Key facts
- Europol identified cryptocurrency wallets as the primary risk for quantum attacks.
- Hash functions securing blockchains are largely resistant to quantum attacks.
- Migrating all unspent Bitcoin transaction outputs could require 76 days of cumulative downtime.
- The 'harvest now, decrypt later' tactic makes government communications and confidential business data plausible targets.
- The EU's NIS Cooperation Group recommended member states adopt a post-quantum migration strategy by the end of 2026.
Europol, the European Union's law enforcement agency, has issued a stark warning about the potential impact of quantum computing on the cryptocurrency sector. In two reports published Wednesday, the agency urged immediate preparation for a future where quantum computers could break current encryption standards.
The European Cybercrime Centre, a division of Europol, pinpointed cryptocurrency wallets as the "primary point of exposure to quantum threats." The reports explain that wallets use a pair of keys: a private key for authorizing transactions and a public key for verification. A powerful quantum computer could potentially derive a private key from an exposed public key, allowing attackers to steal funds. This event is often referred to as Q-Day.
While the hash functions that secure blockchains and underpin mining are considered largely quantum-safe due to the immense computational power required to break them, the security of wallet keys is a more immediate concern. The reports highlight that wallets with already visible public keys on the blockchain cannot be secured retroactively. For these, the only recourse is a pre-emptive migration of funds to new, quantum-resistant wallets. Blockchain analytics firm Glassnode estimated in May that approximately 6.04 million BTC, or 30.2% of the total issued supply, has already had its public key exposed.
Upgrading Bitcoin's security to be quantum-resistant presents significant technical challenges. Post-quantum signature standards are substantially larger than current ones, which could strain block space, increase transaction fees, and slow down confirmation times. A 2024 study cited by Europol suggests that migrating all unspent transaction outputs could necessitate at least 76 days of cumulative network downtime.
Europol referenced roadmaps from companies like IBM and Microsoft, which target the development of fault-tolerant quantum computers by 2029. Surveys of experts indicate a notable probability, between 28% and 49%, of a machine capable of breaking RSA-2048 encryption within the next decade. Google's recent research has also suggested lower resource estimates for attacking the elliptic curve cryptography used by Bitcoin.
Industry players are already acknowledging the threat. Coinbase's quantum advisory council has advised developers to commence post-quantum migration efforts. Ripple and the Stellar Development Foundation have released their own migration roadmaps. Furthermore, a consortium of nine firms, including BlackRock and Coinbase, has pledged $15 million over three years for Bitcoin security research, with a focus on quantum defenses.
A second Europol report, developed with Spain's University Carlos III of Madrid, examined the "harvest now, decrypt later" tactic, where encrypted data is collected today for future decryption by quantum computers. This poses a risk to widely used protocols like TLS, SSH, and OpenPGP, with government communications and confidential business data being the most plausible targets. While there's no clear evidence of this tactic being widely exploited yet, the EU's financial supervisors have also flagged this concern. Europol recommends a European Commission-led working group to regularly brief policymakers on post-quantum strategies, with the U.S. National Institute of Standards and Technology proposing a phase-out of classical public-key cryptography by 2035.
