Europol published two reports on Wednesday covering security risks tied to quantum computing, and the report focused on cryptocurrencies identifies wallets as the most exposed part of the system. The agency called on organizations, policymakers and the crypto industry to start preparing now.
In the report, Europol’s European Cybercrime Centre said the keys used to control wallets and authorize transactions are the main point of exposure. A quantum computer with sufficient power could derive a wallet’s private key from its public key, allowing an attacker to spend the funds.
Europol said the hash functions that secure the blockchain itself remain largely resistant to quantum attacks. Machines with that capability do not yet exist, and the agency said in its press release that the timeline for such capabilities remains uncertain.
Unchained reported in April that a Google paper pointed to 2029 as the year quantum computers could break the cryptography securing Bitcoin and Ethereum.
Europol says collapse is not the base case
The report concluded that 「Cryptocurrencies will not collapse due to quantum computing」, while adding that long-term security will require proactive defense.
Its main findings include:
- Proactive adaptation is the more likely outcome, rather than systemic collapse.
- Wallet providers should begin testing and deploying wallets enabled for post-quantum cryptography.
- Blockchain projects should build post-quantum algorithms into their core protocols.
- Users should move funds to quantum-resistant wallets once those wallets become available.
For wallets with public keys that are already exposed, the report said there is no cryptographic fix. The only solution it offered is to move funds to new, unexposed wallets before any attack takes place.
Bitcoin migration could take months and consume block space
Europol cited a 2024 paper that estimated the minimum cumulative downtime required to upgrade every Bitcoin UTXO to post-quantum signatures at 76 days.
As one example, the agency said the migration would take about 300 days if only one-quarter of each block’s capacity were allocated to the process.
Europol also said signatures from NIST-standardized post-quantum schemes are 10 to 120 times larger than the ECDSA signatures Bitcoin uses today. That, it warned, could overload block space and push fees higher.
Second report looks at store-now-decrypt-later attacks
The second report examines attackers who collect encrypted data now and wait to decrypt it once more powerful computers become available.
That report was developed with University Carlos III of Madrid. Europol said there is no clear evidence that this technique is being used systematically at scale.

