Europol published two reports on Wednesday calling on organizations, policymakers and the cryptocurrency industry to prepare for quantum-computing threats now.
The agency’s European Cybercrime Centre said crypto wallet keys are the main exposure point for quantum attacks, while the hash functions used to secure blockchains still appear broadly quantum-resistant at this stage.
Wallets with exposed public keys face the clearest risk
The report said a sufficiently capable quantum computer could derive a private key from an exposed public key, giving an attacker a way to transfer assets without authorization. For wallets whose public keys are already visible on-chain, protection cannot be added after the fact. Holders would need to move funds to new wallets before an attack becomes possible.
Glassnode estimated in May that 6.04 million BTC already have exposed public keys, equal to 30.2% of issued supply.
Migration would be costly
Europol said post-quantum signatures standardized by the National Institute of Standards and Technology, or NIST, are 10 to 120 times larger than the ECDSA signatures Bitcoin currently uses. Migrating all Bitcoin unspent transaction outputs would require at least 76 cumulative days of downtime, according to the report.
Common internet protocols were also flagged
A second Europol report said widely used protocols including TLS, SSH and OpenPGP face a “harvest now, decrypt later” risk. Still, the report added that there is no clear evidence this approach has been exploited at scale so far.
For payments, Europol said the more direct quantum risk is not retrospective decryption, but real-time interception during the short window before a transaction is confirmed.

