Newsroom
7 October, 2026 / News / AI / Tags: quantum, europol, keys, upgrades, exposed

EU agency releases reports on quantum threats to cryptocurrency wallets and long-term encrypted data, stressing phased post-quantum upgrades before practical attacks emerge
Europol, the European Union's law enforcement agency, published two reports on October 7 calling on the cryptocurrency industry and organizations handling sensitive information to begin preparations for quantum computing risks. The reports stress that while capable quantum systems do not yet exist and no firm timeline is available, the scale of required upgrades across decentralized networks means work should start immediately.
The first report, titled “Quantum Computing and Cryptocurrencies” and issued by Europol’s European Cybercrime Centre, identifies cryptographic keys that control wallets and authorize transactions as the primary point of exposure. A sufficiently powerful quantum computer could theoretically derive a private key from a publicly exposed public key, enabling an attacker to sign transactions and transfer funds without the owner’s consent.
Hash functions that underpin blockchain integrity and mining remain comparatively more resistant to quantum attacks. Europol therefore focuses its recommendations on wallet security, key management and public-key exposure rather than treating the underlying blockchain networks as the central vulnerability.
“Cryptocurrencies will not collapse due to quantum computing,” the agency stated. Proactive adaptation is described as the most probable outcome. The reports call for a phased transition to quantum-resistant cryptography, with blockchain developers, wallet providers, policymakers and users all playing roles. Coordinating upgrades across decentralized systems is presented as a particular challenge that makes early action essential.
Addresses whose public keys have already appeared on-chain cannot be secured retroactively. This includes holdings associated with Bitcoin’s earliest period. Europol notes that new post-quantum signature schemes can be substantially larger than current Elliptic Curve Digital Signature Algorithm signatures, complicating any network-wide conversion of unspent transaction outputs.
A 2024 study cited in the report estimated that converting every bitcoin unspent transaction output to a quantum-resistant format would require at least 76 days of cumulative block space. Allocating only a portion of each block to the migration could extend the process to around 300 days. The core difficulty, according to Europol, lies less in identifying replacement cryptography and more in securing consensus across a global, decentralized network before exposed wallets become practical targets.
The agency recommends cryptographic agility so systems can replace algorithms as requirements evolve. Developers and wallet providers will need to coordinate protocol and wallet upgrades while communicating migration steps clearly to users.
The second report, “Harvest Now, Decrypt Later,” produced jointly with Carlos III University of Madrid, examines a separate threat. Attackers could collect and store encrypted information today, then attempt decryption once more advanced computing capabilities become available. Quantum computers are not required during the collection phase.
This risk is most relevant to data that must remain confidential for many years, such as government communications, intellectual property, medical records and law-enforcement files. Europol found no clear evidence that the tactic is being systematically exploited at scale. The storage, processing and technical demands involved make high-value, long-lived information the more plausible target.
Actual exposure depends on the encryption protocols, configurations and key-management practices protecting the data. Recommendations include retiring outdated protocols, limiting unnecessary data retention, improving flexible key management and testing post-quantum solutions in phases.
Both reports emphasize that the timing of practical quantum capabilities remains uncertain. Organizations should identify systems that rely on vulnerable cryptography, assess which information requires long-term protection and plan upgrades incrementally. For cryptocurrency networks, preparation involves coordinated work on protocols and wallets together with transparent communication about future requirements.
Europol frames the issue as a preparation challenge rather than an immediate attack scenario. No publicly demonstrated quantum computer can currently derive cryptocurrency private keys at the scale needed to compromise modern blockchain signature systems. The agency’s guidance centers on beginning the transition now so that systems can adapt before any practical threat materializes.









