Europol's European Cybercrime Centre published two reports on October 7, 2026, identifying cryptocurrency wallets — not blockchains themselves — as the primary point of exposure to quantum computing attacks. The agency's assessment: a sufficiently powerful quantum computer could derive private ke...
Europol's European Cybercrime Centre published two reports on October 7, 2026, identifying cryptocurrency wallets — not blockchains themselves — as the primary point of exposure to quantum computing attacks. The agency's assessment: a sufficiently powerful quantum computer could derive private keys from exposed public keys, potentially enabling unauthorized transfers from legacy addresses holding an estimated 6.9 million BTC ($586 billion) and 55–60% of all ETH.
The reports land weeks after the Joint Committee of European Supervisory Authorities issued a September 2026 alert warning that quantum threats "could materialize earlier than viable commercial application." They also arrive seven months after Google Quantum AI published a paper estimating that fewer than 500,000 physical qubits — a 20x reduction from prior estimates — could break the secp256k1 elliptic curve underpinning Bitcoin and Ethereum wallets.
No publicly demonstrated quantum computer can currently execute this attack. Europol's message is not that collapse is imminent, but that the industry's migration window is narrower than most participants assume, and that "harvest now, decrypt later" adversaries may already be stockpiling on-chain data for future decryption.
Europol's European Cybercrime Centre (EC3) released two companion documents on October 7, 2026:
"Quantum Computing and Cryptocurrencies" — assesses the technical threat quantum computing poses to wallet-level cryptography. The report identifies exposed public keys as the attack surface, not blockchain consensus mechanisms or hash functions. Bitcoin's SHA-256 hashing is described as "largely quantum-safe."
"Harvest Now, Decrypt Later" — developed jointly with Carlos III University of Madrid. This report examines the risk that adversaries are already collecting encrypted blockchain data for future decryption once cryptographically relevant quantum computers (CRQCs) become available.
The distinction Europol draws is precise: blockchain infrastructure is not the near-term target. Wallet keys are. The protocols' consensus layers, mining algorithms, and hash-based address derivation remain comparatively resistant to quantum attack vectors. The vulnerability sits at the signature layer — specifically, the elliptic curve digital signature algorithm (ECDSA) and Ed25519 schemes used to authorize transactions.
Europol's technical assessment centers on Shor's algorithm, which can solve the elliptic curve discrete logarithm problem (ECDLP) exponentially faster on a quantum computer than any classical approach. Once a public key is exposed on-chain, a quantum attacker could theoretically derive the corresponding private key.
Public keys become exposed in several ways:
For Ethereum, the exposure is structural. Every account that has ever initiated a transaction has its public key permanently visible on-chain. The network was designed around persistent, reused addresses rather than one-time hashed outputs.
Multiple independent analyses have attempted to measure the scale of quantum-vulnerable holdings:
| Source | Bitcoin Exposed | Methodology | |--------|----------------|-------------| | Google Quantum AI (March 2026) | ~6.9 million BTC | UTXO analysis of exposed public keys | | Glassnode (May 2026) | 6.04 million BTC | On-chain forensics | | Coinbase Advisory Board (2026) | ~6.9 million BTC | Address-type classification | | CoinDesk tally (2026) | ~7 million BTC | Aggregate estimates |
The structural breakdown, according to PostQuantum.com's analysis:
At current prices, the total exposed Bitcoin amounts to approximately $586 billion, according to CryptoQuant data cited in Europol's findings.
Ethereum's exposure is proportionally larger. Two independent 2026 reconstructions converge on 55–60% of all ETH having exposed public keys — approximately 61–79 million ETH. This reflects the network's account-based architecture, where any outbound transaction permanently reveals the sender's public key.
On March 30, 2026, Google Quantum AI published "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities," co-authored with researchers from the Ethereum Foundation and Stanford University. The paper presented two optimized quantum circuits for solving the 256-bit ECDLP on the secp256k1 curve.
The headline finding: fewer than 500,000 physical qubits could break the cryptography in approximately nine minutes on a superconducting architecture. Previous best estimates had placed the requirement in the millions of qubits.
This represents roughly a 10x improvement in spacetime volume over prior single-instance estimates and a 20x reduction in the physical qubit count. The paper does not claim Bitcoin is broken today. It does not predict when a 500,000-qubit machine will be built. IBM's current largest processor, Heron, operates at 156 qubits. Google's Willow chip reached 105 qubits in December 2024.
The gap between 105 qubits and 500,000 remains vast. But the trend line — and the pace at which estimates are being revised downward — is what prompted Europol's action.
The second Europol report addresses what may be the more immediate risk. "Harvest now, decrypt later" (HNDL) describes a strategy where adversaries collect encrypted data today, store it, and wait for quantum decryption capabilities to mature.
For blockchains, this threat is structurally different from conventional HNDL targeting encrypted communications. Blockchain data is public, permanent, and cannot be retroactively encrypted or deleted. Every exposed public key is already available to any observer. The "harvesting" requires no sophisticated access — only a node or a block explorer.
Europol's report states there is "no clear evidence that harvest-now-decrypt-later attacks are currently being conducted systematically at scale." However, the agency notes the attack requires minimal cost and effort to execute: downloading and archiving blockchain data is trivially inexpensive.
A 2025 Federal Reserve working paper by Jillian Mascelli and Megan Rodden, titled "Harvest Now Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks," reached similar conclusions. The Fed paper emphasized that unlike traditional databases, blockchain records cannot be deleted or retroactively re-encrypted, making the HNDL threat to distributed ledgers fundamentally different from the threat to conventional encrypted communications.
The blockchain industry's response has been uneven. Of the top 26 blockchain protocols by market capitalization, 24 rely exclusively on quantum-vulnerable signature schemes — ECDSA or Ed25519 — according to a 2026 survey by Bex Research.
Notable exceptions and early movers:
Bitcoin — BIP 360 (Draft): Merged into the Bitcoin BIPs repository on February 13, 2026. Authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, BIP 360 introduces Pay-to-Merkle-Root (P2MR), a proposed output type that removes Taproot's key-path spend to address the most exposed modern address type. BTQ Technologies has implemented BIP 360 on a testnet. The proposal remains in community review; no mainnet activation is scheduled.
Sui — Native Post-Quantum Accounts: Targeting testnet deployment of ML-DSA-65 accounts by end of 2026 and mainnet activation in Q1 2027. Sui's "Address Alias" feature would allow users to attach quantum-resistant keys to existing addresses without moving funds.
BitGo: Tested post-quantum multiparty computation signing protocols.
Coinbase: Designing multi-signature infrastructure with post-quantum components.
Galaxy Digital: Established a $5 million research fund in July 2026 focused on post-quantum cryptographic migration.
NIST finalized the first three post-quantum cryptography standards in August 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The standards target deprecation of quantum-vulnerable algorithms by 2035. The EU's roadmap calls for high-risk use cases to be protected by 2030.
Europol's report acknowledges that migration is not straightforward. The core technical constraint: NIST-standardized post-quantum signatures are 10 to 120 times larger than current ECDSA signatures. This has direct implications for block size, transaction throughput, and storage costs.
A 2024 arXiv study estimated that migrating all Bitcoin addresses to quantum-safe formats would require approximately 76 cumulative days of network processing time, assuming current block parameters. This figure does not account for Ethereum or other chains.
The coordination challenge is arguably harder than the technical one. Migration requires action from individual wallet holders, many of whom control keys to dormant addresses. The 2.3 million BTC in dormant, quantum-vulnerable addresses may be permanently unmigrable — either because the key holders are deceased, keys are lost, or the holders are unresponsive.
Europol's recommendation: a phased migration involving coordinated action among protocol developers, wallet providers, exchanges, regulators, and end users. The agency stops short of recommending specific timelines but states the transition should begin before a CRQC is demonstrated.
The European Supervisory Authorities' September 2026 alert adds regulatory weight, warning that quantum threats "could materialize earlier than viable commercial application" — meaning the attack may arrive before quantum computing reaches broad commercial utility.
Europol's twin reports establish a clear regulatory signal: European law enforcement views the quantum threat to cryptocurrency as real, proximate enough to warrant formal assessment, and concentrated at the wallet layer rather than the protocol layer. The distinction matters. It means the threat is addressable through cryptographic migration rather than requiring fundamental redesign of blockchain consensus mechanisms.
The economic stakes are quantifiable. Between $586 billion in exposed Bitcoin and a majority of Ethereum's supply, the assets at theoretical risk are material. The migration path exists — NIST standards are finalized, BIP 360 is drafted, Sui has a testnet roadmap — but activation timelines remain indeterminate and the coordination problem is unsolved.
The reports do not predict when quantum computers will reach the necessary capability. What they establish is that the preparation window is finite, the exposed surface area is measured in hundreds of billions of dollars, and the cost of inaction is asymmetric: harvested data cannot be unharvested.