Europol is calling on crypto developers, exchanges and users to begin a gradual shift toward post-quantum security, warning that exposed wallet keys could eventually become a target for powerful quantum computers.
The European law enforcement agency said in a report released Wednesday that cryptocurrency wallets are more likely to represent the main point of vulnerability than the blockchains themselves when quantum attacks become possible.
Quantum computers capable of breaking current cryptographic protections do not yet exist, and Europol did not forecast when they might arrive. The agency instead argued that the industry should prepare in advance, saying “proactive adaptation, rather than systemic collapse, is the most likely outcome.”
Its recommendations include upgrading wallets, adopting post-quantum cryptography and coordinating the transition among developers, miners, exchanges and users.
Bitcoin researchers and institutions are increasingly treating 2029 as a deadline for establishing credible quantum-resistant migration strategies. IBM said in July that it expects quantum computing to begin producing significant commercial revenue within the next two to four years.
According to Europol’s European Cybercrime Center, a sufficiently capable quantum computer could derive a private key from an exposed public key and then use that key to transfer the associated cryptocurrency.
Exposed Public Keys Pose the Greater Risk
Europol highlighted a distinction between the security of a blockchain and the cryptography used to control individual wallets. Hash functions that protect blockchain history and support Bitcoin mining are considered substantially more resistant to quantum attacks than the public-key cryptography used to authorize transactions.
“Cryptocurrencies will not collapse due to quantum computing,” Europol said. The more immediate concern is whether attackers could take control of funds in vulnerable wallets, rather than whether quantum technology could rewrite Bitcoin’s blockchain.
The risk is particularly pronounced for Bitcoin addresses dating back to the network’s earliest years, often called the Satoshi era. Public keys for many of these addresses have already been revealed on-chain. If quantum computing reaches sufficient power, those exposed keys could potentially be used to derive the corresponding private keys.
Europol estimates that roughly 6.9 million BTC are held in addresses with exposed public keys. The total includes early pay-to-public-key outputs and numerous holdings that have remained untouched for years.
The agency said there is no way to make an already exposed public key secure retroactively. That has intensified discussions within the Bitcoin community about how Satoshi-era holdings should be treated, including the increasingly debated question of whether vulnerable BTC should be frozen before quantum attacks become practical.
Quantum-Proofing Bitcoin Could Take Months
The network would also face a substantial technical challenge in migrating existing Bitcoin outputs to quantum-resistant cryptography. Europol referenced a 2024 study that estimated converting every Bitcoin unspent transaction output, or UTXO, could require at least 76 days of cumulative block space.
If just 25% of each block were allocated to the migration, the process could take around 300 days, according to the study.
There is also a size trade-off with post-quantum signatures. Europol said newer signature schemes can be 10 to 120 times larger than Bitcoin’s current Elliptic Curve Digital Signature Algorithm, or ECDSA, signatures.
ECDSA is the cryptographic mechanism Bitcoin uses to prove ownership and authorize transactions.
The challenge for Bitcoin is therefore not simply creating a replacement for ECDSA. The more difficult task is coordinating a decentralized network of developers, miners, exchanges, wallet providers and users to adopt quantum-resistant technology before exposed wallets become viable targets.





