Europol on Wednesday published two reports urging industry participants and policymakers to prepare early for quantum-computing threats.
Wallets identified as the main exposure point
One of the reports, Quantum Computing and Cryptocurrencies, was written by Europol’s European Cybercrime Centre. It says crypto wallets are the 「main exposure point」 for quantum threats. Wallets rely on private keys to authorize transactions and on public keys for verification. According to the report, a sufficiently powerful quantum computer could derive a private key from an exposed public key, allowing an attacker to move funds without authorization. The report refers to that point as Q-Day.
It adds that the hash functions used to link blocks and support mining are broadly quantum resistant.
Report says crypto would not collapse, but calls for proactive defense
The report argues that cryptocurrencies would not collapse because of quantum computing, but it recommends 「proactive defense」. That includes a phased transition to post-quantum cryptography, along with stronger wallet security and better key management.
For wallets whose public keys have already been exposed on-chain, the report says there is no remedy after the fact. The only solution, it says, is to migrate in advance.
Bitcoin migration could bring capacity and cost trade-offs
Glassnode estimated in May this year that 6.04 million BTC, or 30.2% of issued supply, already had exposed public keys.
The report also says upgrading Bitcoin would carry costs. Post-quantum signatures standardized by the National Institute of Standards and Technology, or NIST, are 10 to 120 times larger than the Elliptic Curve Digital Signature Algorithm, or ECDSA, signatures currently used by Bitcoin. That could overload block space and push transaction fees higher. Citing a 2024 study, the report says migrating all unspent transaction outputs would require at least 76 days of cumulative downtime.
Second report examines harvest-now-decrypt-later attacks
The second report, Harvest Now, Decrypt Later, was completed with Universidad Carlos III de Madrid in Spain. It studies the practice of collecting encrypted data today for decryption at a later date, and finds risks in protocols including TLS, SSH and OpenPGP.

