Europol says quantum computers threaten exposed crypto wallets, not blockchains

Editorial illustration: A violet beam from a cylindrical apparatus strikes a metal key attached to a black wallet, with linked transparent blocks in the background.

In brief

  • Crypto wallets, not blockchains, are the main exposure point for future quantum attacks, Europol says.
  • Quantum computers capable of the attack don't exist yet; Europol gave no timeline.
  • Europol urged developers, miners, exchanges and users to begin a phased post-quantum transition now.
  • A 2024 study cited by Europol puts a full bitcoin UTXO migration at 76+ days of block space.

Wallets, not ledgers

The distinction matters. Europol said the hash functions securing blockchain history, including bitcoin mining, remain far more resistant to quantum attacks than the public-key cryptography that controls wallets. On bitcoin, that layer is ECDSA (the mechanism that proves ownership of coins and authorizes transfers on the network).

So the risk isn't a rewritten ledger. It's ownership. CoinDesk framed the immediate concern as the ownership of assets held in wallets, not whether a quantum computer could rewrite the bitcoin blockchain.

Machines capable of that attack don't exist yet, and Europol didn't predict when they will.

“Cryptocurrencies will not collapse due to quantum computing,” Europol said.

The agency said proactive adaptation, rather than systemic collapse, was the most likely outcome.

The Satoshi-era problem

Addresses from Bitcoin's earliest days (the so-called Satoshi era) already have public keys visible onchain, and Europol said exposed keys can't be made safe retroactively. CoinDesk, which didn't give a source for the figure, put the amount sitting in addresses with exposed public keys at roughly 6.9 million bitcoin. The outlet also described a debate in the bitcoin community over whether to freeze BTC in Satoshi-era wallets.

Migration eats block space

Europol urged the industry to begin a phased transition now through wallet upgrades, post-quantum cryptography and coordination among developers, miners, exchanges and users. It won't be quick. A 2024 study cited by Europol estimated that converting every bitcoin UTXO to a quantum-resistant format would take at least 76 days of cumulative block space; reserving 25% of each block for the job would stretch that to about 300 days.

Size is another hurdle. The report said new post-quantum signature schemes can be 10 to 120 times larger than bitcoin's current ECDSA signatures.

CoinDesk reported that bitcoin researchers and institutions increasingly see 2029 as the point by which credible quantum-resistant migration plans need to be in place. Its read is that the hard part isn't finding replacement cryptography, it's persuading a decentralized network to adopt it before exposed wallets become targets.

Frequently asked questions

Can quantum computers break the bitcoin blockchain itself?

Europol said the hash functions that secure blockchain history, including bitcoin mining, remain far more resistant to quantum attacks than wallet cryptography. The agency identified wallets as the main exposure point, since a sufficiently powerful quantum computer could derive a private key from a public key and spend the funds.

When will quantum computers be able to attack crypto wallets?

Europol said quantum computers capable of such attacks don't exist yet, and it didn't predict when they will. Separately, CoinDesk reported that bitcoin researchers and institutions increasingly see 2029 as the point by which credible quantum-resistant migration plans need to be in place.

How long would a quantum-resistant bitcoin migration take?

A 2024 study cited by Europol estimated that converting every bitcoin UTXO to a quantum-resistant format would require at least 76 days of cumulative block space. Reserving 25% of each block for the migration would stretch that to about 300 days, and post-quantum signatures can be 10 to 120 times larger than ECDSA signatures.