France to ban non-quantum encryption by 2027 amid BTC risk
France Sets 2027 Ban on Non‑Quantum‑Safe Encryption, 6.04M BTC Potentially Exposed
France’s cybersecurity agency ANSSI will stop certifying security products without quantum‑resistant encryption from 2027. The mandate applies to government agencies and critical infrastructure, with full migration to post‑quantum cryptography required by 2030.
Glassnode’s May 2026 report shows 6.04 million BTC — about 30.2% of supply — have public keys visible on‑chain, making them theoretically vulnerable to quantum attacks.
---
Structurally exposed coins:
- **1.92M BTC** (~9.6% of supply) in outputs like P2PK from early mining rewards, bare multisig scripts, and Taproot P2TR.
Operationally exposed coins:
- **4.12M BTC** (~20.6% of supply) from address reuse, partial UTXO spends, and custodial practices.
- Exchanges hold an estimated 1.63–1.66M BTC in this vulnerable category.
---
69.8% of supply — 13.99M BTC — remain safe, with no public‑key exposure at rest. Sovereign holdings of the US, UK, and El Salvador show zero exposure.
Threat vector:
Bitcoin’s ECDSA signatures over secp256k1 could be broken by Shor’s algorithm on a quantum computer, enabling private key recovery for already‑exposed public keys. Hash‑of‑pubkey types (P2PKH) offer protection until spent.
---
ANSSI roadmap:
- Inventory sensitive data by end‑2026.
- Map affected systems by end‑2027.
- Complete PQC migration by 2030.
Other institutions: Google targets PQC adoption by 2029. NIST plans to retire RSA/ECC around 2030–2035. Academic estimates suggest 1,754 logical qubits could compromise secp256k1, with realistic timelines of 10–20 years.
Glassnode’s exposure figure aligns with earlier ranges (Deloitte: ~4M BTC; Chaincode Labs: 4–10M BTC) but uses stricter criteria.





