Wednesday, September 23, 2026

EU Supervisors Flag Quantum Risk to Blockchain Security

Photorealistic close-up of a glowing private key icon on a sleek wallet with a quantum circuit overlay, newsroom backdrop.

EU Supervisors Flag Quantum Risk to Blockchain Security

European financial supervisors have called for early preparation against quantum-computing risks that could eventually undermine cryptographic systems used across finance and blockchain networks. The warning treats quantum computing as an emerging infrastructure risk rather than an imminent security breach, with regulators emphasizing preparedness before cryptographically relevant machines become available.

In their joint Autumn 2026 risk update, the European Banking Authority, EIOPA and ESMA said advanced quantum computers could undermine cryptographic systems protecting communications, transactions, databases and blockchains. The authorities specifically recommend planning and preparing for quantum risks rather than waiting for commercially viable quantum applications to emerge. The report also notes that information collected today could potentially be decrypted later under a “harvest now, decrypt later” threat model.

Quantum Threat Centers on Existing Cryptography

For cryptocurrencies, the risk depends on the cryptographic primitive and how public keys are exposed. Google Quantum AI estimated in March that a future cryptographically relevant quantum computer could solve the 256-bit elliptic-curve discrete-logarithm problem using fewer than 500,000 physical superconducting qubits under its assumptions. That estimate represented roughly a 20-fold reduction from previous physical-qubit requirements, but Google did not claim such a machine exists today.

The impact would not be identical across every blockchain. Ethereum externally owned accounts currently rely on secp256k1 ECDSA, while Bitcoin uses both ECDSA and Schnorr signatures depending on the output type and spending path. A sufficiently capable quantum system running Shor’s algorithm could threaten elliptic-curve signatures when the relevant public key is available, creating a migration problem for wallets, custodians and protocols rather than an immediate failure of blockchain hashing itself.

Blockchain developers are already exploring different migration strategies. Stellar has outlined a three-stage quantum preparedness plan that targets post-quantum verification in Soroban during 2026 and protocol-level quantum-safe signer support in 2027. Stellar expects technical readiness work to be completed in 2027, while the eventual deprecation of Ed25519 remains dependent on the threat environment and ecosystem readiness.

Bitcoin and Ethereum Map Different Migration Paths

Bitcoin developers are considering a more disruptive approach through draft BIP-361. The proposal would follow deployment of a post-quantum output type and progressively restrict legacy quantum-vulnerable outputs. BIP-361 remains a draft rather than an approved Bitcoin consensus change, but its staged design illustrates how protecting existing holdings could eventually require wallet migrations and consensus-level restrictions. The proposal has been examined in more detail through SatoshiPick’s coverage of potentially vulnerable legacy Bitcoin UTXOs.

Ethereum has meanwhile set a more explicit protocol target. The Ethereum Foundation said this month that its Protocol cluster is aiming for Ethereum L1 to become quantum-resistant across execution, consensus and data by December 2029. The 2029 date is a self-imposed engineering target, not a prediction that a quantum attack will become possible then. Ethereum’s roadmap includes post-quantum keys, signature verification, validator attestations and eventually quantum-safe data commitments. That effort builds on the network’s broader multi-year quantum-resistance roadmap.

Other networks are already moving individual components into production. Algorand recently introduced native quantum-resilient accounts, while NEAR activated ML-DSA-65 account signing on Mainnet. Those deployments provide account-level protection but should not automatically be interpreted as making every protocol layer quantum-resistant.

For European institutions, the regulatory milestone is more immediate than the underlying quantum threat. The ESAs note that DORA already requires financial entities to use state-of-the-art cryptography, while the EU NIS Cooperation Group has recommended that member states adopt post-quantum migration strategies by the end of 2026. The next concrete step is therefore cryptographic inventory and migration planning, not emergency abandonment of existing blockchain systems.

Satoshipick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.