
As AI-assisted breakthroughs in mathematics and cryptography quickly accumulate, a strange collision is forming between Bitcoin security and EU financial regulation.
On October 6, 2026, OpenAI published a broad collection of new mathematical results produced by an internal frontier model. Two days later, Ethereum researcher Justin Drake warned cryptocurrency holders to prepare for a worst-case scenario in which AI-assisted mathematical research discovers attacks against the elliptic-curve cryptography protecting Bitcoin and Ethereum far sooner than expected.
While no practical key-recovery attack has been publicly demonstrated, his immediate advice for large holders was more mundane: where possible, keep long-term funds behind addresses whose public keys have never appeared onchain.
That means Bitcoin’s only workable precaution against both quantum- and AI-assisted compromise now runs straight into the EU Crypto Travel Rule.
Regulation (EU) 2023/1113 requires crypto exchanges and other crypto-asset service providers to assess whether customers own or control self-hosted addresses in certain transfers above €1,000. The European Banking Authority then approved verification methods that include small transactions and cryptographic signatures.
Coinbase’s EU implementation shows where this can lead. Its Bitcoin instructions tell customers how to verify a wallet with a small transaction, acknowledge that Bitcoin wallets rotate addresses for privacy, then tell users they can keep sending to the same verified address to avoid repeating the test. Coinbase also offers extended-public-key disclosure as another way around repeated verification.
For Bitcoin outputs whose long-term protection partly comes from keeping their public key hidden, that can turn a compliance exercise into a permanent security risk.
Key takeaways
The EU requires ownership or control checks for qualifying self-hosted-address transfers above €1,000.
EBA guidance expressly permits verification by a predefined crypto transfer, digital signature, address display or other method considered sufficiently reliable. It also permits verified addresses to be whitelisted for future transfers.
Modern Bitcoin wallets can conceal underlying public keys until a user performs either a transfer or digital signature with the address concerned.
Coinbase tells EU customers using its small-deposit test to send from the wallet address they want verified. For Bitcoin, it then recommends sending future funds to the previously verified address if users want to avoid repeating the test.
Coinbase also lets Bitcoin users submit an xpub, which can expose a whole branch of derived public keys rather than one address.
The problem is exposing that public key can be permanent and, while AI and quantum computers can’t demonstrably steal Bitcoin from exposed public keys today, future cryptanalytic capability is unknown.
Bitcoin holders are being told to think about public-key exposure
Bitcoin does not protect every output type in the same way.
A P2WPKH output contains a hash of a public key. When the output is later spent, the Bitcoin witness contains the signature and public key. Until that happens, the public key itself does not need to appear onchain.
Taproot works differently. BIP-341 says its public key is included directly in the output rather than storing only a hash of it. A bc1p Taproot output therefore does not get the same protection from long-term public-key concealment.
This difference has become important enough to produce a proposed Bitcoin upgrade. Draft BIP-360, Pay-to-Merkle-Root, is specifically designed around resistance to what its authors call “long exposure attacks.” Those are attacks in which a future cryptographically relevant quantum computer, or another cryptanalytic breakthrough, has plenty of time to work against an already exposed public key.
The proposal categorizes unused P2PKH and P2WPKH outputs differently from Taproot and reused outputs, and explicitly warns that xpubs and wallet descriptors also reveal vulnerable public-key information.
That leaves long-exposure protection as one of the few precautions a holder can take without waiting for Bitcoin’s signature system to change, and it makes needlessly giving out one’s public key a particularly stupid thing for a compliance regime to encourage.
The EU created this verification checkpoint
Regulation (EU) 2023/1113 expanded the EU Travel Rule to crypto-assets. Its stated purpose is to make money laundering and terrorist financing harder by making transfers more traceable. The rules have applied since December 30, 2024.
For transfers exceeding €1,000 to a self-hosted address, Article 14 requires the originator’s crypto-asset service provider to take adequate measures to assess whether the address is owned or controlled by its customer. Article 16 imposes the corresponding requirement for qualifying transfers coming from a self-hosted address. The regulation also says the provider is not allowed to execute a transfer before complying with Article 14’s requirements.
Its final guidelines say providers should use at least one verification method. The approved list includes unattended verification displaying the address, attended verification, sending a predefined amount between the self-hosted address and the provider, digitally signing a specific message using the key corresponding to the address, or another sufficiently reliable technical method. If one method is not reliable enough, the provider should combine methods.
Once an exchange is satisfied, the EBA says it may document the address and stop reapplying the verification measures to later transfers involving that same address. The guidelines explicitly call this “whitelisting.”
In light of the impending cryptographic risks facing cryptocurrencies, this creates a huge incentive problem.
Bitcoin’s security architecture makes fresh addresses disposable by design. A whitelisted compliance address, on the other hand, becomes more convenient the more often it is reused.
Brussels is already looking at Europeans’ savings
The Bitcoin rule also lands in an uncomfortable wider context.
Europe faces a serious demographic squeeze. The EU fertility rate fell to 1.34 children per woman in 2024, its lowest level in Eurostat’s series, while the latest projections put the EU population peak at about 453.3 million in 2029 before a decline toward 398.8 million by 2100. The working-age share is also projected to fall substantially.
Against that unfavorable backdrop, Brussels has accumulated enormous spending ambitions. Official EU figures put support to Ukraine since 2022 at €224.5 billion. The Draghi competitiveness report estimated another €750 billion to €800 billion in additional investment every year would be required to meet Europe’s stated objectives, including the green transition, digital investment, research and greater defense spending. Draghi also noted that European companies were already paying electricity prices roughly two to three times those faced by U.S. competitors.
Migration adds another cost pressure where supply is already failing. A 2025 European Commission housing paper found that immigration can exacerbate housing shortages and strain urban infrastructure, with the literature generally associating immigration with higher local house prices and rents where housing supply cannot respond quickly enough.
Brussels’ answer to these financing pressures increasingly includes Europeans’ private savings. The Commission’s Savings and Investments Union was explicitly created to channel more savings into its pet projects. It points to roughly €10 trillion of EU household savings held in bank deposits, and it encourages citizens to allocate savings toward investments financing objectives including the climate transition, “innovation” and defense. In 2026, the Commission was also pushing member states toward stronger supplementary pension systems, auto-enrollment and greater retail participation in capital markets.
While the Commission describes this as giving households better returns and more investment options, Europeans are not exactly eager to invest even more into the projects that have brought Europe’s economy to its precarious position today. While it is not (yet) confiscation, and account holders retain investment choices, the political direction is impossible to miss. Faced with demographic decline, weak competitiveness and extraordinarily expensive policy goals, the EU increasingly talks about Europe’s household savings as capital that should be mobilized toward objectives chosen in Brussels.
The EU’s track record of reckless disregard for Europeans’ financial well-being gives cryptocurrency holders little reason to grant regulators a presumption of wisdom when another EU financial rule creates avoidable risk around their savings. Europeans have repeatedly footed the bill for EU policies whose costs inevitably emerge through taxes, energy prices, housing pressure, public debt or systemic malinvestment.
A mandatory crypto-compliance checkpoint deserves especially hard scrutiny when it specifically degrades the security properties of the asset being regulated.
Coinbase shows what the rule becomes in practice
Coinbase provides the clearest documented example.
Its EU help page says customers sending cryptocurrency to a self-custody wallet may be required to prove that they own it. Users can link a Coinbase Wallet, sign a message, or complete a small-deposit test.
Under the small-deposit method, Coinbase gives the customer an exact amount to send back to Coinbase and instructs the customer to make sure the funds are coming from “the wallet address you want to verify.” Once the transaction succeeds, Coinbase marks the wallet as verified and permits withdrawals to it.
Then Coinbase acknowledges the problem it has created.
Its documentation notes that Bitcoin wallets may rotate addresses for privacy and that verification applies only to the specific verified address. Its recommendation for avoiding another verification test is to keep sending funds to the verified address Coinbase emailed to the customer.
That means customers are explicitly encouraged to expose their public keys and then keep using addresses whose public key have been exposed, making them targets for future attacks.
If a Coinbase verification transaction spends a P2WPKH or P2PKH output tied to the address that will subsequently be reused, that spending transaction reveals the corresponding public key. P2WPKH does this explicitly through the transaction witness. If the user later accumulates long-term savings at that reused address, the public key has already been exposed permanently onchain.
The compliance test has then destroyed the long-exposure protection the Bitcoin address originally had.
The xpub workaround can expose much more
Coinbase offers Bitcoin users another route: submit an extended public key so Coinbase can recognize addresses belonging to the wallet and stop demanding repeated test deposits.
That convenience comes with a larger disclosure.
BIP-32 defines an extended public key as a public key plus chain code and allows non-hardened descendant public keys to be derived from it. An xpub can therefore describe an entire public-key branch of a hardware wallet rather than one receiving address. BIP-32 itself warns that extended public keys need greater care because they correspond to a subtree of keys.
BIP-360 goes further for the specific future threat considered here. It explicitly lists xpubs and wallet descriptors as revealing quantum-vulnerable public-key information.
If a future attack made private-key recovery from public keys practical, an exchange database containing xpubs could become an extremely attractive target.
That danger differs from the onchain problem. A public key exposed by spending is visible forever to everyone. An xpub handed to an exchange is offchain information, but one breach, insider leak or future compromise could expose an entire derived wallet branch.
Calling that a harmless verification shortcut would be reckless.
The EU created the pressure toward the worst verification method
The EBA does permit less intrusive approaches, at least in theory. Its guidance includes verification in which the customer displays an address during remote onboarding.
The problem is incentive design.
The crypto-asset service provider carries the compliance obligation. It needs evidence strong enough to satisfy its regulator. Cryptographic signatures and blockchain transactions create machine-verifiable records. A user displaying an address may be easier on that user’s cryptographic hygiene, but it would require additional identity checks, staff or procedural judgment.
Industry responses during the EBA consultation warned about exactly these implementation problems. Respondents raised concerns about the practicality of ownership verification for self-hosted wallets, the limited information available from blockchain analytics and the lack of infrastructure capable of tying real-world identities reliably to non-custodial addresses. Ledger argued that the regime placed disproportionate burdens on self-hosted-wallet transfers.
However, nothing stops an EU bureaucrat determined to implement terrible and impractical ideas. Least of all the valid objections of leading professionals in the relevant industry being targeted.
While Brussels can legally say it never wrote “expose your wallet to attacks or we won’t let you send coins to it” into the law, that is a weak defense when the rule creates a compulsory proof problem that can only be solved by recommending exactly that behavior.
Does ownership verification even stop the crimes used to justify it?
There is another problem with the bargain: proving ownership of an address does not prove the final destination of the money.
A customer can verify Address A, receive Bitcoin there, then immediately transfer it to Address B. A criminal can do the same.
A scam victim can correctly prove ownership of his own wallet, then willingly send the funds to a scammer because he has been manipulated into doing so.
Message signatures have similar limits. BIP-322, Bitcoin’s standard for generalized signed messages, explicitly states that no message-signing protocol can prove enduring control of funds because a signature becomes stale and a person possessing a secret key can sign on somebody else’s behalf.
Ownership verification may help investigators connect a known exchange customer to an address at a particular moment. It can create an audit trail and give investigators another data point.
That may have some unquantified investigative value, but it doesn’t even remotely come close to changing what happens to the coins after they leave the crypto-asset service provider’s platform.
The EU has therefore imposed a security-sensitive verification requirement whose preventive value is near zero, while its implementation creates permanent cryptographic exposure.
What Bitcoin holders should do now
There is no demonstrated AI or quantum attack capable of deriving ordinary Bitcoin private keys from exposed public keys today. Rushing coins around carelessly can lose money through much more conventional errors.
The reasonable response is better key hygiene.
▪ Know what address type you are using. P2WPKH bc1q outputs can hide the public key until spending. Traditional P2PKH outputs have a similar public-key-hash property. Taproot bc1p outputs expose an output public key from the beginning, so moving funds there does not provide the same defense against long-exposure key recovery.
▪ Before withdrawing significant savings from an EU exchange, find out what self-hosted-wallet verification method it will demand. Ask whether an option exists that does not require spending from the intended savings address, signing with that address or revealing an xpub.
▪ Treat xpubs as sensitive wallet information, not ordinary receiving addresses.
▪ And do not reuse a spent address merely because an exchange has made reuse more convenient. BIP-360 specifically identifies reused outputs and exposed public keys as long-exposure concerns.
Popular AI has covered the broader pattern of regulation creating technical control points in its guide to AI regulation and policy: who controls what you can build, while the speed at which AI is compressing security assumptions is discussed in Stronger AI cyber tools mean developers need faster fixes.
More on AI and security:
The EU created a security problem it should fix
While Brussels’ EU Crypto Travel Rule does not explicitly order Bitcoin holders to expose their public keys, the evidence is more damning when stated accurately.
The EU made proof of self-hosted-wallet ownership mandatory in qualifying transfers. Its banking regulator approved transaction-based verification, digital signatures and address whitelisting. Coinbase then implemented a Bitcoin process that tells customers how to perform a verification transaction, warns that Bitcoin normally rotates addresses for privacy, and recommends continued use of the already verified address if the customer wants to avoid repeating the test.
At exactly the same time, Bitcoin researchers are working on defenses against long-exposure attacks whose basic premise is simple: do not expose vulnerable public keys earlier or longer than necessary.
A government that forces financial institutions to create cryptographic checkpoints has a responsibility to at least understand the cryptography it is interfering with.
Regulators should require verification methods that preserve public-key secrecy wherever technically possible. Exchanges should not be forced to encourage address reuse for compliance convenience. Xpub disclosure should carry an explicit security and privacy warning. Any method that unnecessarily transforms a fresh key-hiding Bitcoin output into a permanently exposed target should be treated as defective compliance design.
The EU’s desperate obsession with controlling citizens’ finances in the name of fighting financial crime may simply end up creating a convenient list of future victims for the next generation of financial criminals.
Explore more from Popular AI:
Start here | Local AI | Builds & gear | Autonomy & policy | Fixes & guides | Popular AI podcast











Does the EU Crypto Travel Rule make Bitcoin users safer, or does linking identities to crypto activity create a new kind of risk?