Loading prices…
STKR NewsSTKR News0 of 3 free this month
Future Tech

EU watchdogs warn quantum computers could pick crypto’s locks

European regulators are sounding the alarm on quantum threats to blockchain security, forcing founders to choose between proactive migration and systemic vulnerability.

Originally on Cointelegraph →
AB

Adrian Boysel

Contributor

Sep 23, 2026

4 min read

Photo illustration / STKR News

The Clock is Ticking on Elliptic Curve Cryptography

European Union financial regulators have finally decided to weigh in on a topic that has been a mainstay of technical forums for a decade: the quantum threat to blockchain security. The European Supervisory Authorities recently released a report suggesting that the arrival of commercially viable quantum computers could effectively pick the digital locks that keep billions of dollars in assets secure. For builders, this isn't just another regulatory headache; it is a fundamental shift in how we think about the longevity of the code we write today.

Most blockchains, including the two heavyweights, Bitcoin and Ethereum, rely on cryptographic standards like Elliptic Curve Cryptography (ECC) or the Elliptic Curve Digital Signature Algorithm (ECDSA). These systems are incredibly secure against traditional computers because solving the mathematical problems behind them would take a standard machine thousands of years. However, quantum computers operate on different physics. Algorithms designed specifically for these machines could theoretically crack these signatures in minutes or even seconds.

The European Warning Shot

The EU’s assessment isn't just about fear-mongering; it’s a push for what they call "crypto-agility." The regulators are concerned that if a breakthrough in quantum hardware happens suddenly, the fragmented and slow-moving nature of decentralized governance won't be able to pivot fast enough. They are looking at this through the lens of systemic financial risk. If a major chain’s private keys can be derived from public keys, the entire premise of self-custody collapses.

For those of us in the trenches building these systems, this report serves as a reminder that the "set it and forget it" mentality of smart contract deployment is dangerous. We have to start building with the assumption that our underlying cryptographic primitives will need to be swapped out, possibly under duress, within the next decade.

Ethereum’s 2029 Horizon

Vitalik Buterin and the Ethereum core researchers have been vocal about this for years, but the timeline is becoming more defined. The current target for "quantum-proofing" Ethereum is roughly 2029. This isn't just a simple software update. Moving a global state machine to post-quantum cryptography (PQC) involves changing how transactions are signed and how addresses are generated.

The challenge for Ethereum is the massive amount of legacy data. Millions of existing accounts are tied to ECDSA. A migration plan would likely involve a new transaction type that allows users to "prove" ownership of their old accounts using new, quantum-resistant signatures. It is a massive undertaking that could lead to significant bloat if not handled correctly. As a founder, you need to watch how this transition impacts gas fees and user experience. If a quantum-secure transaction costs ten times more than a standard one, adoption will stall.

Bitcoin’s Conservatism vs. The Quantum Threat

Bitcoin is in a tougher spot. The culture of the Bitcoin network is intentionally resistant to change. While there are draft migration plans and discussions about implementing Winternitz signatures or other PQC methods, the path to consensus is long and winding. Some Bitcoin purists argue that the threat is still decades away and that rushing into new, unproven cryptography could introduce more bugs than it solves.

However, the risk is asymmetric. If a quantum computer successfully drains a high-value "Satoshi-era" wallet, the market confidence in Bitcoin could evaporate overnight. For builders in the Bitcoin ecosystem, the focus should be on layer-2 solutions that can experiment with quantum resistance more freely than the base layer. Waiting for a hard fork on the mainnet is a high-stakes gamble.

What This Means for Founders and Builders

If you are building an application today, you cannot ignore the shift toward PQC. It’s no longer a science fiction scenario. Here is how you should be looking at this from a strategic perspective:

  • Technical Debt: Every line of code that assumes ECDSA is the permanent standard is future technical debt. Build your systems to be modular. If you need to switch libraries or signature schemes in five years, how painful will that be?
  • Regulatory Pressure: The EU report is a signal that future compliance standards will likely include requirements for quantum-readiness. If you’re targeting institutional users, they will start asking about your PQC roadmap sooner rather than later.
  • User Education: Eventually, users will have to take action to migrate their assets to new, secure addresses. The UX around this will be a nightmare. Founders who can simplify this transition will win the trust of the market.

The Reality Check

We should be skeptical of the hype on both sides. We don't have a cryptographically relevant quantum computer yet. We might not have one by 2029. But the cost of being wrong is total liquidation of the ecosystem. The EU's interest in this indicates that the "black swan" event of quantum decryption is now being modeled as a probable risk by central authorities.

We are entering an era where the mathematical foundations of the internet are being rebuilt. As builders, our job isn't to panic, but to ensure that the systems we create today don't become the ruins of tomorrow. Crypto-agility isn't just a buzzword; it’s a survival requirement. If your roadmap doesn't include a plan for when the math changes, you don't have a long-term roadmap.

The threat of quantum computing isn't that it will happen tomorrow, but that when it does, it will happen all at once. The time to build the bridge is before the flood starts.

Strategic Takeaway

The core takeaway here is that the window for "ignorance is bliss" regarding quantum threats is closing. European regulators are signaling that they will eventually mandate quantum-resistant standards for any entity operating within their jurisdiction. For founders, this means prioritizing modularity in your cryptographic architecture. Don't marry your protocol to a single signature scheme. Build the hooks for PQC now, so you aren't scrambling when the first quantum-derived private key hits the news cycle.


Read the original at Cointelegraph →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses