NewsCryptoEuropol: Quantum Threat to Crypto Sits With Exposed Wallets, Not Blockchains

Europol: Quantum Threat to Crypto Sits With Exposed Wallets, Not Blockchains

Author: Cryptopolitan·

Key Takeaways

  • •A Europol report concluded that quantum computers will not break blockchain networks, but wallets with exposed public keys represent the primary point of quantum risk.
  • •Approximately 6.04 million BTC, or 30.2% of the supply, had exposed public keys as of May, with another estimate placing the figure closer to 6.9 million BTC.
  • •A 2024 study cited by Europol estimates that moving all of Bitcoin's exposed transaction histories to quantum-resistant formats would require at least 76 days of total network downtime.
  • •Post-quantum signatures standardized by NIST are 10 to 120 times larger than Bitcoin's ECDSA signatures and could fill block space, increase fees, and slow confirmations.
  • •Migration efforts are underway, with the European Commission targeting a shift to quantum-resistant systems by end of 2026, Ethereum's post-quantum infrastructure set for 2029, and Bitcoin developers exploring the BIP-360 soft fork.
Europol: Quantum Threat to Crypto Sits With Exposed Wallets, Not Blockchains

Quantum computers will not be able to break blockchains, but wallets whose public keys can be seen on the blockchain will need to move their money before an attack, according to a report released Wednesday by Europol, the European Union's law enforcement agency.

The agency's European Cybercrime Centre, which produced the report, described wallets as "the primary point of exposure to quantum threats." A PDF version of the study is available on Europol's website. The distinction matters: it places the quantum risk with individual key holders rather than with the integrity of the networks themselves.

Roughly 6.04 million BTC already carry exposed public keys

A public key is what allows the network to verify that a wallet has signed a transaction, while wallets use a private key to sign transactions. According to the report, if a quantum computer was strong enough, it could use an open public key to derive the private key and spend the coins.

Hash functions that connect blocks and keep mining secure remain considerably harder to break. The report says that breaking a 256-bit hash would take roughly 2^128 quantum operations, which it describes as "still astronomically high with foreseeable technology."

The report's conclusion is that "cryptocurrencies will not collapse due to quantum computing." It adds, "Proactive adaptation, rather than systemic collapse, is the most likely outcome."

There is no cryptographic fix for wallets that leave their public keys open. "The only solution is pre-emptive migration," the report says — a process in which owners move their money to new wallets that will not be attacked first.

One on-chain count shows that as of May, 6.04 million BTC, or 30.2% of the supply, had their public keys exposed. Another estimate puts the figure closer to 6.9 million BTC. The totals include early pay-to-public-key outputs and Satoshi-era coins that have not been moved in a long time. Opinion in the Bitcoin community is already divided over whether coins in Satoshi-era wallets should be frozen — a debate with direct consequences for migration, since coins that are frozen in place cannot take part in it.

Bitcoin's transition could require 76 days of downtime

Europol cites a 2024 study that says it would take at least 76 days of total downtime to move all of Bitcoin's exposed transaction histories to a format that cannot be read by quantum computers. Committing 25% of each block to the task would stretch the job by roughly 300 additional days.

Post-quantum signatures standardized by the U.S. National Institute of Standards and Technology (NIST) are 10 to 120 times larger than the ECDSA signatures used by Bitcoin. The report says they might fill up block space, push fees higher, and make confirmations take longer. By the report's own numbers, the harder problem is not whether Bitcoin's cryptography can be broken but whether its blocks can absorb the change.

'Harvest now, decrypt later'

A second report, titled "Harvest Now, Decrypt Later," was written with help from the University Carlos III of Madrid in Spain. It describes attackers who store encrypted data today so they can crack it later. Europol has not found any strong proof that this method is being used on a large scale, but said high-value information that must stay secret for years would be the most likely target. The threat, in other words, is one of timing: data hoarded now only gains value once a capable machine actually exists.

Migration efforts are already underway elsewhere. As Cryptopolitan reported in September, the European Commission wants member states to begin moving to quantum-resistant systems by the end of 2026 and to complete the migration of high-risk systems before 2030. Ethereum's core post-quantum infrastructure is set to launch in 2029, and Bitcoin developers are exploring the BIP-360 soft fork.

Also in September, Cryptopolitan reported that more than 100 researchers using AI coders cut by 86.1% the resources needed for a single quantum attack on Bitcoin. The machine capable of handling this kind of attack does not exist yet, and Europol did not say when it would. Until it does, the only fixed dates in the quantum timeline belong to the migration side — which is precisely where the report says the work needs to happen.