Europol says crypto wallet keys are the main exposure point in a quantum attack

Europol says crypto wallet keys are the main exposure point in a quantum attack

N
News Editor
2026-10-07 10:55:51
Europol on Wednesday released two reports urging organizations, policymakers and the crypto industry to prepare now for the security risks tied to quantum computing. The agency’s European Cybercrime Centre said crypto wallet keys represent the main exposure point, while the hash functions used to secure blockchains remain broadly resistant to quantum attacks for now. According to the report, a sufficiently powerful quantum computer could derive private keys from already exposed public keys, allowing attackers to move funds without authorization. Wallets whose public keys are already visible on-chain cannot be protected after the fact, meaning holders would need to move assets to new wallets before such an attack becomes possible. Europol also cited a May estimate from Glassnode showing that 6.04 million BTC, or 30.2% of issued supply, already have exposed public keys. A separate report said common protocols including TLS, SSH and OpenPGP face a “harvest now, decrypt later” risk, though Europol said there is no clear evidence that the method has been used at scale so far.

Europol published two reports on Wednesday calling on organizations, policymakers and the cryptocurrency industry to prepare for quantum-computing threats now.

The agency’s European Cybercrime Centre said crypto wallet keys are the main exposure point for quantum attacks, while the hash functions used to secure blockchains still appear broadly quantum-resistant at this stage.

Wallets with exposed public keys face the clearest risk

The report said a sufficiently capable quantum computer could derive a private key from an exposed public key, giving an attacker a way to transfer assets without authorization. For wallets whose public keys are already visible on-chain, protection cannot be added after the fact. Holders would need to move funds to new wallets before an attack becomes possible.

Glassnode estimated in May that 6.04 million BTC already have exposed public keys, equal to 30.2% of issued supply.

Migration would be costly

Europol said post-quantum signatures standardized by the National Institute of Standards and Technology, or NIST, are 10 to 120 times larger than the ECDSA signatures Bitcoin currently uses. Migrating all Bitcoin unspent transaction outputs would require at least 76 cumulative days of downtime, according to the report.

Common internet protocols were also flagged

A second Europol report said widely used protocols including TLS, SSH and OpenPGP face a “harvest now, decrypt later” risk. Still, the report added that there is no clear evidence this approach has been exploited at scale so far.

For payments, Europol said the more direct quantum risk is not retrospective decryption, but real-time interception during the short window before a transaction is confirmed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.