Europol on Wednesday released two reports urging organizations, policymakers and the cryptocurrency industry to start preparing for quantum computers capable of breaking widely used encryption.

The first report, Quantum Computing and Cryptocurrencies, was produced by Europol’s European Cybercrime Centre. It identifies cryptocurrency wallets as "the primary point of exposure to quantum threats." Wallets depend on a key pair: a private key that authorizes transactions and a public key that the network uses for verification.
According to the report, a sufficiently powerful quantum computer could derive a private key from an exposed public key, allowing an attacker to spend funds without authorization. The report refers to that point as Q-Day.
Europol says cryptocurrencies would not collapse
The report says the hash functions that link blocks and support mining are largely quantum-safe. Breaking a 256-bit hash would still require a number of operations it describes as "astronomically high with foreseeable technology."
Its conclusion states that "Cryptocurrencies will not collapse due to quantum computing," while also recommending "proactive defence" to protect long-term security. Europol calls for a phased transition to quantum-resistant cryptography, together with stronger wallet security and better key management.
Exposed public keys leave only one option
For wallets whose public keys are already visible on-chain, the report says there is no way to secure them after the fact. "The only solution is pre-emptive migration," meaning owners would need to move funds to new wallets before any attack takes place.
Blockchain analytics firm Glassnode estimated in May that 6.04 million BTC, equal to 30.2% of the issued supply, has already had its public key exposed.
Bitcoin migration would come with heavy trade-offs
The report says upgrading Bitcoin would carry significant costs. Post-quantum signatures standardized by the U.S. National Institute of Standards and Technology are 10 to 120 times larger than the ECDSA signatures Bitcoin uses today. That, Europol says, could overload block space, raise fees and slow confirmation times.
It cites a 2024 study estimating that migrating every unspent transaction output would require at least 76 days of cumulative downtime. If the work used only 25% of each block, the process would take roughly 300 days.
2029 appears repeatedly in industry and research timelines
The report points to IBM’s roadmap, which targets a fault-tolerant quantum computer by 2029. It also cites a 2025 survey in which 32 experts put the probability of a machine breaking RSA-2048 encryption in 24 hours within the next decade at 28% to 49%.
Microsoft also expects scalable quantum computing by 2029. Europol further notes that Google research published in March, along with an AI-assisted competition in September, both reduced resource estimates for attacking the elliptic curve cryptography used by Bitcoin.
On the industry side, Coinbase’s quantum advisory council urged developers in June to begin post-quantum migration work immediately. Ripple and the Stellar Development Foundation have also published migration roadmaps. In July, nine firms including BlackRock, Coinbase and Strategy pledged a combined $15 million over three years for Bitcoin security research, including quantum defenses.
The second report focuses on "harvest now, decrypt later"
The second paper, Harvest Now, Decrypt Later, was developed with Spain’s University Carlos III of Madrid. It examines attackers who collect encrypted data today and decrypt it later once quantum capabilities improve.
The report found that widely used protocols including TLS, SSH and OpenPGP are susceptible, with the level of risk depending on configuration and key management.
It says there is "currently no clear evidence" that this technique is being exploited systematically at scale. Given the resources required, government communications and confidential business data are described as the most plausible targets.
EU bodies are already setting migration deadlines
The article notes that the European Union’s three financial supervisors flagged the same tactic in September. They warned that a quantum computer capable of breaking encryption could arrive before the technology has any viable commercial use.
The EU’s NIS Cooperation Group has recommended that member states adopt a post-quantum migration strategy by the end of 2026.
Payments face a more immediate interception threat
For payments, the cryptocurrency report says real-time interception is a more immediate quantum risk than retrospective decryption. It describes a "just-in-time" attack in which a quantum computer derives a private key during the short window between a transaction exposing its public key and that transaction being confirmed.
Europol recommends a European Commission-led working group that would include Europol, the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, with regular briefings for policymakers.
According to the second report, the U.S. National Institute of Standards and Technology has proposed deprecating today’s most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035.

