Cryptocurrency wallets, rather than blockchains themselves, are the main point of exposure to future quantum-computing attacks, Europol said in a report published Wednesday.
Quantum computers capable of carrying out such attacks do not exist yet, and Europol did not predict when they will. However, the European Union’s law enforcement agency said “proactive adaptation, rather than systemic collapse, is the most likely outcome.”
Europol urged the industry to begin a phased transition now through wallet upgrades, post-quantum cryptography and coordination among developers, miners, exchanges and users.
Bitcoin researchers and institutions increasingly see 2029 as the point by which credible quantum-resistant migration plans need to be in place. IBM said in July that it expects quantum computing to generate significant commercial revenue in the next two to four three years.
A sufficiently powerful quantum computer could derive a private key from a public key and spend the associated funds, Europol’s European Cybercrime Center said in its Quantum Computing and Cryptocurrencies report.
The agency aimed to draw a clear distinction often lost in warnings about quantum computing: the hash functions that help secure a blockchain’s history, including bitcoin mining, remain far more resistant to quantum attacks than the public-key cryptography used to control wallets.
“Cryptocurrencies will not collapse due to quantum computing,” Europol said. The immediate concern is ownership of the assets held in wallets, not whether a quantum computer could rewrite the bitcoin blockchain.
That distinction is more critical for addresses from the earliest days of Bitcoin – referred to as the "Satoshi era" – whose public keys have already become visible onchain. A powerful enough quantum computer could use those keys to drive the corresponding private key. Roughly 6.9 million bitcoin sit in addresses with exposed public keys, including early pay-to-topublic-key outputs and many long-dormant holdings.
Europol said exposed keys cannot be made safe retroactively, an issue that has sparked massive debates and controversies across the bitcoin community as the dilemma of whether or not to freeze BTC in Satoshi-era wallets increases as the quantum threat nears.
The more difficult task today is updating the network itself. Europol cited a 2024 study estimating that converting every bitcoin unspent transaction output, or UTXO, to a quantum-resistant format would require at least 76 days of cumulative block space. Reserving 25% of each block for the migration, that study adds, would stretch that process to about 300 days.