is not specific to crypto assets, but it establishes a policy timeline against which the ESAs' warning about Bitcoin now sits.

For European supervisors, the inclusion of quantum computing in a routine risk and vulnerabilities report signals that the issue has moved from the periphery of academic cryptography discussions into the standard monitoring toolkit used to track threats to the financial system. The report gives no indication of a specific timeline for when a capable quantum machine might exist, only that preparations, both at the level of blockchain protocols and broader financial infrastructure, should not wait for that certainty to arrive first.