0x229f8ddc229f…229f8ddf
Europol: Quantum Threat Targets Wallets, Not Blockchains — 6.9M BTC Exposed
Europol says 6.9M BTC sit at addresses with exposed public keys and urges a phased post-quantum migration, stressing wallets — not blockchains — face the real quantum risk.

Outputs
Europol report published Wednesday identifies wallets, not blockchains, as the main quantum-computing exposure point.
About 6.9 million bitcoin sit at addresses with exposed public keys, including Satoshi-era and long-dormant holdings.
A 2024 study cited by Europol estimates a full quantum-resistant UTXO migration needs at least 76 days of block space, or ~300 days at 25% of each block.
Post-quantum signature schemes can be 10 to 120 times larger than Bitcoin's current ECDSA signatures.
Bitcoin researchers increasingly see 2029 as the deadline for credible quantum-resistant migration plans.
Roughly 6.9 million bitcoin sit at addresses with exposed public keys, Europol said in a report published Wednesday, making wallets — not blockchains — the primary point of exposure to future quantum-computing attacks.
The EU's law enforcement agency urged developers, miners, exchanges and users to begin a phased transition to quantum-resistant security immediately, warning that the central challenge is coordinating a global networkwide migration before vulnerable wallets become targets. Quantum computers capable of deriving private keys from public keys do not yet exist, and Europol declined to predict when they will arrive.
"Cryptocurrencies will not collapse due to quantum computing," Europol's European Cybercrime Center wrote in its Quantum Computing and Crypturrencies report. Instead, the agency said "proactive adaptation, rather than systemic collapse, is the most likely outcome."
What is actually at risk?
Europol drew a distinction often lost in public warnings about quantum computing. The hash functions securing a blockchain's history, including Bitcoin mining, remain far more resistant to quantum attacks than the public-key cryptography controlling wallets. A sufficiently powerful quantum computer could derive a private key from an exposed public key and spend the associated funds, but it could not rewrite the Bitcoin blockchain.
The distinction matters most for addresses from Bitcoin's earliest days — the so-called "Satoshi era" — whose public keys have already become visible on-chain. Exposed keys include early pay-to-public-key outputs and many long-dormant holdings.
Europol said exposed keys cannot be made safe retroactively. That limitation has fueled debate across the Bitcoin community over whether to freeze BTC in Satoshi-era wallets as the quantum threat approaches.
How long would migration take?
Updating the network itself is the harder task. Europol cited a 2024 study estimating that converting every Bitcoin unspent transaction output (UTXO) to a quantum-resistant format would require at least 76 days of cumulative block space. Reserving 25% of each block for migration would stretch the process to about 300 days.
New post-quantum signature schemes compound the problem. According to the report, they can be 10 to 120 times larger than Bitcoin's current Elliptic Curve Digital Signature Algorithm (ECDSA) signatures — the mechanism that proves ownership of bitcoin and authorizes fund transfers on the network.
Bitcoin's challenge is less about finding replacement cryptography than persuading a global, decentralized network to adopt it before exposed wallets become targets.
What timeline are researchers working with?
Bitcoin researchers and institutions increasingly view 2029 as the point by which credible quantum-resistant migration plans need to be in place. IBM said in July it expects quantum computing to generate significant commercial revenue within the next two to four years.
Europol's report effectively sets an operational deadline for exchanges and custodians: begin post-quantum wallet upgrades now, or risk holding assets whose ownership could eventually be contested by whoever controls a cryptographically relevant quantum computer.
via CoinDesk (Source)