Europol: quantum threat for cryptocurrencies concerns exposed wallets, not blockchains
Najważniejsze informacje
- •The Europol report concluded that quantum computers will not break blockchain networks, but wallets with exposed public keys are the primary point of quantum risk.
- •As of May, approx. 6.04 million BTC, i.e. 30.2% of the supply, had exposed public keys, and another estimate places this figure closer to 6.9 million BTC.
- •A 2024 study cited by Europol estimates that moving all of Bitcoin's exposed transaction histories to quantum-resistant formats would require at least 76 days of total network downtime.
- •Post-quantum signatures standardized by NIST are 10 to 120 times larger than Bitcoin's ECDSA signatures and could fill block space, increase fees, and extend confirmation times.
- •Migration efforts are underway: the European Commission plans to move to quantum-resistant systems by the end of 2026, Ethereum's post-quantum infrastructure is scheduled for 2029, and Bitcoin developers are analyzing the BIP-360 soft fork.

Quantum computers will not be able to break blockchains, but wallets whose public keys are visible on the blockchain will need to move their funds before a potential attack — according to a report published on Wednesday by Europol, the law enforcement agency of the European Union.
The agency's European Cybercrime Centre, author of the report, stated that wallets are "the primary point of exposure to quantum threats." A PDF version of the study is available on the Europol website. This distinction matters: it places the quantum risk with individual key holders, not with the integrity of the networks themselves.
Approx. 6.04 million BTC already has exposed public keys
The public key allows the network to verify that a wallet has signed a transaction, while wallets use a private key to sign transactions. According to the report, if a quantum computer was sufficiently powerful, it could use an exposed public key to derive the private key and spend the coins.
Hash functions connecting blocks and securing mining remain considerably harder to break. The report states that breaking a 256-bit hash would require approx. 2^128 quantum operations, which the authors describe as "still an astronomically high value with foreseeable technology."
The report's conclusion is that "cryptocurrencies will not collapse due to quantum computing." It adds: "Proactive adaptation, rather than systemic collapse, is the most likely outcome."
For wallets that leave public keys exposed, there is no cryptographic solution. "The only solution is pre-emptive migration," the report states — meaning owners move their funds to new wallets that will not be attacked first.
One on-chain count shows that as of May, 6.04 million BTC, i.e. 30.2% of the supply, had exposed public keys. Another estimate places this figure closer to 6.9 million BTC. These totals include early pay-to-public-key outputs and Satoshi-era coins that have not been moved for a long time. The Bitcoin community is already divided on the question of whether coins in Satoshi-era wallets should be frozen — a debate with direct consequences for migration, as frozen coins cannot participate in it.
Bitcoin's transition may require 76 days of downtime
Europol cites a 2024 study according to which moving all of Bitcoin's exposed transaction histories to a format unreadable by quantum computers would require at least 76 days of total network downtime. Allocating 25% of each block to this task would extend the work by approx. another 300 days.
Post-quantum signatures standardized by the U.S. National Institute of Standards and Technology (NIST) are 10 to 120 times larger than the ECDSA signatures used by Bitcoin. The report states that they could fill block space, increase fees, and extend confirmation times. According to the report's own calculations, the harder problem is not whether Bitcoin's cryptography can be broken, but whether its blocks can absorb this change.
"Harvest now, decrypt later"
A second report, titled "Harvest Now, Decrypt Later," was written with the participation of the University Carlos III of Madrid in Spain. It describes attackers who store encrypted data today to decrypt it later. Europol has not found strong evidence that this method is being used on a large scale, but pointed out that high-value information that must remain secret for years would be the most likely target. In other words, the comes down to timing: data collected now gains value only when a suitably capable machine actually comes into existence.
Migration efforts are already underway elsewhere. As Cryptopolitan reported in September, the European Commission wants member states to begin moving to quantum-resistant systems by the end of 2026 and to complete the migration of high-risk systems before 2030. Ethereum's core post-quantum infrastructure is scheduled to launch in 2029, and Bitcoin developers are analyzing the BIP-360 soft fork.
Also in September, Cryptopolitan reported that over 100 researchers using AI coding tools reduced by 86.1% the resources needed for a single quantum attack on Bitcoin. A machine capable of carrying out such an attack does not exist yet, and Europol did not specify when it would. Until then, the only fixed dates in the quantum timeline belong to the side of migration — which is precisely where, as the report states, the work needs to be undertaken.