Europol Warns Crypto Wallets Are 'Primary Risk' for Quantum Attacks

Europol released two reports warning that quantum computing poses a material risk to cryptocurrencies and encrypted communications, and urged early preparation. Its cybercrime centre singled out wallet private keys as the primary vulnerability while finding blockchain hash functions largely resistant to foreseeable quantum attacks.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Europol Warns Crypto Wallets Are 'Primary Risk' for Quantum Attacks

Why It Matters

If powerful quantum computers arrive as some roadmaps and expert surveys suggest, attackers could derive private keys from exposed public keys and steal funds; because public keys already revealed on-chain cannot be retroactively protected, migration planning and policy coordination are time-sensitive steps. The reports also highlight the related risk that adversaries could harvest encrypted data now and decrypt it later when quantum capability exists.

Key Facts

  • Publisher: Europol (European Cybercrime Centre) and a joint report with University Carlos III of Madrid
  • Primary vulnerability identified: Cryptocurrency wallet private keys exposed via public keys
  • Blockchains' resistance: Hash functions (e.g., 256-bit) deemed largely quantum-safe with 'astronomically high' break cost given foreseeable technology
  • Estimate of exposed Bitcoin: Glassnode estimated 6.04 million BTC (30.2% of issued supply) has had public keys exposed (May)
  • Migration cost estimate: A 2024 study cited: making every Bitcoin output quantum-safe would require ≥76 days of cumulative network downtime (≈300 days if using 25% of block space)

Europol published two reports advising the crypto industry, policymakers and other organizations to start preparing now for quantum computers capable of breaking commonly used public-key cryptography. In Quantum Computing and Cryptocurrencies, the agency's European Cybercrime Centre identified wallet private keys as the main point of exposure: because wallets use a private/public key pair, a sufficiently capable quantum computer could derive a private key from an exposed public key and allow unauthorized spending — a scenario the report calls Q-Day. The report judges the cryptographic hash functions that link blockchain blocks and secure mining to be largely resistant to quantum attacks in the foreseeable future, saying that breaking a 256-bit hash would still require an "astronomically high" number of operations. Still, Europol recommended a phased transition to quantum-resistant cryptography, stronger wallet security and improved key management to ensure long-term resilience. Europol stressed that wallets whose public keys are already visible on-chain cannot be secured retroactively; holders must migrate funds to new, quantum-safe wallets before an attack. The report cites a Glassnode estimate that about 6.04 million BTC, roughly 30.2% of issued supply, has had its public key exposed. It also notes practical migration costs: NIST-standard post-quantum signatures are substantially larger than current ECDSA signatures, which could congest block space, raise fees and slow confirmations. A 2024 study cited by Europol estimated that migrating every unspent transaction output would need at least 76 days of cumulative network downtime, or about 300 days if the effort consumed 25% of each block's capacity. The second Europol report, Harvest Now, Decrypt Later, examined the threat from adversaries who capture encrypted data today to decrypt once quantum capability exists. It found common protocols like TLS, SSH and OpenPGP vulnerable depending on configuration and key management, but said there is no clear evidence of systematic, large-scale exploitation so far. Europol recommended coordinated policy work — including a proposed European Commission-led working group with ENISA and other bodies — and pointed to timelines and expert surveys (including IBM, Microsoft and a 2025 expert poll) that suggest fault-tolerant, scalable quantum machines could be feasible within the next decade, elevating the urgency of migration planning.

Keep Reading