Europol published two reports warning that crypto wallets, not blockchain hash functions, are the weakest point against future quantum computing attacks. The EU agency says private keys could be derived from exposed public keys, putting millions of Bitcoin at risk, and is urging a phased migration to quantum-resistant cryptography starting now.
Europol's European Cybercrime Centre named crypto wallets the primary point of exposure to quantum threats in a report published Wednesday, while the hash functions that secure blockchains stay largely resistant. A sufficiently powerful quantum computer could derive a wallet's private key from an exposed public key, letting an attacker spend funds without authorization.
Wallet keys are the weak link
Wallets rely on a private key that authorizes transactions and a public key the network uses to verify them. Europol's report explains that quantum machines could run algorithms like Shor's to deduce a private key from an exposed public key, a scenario the industry calls Q-Day.
Public-key exposure already affects a large share of supply: Glassnode estimated in May that 6.04 million BTC, or 30.2% of issued supply, has already had its public key exposed, since those keys cannot be secured after the fact. CryptoQuant separately estimates that approximately 6.9 million Bitcoin sit in legacy or reused addresses facing potential quantum vulnerabilities, a stash CryptoQuant valued at around $586 billion at the time.
Migration carries its own costs
Upgrading Bitcoin isn't free. Europol's report cites a 2024 study estimating that making every Bitcoin output quantum-safe would require at least 76 days of cumulative network downtime, or roughly 300 days if the work took up 25% of each block. NIST-standardized post-quantum signatures run 10 to 120 times larger than the ECDSA signatures Bitcoin uses today, which the report says threatens to overload block space and raise fees.
A second threat: harvest now, decrypt later
The agency's second report, developed with Spain's University Carlos III of Madrid, examines "harvest now, decrypt later," where attackers collect encrypted data today to crack it once quantum hardware matures. The report found widely used protocols including TLS, SSH and OpenPGP susceptible, though it says there is currently no clear evidence the technique is being exploited at scale.
Europol's warning echoes a September alert from the EU's three financial supervisors, who said a capable quantum computer could arrive before the technology has any viable commercial use. According to Europol's report: "Cryptocurrencies will not collapse due to quantum computing", though it recommends a phased transition to quantum-resistant cryptography and stronger key management starting now rather than once Q-Day arrives.
Sources: Decrypt, Crypto Briefing
Trading involves risk.