Europol urges early action on quantum threats in two new reports

Europol urges early action on quantum threats in two new reports

N
News Editor
2026-10-07 10:51:16
Europol on Wednesday released two reports calling on industry participants and policymakers to prepare for quantum-computing risks before they become operational. One report, written by the agency’s European Cybercrime Centre and titled Quantum Computing and Cryptocurrencies, says crypto wallets are the main point of exposure because a sufficiently powerful quantum computer could derive a private key from an exposed public key and let an attacker move funds without authorization. The report refers to that moment as Q-Day. At the same time, it says the hash functions used to link blocks and support mining are broadly quantum resistant, and argues cryptocurrencies would not collapse because of quantum computing alone. Instead, it recommends proactive defenses, including a phased move to post-quantum cryptography, stronger wallet security and better key management. It also says wallets whose public keys are already exposed on-chain cannot be fixed after the fact and must be migrated in advance. Europol’s second report, completed with Universidad Carlos III de Madrid, examines harvest-now-decrypt-later attacks and identifies risks for protocols including TLS, SSH and OpenPGP.

Europol on Wednesday published two reports urging industry participants and policymakers to prepare early for quantum-computing threats.

Wallets identified as the main exposure point

One of the reports, Quantum Computing and Cryptocurrencies, was written by Europol’s European Cybercrime Centre. It says crypto wallets are the 「main exposure point」 for quantum threats. Wallets rely on private keys to authorize transactions and on public keys for verification. According to the report, a sufficiently powerful quantum computer could derive a private key from an exposed public key, allowing an attacker to move funds without authorization. The report refers to that point as Q-Day.

It adds that the hash functions used to link blocks and support mining are broadly quantum resistant.

Report says crypto would not collapse, but calls for proactive defense

The report argues that cryptocurrencies would not collapse because of quantum computing, but it recommends 「proactive defense」. That includes a phased transition to post-quantum cryptography, along with stronger wallet security and better key management.

For wallets whose public keys have already been exposed on-chain, the report says there is no remedy after the fact. The only solution, it says, is to migrate in advance.

Bitcoin migration could bring capacity and cost trade-offs

Glassnode estimated in May this year that 6.04 million BTC, or 30.2% of issued supply, already had exposed public keys.

The report also says upgrading Bitcoin would carry costs. Post-quantum signatures standardized by the National Institute of Standards and Technology, or NIST, are 10 to 120 times larger than the Elliptic Curve Digital Signature Algorithm, or ECDSA, signatures currently used by Bitcoin. That could overload block space and push transaction fees higher. Citing a 2024 study, the report says migrating all unspent transaction outputs would require at least 76 days of cumulative downtime.

Second report examines harvest-now-decrypt-later attacks

The second report, Harvest Now, Decrypt Later, was completed with Universidad Carlos III de Madrid in Spain. It studies the practice of collecting encrypted data today for decryption at a later date, and finds risks in protocols including TLS, SSH and OpenPGP.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.