Key Points:
- Europol says exposed cryptocurrency public keys are the primary point of quantum risk, rather than an imminent threat to blockchain networks themselves.
- A sufficiently powerful quantum computer could potentially use Shor’s algorithm to derive a private key from an exposed public key and authorize unauthorized transactions.
- Europol is urging phased post-quantum migration now, giving developers, exchanges and users time to upgrade cryptographic systems before quantum capabilities become a practical threat.
European law-enforcement agencies are urging the cryptocurrency industry to begin preparing for quantum computing threats, but with a more precise warning than the broad claim that quantum machines could simply “break” blockchains. A new Europol report identifies the cryptographic keys controlling exposed cryptocurrency wallets as the principal vulnerability and calls for phased migration toward post-quantum security before sufficiently powerful machines become available.
The Risk Is Concentrated in Exposed Keys
Europol’s analysis distinguishes between the security of a blockchain’s underlying consensus mechanisms and the cryptography used to authorize transactions. The immediate concern is that a sufficiently capable quantum computer could derive a private key from an exposed public key, allowing an attacker to sign transactions and move assets without the legitimate owner’s authorization.
That distinction matters for investors because not every crypto address carries the same level of quantum exposure. Assets held in wallets where the relevant public key has not been exposed face a different risk profile from funds associated with addresses that have already revealed the information needed for a future quantum attack. The issue is therefore partly a key-management problem, not simply a question of whether Bitcoin, Ethereum or another blockchain can survive quantum computing.
There Is No Quantum Deadline Yet
Europol does not provide a specific date for when quantum computers will become capable of breaking today’s cryptography. Instead, the agency argues that uncertainty over the timeline should not delay preparation because upgrading financial and blockchain infrastructure can take years.
The urgency has increased alongside research into the resources required for potential attacks. In September, researchers reported reducing the estimated computational cost of a key step in attacking the secp256k1 elliptic-curve cryptography used by Bitcoin and Ethereum by more than 50% compared with a March Google benchmark. The researchers emphasized that no existing quantum computer can use the result to break either network.
For institutional investors, that distinction is critical: the current threat is prospective rather than operational, but cryptographic migration itself is a long-duration infrastructure project.
Migration Will Require Coordination Across the Industry
Europol recommends a phased transition toward post-quantum cryptography, prioritizing systems and assets according to their exposure and importance. The approach applies beyond individual users to exchanges, wallet providers, blockchain developers and other organizations responsible for digital-asset infrastructure.
The transition also creates practical challenges. New cryptographic systems must coexist with existing infrastructure, maintain interoperability and avoid disrupting access to funds. Exchanges and custodians will have to consider how legacy addresses, dormant assets and large institutional holdings are migrated without creating new operational or custody risks.
Bitcoin and Ethereum Face Different Migration Questions
The scale of the issue can already be seen in Bitcoin’s historical address structure. Research cited by CoinDesk has estimated that approximately 1.7 million BTC sit in roughly 20,000 early pay-to-public-key addresses where public keys are directly exposed onchain. Some of those coins are believed to be inaccessible because their owners have lost their keys, creating a particularly difficult question for any future quantum transition.
For crypto markets, the key issue over the coming years will be whether networks can establish credible migration paths before quantum hardware reaches a level capable of exploiting exposed keys. Post-quantum readiness could increasingly become part of institutional due diligence, particularly for custodians and protocols holding significant long-term assets. Europol’s warning therefore points less to an immediate market shock than to a technology transition that developers and asset managers cannot afford to leave until the last moment.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible