Europol’s European Cybercrime Centre concluded Wednesday that cryptocurrency wallets, rather than the blockchains they operate on, are the primary point of exposure to future quantum-computin
Europol’s European Cybercrime Centre concluded Wednesday that cryptocurrency wallets, rather than the blockchains they operate on, are the primary point of exposure to future quantum-computing attacks. In a report published October 7, the European Union’s law-enforcement agency urged developers, exchanges, miners, and users to begin a phased shift to post-quantum security now, even though machines capable of carrying out such attacks do not yet exist.
The report draws a distinction that earlier warnings often blurred: the hash functions that secure a blockchain’s history, including Bitcoin mining, remain far more resistant to quantum attack than the public-key cryptography used to control wallets. A sufficiently powerful quantum computer could derive a private key from a public key and spend the associated funds. “Cryptocurrencies will not collapse due to quantum computing,” Europol said, and “proactive adaptation, rather than systemic collapse, is the most likely outcome.”
Why Wallets, Not Blockchains, Are the Exposure
The distinction turns on where keys become visible. When a Bitcoin address moves funds, its public key is recorded onchain, which would let a future quantum computer work backward toward the private key. Bitcoin’s Elliptic Curve Digital Signature Algorithm, or ECDSA, is the vulnerable element, not the SHA-256 hash function that underpins mining and the ledger. Europol estimates roughly 6.9 million bitcoin sit in addresses with exposed public keys, including early pay-to-public-key outputs and long-dormant holdings from the network’s earliest days, the population at the center of the debate over whether quantum computers can break Bitcoin.
The Coins That Cannot Be Fixed Retroactively
Exposed keys cannot be made safe after the fact, which is why the oldest coins, tied to the network’s so-called Satoshi era, carry the most risk. The warning follows a September notice from Europe’s three financial supervisory authorities, which said quantum computing could undermine the cryptography behind blockchains and told supervisors and market participants to prepare before the threat materializes. Europol’s harder problem is not finding replacement cryptography but persuading a decentralized global network to adopt it before vulnerable wallets become targets.
What a Network-Wide Migration Requires
Europol cited a 2024 study estimating that converting every Bitcoin unspent transaction output to a quantum-resistant format would require at least 76 days of cumulative block space, stretching to about 300 days if only a quarter of each block were reserved for the work. New post-quantum signature schemes can be 10 to 120 times larger than ECDSA signatures, which adds a data-cost layer to what is already a coordination challenge across miners, developers, and exchanges.
What Happens Next
Bitcoin researchers and institutions increasingly treat 2029 as the point by which credible migration plans need to be in place, a timeline that tracks IBM’s July forecast that quantum computing is nearing a commercial breakthrough. Europol did not predict when an attack-capable machine will arrive. Its recommendation is procedural rather than alarmist: begin wallet upgrades and post-quantum cryptography now so that adaptation, not a scramble, becomes the industry’s default.