On September 23, 2026, the Joint Committee of Europe's three financial regulators — the EBA, ESMA, and EIOPA — added quantum computing to the official systemic risk register for financial markets. The warning states that cryptographic threats "could materialise faster than any commercially viable...
"I know people don't like this proposal. I don't like it either. But I wrote it because I dislike the alternative even more." — Jameson Lopp, Bitcoin developer and co-author of BIP-361
On September 23, 2026, the Joint Committee of Europe's three financial regulators — the EBA, ESMA, and EIOPA — added quantum computing to the official systemic risk register for financial markets. The warning states that cryptographic threats "could materialise faster than any commercially viable application" of quantum technology. Five days earlier, the G7 Cybersecurity Working Group published "Preparing for the Post-Quantum Era: A Call to Action," urging governments and organizations to begin migration to post-quantum cryptography (PQC) immediately.
The regulatory pressure arrives as technical estimates have tightened sharply. Google Quantum AI's March 2026 paper reduced the estimated qubit requirement to break Bitcoin's secp256k1 elliptic curve from millions of physical qubits to fewer than 500,000 — a 20x reduction from prior estimates. On superconducting architectures with 10⁻³ error rates, the estimated runtime to derive a private key from an exposed public key is approximately nine minutes. Meanwhile, leading quantum hardware has reached 1,386 qubits (IBM Kookaburra), with five organizations demonstrating verified logical qubits: QuEra (96), Quantinuum (48), Atom Computing (24), Google (1), and Nord Quantique (1).
The gap between current capability and the cryptographic break threshold remains large. But the direction of travel — hardware scaling faster than expected, resource estimates shrinking, regulators moving first — has forced Bitcoin, Ethereum, and Solana into concurrent migration planning, each with distinct engineering tradeoffs.
Bitcoin, Ethereum, and most proof-of-stake chains rely on elliptic-curve cryptography (ECC) — specifically the secp256k1 curve — for transaction signing. A sufficiently powerful quantum computer running Shor's algorithm can derive private keys from public keys in polynomial time, rendering ECC-based signatures worthless.
The operative question is not whether quantum computers will break ECC. The mathematical proof exists. The question is when hardware will be sufficient to execute the attack.
Current hardware state (as of September 2026):
| Organization | Physical Qubits | Logical Qubits | Architecture | |---|---|---|---| | IBM (Kookaburra) | 1,386 (4,158 multi-chip) | — | Superconducting | | Atom Computing | 1,225 | 24 | Neutral atom | | Google (Willow) | 1,000 | 1 | Superconducting | | QuEra | 448 | 96 | Neutral atom | | Quantinuum | 98 | 48 | Trapped ion |
Required to break secp256k1 (Google Quantum AI, March 2026):
The gap between current hardware (~1,400 physical qubits) and the attack threshold (~500,000) is roughly 350x. However, the Google paper — co-authored with Ethereum Foundation and Stanford University researchers — cut the previous resource estimate by 20x. According to Quantum Computing Report analysis, if hardware scaling continues at its current trajectory and resource estimates continue to shrink, the intersection point falls within 7–12 years.
The more immediate risk is the "harvest now, decrypt later" attack vector identified by ESMA: adversaries can record blockchain transactions today — all of which are publicly visible — and retroactively derive private keys once quantum capability matures. Approximately 6.9 million BTC ($586 billion at current prices) held in older pay-to-public-key (P2PK) and reused addresses have public keys already exposed on-chain, making them targets for future quantum attack without requiring real-time interception.
Three overlapping regulatory timelines now govern post-quantum migration:
NIST Standards (August 2024): FIPS 203, 204, and 205 established the first finalized PQC standards — CRYSTALS-KYBER for key encapsulation, CRYSTALS-Dilithium for digital signatures, and SPHINCS+ for hash-based signatures. NIST plans to deprecate RSA and ECC at the 112-bit security level by January 2030 and disallow all RSA and ECC variants by 2035.
EU Coordinated Roadmap (June 2025, enforced 2026): The European Commission mandates all member states initiate PQC transition by end of 2026. High-risk scenarios — which regulators have indicated include digital-asset custody — must complete migration by end of 2030.
G7 Call to Action (September 3, 2026): The G7 Cybersecurity Working Group document categorizes quantum computing as a significant cybersecurity risk requiring advance preparation. While not explicitly mentioning cryptocurrencies, the call encompasses all systems relying on ECC and RSA.
For digital-asset custodians, exchanges, and institutional holders, these timelines create compliance obligations independent of when quantum hardware actually reaches attack capability. Enterprise platforms that have not completed PQC migration by 2030 face potential invalidation of digital-asset signature chains under future regulatory frameworks, according to analysis by Ancilar.
Bitcoin's response to the quantum threat centers on two proposals that together represent the most contentious governance challenge since the block-size wars.
BIP-360 (merged February 11, 2026): Introduces Pay-to-Merkle-Root (P2MR), a new SegWit version 2 output type. P2MR operates with nearly the same functionality as Taproot (P2TR) but removes the key-path spend — the component most vulnerable to quantum attack. Public keys remain off-chain until spending, shrinking the attack surface for new coins. A P2MR control block is 1 + 32m bytes (where m is Merkle tree depth) versus P2TR's 33 + 32m bytes. The size increase over standard P2TR key-path spends is modest relative to the post-quantum signature schemes it enables.
BIP-361 (draft, April 2026): Authored by Jameson Lopp and five co-authors including Pierre-Luc Dallaire-Demers and Christian Papathanasiou, BIP-361 proposes a structured sunset of all legacy signature types across three phases:
The most controversial element: approximately 1.7 million BTC in P2PK addresses — including roughly 1.1 million BTC attributed to Satoshi Nakamoto, valued at approximately $74 billion — would be frozen if their holders do not migrate. As of March 2026, more than 34% of all bitcoin (6.5–6.9 million BTC) has exposed public keys on-chain.
BIP-361 remains a draft with no activation parameters or signaling mechanism defined. Bitcoin's decentralized governance requires broad consensus among miners, node operators, and developers — a process that historically takes years for uncontroversial changes. The quantum migration is not uncontroversial.
Governance risk: Bitcoin cannot patch this vulnerability the way a centralized system updates its software. The migration requires holders to actively move their coins to new address types — a coordination problem with no precedent at this scale.
Ethereum's approach differs architecturally. Rather than a single protocol-wide migration, Ethereum plans to use account abstraction to provide "signature agility" — allowing individual accounts to switch signature schemes independently.
EIP-8141 (targeting Hegotá hard fork, H2 2026–2027): Vitalik Buterin described EIP-8141 on February 28, 2026 as "an omnibus that wraps up and solves every remaining problem that AA was facing" since 2016. Once live, any externally-owned account gains the ability to use multisig approval, key rotation, quantum-resistant signatures, batched transactions, and alternative gas payment methods.
Four vulnerable cryptographic layers (per Buterin's February 2026 roadmap):
Ethereum's target for infrastructure-level quantum resistance is 2029. The account-abstraction path means individual users can migrate to post-quantum signature schemes (e.g., CRYSTALS-Dilithium or SPHINCS+) without waiting for the entire network to upgrade.
Advantage: Opt-in migration reduces coordination overhead. Users and applications can migrate on their own timeline once EIP-8141 is live.
Risk: The rollup ecosystem introduces additional attack surface. Solana co-founder Anatoly Yakovenko has publicly questioned whether Ethereum's Layer 2 solutions may face quantum risk that the L1 migration plan does not address. If rollup proving systems rely on ECC-based cryptography, their security guarantees degrade independently of mainnet upgrades.
Solana's quantum migration reveals the starkest engineering tradeoff among the three chains. The Solana Foundation identified the Falcon signature scheme (NIST candidate for FIPS 206) as its preferred PQC standard, with core developer teams Anza and Firedancer independently building implementations.
The throughput problem: Early testing shows quantum-safe signatures are up to 40x larger than current ECC signatures and made the network approximately 90% slower. For a chain that processes thousands of transactions per second and markets sub-second finality, a 90% throughput reduction is not viable in production.
Proposed mitigation: Solana is exploring off-chain verification to maintain mainnet speed — effectively moving PQC signature verification off the critical path. This preserves performance but introduces new trust assumptions about the off-chain verification layer.
Existing partial solution: The Winternitz Vault, already available on Solana, uses hash-based, quantum-resistant signatures that do not rely on elliptic-curve cryptography. However, this is a specialized tool, not a network-wide migration path.
Speed advantage: Solana's high throughput means a network-wide migration could theoretically execute in hours or days, versus the multi-year coordination required for Bitcoin. The centralized foundation structure also allows faster decision-making on upgrade parameters.
| Dimension | Bitcoin | Ethereum | Solana | |---|---|---|---| | PQC proposal | BIP-360 (P2MR) + BIP-361 (migration/sunset) | EIP-8141 (account abstraction) | Falcon signatures + off-chain verification | | Status | BIP-360 merged; BIP-361 draft | EIP-8141 targeting Hegotá fork | Early implementation, testing phase | | Migration model | Mandatory (Phase B freezes non-migrated coins) | Opt-in (account-level signature agility) | Network upgrade (foundation-directed) | | Exposed value at risk | $586B (6.9M BTC with exposed public keys) | Not quantified; 4 cryptographic layers vulnerable | Not quantified; 40x signature size increase | | Performance impact | Modest (P2MR slightly larger than P2TR) | Minimal (abstraction layer absorbs complexity) | Severe (90% throughput reduction in early tests) | | Governance model | Decentralized consensus (multi-year process) | Core dev + community (Hegotá fork timeline) | Foundation-directed (faster execution) | | Target completion | ~7 years post-activation (no activation date set) | 2029 | No firm timeline published | | Satoshi coins risk | ~1.1M BTC ($74B) frozen if no migration | N/A | N/A |
The EU's Joint Committee of financial regulators added quantum computing to the systemic risk register on September 23, 2026, stating threats "could materialise faster than any commercially viable application." The G7 issued a parallel call to action on September 3.
Google Quantum AI's March 2026 paper reduced the estimated qubit requirement to break Bitcoin's secp256k1 curve by 20x, from millions to fewer than 500,000 physical qubits. Current hardware stands at ~1,400 physical qubits — a 350x gap, but one that is narrowing.
NIST will deprecate ECC by 2030 and disallow it by 2035. The EU mandates member states begin PQC transition by end of 2026. Digital-asset custodians face compliance deadlines independent of when quantum attack capability actually arrives.
Bitcoin's BIP-360 (merged) and BIP-361 (draft) propose the most aggressive migration path: mandatory address migration with a coin-freeze mechanism that would affect ~6.9 million BTC ($586B), including Satoshi's estimated holdings.
Ethereum's EIP-8141 account-abstraction approach allows opt-in, account-level migration to PQC signatures, with a 2029 target — but leaves rollup-layer quantum exposure unaddressed.
Solana faces a 90% throughput reduction with current PQC implementations but can execute network-wide upgrades in hours. The tradeoff between security and speed remains unresolved.
No major blockchain has activated a post-quantum upgrade in production. All three are in planning or draft stages. The regulatory clock is now ticking faster than the engineering timelines.
The post-quantum migration challenge is not a future hypothetical. It is a present compliance and engineering problem with regulatory deadlines attached. The EU, NIST, and G7 have all established timelines that will affect digital-asset custody, institutional participation, and protocol-level architecture within the next 3–4 years.
Each chain's migration path reflects its architectural DNA. Bitcoin's decentralized governance produces the most technically thorough proposal (BIP-360/361) but also the slowest activation timeline and the highest political cost — freezing Satoshi's coins is an existential governance question, not just a technical one. Ethereum leverages its account-abstraction roadmap to offer the smoothest user-facing migration but has not yet addressed the quantum exposure across its rollup stack. Solana can move fastest organizationally but must solve a fundamental performance problem first.
The data points in one direction: the timeline to quantum capability is compressing while migration timelines remain measured in years. The gap between those two curves is the risk.