Quantum Risks and Bitcoin Wallet Exposure Across EU
Europol published two companion reports warning that quantum computing poses a specific, manageable threat to cryptocurrencies: not the blockchain itself, but the wallets that hold keys. The agency’s European Cybercrime Centre found that public-key cryptography in wallets is the “primary point of exposure,” because a sufficiently powerful quantum computer could derive a private key from an exposed public key and authorize transactions without the owner’s consent. By contrast, hash functions that secure blockchains, such as Bitcoin’s SHA-256, are described as largely resistant to foreseeable quantum attacks, leading Europol to conclude that “cryptocurrencies will not collapse due to quantum computing.”
The reports emphasize that wallets whose public keys have already been revealed on-chain cannot be retroactively secured. The only practical remedy for those is pre-emptive migration: moving funds to new addresses before any capable quantum attacker emerges. Analytics firm Glassnode estimated in May that 6.04 million BTC — about 30.2% of issued supply — already had exposed public keys. Europol’s reporting cites a similar ballpark, stating roughly 6 to 6.9 million BTC, or about 30% of supply, sits in addresses with exposed public keys. Much of this exposure stems from address reuse and exchange custody practices; Taproot and some early address formats also reveal keys by default once spent from.
Technical and coordination challenges make migration costly. Post-quantum signatures standardized by NIST are 10 to 120 times larger than the ECDSA signatures used today, which could overload block space, increase fees, and slow confirmations. A cited study estimates that migrating every unspent transaction output would require at least 76 days of cumulative network downtime; spreading the work across 25% of each block would stretch that to roughly 300 days. The companion report, “Harvest Now, Decrypt Later,” warns that attackers might collect encrypted data now to decrypt later when quantum resources exist, noting no clear evidence of widespread exploitation to date but highlighting plausible targets like government and confidential business communications.
Europol recommends a phased transition to quantum-resistant cryptography, improvements to wallet security and key management, and a commission-led working group including ENISA and other authorities to brief policymakers. The reports also reference industry responses: Coinbase’s advisory council urged post-quantum migration work, Ripple and the Stellar Development Foundation published roadmaps, and several firms pledged funding for Bitcoin security research. Europol’s overall message is cautious: the protocol layer appears robust for now, but individual holders and custodians must act proactively to protect exposed keys before a capable quantum machine arrives.