Bitcoin Quantum Risk: Europol Warns Wallets, Not Chain
By Azness Team ·
Europol says Bitcoin quantum risk is concentrated in wallets, not blockchains, and urges a phased migration to post-quantum cryptography before 2030.
Europol has just published a report on Bitcoin quantum risk, and its core conclusion is more nuanced than the headlines suggest: the blockchain itself is not the weak link, but the wallets holding your coins might be. The European Cybercrime Centre identified cryptocurrency wallets—specifically the public-key cryptography that secures them—as the primary exposure point to future quantum attacks. But the agency also stated plainly that cryptocurrencies will not collapse due to quantum computing.
What Europol Actually Said About Bitcoin Quantum Risk
The report, titled Quantum Computing and Cryptocurrencies, came out on Wednesday. Europol's central point is that hash functions—the cryptographic binding that protects blockchain history and underlies Bitcoin mining—hold up far better against quantum attacks than the public-key cryptography wallets rely on. Cracking a 256-bit hash would demand an astronomically large number of operations under any technology now foreseeable.
Wallets are a separate matter. If a quantum computer powerful enough ever came into being, it could work out a private key from a public key and drain the funds tied to it. The danger is greatest for Bitcoin's oldest addresses—the so-called Satoshi era—since their public keys are already exposed on-chain. CoinDesk puts the total at roughly 6.9 million bitcoin held in addresses with visible public keys. A May estimate from Glassnode, cited by Decrypt, gives 6.04 million BTC, equal to 30.2% of issued supply.
Above all, Europol emphasized that exposed keys cannot be retroactively secured. For those wallets, pre-emptive migration to quantum-resistant cryptography is the sole remedy. Quantum computers able to break wallet cryptography don't exist yet, and Europol offered no prediction for when they might.
Why This Matters for Bitcoin Holders
The upshot in practice: quantum risk to Bitcoin isn't a binary event. It's a migration challenge, and migrating something the size of Bitcoin takes time. One 2024 study calculated that moving every bitcoin UTXO into a quantum-resistant format would consume at least 76 days of cumulative block space. Reserving only 25% of each block for migration would drag the process out to roughly 300 days. On top of that, post-quantum signature schemes are 10 to 120 times larger than the ECDSA signatures Bitcoin uses today—which translates into more block space, steeper fees and slower confirmations throughout any transition.
Europol flagged another, less obvious danger: a just-in-time attack, in which a quantum computer extracts a private key during the short interval between a transaction revealing its public key and that transaction being confirmed. When it comes to payments, real-time interception represents a nearer-term quantum hazard than retrospective decryption.
The agency's second report, Harvest Now, Decrypt Later, produced together with Spain's University Carlos III of Madrid, identified TLS, SSH and OpenPGP as vulnerable to harvest-now-decrypt-later attacks—the practice of gathering encrypted data today in order to decrypt it later. Government communications and confidential business data rank as the likeliest targets. Europol observed that no clear evidence currently shows such attacks being carried out systematically at scale.
- Wallet migration is the real work. Exposed keys cannot be retroactively secured.
- Block space is the bottleneck. Post-quantum signatures are much larger than ECDSA.
- Coordination is essential. Developers, miners, exchanges and users all need to move together.
Market Reaction and Timing Signals
Bitcoin is trading at $82,964.00, down 4.19% in the last 24 hours, with $37,928,967,648 in volume and a market cap of $1,667,365,725,169. There is no evidence in the research notes that this move is tied to the Europol report, and short-term price action is driven by many factors. Still, the quantum conversation is gaining institutional momentum.
IBM said in July that it expects quantum computing to generate substantial commercial revenue over the coming two to three years, with a roadmap targeting a fault-tolerant quantum computer by 2029. Microsoft shares a similar 2029 target for scalable quantum computing. A 2025 poll of 32 experts estimated the likelihood that a machine could crack RSA-2048 encryption within 24 hours over the next ten years at 28% to 49%. In June, Coinbase's quantum advisory council urged developers to begin post-quantum migration efforts. Ripple and the Stellar Development Foundation have each published migration roadmaps. And in July, nine companies—BlackRock, Coinbase and Strategy among them—pledged a combined $15 million over three years toward Bitcoin security research, quantum defenses included.
What to Watch Next
Compliance windows are narrowing. The EU's NIS Cooperation Group urged member states to have a post-quantum transition plan in place by the end of 2026. Under NIST's proposal, today's most widely used public-key setups would be deprecated by 2030, with classical public-key cryptography retired entirely by 2035. Europol backs a working group steered by the European Commission—bringing in Europol, ENISA and the EU Anti-Money Laundering Authority—to give policymakers consistent briefings. And a growing number of Bitcoin researchers and institutions now treat 2029 as the deadline by which workable quantum-resistant migration plans must exist.
Europol's broader position is that the likeliest outcome is proactive adaptation rather than systemic collapse. That is no grounds for complacency—rather, it is an argument for a staged transition built on wallet upgrades, post-quantum cryptography and ecosystem-wide coordination. For holders, the crucial question isn't whether quantum computers will show up tomorrow, but whether the Bitcoin network can pull off a migration before they do.
FAQ
What is Bitcoin quantum risk?
Bitcoin quantum risk is the prospect that a future quantum computer might break the public-key cryptography safeguarding Bitcoin wallets, enabling an attacker to derive a private key from a public key and spend the funds. Europol maintains that the blockchain's hash functions are considerably more resistant, which makes wallets the main point of exposure.
Why did Europol publish a report on quantum computing and cryptocurrencies?
Europol's European Cybercrime Centre issued the report to make clear where the genuine quantum exposure lies and to push for a phased shift to quantum-resistant cryptography. It released a second report as well, on harvest-now-decrypt-later attacks, prepared with Spain's University Carlos III of Madrid.
How many bitcoin are in addresses with exposed public keys?
CoinDesk reports roughly 6.9 million bitcoin sitting in addresses with exposed public keys. A May estimate from Glassnode, cited by Decrypt, gives 6.04 million BTC, or 30.2% of issued supply. Those keys can't be retroactively secured, leaving migration as the only path for such wallets.
Market snapshot
Prices at the time of writing (Oct 7, 2026 15:15 UTC).
- Bitcoin (BTC): $82,964.00 — 24h -4.19%
Related reading
- IMF El Salvador Bitcoin Deal: $138M Disbursed, No New BTC
- Bitcoin Rally Pause: Traders Eye Correction as BTC Stalls
- Shielded Bitcoin Proposal: Privacy Without Changing BTC
More in News.
Sources
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices are highly volatile — always do your own research before investing.
bitcoin quantum europol security cryptography