0x0e0ebfe70e0e…0e0ebfe4
Europol Flags Crypto Wallets as 'Primary Risk' for Quantum Attacks
Europol's European Cybercrime Centre published two reports on Wednesday identifying cryptocurrency wallets as the primary point of exposure to quantum threats, with 6.04 million BTC already at risk.

Outputs
Europol published two reports on Wednesday identifying crypto wallets as the primary point of exposure to quantum threats.
Glassnode estimated in May that 6.04 million BTC (30.2% of supply) has exposed public keys.
A 2024 study cited by Europol estimates migrating all Bitcoin outputs to quantum-safe signatures would require at least 76 days of cumulative network downtime.
IBM targets a fault-tolerant quantum computer by 2029; NIST proposes deprecating common public-key configurations by 2030.
Nine firms including BlackRock, Coinbase and Strategy pledged $15 million over three years for Bitcoin security research in July.
Europol's European Cybercrime Centre published two reports on Wednesday identifying cryptocurrency wallets as "the primary point of exposure to quantum threats" and calling on the industry and EU policymakers to begin migration toward post-quantum cryptography.
The first report, Quantum Computing and Cryptocurrencies, warns that a sufficiently powerful quantum computer could derive a private key from an exposed public key, enabling unauthorized spending. That moment, often called Q-Day, would compromise wallet security even though the hash functions linking blocks remain largely quantum-safe. Breaking a 256-bit hash, the report notes, would require a number of operations it calls "astronomically high with foreseeable technology."
"Cryptocurrencies will not collapse due to quantum computing," the report concludes, while recommending "proactive defence" and a phased transition to quantum-resistant cryptography alongside improvements to wallet security and key management.
How exposed is the Bitcoin network today?
Wallets whose public keys have already been broadcast on-chain cannot be retroactively secured. For those, the report states, "the only solution is pre-emptive migration." Blockchain analytics firm Glassnode estimated in May that 6.04 million BTC, equal to 30.2% of issued supply, has already had its public key exposed, leaving those coins reliant on users moving funds to new wallets before any attack.
Upgrading Bitcoin carries measurable costs. NIST-standardized post-quantum signatures run 10 to 120 times larger than the ECDSA signatures the network uses today, threatening to overload block space, raise transaction fees and slow confirmations. The report cites a 2024 study estimating that migrating every unspent transaction output would require at least 76 days of cumulative downtime, or roughly 300 days if the migration work consumed 25% of each block.
What is the timeline for quantum capability?
Europol points to vendor roadmaps and academic surveys as evidence that the threat window is narrowing. IBM targets a fault-tolerant quantum computer by 2029, and Microsoft expects scalable quantum computing on the same horizon. A 2025 survey cited in the report found that 32 experts placed the odds of a machine breaking RSA-2048 encryption within 24 hours in the next decade at 28% to 49%. Google research published in March and an AI-assisted competition in September both lowered the resource estimates required to attack the elliptic curve cryptography Bitcoin uses.
In the U.S., the National Institute of Standards and Technology has proposed deprecating today's most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035, according to Europol's second report. The EU's NIS Cooperation Group has recommended that member states adopt a post-quantum migration strategy by the end of 2026.
How is the industry responding?
Coinbase's quantum advisory council urged developers in June to begin post-quantum migration work immediately, while Ripple and the Stellar Development Foundation have published their own migration roadmaps. In July, nine firms including BlackRock, Coinbase and Strategy pledged a combined $15 million over three years for Bitcoin security research, with quantum defenses among the stated priorities.
Europol recommends establishing a European Commission-led working group, with participation from Europol, the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, to brief policymakers on quantum risk at regular intervals.
What is the 'harvest now, decrypt later' risk?
The second Europol report, Harvest Now, Decrypt Later, was developed with Spain's University Carlos III of Madrid. It examines attackers who collect encrypted data today in anticipation of future decryption capability, finding widely used protocols such as TLS, SSH and OpenPGP susceptible to varying degrees depending on configuration and key management.
The report notes "currently no clear evidence" that the technique is being systematically exploited at scale, but identifies government communications and confidential business data as the most plausible targets given the resources required. The European Union's three financial supervisors flagged the same tactic in September, warning that a quantum computer capable of breaking encryption could arrive before the technology has any viable commercial use.
For cryptocurrency payments, the report describes a "just-in-time" attack in which a quantum computer derives a private key during the short window between a transaction exposing its public key and its confirmation on-chain — a scenario Europol classifies as a more immediate risk than retrospective decryption.
The EU's end-of-2026 migration recommendation and NIST's 2030 deprecation deadline set the earliest regulatory clock for a sector whose largest wallets, by Bitcoin count, have already broadcast keys that no future cryptographic upgrade can retroactively protect.
via europol.europa.eu (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles