Bitcoin

Europol Names Crypto Wallets as the Main Quantum Attack Risk

About 6.04m BTC, 30.2% of the supply issued, already sits in wallets with exposed public keys.

⏱ 2 min read Bitcoin
Quick Summary
  • Europol says blockchain hashing is largely quantum-resistant and crypto will not collapse
  • Quantum-safe signatures are 10 to 120 times larger than Bitcoin's, which could raise fees
  • The nearer risk is a live attack in the gap between a transaction going out and confirming

Europol has identified crypto wallets as the main point of exposure if quantum computers become powerful enough to break today’s cryptography.

The EU’s law enforcement agency set out the finding in a report from its European Cybercrime Centre, published on Wednesday. Its conclusion is measured: cryptocurrencies “will not collapse due to quantum computing,” but holders and developers need a “proactive defence.”

Why wallets, not blockchains

A crypto wallet uses a private key to authorise transactions and a public key to verify them. A sufficiently powerful quantum computer could work out the private key from an exposed public key, and spend the funds.

The blockchain itself is in a stronger position. The hash functions that link blocks together and underpin mining are largely quantum-resistant, and Europol said the cost of breaking a 256-bit hash would remain “astronomically high with foreseeable technology.”

That puts the risk on the coins whose public keys are already visible on-chain. Data from Glassnode in May put that at about 6.04 million BTC, 30.2% of the supply issued so far. For those coins, the report says, “the only solution is pre-emptive migration” to new wallets.

The nearer threat

Europol flagged a more immediate risk than old keys being cracked later. When a transaction is sent, its public key becomes visible before the transaction is confirmed. A fast enough quantum attacker could, in principle, derive the key in that window and redirect the funds.

The cost of fixing it

Moving Bitcoin to quantum-resistant cryptography is not cheap. Signatures approved by the US standards body NIST are 10 to 120 times larger than Bitcoin’s current ECDSA signatures, which could strain block space, push up fees and slow confirmations. One 2024 study estimated that converting every Bitcoin output would need at least 76 days of cumulative downtime, or about 300 days if the work used a quarter of each block.

Europol wants a European Commission-led working group, including the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, to brief policymakers regularly on the threat.

⚖️ Our Verdict ⚖️ Watch and Wait

This is a law enforcement agency telling holders where the risk sits, not a warning that it has arrived. The fix is known, but for coins with exposed keys it means moving them, and for Bitcoin itself it means a costly upgrade that is still being debated.