
Europol has warned that future quantum computers could threaten cryptocurrency wallets and long-lived encrypted data, urging the crypto industry to begin security preparations before practical attacks become possible.
Summary
- Europol says quantum computers could expose cryptocurrency wallets by deriving private keys from public keys.
- Europol recommends phased migration to post-quantum cryptography, stronger wallet security, and improved key management practices.
- NIST has finalized three post-quantum standards and urges organizations to begin migration as soon possible.
- Bitcoin developers are debating post-quantum migration proposals while custodians test quantum-resistant wallet controls and signatures.
- Europol says there is no clear evidence harvest-now-decrypt-later attacks are being systematically used at scale.
Europol published two reports on Oct. 7 examining how advances in quantum computing could affect digital assets and sensitive information. The agency said the timing of a capable quantum computer remains uncertain, but upgrading cryptographic systems across decentralized networks could take years.
The first report focuses on cryptocurrency wallets, while the second examines attackers storing encrypted information today for possible decryption years later. Europol did not say current quantum machines can break cryptocurrency security.
Quantum threats focus on crypto wallet keys
Europol’s cryptocurrency report identifies wallet authorization keys as the main potential point of exposure. Many blockchain systems rely on public-key cryptography to prove that a wallet owner authorized a transaction.
A sufficiently capable quantum computer could theoretically use an exposed public key to calculate its corresponding private key. An attacker could then sign transactions and transfer assets without permission, Europol said.
The agency drew a distinction between digital signatures and blockchain hash functions. Europol said cryptographic hash functions used for important parts of blockchain security are comparatively resistant to quantum attacks. The report therefore focuses heavily on wallet signatures, public-key exposure and key management.
Its findings do not predict an inevitable collapse of cryptocurrencies. Europol instead recommends a phased migration toward post-quantum cryptography, with blockchain developers, wallet providers, policymakers and users coordinating future upgrades.
Bitcoin developers are already discussing parts of that problem. Draft BIP-361 proposes a planned migration away from legacy ECDSA and Schnorr signatures after a post-quantum Bitcoin output type becomes available. The proposal remains a draft and has not been activated on Bitcoin.
As crypto.news previously reported, related Bitcoin proposals have sparked debate over how users could move vulnerable coins and what should happen to dormant funds that never migrate.
Quantum security work has already reached crypto wallets
Some crypto custodians and blockchain developers have started testing post-quantum systems before a practical threat exists.
BitGo and Silence Laboratories tested post-quantum multiparty computation signing earlier this year. As crypto.news reported, the demonstration used ML-DSA inside an institutional custody workflow to test how quantum-resistant signatures could fit existing wallet infrastructure.
BitGo later introduced four controls for supported institutional Bitcoin wallets. In related crypto.news coverage, the company added tools for measuring public-key exposure, consolidating outputs and helping users move funds from addresses considered more exposed under a future quantum scenario.
Coinbase is working on a similar custody problem. Crypto.news reported in September that the company was designing infrastructure capable of supporting different post-quantum signature schemes, since Bitcoin developers have not yet selected a final replacement standard.
Other networks are pursuing account-level changes. Sui plans optional quantum-safe authentication based on NIST-approved signature schemes, with native post-quantum accounts targeted for mainnet in 2027. As crypto.news reported, the proposal would let users retain existing recovery information while adopting new authentication methods.
Monad researchers have proposed separating blockchain addresses from their authentication keys. In related coverage, the design would allow keys to change without requiring users to abandon the same account address. The proposal remains under development.
NIST standards give developers migration options
Europol’s recommendation comes after the U.S. National Institute of Standards and Technology finalized its first major post-quantum cryptography standards.
NIST approved FIPS 203, FIPS 204 and FIPS 205 in August 2024. The standards cover quantum-resistant key establishment and digital signatures.
FIPS 203 specifies ML-KEM, derived from CRYSTALS-Kyber, for establishing shared secrets. FIPS 204 specifies ML-DSA, derived from CRYSTALS-Dilithium, for digital signatures. FIPS 205 uses the hash-based SLH-DSA signature system derived from SPHINCS+.
NIST says organizations should begin moving toward quantum-resistant systems now. Its planned transition would deprecate and eventually remove quantum-vulnerable algorithms from NIST standards by 2035, while higher-risk systems are expected to move earlier.
The agency continues developing other options. HQC was selected for standardization in March 2025 as another key-establishment algorithm, while FALCON is being developed as a separate digital-signature standard.
Europol had already addressed migration planning in January. A report on financial services recommended a risk-based transition that identifies vulnerable cryptography first and prioritizes systems based on their exposure and importance.
Stored encrypted data faces a separate quantum risk
Europol’s second Oct. 7 report examines what security researchers call “harvest now, decrypt later.”
Under the scenario, attackers collect encrypted information even though they cannot currently read it. They store the material until future computing systems become capable of breaking the encryption protecting it.
Europol said the threat is most relevant for information that needs to remain confidential for years, including government communications, medical records, intellectual property and law-enforcement files.
The report, developed with University Carlos III of Madrid, says actual exposure depends on the encryption protocols, configurations and key-management methods protecting the data.
Europol found no clear evidence that harvest-now-decrypt-later attacks are currently being conducted systematically at scale. Collecting and retaining large amounts of encrypted information would require substantial storage, processing capacity and technical resources.
Long-lived and high-value information remains the more plausible target under the report’s scenario. Europol recommends removing outdated protocols, reducing unnecessary data retention and testing post-quantum systems before quantum attacks become practical.
Crypto migration could take years
The timetable remains one of the largest uncertainties surrounding quantum threats.
No publicly demonstrated quantum computer can currently derive cryptocurrency private keys at the scale required to steal assets protected by modern blockchain signature systems. Europol therefore frames the issue as a preparation problem instead of an active cryptocurrency attack.
Migration itself could prove difficult because decentralized networks require coordination among developers, wallet companies, exchanges, custodians, miners or validators and individual asset holders.
Ledger CTO Charles Guillemet has argued that Bitcoin’s hardest problem may be migrating wallets and existing funds safely after developers agree on a new signature scheme. As crypto.news reported, dormant coins and users who fail to move assets create extra technical and governance questions.
Galaxy Digital has committed money to that work. In related crypto.news coverage, the company created a $5 million program in July to fund Bitcoin research covering quantum-resistant signatures, migration tools and security audits.
Europol’s recommendation calls for cryptocurrency projects to identify exposed assets first, improve wallet and key-management practices, test post-quantum alternatives and communicate future migration requirements clearly to users.

