EU law enforcement agencies urged developers, exchanges, and users to initiate phased post-quantum migrations immediately to prevent future unauthorized fund transfers.
Cryptocurrency wallets, rather than the underlying blockchains themselves, represent the primary point of exposure to future quantum-computing attacks, Europol warned in a comprehensive report published Wednesday.
While fully functional quantum computers capable of carrying out such advanced cryptographic attacks do not yet exist, and the European Union’s premier law enforcement agency stopped short of predicting an exact timeline for their arrival, the findings emphasize that proactive adaptation, rather than systemic technological collapse, remains the most likely outcome for the digital asset ecosystem. Europol strongly urged the broader industry to begin a phased transition immediately through comprehensive wallet upgrades, the adoption of post-quantum cryptography, and close coordination among developers, miners, exchanges, and everyday users.
The release of the report comes as Bitcoin researchers and financial institutions increasingly focus on the late 2020s as a critical window. Many experts view 2029 as the absolute deadline by which credible, quantum-resistant migration plans need to be formally established and implemented. Meanwhile, commercial hardware developers are pressing forward aggressively; IBM stated in July that it expects quantum computing to generate significant commercial revenue within the next two to four years, signaling rapid advancements in hardware capabilities that heighten the urgency for cryptographic preparedness.
According to Europol’s European Cybercrime Center, which detailed the findings in its newly released report titled Quantum Computing and Cryptocurrencies, a sufficiently powerful quantum computer could theoretically derive a private key from a known public key, granting the attacker the ability to sign transactions and spend the associated funds without authorization.
The agency’s analysis aimed to draw a clear technical distinction that is frequently lost in broader, sensationalized warnings about the dawn of the quantum age: the hash functions that help secure a blockchain’s historical ledger and power processes like Bitcoin mining remain far more resistant to quantum attacks than the public-key cryptography utilized to control individual user wallets.
"Cryptocurrencies will not collapse due to quantum computing," Europol stated in the report. The immediate and pressing concern centers entirely on the secure ownership and control of the digital assets held inside specific wallets, rather than whether a quantum machine could successfully rewrite or subvert the fundamental Bitcoin blockchain.

This vital distinction carries profound implications, particularly for addresses originating from the earliest days of Bitcoin—commonly referred to as the "Satoshi era"—whose public keys have already been exposed and rendered visible directly on the blockchain. A powerful enough quantum computer could potentially exploit those historical keys to calculate the corresponding private keys. Approximately 6.9 million bitcoin currently sit in addresses featuring exposed public keys, a figure that includes early pay-to-public-key outputs and a vast number of long-dormant holdings that have remained untouched for over a decade.
Europol noted that these exposed historical keys cannot be made safe retroactively through standard patches, an intractable architectural reality that has sparked intense debates, fierce controversies, and deep ideological divisions across the global Bitcoin community. As the theoretical quantum threat draws closer, the community continues to grapple with the polarizing dilemma of whether or not to freeze balances held in these vulnerable Satoshi-era wallets.
Beyond addressing historical vulnerabilities, the more logistically difficult task facing the ecosystem today involves updating the operational network itself to withstand future cryptographic threats. Europol cited a 2024 academic study estimating that converting every unspent transaction output, or UTXO, across the Bitcoin network into a secure, quantum-resistant format would require at least 76 days of cumulative block space under ideal conditions. If the network were to prudently reserve only 25% of each block’s capacity exclusively for this critical migration process, that timeline would stretch significantly to approximately 300 days of continuous network adjustment.
Compounding this engineering challenge, new post-quantum signature schemes are vastly larger than the cryptographic mechanisms currently deployed. The report highlighted that modern post-quantum signature schemes can easily range from 10 to 120 times larger than Bitcoin’s current Elliptic Curve Digital Signature Algorithm, known as ECDSA. The ECDSA serves as the foundational cryptographic mechanism that proves ownership of funds and authorizes secure transfers across the decentralized network.
Ultimately, the core challenge facing Bitcoin and similar decentralized networks is less about discovering viable replacement cryptography and far more about persuading a vast, global, and decentralized community of stakeholders to adopt these complex upgrades collectively before vulnerable wallets become viable targets for advanced threat actors.
