Europol Says Quantum Computing Won't Break Bitcoin, but Exposed Wallets Remain Vulnerable
Key Takeaways
- •Europol's European Cybercrime Centre concluded on October 7, 2026, that quantum computing will not cause cryptocurrencies to collapse.
- •Wallets using public-key cryptography such as Bitcoin's ECDSA are the primary quantum vulnerability, while the blockchain's hash functions like SHA-256 are largely resistant to quantum attacks.
- •Approximately 6 to 6.9 million BTC, roughly 30% of Bitcoin's supply, sits in addresses with exposed public keys that cannot be protected retroactively.
- •Europol recommends phased adoption of post-quantum cryptography paired with wallet upgrades, building on NIST's first PQC standards finalized in 2024.
- •Migrating all Bitcoin unspent transaction outputs could require more than 76 days of cumulative processing time, making early coordination and proactive holder action essential.

Europe's top police agency has weighed in on crypto's favorite doomsday scenario, and its verdict is that the sky is not falling—though a significant share of Bitcoin's supply may not be safe.
On October 7, 2026, Europol's European Cybercrime Centre (EC3) published two reports examining how quantum computing could affect cryptocurrencies and encrypted data. The central finding was blunt: "Cryptocurrencies will not collapse due to quantum computing."
Yet the agency made clear that "will not collapse" is not the same as "nothing to worry about." The reports draw a sharp line between the blockchain itself and the wallets people use to hold their coins.
What Europol Found
The primary report, titled "Quantum Computing and Cryptocurrencies – Bridging Technical Expertise and Decision-Making," splits crypto security into two layers, aiming to translate technical quantum risk into planning guidance for decision-makers.
The first layer is the blockchain itself. Europol describes it as a vault whose integrity holds because it relies on hash functions such as Bitcoin's SHA-256, the agency says are largely resistant to quantum attacks. The second layer—wallets built on public-key cryptography, in Bitcoin's case the Elliptic Curve Digital Signature Algorithm (ECDSA)—is identified as the "primary point of exposure."
The concern is specific. A sufficiently powerful quantum computer could work backward from an exposed public key, derive the matching private key, and then sign transactions the owner never approved. The split tracks how quantum attacks are understood to work: Shor's algorithm, which underpins the threat to elliptic-curve signatures, has no comparably devastating counterpart against hash functions.
The 30% Problem
The most striking figure in the report concerns scale: approximately 6 to 6.9 million BTC sit in addresses whose public keys have already been exposed, which Europol pegs at roughly 30% of Bitcoin's supply.
Exposure is largely a byproduct of how Bitcoin works. Most address types reveal only a hash of the public key until coins are spent, and the act of spending places the full public key on the public ledger permanently. Once that happens, the exposure is a one-way door.
According to the agency, the only real protection is moving those funds to safe wallets before a capable quantum machine arrives, because exposed keys cannot be secured retroactively. Europol recommends a phased adoption of post-quantum cryptography (PQC)—encryption schemes designed to hold up even against quantum computers—paired with wallet upgrades. The field is no longer purely theoretical: the U.S. National Institute of Standards and Technology (NIST) finalized its first PQC standards in 2024, giving wallet developers reference algorithms to build against.
Easier Said Than Migrated
Europol flags coordination as a central challenge. Bitcoin has no IT department that can push a mandatory update and call it a day. The report estimates that migrating all Bitcoin unspent transaction outputs (UTXOs) could require more than 76 days of cumulative processing time under certain assumptions.
The reports also build on earlier Europol assessments of quantum technology published in 2023. The new work narrows that broader lens to what quantum risk means for digital assets specifically, while the companion report addresses the wider threat to encrypted data.
What It Means for Holders and Builders
For investors, the issue is less whether Bitcoin as a network survives quantum computing and more whether a specific holder's coins sit in a vulnerable address. Holders with exposed public keys face a risk that cannot be patched later. Under Europol's analysis, the remedy is proactive migration, which shifts much of the responsibility from the protocol to individual users.
The thorniest question involves coins whose owners never act. If roughly 30% of supply sits in exposed addresses, and protection depends on owners moving funds themselves, it is not obvious how every one of those coins gets secured. And if a full migration could take more than 76 days of processing time, waiting until quantum machines are actually ready would leave very little room for error.
The practical markers to watch follow directly from Europol's recommendations: whether wallet providers begin shipping quantum-resistant address options, and whether Bitcoin developers converge on shared migration standards while the timeline still allows for the phased approach the agency describes.