Europol has issued two reports warning that future quantum computers could threaten cryptocurrency wallets and long-lived encrypted data, urging the crypto industry and policymakers to begin security preparations now. The European Union law enforcement agency published the reports on Oct. 7, cautioning that cryptocurrency wallets are the primary point of exposure to quantum threats.
The first report, Quantum Computing and Cryptocurrencies, produced by Europol's European Cybercrime Centre, explains that wallets rely on a public-private key pair. A sufficiently powerful quantum computer could derive a private key from an exposed public key, allowing an attacker to spend funds without authorization. Europol did not say current quantum machines can break cryptocurrency security, but it recommended a phased transition to quantum-resistant cryptography and stronger wallet security.
According to the report, blockchain hash functions are largely resistant to quantum attacks, but wallets whose public keys are already visible on-chain cannot be secured after the fact. Blockchain analytics firm Glassnode estimated that 6.04 million BTC, or 30.2% of issued supply, has already had its public key exposed. Europol said the only solution for those wallets is pre-emptive migration, moving funds to new wallets before an attack becomes possible.
The report also cited a study estimating that migrating every unspent Bitcoin transaction output would require at least 76 days of cumulative network downtime, or roughly 300 days if the work occupied 25% of each block. NIST-standardized post-quantum signatures are 10 to 120 times larger than Bitcoin's current ECDSA signatures, threatening to overload block space, raise fees and slow confirmations.
Europol pointed to IBM's road map targeting a fault-tolerant quantum computer by 2029 and Microsoft's expectation of scalable quantum computing by the same year. It also noted that Google research has lowered resource estimates for attacking elliptic curve cryptography used by Bitcoin. Coinbase's quantum advisory council urged developers in June to begin post-quantum migration work, while Ripple and the Stellar Development Foundation have published migration roadmaps. In July, nine firms including BlackRock, Coinbase and Strategy pledged $15 million over three years for Bitcoin security research, including quantum defenses.
The second report, Harvest Now, Decrypt Later, developed with Spain's University Carlos III of Madrid, examines attackers who collect encrypted data today to decrypt it later. Europol found no clear evidence that such attacks are being systematically exploited at scale, but warned that widely used protocols such as TLS, SSH and OpenPGP are susceptible. The EU's financial supervisors flagged the same tactic in September, and the NIS Cooperation Group recommended member states adopt a post-quantum migration strategy by the end of 2026.
Meanwhile, the U.S. National Institute of Standards and Technology has finalized three post-quantum cryptography standards, FIPS 203, FIPS 204 and FIPS 205, and has proposed deprecating today's most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035.
Bitcoin developers are already discussing migration through draft BIP-361, which proposes moving away from legacy ECDSA and Schnorr signatures after a post-quantum output type becomes available. Institutional custodian BitGo and Silence Laboratories have tested post-quantum multiparty computation signing, and BitGo later introduced tools to measure public-key exposure and consolidate outputs. Coinbase is designing infrastructure to support different post-quantum signature schemes, while Galaxy Digital created a $5 million program to fund Bitcoin quantum-resistant signature research and migration tools.