In brief
- Europol, the European Union's law enforcement agency, published two reports Wednesday urging the crypto industry and policymakers to prepare now for quantum computing threats.
- Its cybercrime center found that wallet keys are the primary point of exposure, while the hash functions securing blockchains remain largely resistant to quantum attacks.
- A study cited by Europol estimates that making every Bitcoin output quantum-safe would require at least 76 days of cumulative network downtime.
EU law enforcement agency Europol published two reports Wednesday urging organizations, policymakers and the cryptocurrency industry to begin preparing now for quantum computers capable of breaking widely used encryption.
The first, Quantum Computing and Cryptocurrencies, produced by Europol's European Cybercrime Centre, identifies cryptocurrency wallets as "the primary point of exposure to quantum threats." Wallets rely on a pair of keys: a private key that authorizes transactions and a public key the network uses to verify them.
A sufficiently powerful quantum computer could derive a private key from an exposed public key, letting an attacker spend funds without authorization, the report says, a moment that’s often referred to as Q-Day.
The hash functions that link blocks and underpin mining are largely quantum-safe, the report says, since breaking a 256-bit hash would still take a number of operations it calls "astronomically high with foreseeable technology."
"Cryptocurrencies will not collapse due to quantum computing," the report concludes, while recommending “proactive defence” to ensure their long-term security. It recommends a phased transition to quantum-resistant cryptography, alongside improvements to wallet security and key management.
Wallets whose public keys are already visible on-chain cannot be secured after the fact. For those, "the only solution is pre-emptive migration," the report says, with owners moving funds to new wallets before any attack. Blockchain analytics firm Glassnode estimated in May that 6.04 million BTC, or 30.2% of the issued supply, has already had its public key exposed.

Upgrading Bitcoin carries its own costs. NIST-standardized post-quantum signatures are 10 to 120 times larger than the ECDSA signatures Bitcoin uses today, which the report says threatens to overload block space, raise fees and slow confirmations. It cites a 2024 study estimating that migrating every unspent transaction output would require at least 76 days of cumulative downtime, or roughly 300 days if the work took up 25% of each block.
The report cites IBM's roadmap, which targets a fault-tolerant quantum computer by 2029, and a 2025 survey in which 32 experts put the odds of a machine breaking RSA-2048 encryption in 24 hours within the next decade at 28% to 49%.
Microsoft likewise expects scalable quantum computing by 2029, while Google research in March and an AI-assisted competition in September both lowered resource estimates for attacking the elliptic curve cryptography Bitcoin uses.
Coinbase's quantum advisory council urged developers in June to begin post-quantum migration work now, while Ripple and the Stellar Development Foundation have published migration roadmaps. In July, nine firms including BlackRock, Coinbase and Strategy pledged a combined $15 million over three years for Bitcoin security research, including quantum defenses.
“Harvest now, decrypt later”
The second report, Harvest Now, Decrypt Later, developed with Spain's University Carlos III of Madrid, examines attackers who collect encrypted data today to decrypt it later. It found widely used protocols such as TLS, SSH and OpenPGP susceptible, with risk varying by configuration and key management.
There is "currently no clear evidence" that the technique is being systematically exploited at scale, the report says. The resources required make government communications and confidential business data the most plausible targets.
The European Union's three financial supervisors flagged the same tactic in September, warning that a quantum computer capable of breaking encryption could arrive before the technology has any viable commercial use. The EU's NIS Cooperation Group has recommended that member states adopt a post-quantum migration strategy by the end of 2026.
For payments, the cryptocurrency report says real-time interception poses a more immediate quantum risk than retrospective decryption. It describes a "just-in-time" attack, in which a quantum computer derives a private key during the short window between a transaction exposing its public key and that transaction being confirmed.
Europol recommends a European Commission-led working group, including Europol, the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, to brief policymakers regularly. The U.S. National Institute of Standards and Technology has proposed deprecating today's most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035, according to the second report.

