Europol's European Cybercrime Centre (EC3) published two reports on October 7, 2026, identifying cryptocurrency wallet keys — not blockchain protocols themselves — as the primary attack surface for quantum computers. The reports name exposed public keys in legacy Bitcoin addresses as the most imm...
"Bitcoin's hardest problem may be migrating wallets and existing funds safely." — Charles Guillemet, CTO, Ledger
Europol's European Cybercrime Centre (EC3) published two reports on October 7, 2026, identifying cryptocurrency wallet keys — not blockchain protocols themselves — as the primary attack surface for quantum computers. The reports name exposed public keys in legacy Bitcoin addresses as the most immediate vulnerability, with approximately 6.9 million BTC ($586 billion at current prices) sitting in addresses where public keys are visible on-chain.
The agency's assessment arrives seven months after Google Quantum AI published resource estimates showing that breaking 256-bit elliptic curve cryptography — the system securing most cryptocurrency wallets — could require fewer than 1,200 logical qubits and under 500,000 physical qubits, roughly a 20x reduction from prior estimates. No quantum computer can execute this attack today, but Europol warns the threat is already active: adversaries can archive on-chain public key data now and decrypt it once a cryptographically relevant quantum computer (CRQC) exists, a tactic known as "harvest now, decrypt later" (HNDL).
The reports urge blockchain developers, wallet providers, policymakers, and users to begin a phased, systematic transition to post-quantum cryptography (PQC) before threats materialize — not after.
Europol's EC3 published two simultaneous reports on October 7 under the broad theme of quantum computing threats to cryptocurrencies. The second report, developed in collaboration with Universidad Carlos III de Madrid, focused specifically on HNDL attacks against encrypted data.
The core finding: Bitcoin's SHA-256 hash functions remain largely quantum-resistant. The vulnerability lies not in the blockchain itself but in the elliptic curve digital signature algorithm (ECDSA) used to generate wallet key pairs. Specifically, legacy address types that expose raw public keys on-chain — pay-to-public-key (P2PK) outputs and addresses where keys have been revealed through prior transactions — create a permanent, publicly accessible dataset that a future quantum computer could exploit using Shor's algorithm.
Europol's distinction matters. It narrows the threat from a vague "quantum will break crypto" narrative to a specific, measurable vulnerability in key management infrastructure.
According to analysis published in Google Quantum AI's March 2026 whitepaper, approximately 6.9 million BTC — about 34% of circulating supply — reside in addresses with publicly visible keys on-chain. At current prices, that represents roughly $586 billion in exposed value.
The exposure breaks down by address type:
P2PK outputs: Approximately 1.72 million BTC. These legacy outputs, common in Bitcoin's earliest years, record the recipient's raw public key directly in the locking script. The key is visible from the moment coins are received. There is no hash protection and no time-limited exposure window.
Reused addresses: Any address that has sent a transaction has its public key permanently recorded on-chain. Standard P2PKH and P2SH addresses protect the public key behind a hash until the first spend, but once a transaction is broadcast, the key is exposed.
Taproot key-path spends: Europol specifically flagged Taproot key-path spends as a newer category of exposure, since Taproot outputs reveal the public key when spent via the key path.
Dormant coins: Approximately 2.3 million BTC with exposed keys have not moved in at least five years. These coins cannot be migrated to quantum-safe addresses unless their holders actively move them — and some holders may have lost access to their private keys entirely.
P2PK coins present a particular problem. Migration requires the current private key, meaning coins belonging to lost or abandoned wallets — including an estimated 1.1 million BTC attributed to Bitcoin's creator — are permanently exposed. No protocol upgrade can retroactively protect them.
On March 31, 2026, Google Quantum AI published a 57-page whitepaper that materially compressed the estimated resources needed to break ECDLP-256, the cryptographic problem underpinning Bitcoin wallet security.
The team compiled two quantum circuits implementing Shor's algorithm:
| Circuit | Logical Qubits | Toffoli Gates | Physical Qubits | Runtime | |---------|----------------|---------------|-----------------|---------| | A | < 1,200 | 90 million | < 500,000 | Minutes | | B | < 1,450 | 70 million | < 500,000 | Minutes |
These figures represent approximately a 20x reduction in physical qubit requirements compared to previous estimates. The paper was authored by Ryan Babbush, Director of Research for Quantum Algorithms, and Hartmut Neven, VP of Engineering at Google Quantum AI.
No existing quantum computer approaches these specifications. IBM's most advanced systems operate in the range of 1,000-1,200 physical qubits. The gap between physical qubits (noisy, error-prone) and logical qubits (error-corrected, computational) remains substantial. But the direction of the estimates — consistently downward — is the data point that Europol, the Federal Reserve, and industry participants have cited as reason to accelerate migration timelines.
Google verified its claims using zero-knowledge proofs, according to the blog post, "without us leaking sensitive attack details."
The Europol reports gave particular emphasis to the HNDL threat, where adversaries archive today's on-chain data for future decryption. For Bitcoin, the attack is structurally different from traditional HNDL against encrypted communications: the data is already public.
Every exposed public key on the Bitcoin blockchain is permanently recorded in an immutable, globally replicated ledger. A well-resourced adversary — state or private — does not need to intercept traffic or infiltrate systems. The data is freely available. Archiving it is trivial. The only missing component is the quantum hardware to process it.
A September 2025 working paper from the Federal Reserve (FEDS No. 2025-93), authored by Jillian Mascelli of the Board of Governors and Megan Rodden of the Federal Reserve Bank of Chicago, formalized this risk. The paper concluded that "no existing method can retroactively safeguard data already recorded on public distributed ledgers." Post-quantum cryptography can protect future transactions, but historical data is permanently exposed.
Europol noted there is "no clear evidence harvest-now-decrypt-later attacks are being systematically used at scale." The absence of evidence, however, reflects the nature of the attack: successful HNDL is invisible until decryption occurs.
Transitioning Bitcoin to quantum-resistant cryptography involves trade-offs that Europol's report acknowledged but did not resolve.
Signature bloat. NIST-standardized post-quantum signatures (ML-DSA under FIPS 204, SLH-DSA under FIPS 205) are 10 to 120 times larger than current ECDSA signatures. On a network that already debates block size constraints, signature bloat would increase transaction sizes, reduce throughput, and raise fees — or require consensus changes to accommodate larger data.
Migration duration. A 2024 study estimated that migrating all unspent transaction outputs (UTXOs) to quantum-safe addresses would require 76 days of cumulative network downtime. The practical impossibility of coordinated downtime on a permissionless network means migration would need to occur gradually, leaving a mixed-cryptography network for an extended transition period.
Abandoned coins. An estimated 3-4 million BTC are believed to be in lost or inaccessible wallets. These coins cannot be migrated. Any protocol change that invalidates non-quantum-resistant addresses would effectively burn these coins — a governance decision with no precedent in Bitcoin's history.
BIP-360, authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, proposes a new output type — pay-to-quantum-resistant-hash (P2QRH) — that replaces ECDSA with NIST-approved post-quantum algorithms, principally ML-DSA. The proposal was merged as a draft on February 13, 2026.
BTQ Technologies activated BIP-360 on its Bitcoin Quantum Testnet in March 2026, marking the first live test of the proposal. The standard has not been activated on Bitcoin mainnet and remains in deliberation.
Other industry responses:
BIP-361 (draft) addresses the migration mechanics — how existing UTXOs would move to post-quantum output types once BIP-360 is available on mainnet. Neither proposal has a confirmed activation timeline.
Europol's report lands amid a broader regulatory push toward post-quantum readiness across Europe:
In the United States, President Biden's 2022 National Security Memorandum 10 (NSM-10) directed agencies to migrate vulnerable systems to quantum-resistant cryptography by 2035. NIST has finalized three PQC standards (FIPS 203, 204, 205) and selected HQC as a fifth algorithm in March 2025.
The regulatory trajectory suggests that if cryptocurrency networks do not develop credible quantum-resistant migration paths independently, external compliance requirements may be imposed — particularly for institutional custody and exchange infrastructure operating within regulated jurisdictions.
Europol's October 7 reports convert what was previously a theoretical risk into a structured threat assessment backed by law enforcement, central bank research, and corporate resource estimates. The agency's framing is specific: the vulnerability is in wallet key infrastructure, the exposed surface is quantifiable at 6.9 million BTC, and the timeline depends on quantum hardware progress that is accelerating.
The economic implications for the cryptocurrency ecosystem are material. Migration to post-quantum cryptography will impose costs — larger transactions, higher fees, complex coordination across a permissionless network, and unresolvable exposure for abandoned coins. The alternative — inaction — risks a scenario where a CRQC arrives before defenses are in place, with $586 billion in exposed assets and no ability to retroactively protect them.
The data does not support panic. No quantum computer can execute this attack today. But the data also does not support complacency. The estimates are moving in one direction, the regulatory deadlines are set, and the on-chain exposure is permanent.