Europol says quantum risk to crypto lies in exposed wallet keys, not blockchains

Europol says quantum risk to crypto lies in exposed wallet keys, not blockchains

N
News Editor
2026-10-07 13:20:54
Europol said the main future quantum-computing risk for cryptocurrencies is not a collapse of blockchains themselves, but the possibility that sufficiently powerful quantum machines could derive private keys from already exposed public keys and drain vulnerable wallets. In a report published Wednesday, the European Union law enforcement agency said wallets are the primary point of exposure, while the hash functions that protect blockchain history, including those used in bitcoin mining, are far more resistant to quantum attacks. The report said about 6.9 million BTC are held at addresses with exposed public keys, including early pay-to-public-key outputs and many long-dormant wallets from Bitcoin’s earliest period. Europol added that exposed keys cannot be made safe retroactively, a point that has fueled debate in the bitcoin community over whether Satoshi-era wallets should eventually be frozen as the quantum threat gets closer. Europol urged developers, miners, exchanges and users to begin a phased migration now through wallet upgrades, post-quantum cryptography and networkwide coordination. It cited a 2024 study estimating that converting every bitcoin UTXO to a quantum-resistant format would require at least 76 days of cumulative block space, or about 300 days if 25% of each block were reserved for the transition. The agency said the harder problem is coordinating adoption across a global decentralized network before vulnerable wallets become targets.

Europol said cryptocurrency wallets, rather than blockchains themselves, are the main point of exposure to future quantum-computing attacks, warning that the most immediate long-term risk is unauthorized spending from wallets with exposed public keys.

In a report published Wednesday, the European Union law enforcement agency said quantum computers capable of carrying out such attacks do not yet exist, and it did not say when they might. Even so, Europol argued that the likely outcome is adaptation rather than failure, writing that 「proactive adaptation, rather than systemic collapse, is the most likely outcome」.

Wallet control is the weak point, not blockchain history

The report, titled Quantum Computing and Cryptocurrencies and issued by Europol’s European Cybercrime Center, drew a distinction it said is often blurred in public warnings about quantum computing.

According to Europol, the hash functions that help secure a blockchain’s history, including bitcoin mining, are much more resistant to quantum attacks than the public-key cryptography used to control wallets. In the agency’s words, 「Cryptocurrencies will not collapse due to quantum computing」.

That means the central concern is ownership of assets held in wallets, not whether a quantum computer could rewrite the bitcoin blockchain. A sufficiently powerful quantum computer could derive a private key from a public key and then spend the associated funds, the report said.

About 6.9 million BTC sit in addresses with exposed public keys

Europol said the distinction matters most for addresses from Bitcoin’s earliest period, often described as the “Satoshi era,” because their public keys are already visible onchain. If quantum hardware becomes powerful enough, those public keys could be used to derive the corresponding private keys.

The report estimated that roughly 6.9 million bitcoin are held at addresses with exposed public keys. That total includes early pay-to-public-key outputs and many long-dormant holdings.

Europol also said exposed keys cannot be made safe retroactively. That problem has already triggered major debate and controversy across the bitcoin community as the question of whether BTC in Satoshi-era wallets should be frozen becomes more pressing alongside the quantum threat.

Europol calls for a phased migration now

The agency urged the industry to begin a phased transition immediately. It pointed to wallet upgrades, post-quantum cryptography and coordination among developers, miners, exchanges and users as the main steps needed to reduce future risk.

Europol said the harder task is not simply finding replacement cryptography. The bigger challenge is persuading a global decentralized network to adopt it before exposed wallets become attractive targets.

Bitcoin researchers and institutions increasingly view 2029 as the point by which credible quantum-resistant migration plans need to be in place. IBM said in July that it expects quantum computing to generate significant commercial revenue in the next two to four three years.

Migration would consume substantial block space

Updating the network itself may be the more difficult engineering problem. Europol cited a 2024 study estimating that converting every bitcoin unspent transaction output, or UTXO, to a quantum-resistant format would require at least 76 days of cumulative block space.

If 25% of each block were reserved for that migration, the same study said the process would stretch to about 300 days.

The report added that new post-quantum signature schemes can be 10 to 120 times larger than bitcoin’s current Elliptic Curve Digital Signature Algorithm, or ECDSA, signatures. ECDSA is the cryptographic mechanism used to prove ownership of bitcoin and authorize transfers on the network.

For Europol, the issue is no longer just whether replacement cryptography exists. The real test is whether the bitcoin network can coordinate a global migration before vulnerable wallets become targets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.