Europol is urging cryptocurrency developers, exchanges and users to start preparing for post-quantum security upgrades now, with the goal of preventing future attackers from using quantum computers to access vulnerable funds.
In a report released Wednesday, the European law enforcement agency said crypto wallets are likely to be the main target of future quantum attacks rather than the blockchains themselves.
Quantum computers capable of performing such attacks have not yet been developed, and Europol did not estimate when they could become available. Instead, the agency said the industry is more likely to experience “proactive adaptation, rather than systemic collapse.”
Europol recommended a gradual migration to quantum-resistant technology, including wallet upgrades, post-quantum cryptography and coordination between developers, miners, exchanges and cryptocurrency users.
Bitcoin researchers and institutions are increasingly pointing to 2029 as the timeframe by which credible plans for quantum-resistant migration should be established. IBM said in July that it expects quantum computing to begin generating significant commercial revenue within the next two to four years.
The European Cybercrime Center warned that a sufficiently powerful quantum computer could potentially calculate a private key from a publicly exposed key and then use it to move the funds associated with that wallet.
Quantum Risk Centers on Exposed Wallet Keys
Europol said discussions about quantum computing often overlook an important difference between blockchain security and wallet security. Hash functions used to protect blockchain history and support Bitcoin mining are considerably more resistant to quantum attacks than the public-key cryptography used to authorize transactions.
“Cryptocurrencies will not collapse due to quantum computing,” Europol said. The greater concern is that quantum technology could allow attackers to take control of funds in vulnerable wallets, rather than enable them to rewrite Bitcoin’s blockchain.
The problem is especially relevant to Bitcoin addresses from the network’s earliest period, commonly referred to as the Satoshi era. Public keys associated with many of these addresses are already visible on-chain, potentially allowing a sufficiently capable quantum computer to derive their corresponding private keys.
Around 6.9 million BTC are currently held in addresses with exposed public keys. The figure includes early pay-to-public-key outputs as well as many coins that have remained dormant for long periods.
Europol noted that exposed public keys cannot be secured retroactively. That limitation has intensified debate in the Bitcoin community over how Satoshi-era coins should be handled and whether funds in vulnerable addresses should eventually be frozen as the quantum threat becomes more credible.
Bitcoin Faces a Large-Scale Migration Challenge
Moving existing Bitcoin holdings to quantum-resistant technology presents another problem. Europol referenced a 2024 study estimating that converting every Bitcoin unspent transaction output, or UTXO, to a quantum-resistant format would require at least 76 days of cumulative block space.
The same study estimated that dedicating 25% of available block space to the migration would extend the process to roughly 300 days.
Post-quantum cryptographic systems could also require significantly more blockchain space. Europol said newer signature schemes can be 10 to 120 times larger than Bitcoin’s current Elliptic Curve Digital Signature Algorithm, or ECDSA, signatures.
ECDSA is the cryptographic mechanism Bitcoin uses to establish ownership and authorize transfers of funds.
For Bitcoin, the fundamental challenge is therefore not simply developing stronger cryptographic algorithms. The harder task is coordinating a decentralized global network so that wallets, exchanges and other infrastructure migrate to quantum-resistant systems before exposed keys become vulnerable to sufficiently powerful quantum computers.

































