Key Highlights
- Europol identified crypto wallets and public-key cryptography as the primary exposure to future quantum attacks.
- A sufficiently powerful quantum computer could use Shor’s algorithm to derive private keys from exposed public keys.
- Blockchain hash functions are considered more resistant to quantum attacks, with larger security parameters able to reduce some risks.
Europol’s European Cybercrime Centre (EC3) has warned that advances in quantum computing could eventually put parts of cryptocurrency security infrastructure at risk, particularly the public-key cryptography used by wallets.
According to Europol’s October 7 report, titled “Quantum Computing and Cryptocurrencies – Bridging technical expertise and decision-making,” the agency examined how quantum computers could affect digital assets and the cryptographic systems used by blockchain networks.
The report does not suggest that quantum computing poses an immediate threat to the broader cryptocurrency ecosystem. Instead, it outlines how the industry could prepare for future quantum threats through incremental upgrades and a transition to post-quantum cryptography.
Crypto wallets face the main quantum risk
According to Europol, the main concern is not the blockchain ledger itself but the cryptographic keys that control cryptocurrency funds. Crypto wallets rely on public-key cryptography to authorize transactions. A private key allows a user to spend funds, while the corresponding public key is used by the network to verify transactions.
Europol said sufficiently powerful, fault-tolerant quantum computers could eventually use Shor’s algorithm to derive private keys from publicly available information. That could allow an attacker to create valid signatures and move funds without authorization.
The report therefore identifies cryptocurrency wallets as the “primary point of exposure” to quantum threats.
The risk is particularly relevant for addresses whose public keys have already been exposed. Europol said those keys cannot be made quantum-safe retroactively, meaning funds would need to be moved to new, quantum-resistant addresses before practical quantum attacks become possible.
Blockchain hashes are more resistant
Europol distinguishes the risk to wallet keys from the security of blockchain data itself.
Blockchains use cryptographic hash functions to link transactions and blocks and, in proof-of-work systems, to secure mining. Proof-of-stake networks also rely on hashes for parts of their data and consensus infrastructure.
The report said these hash functions are largely resistant to quantum attacks, although quantum algorithms can reduce their effective security. This is where Grover’s algorithm becomes relevant. Unlike Shor’s algorithm, which can break certain public-key systems, Grover’s algorithm provides a quadratic speedup for certain search problems.
Europol said its impact on cryptographic hashes and symmetric encryption can generally be addressed by using larger security parameters.
For example, a 256-bit hash would still require an extremely large amount of computational effort to attack even with the theoretical quantum speedup described in the report.
Shor’s algorithm targets public-key cryptography
Shor’s algorithm can solve the mathematical problems underlying widely used public-key cryptographic systems, including elliptic-curve cryptography (ECC), which is used by many cryptocurrency networks for digital signatures.
A sufficiently powerful quantum computer could therefore undermine the cryptographic assumptions behind these signature systems.
Europol stressed that the required quantum computers do not yet exist, but said the potential threat is one reason organizations are already working on post-quantum cryptographic standards.
Quantum computers are still limited
The report notes that quantum computing remains at an early stage.
Quantum computers use qubits rather than classical bits, with quantum effects such as superposition, entanglement, and interference allowing certain algorithms to solve specific problems more efficiently than classical computers.
However, building large-scale quantum computers remains difficult.
Europol points to noise and error correction as major technical challenges. Physical qubits are prone to errors, while logical qubits require multiple physical qubits and additional error-correction operations to achieve greater reliability.
The report cites different quantum-computing approaches, including superconducting systems, trapped ions, neutral atoms, photonics, and spin qubits. It also notes that the timeline for a quantum computer capable of breaking current cryptographic systems remains uncertain.
The report references the 2025 Quantum Threat Timeline Report, which surveyed 32 experts from academia and industry on when a quantum computer might be capable of breaking RSA-2048 within 24 hours.
Europol recommends a gradual shift to PQC
Rather than waiting for quantum computers to become capable of breaking existing cryptography, Europol recommends beginning the transition to post-quantum cryptography.
The report points to standards developed by the U.S. National Institute of Standards and Technology (NIST), including post-quantum key-encapsulation and digital-signature standards. For cryptocurrencies, the transition would affect wallets and protocols and could eventually require changes to consensus systems.
Europol also highlights account abstraction, multi-signature arrangements, and address rotation as measures that could reduce exposure during the transition. However, the report makes clear that these measures are not substitutes for quantum-resistant cryptography.
For wallets whose public keys are already exposed, Europol says the practical solution is to move funds before a quantum attack becomes possible.
Migration could be harder than developing PQC
The report identifies migration as one of the biggest challenges facing cryptocurrencies.
Developing quantum-resistant algorithms is only one part of the problem. Decentralized networks must also coordinate upgrades across developers, miners, validators, wallet providers, exchanges, and users.
Unlike centralized financial systems, blockchain networks cannot necessarily impose a single technical upgrade across the entire ecosystem. Europol said even after quantum-resistant algorithms are available, moving millions of wallets and blockchain assets could take years.
The report highlights Bitcoin as an example of the scale of the problem. Existing funds would need to be migrated to quantum-resistant arrangements, while larger post-quantum signatures could increase transaction sizes and place additional pressure on block space.
A study cited by Europol estimated that migrating all Bitcoin UTXOs could require at least 76 days of cumulative continuous downtime if carried out under certain assumptions.
Europol noted that such a disruption would not be practical, meaning any migration would likely have to be phased over time.
Decentralized governance adds another layer to the migration challenge. Developers, node operators, miners, validators, wallet providers, and users may need to agree on the timing and design of upgrades. Disagreement could slow adoption or leave different parts of an ecosystem using different security standards.
Just-in-time quantum attacks could add risk
The report also discusses a potential “just-in-time” quantum attack against cryptocurrency transactions.
Some Bitcoin transaction structures expose a public key only for a short period before a transaction is confirmed. If quantum computers eventually become powerful enough to derive the corresponding private key during that window, an attacker could potentially attempt to steal the funds before confirmation.
The scenario could create a narrower attack window for some transactions, adding another consideration for networks planning their quantum-security transition.
Quantum technology could also be used for Security
Europol also examines whether quantum technologies themselves could eventually help secure blockchain systems. One example is quantum key distribution (QKD), which uses quantum properties to establish shared encryption keys and can detect certain forms of interception.
However, Europol said QKD currently faces practical limitations, including infrastructure costs and distance constraints. The report also discusses proposals for quantum blockchains and quantum cryptocurrencies but describes them as experimental and not ready for widespread deployment.
For the near to medium term, Europol considers classical post-quantum cryptography more practical than relying on quantum-based security systems.
Earlier crypto warnings highlight Quantum transition risks
Europol’s recommendations come as crypto companies and industry figures have discussed how and when networks should prepare for quantum threats.
In July, JAN3 CEO Samson Mow urged Bitcoin developers to be cautious about moving too quickly to post-quantum cryptography. A July 30 Crypto Times report said Mow favored waiting until quantum computing presents a practical threat before making major changes to Bitcoin.
His position highlights one of the challenges Europol identifies: networks must weigh the cost and complexity of upgrading existing infrastructure against the risk of waiting too long to migrate.
The issue has also created opportunities for scams targeting crypto users.
In June, Ledger warned about a physical-mail phishing campaign that falsely claimed users needed to complete a “post-quantum upgrade.” The letters targeted six Ledger device models and directed recipients to a QR code.
The Ledger case shows how growing attention around quantum security can also be used to deceive users.
These incidents do not indicate that a quantum attack on Bitcoin or other cryptocurrencies is imminent. Instead, they illustrate two separate challenges around the transition: deciding when networks should upgrade and ensuring that users can distinguish legitimate security changes from scams.
Europol calls for coordinated Quantum migration
Europol does not conclude that quantum computing will make cryptocurrencies obsolete. Instead, the report calls for coordinated planning among policymakers, blockchain developers and wallet providers.
The agency recommends coordination among policymakers, researchers, private-sector companies and bodies including ENISA, CERT-EU and the European Anti-Money Laundering Authority (AMLA).
For the crypto sector, Europol says wallet and protocol developers should test post-quantum algorithms and establish migration plans before current cryptographic systems become vulnerable.
Also Read: Microsoft Tech-Support Racket Robs US Citizens via Bitcoin ATMs
