In this article5 sections
Roughly 6.04 million bitcoin — about 30.2% of the issued supply — already has its public key visible on-chain, according to a May estimate by the analytics firm Glassnode cited by Decrypt. That exposure is the reason Europol’s European Cybercrime Centre named cryptocurrency wallets the single biggest point of weakness if quantum computers ever become powerful enough to break the encryption protecting them.
The EU law enforcement agency released two reports on Wednesday, Oct. 7, Decrypt reported, pressing the crypto industry, wallet providers and policymakers to start moving toward quantum-resistant cryptography before any such machine exists. One report covers digital assets directly; the other, produced with University Carlos III of Madrid, examines attackers who collect encrypted data today in the hope of decrypting it years later.
Also read: Banks and regulators join quantum-resistant crypto transfer pilot
Key facts
- Europol’s cryptocurrency report identifies wallet keys as “the primary point of exposure to quantum threats,” while concluding that the hash functions linking blocks and securing mining are largely quantum-safe.
- Migrating every unspent transaction output on Bitcoin would take at least 76 days of cumulative network downtime, per a 2024 study cited in the report, or about 300 days if migration work occupied 25% of each block.
- NIST-standardized post-quantum signatures run 10 to 120 times larger than the ECDSA signatures Bitcoin uses today, which the report warns could strain block space, push fees higher and slow confirmations.
- IBM’s roadmap targets a fault-tolerant quantum computer by 2029, and a 2025 survey of 32 experts put the odds of a machine breaking RSA-2048 in 24 hours within a decade at 28% to 49%.
- Europol said there is “currently no clear evidence” that harvest-now-decrypt-later attacks are systematically exploited at scale, though government communications and confidential business data are the most plausible targets.
Wallet keys versus hashes
The two reports draw a line between digital signatures and hash functions. Breaking a 256-bit hash would still require an operation count the report describes as astronomically high with foreseeable technology, so the blockchain itself is not the soft spot. The exposure sits with the key pair that authorizes transactions: a private key for signing and a public key for verification. A sufficiently powerful quantum machine running Shor’s algorithm could work backward from an exposed public key to its private counterpart, letting an attacker spend funds as the owner.
For wallets whose public keys are already on-chain, the report says the only workable route is pre-emptive migration — moving coins to fresh wallets before any attack occurs. That framing turns an engineering question into a coordination problem, because a new signature standard does nothing for dormant addresses whose owners never move their funds.
Also read: Strategy’s $66B Bitcoin Treasury Faces Capital Markets Risk, Not BTC Price: Report
What the second report and other outlets add
The companion report, Harvest Now, Decrypt Later, finds widely deployed protocols including TLS, SSH and OpenPGP susceptible depending on configuration and key management, echoing a September warning from the European Union’s three financial supervisors.
Cryptobriefing reported that CryptoQuant estimates roughly 6.9 million bitcoin sit in legacy or reused addresses facing potential quantum vulnerability, a figure valued at about $586 billion at the time. That number differs from Glassnode’s 6.04 million BTC figure cited by Decrypt; the two firms use different methodologies, and Europol’s report itself cites only the Glassnode estimate.
Crypto.news reported additional detail on industry activity. BitGo and Silence Laboratories tested post-quantum multiparty computation signing earlier this year using ML-DSA inside an institutional custody workflow, and BitGo later added four controls for supported institutional Bitcoin wallets. Coinbase is designing custody infrastructure that could accommodate more than one post-quantum signature scheme because developers have not settled on a final standard. Draft BIP-361 proposes migrating away from legacy ECDSA and Schnorr signatures once a post-quantum output type exists, though Crypto.news noted it remains unactivated.
Why it matters
The practical burden falls on wallet providers and protocol developers, who would have to build, test and ship new signature schemes and then persuade users to move. Users who ignore migration instructions keep assets in addresses that stay exposed indefinitely, since on-chain data is permanent and public. Europol’s recommendation is a phased transition coordinated across developers, wallet firms, policymakers and ordinary holders, paired with better wallet security and key management. The agency also wants a European Commission-led working group including Europol, ENISA and the EU Anti-Money Laundering Authority to brief policymakers regularly. NIST has proposed deprecating today’s common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035.
What to watch
Europol said the arrival date of a capable quantum computer remains uncertain, and Crypto.news reported that no publicly demonstrated machine can currently derive private keys at the scale needed to steal assets. The nearer deadline is policy: the EU’s NIS Cooperation Group has recommended member states adopt a post-quantum migration strategy by the end of 2026, and NIST plans higher-risk systems to move earlier than its 2035 backstop.
None of this is a price forecast, and nothing here should be read as financial advice; crypto markets are volatile and uncertain. The open question for developers is a technical one — which signature scheme replaces ECDSA, and how existing coins move safely.
Reported by decrypt.co.
Sources: Decrypt, Cryptobriefing, Crypto.news

