Europol Warns Crypto Wallets Are Primary Risk for Quantum Attacks
EU law enforcement says crypto wallet keys are the biggest vulnerability to future quantum computing attacks, urging early migration to quantum-safe tools.
Key takeaways
- Exposed keys are widespread. Glassnode data from May 2026 shows 6.04 million BTC, 30.2% of the total supply, has public keys visible on public blockchains.
- Quantum timeline is near. IBM and Microsoft both target fault-tolerant quantum computing capabilities by 2029, per their published roadmaps.
- Migration has high costs. A 2024 study estimates full Bitcoin migration to post-quantum signatures could require 76 days of cumulative network downtime.
What happened
On October 7, 2026, the European Union's law enforcement agency Europol published two reports outlining quantum computing risks to the cryptocurrency sector and broader encrypted digital infrastructure. The first report, produced by Europol's European Cybercrime Centre, identifies cryptocurrency wallets as the primary point of exposure to quantum threats, as they rely on paired private and public keys to authorize and verify transactions. The agency explains that a sufficiently powerful quantum computer could derive a private key from an exposed public key, allowing attackers to spend associated funds without authorization, a scenario often called Q-Day. The report notes that the hash functions underpinning blockchain mining are largely quantum-safe, as breaking a 256-bit hash would require computational resources it describes as astronomically high with foreseeable technology, and concludes that cryptocurrencies will not collapse due to quantum computing if proactive defensive measures are implemented.
Why it matters
The risk is immediate for many existing crypto holdings. Wallets with public keys already posted to blockchains cannot be secured retroactively, so the only solution is for owners to move funds to new, quantum-resistant wallets before any attack occurs. Blockchain analytics firm Glassnode estimated in May 2026 that 6.04 million BTC, equal to 30.2% of Bitcoin's total issued supply, already has exposed public keys. Older Bitcoin addresses make up a large share of this at-risk pool: more than 4.3 million BTC, valued at over $360 billion, are held in these addresses, including an estimated 1.1 million BTC tied to Bitcoin's anonymous creator Satoshi Nakamoto. Even modern addresses carry risk, as public keys become visible when transactions are broadcast before confirmation, creating a short window for quantum attacks.
What is still unclear
- There is no definitive public timeline for when quantum computers will be capable of breaking the elliptic curve cryptography used by Bitcoin. While IBM and Microsoft both target fault-tolerant quantum computing by 2029, a 2025 survey of 32 experts put the odds of a machine breaking RSA-2048 encryption within 24 hours in the next decade at 28% to 49%, with no comparable public odds published for Bitcoin-specific cryptography.
Questions readers ask
Are my crypto funds at risk from quantum computers?
Funds in wallets with exposed public keys are at risk once quantum computers capable of breaking elliptic curve cryptography are operational. Wallets that have never broadcast a public key, and funds moved to new quantum-resistant addresses before such computers exist, are not at risk. Europol recommends migrating at-risk funds to new wallets as soon as possible.
When will quantum computers be able to break crypto encryption?
There is no definitive timeline, but IBM and Microsoft target fault-tolerant quantum computing by 2029. A 2025 survey of 32 experts put the odds of a machine breaking RSA-2048 encryption within 24 hours in the next decade at 28% to 49%.
What is Europol's recommendation for crypto users?
Europol urges wallet providers, developers and users to begin transitioning to quantum-resistant cryptography and improve key management practices now, rather than waiting for quantum attacks to become feasible.