Europol released two reports on Oct. 7, calling on institutions, policymakers and the crypto industry to begin preparing now for quantum computing. One of the reports says the main weak point for cryptocurrencies under a quantum attack is wallet keys, not the blockchain itself.
Wallet keys, not the blockchain, are the main exposure point
The report, titled Quantum Computing and Cryptocurrencies and written by Europol’s European Cybercrime Centre, challenges the prediction that quantum computing will inevitably cause cryptocurrencies to collapse. It says the primary exposure lies in the cryptographic keys used to control wallets and authorize transactions.
According to the report, a sufficiently powerful quantum computer could derive a private key from a public key, allowing an attacker to move funds without the holder’s knowledge. By contrast, the cryptographic hash functions that underpin blockchain integrity are relatively more resistant to quantum attacks. Europol said distinguishing between those two areas is key to understanding the threat and directing protective resources where they are most needed.
Europol calls for a phased transition
The report recommends a phased move to post-quantum cryptography, alongside improvements in wallet security and key management. It says blockchain developers, wallet providers, policymakers and users all have responsibilities in that process.
Europol also said coordinated upgrades are especially difficult on decentralized networks, making early preparation necessary. The crypto industry, it said, needs coordination at both the protocol and wallet level and should clearly inform users about future upgrade and migration requirements.
Second report examines “harvest now, decrypt later”
A separate report, Harvest Now, Decrypt Later, was produced by Europol together with Universidad Carlos III de Madrid in Spain. It looks at the risk that attackers may collect and store encrypted data now, then decrypt it later once computing capacity becomes sufficient.
That approach does not require a quantum computer at the time of collection. The report says it is especially relevant for information that needs to remain confidential for long periods, including government communications, intellectual property, medical records and law enforcement files.
No clear evidence of large-scale use so far
The report says there is currently no clear evidence that this method is being used at scale, because it demands major storage, computing and technical resources. The most likely targets are high-value data that remains sensitive over the long term.
Europol also said the timeline for mature quantum capability remains uncertain, but argued that this should not be the main focus because system adjustments and security upgrades take time. Whatever form the threat eventually takes, it said systems should pursue “crypto agility” so they can switch to new encryption algorithms in time.

