As the possibility grows that quantum computers could threaten cryptocurrency security systems, the European Union law enforcement agency Europol urged the industry and policymakers to take pre-emptive action. It identified cryptocurrency wallets that use private and public keys, rather than the blockchain itself, as the most vulnerable point to quantum attacks.
On Oct. 7 local time, blockchain media outlet Decrypt reported that Europol presented the risks quantum computing could pose to the crypto ecosystem and possible responses in 2 reports released that day.
The European Cybercrime Centre under Europol described cryptocurrency wallets as a "key exposure point" to quantum threats. Wallets use private keys to sign transactions and public keys to verify them. Europol explained that if a sufficiently powerful quantum computer emerges, it could be possible to derive a private key from a public key and steal funds.
In the crypto industry, the point at which quantum computers materially threaten existing cryptographic systems is often called "Q-Day".
Europol assessed that the emergence of quantum computers would not mean cryptocurrencies and blockchains immediately collapse. It judged that hash functions linking the blockchain and mining-based structures are relatively safe areas. It said the computing power required to break a 256-bit hash is "astronomically high" at currently foreseeable technology levels.
The problem, Europol said, is wallets whose public keys are already exposed on the blockchain. It said such wallets would be hard to protect after quantum attacks become a reality, and stressed that the only practical response is to move funds to quantum-resistant wallets before attacks begin.
A substantial amount of bitcoin is estimated to already be in a state of public-key exposure. Glassnode estimated that about 6.04 million BTC was exposed to public keys as of May, accounting for about 30.2 percent of total bitcoin issuance.
A transition to quantum-resistant systems is also not easy. Quantum-resistant signature schemes standardised by the U.S. National Institute of Standards and Technology are currently about 10 to 120 times larger than the ECDSA signatures used by bitcoin. Applying them could increase the burden on block space, leading to higher fees and delays in transaction confirmation.
Europol, citing a 2024 study, analysed that converting all unspent transaction outputs to a quantum-safe state could require a cumulative minimum of 76 days of network downtime. If only 25 percent of each block's capacity is used for the conversion work, it said the period could extend to about 300 days.
Concern is also being fuelled by signs that quantum computer development is speeding up. Europol noted that IBM is targeting a fault-tolerant quantum computer by 2029, and that Microsoft also expects scalable quantum computing around the same time.
In a survey of 32 experts conducted in 2025, the probability that equipment capable of cracking RSA-2048 within 24 hours would emerge within the next 10 years was put at 28 to 49 percent. Google research and a computing race using artificial intelligence were also cited as factors lowering resource estimates needed to attack elliptic-curve cryptography used in bitcoin.
The crypto industry has also begun responding. Coinbase's Quantum Advisory Committee urged developers in June to start work on a quantum-resistant transition now. Ripple and the Stellar Development Foundation also each released a quantum-resistant transition roadmap.
In July, 9 companies including BlackRock, Coinbase and Strategy agreed to provide a total of $15 million over the next 3 years for bitcoin security research and quantum defence.
Europol also focused on "harvest now, decrypt later" attacks across the broader internet, not just cryptocurrency. In that method, attackers collect encrypted data now and decrypt it later when quantum computers with sufficient performance emerge.
Key security protocols such as TLS, SSH and OpenPGP could also be affected depending on configuration and key management. Europol said there is currently no clear evidence that such attacks are being exploited on a large, systematic scale. It analysed that given the large resources required, government communications or corporate confidential information could be more realistic targets.
In crypto payments, real-time attacks during the transaction process were identified as a more direct threat than post-hoc decryption. That is because a so-called "just-in-time attack" may be possible, in which a quantum computer calculates a private key and steals funds during the short window after a public key is exposed in the transaction process and before it is finalised in a block.
Europol accordingly recommended a phased transition to quantum-resistant cryptographic technology, along with stronger wallet security and improved key management. It said the European Union is also speeding up its response. The EU's 3 financial supervisory authorities warned of quantum computer threats in September, and the EU NIS Cooperation Group recommended member states develop quantum-resistant transition strategies by the end of 2026.
Europol also proposed forming a task force led by the European Commission, in which Europol, the EU cybersecurity agency and the EU anti-money laundering authority would regularly share relevant developments with policymakers.
Europol's warning does not mean quantum computers will immediately bring down bitcoin. It is focused on the need to change vulnerable wallets and cryptographic systems before attacks become reality. It said a key future task will be how to move large amounts of bitcoin with already exposed public keys to quantum-safe systems.