Europol’s latest assessment puts the first serious quantum-computing risk at the wallet layer. Public-key cryptography authorizes spending, so a machine capable of running the relevant quantum attack could derive a private key from exposed public information. The report treats that prospect as a security-engineering problem that requires preparation, not as evidence that cryptocurrencies will suddenly stop working.

Wallet signatures and blockchain hashes face different attacks

A cryptocurrency system uses several kinds of cryptography. Wallets rely on public-key signature schemes to prove that a transaction was authorized. Blockchains also use hash functions to link records, support consensus and make past data difficult to alter. Europol says quantum algorithms pose a credible threat to current public-key cryptography, while the hash functions protecting blockchain integrity remain more resistant.

That separation changes the order of work. Teams need to identify where public keys become visible, which signature schemes are in use and how funds can move to quantum-resistant addresses. Replacing a signature scheme is a protocol and wallet migration. It also requires exchanges, custodians, software providers and users to coordinate around compatible transaction formats.

The threat has more than one clock

No attack-capable quantum computer exists today, and Europol does not give a date for one. The report instead describes uncertainty around the number of reliable logical qubits, error correction and the resources needed to run useful attacks. Hardware roadmaps are signals for planning, not proof that a cryptographic break will occur on schedule.

Data exposure creates a separate timing issue. A transaction can reveal the public key needed to verify its signature. If a future attacker could recover the matching private key before confirmation, the attacker could try to redirect the funds. Keys that have already been exposed also create a migration question for assets left at old addresses. A safe plan therefore cannot begin only after a practical attack is demonstrated.

Block space makes migration an operational problem

Post-quantum signatures are not a drop-in replacement with identical costs. Europol notes that NIST-standardized post-quantum schemes can produce signatures 10 to 120 times larger than ECDSA signatures. Larger transactions consume more block space and can affect fees and confirmation capacity.

The report cites a 2024 study estimating that moving all Bitcoin unspent transaction outputs would require at least 76 days of cumulative block capacity if the migration occupied the chain continuously. Reserving one quarter of each block would extend the exercise to roughly 300 days. Those figures are scenario estimates, not a migration schedule, but they show why wallet upgrades, protocol design and user coordination need to be tested before an emergency.

What preparation can establish now

Europol recommends incremental upgrades, adoption of post-quantum cryptography and continued research into quantum-enhanced security. It also calls for guidelines, industry coordination and user education. Account abstraction and multisignature designs may reduce dependence on a single key, but they do not by themselves remove every vulnerable algorithm or resolve the network-wide migration.

A useful readiness review should inventory signature schemes, exposed-key conditions, upgrade paths and recovery procedures. It should also test how wallets and services recognize new address types without confusing a protocol transition with an immediate breach. The practical goal is a staged migration that preserves access to funds while networks still have time to coordinate.

Source: BTCUSA.