The European Union's law enforcement agency, Europol, has warned that future quantum computers could threaten cryptocurrency wallets, potentially allowing attackers to access funds without their owners' permission.
In a report published on October 7, titled Quantum Computing and Cryptocurrencies, Europol explained that the primary vulnerability lies in public-key cryptography rather than the underlying blockchain networks.
The agency emphasized that quantum computers powerful enough to exploit these weaknesses do not currently exist. However, developers, exchanges and cryptocurrency holders should begin preparing for the eventual transition to quantum-resistant security.
Europol recommended phased upgrades to wallets, cryptographic systems and blockchain infrastructure, supported by cooperation among developers, miners, exchanges and users.
Private Keys Are the Main Security Concern
The report highlights an important distinction between the cryptographic technologies protecting blockchain networks and those securing individual cryptocurrency wallets.
Bitcoin relies on hash functions to support mining and protect blockchain integrity, while digital signatures allow users to authorize transactions using private keys.
According to Europol, the signature systems present a more immediate concern because a sufficiently powerful quantum computer could potentially calculate a private key from its corresponding public key.
An attacker obtaining that private key could then authorize transactions and transfer the associated cryptocurrency.
The agency stressed that quantum attacks against wallet ownership do not automatically mean blockchain histories can be rewritten.
Instead, the danger centers on whether attackers could gain control of assets whose public keys are already visible.
Nearly 6.9 Million Bitcoin Could Be Exposed
The potential vulnerability is particularly significant for Bitcoin holdings dating back to the network's earliest years.
Some older Bitcoin transaction formats, including pay-to-public-key outputs, expose public keys directly onchain. Other addresses reveal their public keys when funds are spent.
Researchers estimate that approximately 6.9 million BTC are associated with outputs containing exposed public keys, including some long-dormant holdings from Bitcoin's early history.
These coins are not currently compromised. However, their exposed keys could become targets if quantum computers eventually achieve the capabilities necessary to break existing signature systems.
Europol noted that previously exposed public keys cannot simply be made secret again. Owners would need to transfer their funds to addresses protected by stronger cryptographic mechanisms once those become available.
The situation becomes more complicated when private keys have been lost or wallets remain permanently inactive.
This has generated debate within the Bitcoin community about whether potentially vulnerable coins should eventually face restrictions, particularly those associated with the Satoshi-era supply.
Bitcoin Migration Could Take Months
Developing quantum-resistant cryptography is only part of the challenge. Implementing it across Bitcoin's decentralized network could require substantial time and coordination.
Europol cited a 2024 study estimating that migrating every Bitcoin unspent transaction output, or UTXO, to a quantum-resistant format would require at least 76 days of cumulative block space.
If migration transactions occupied only 25% of available block capacity, the process could take approximately 300 days.
Another complication involves transaction size.
Some post-quantum signature schemes produce signatures 10 to 120 times larger than Bitcoin's traditional ECDSA signatures.
Larger signatures could increase transaction costs, create additional demand for block space and complicate a network-wide transition.
The estimates demonstrate why a successful migration would require preparation well before quantum attacks become practical.
Europol Calls for Early Security Upgrades
Europol urged cryptocurrency developers, exchanges and wallet providers to begin preparing for post-quantum cryptography, rather than waiting for quantum computers to demonstrate a successful attack.
Some Bitcoin researchers and institutions have identified 2029 as an important target for establishing credible migration plans, although Europol did not predict when quantum computers capable of breaking existing wallet signatures might emerge.
The agency's recommendations focus on gradually introducing stronger cryptographic protections while maintaining coordination across the cryptocurrency ecosystem.
For Bitcoin, the central challenge involves securing existing holdings without disrupting a network that depends on decentralized decision-making and broad agreement among participants.
The report ultimately presents quantum computing as a significant long-term security challenge, but not an inevitable catastrophe.
Bitcoin's future security will depend on whether the industry can adopt quantum-resistant signatures and migrate vulnerable funds before sufficiently powerful quantum computers become available.



