Europol says cryptocurrency wallets, not blockchains themselves, are the main point of exposure to future quantum-computing attacks. About 6.9 million BTC sit at addresses with exposed public keys, including early and long-dormant holdings. Computers capable of deriving private keys from those keys do not exist yet, and Europol gave no timeline for when they might.
Why it matters
A sufficiently powerful quantum computer could use an exposed public key to derive the corresponding private key and spend the funds. Europol distinguishes that wallet risk from the cryptography protecting blockchain history and Bitcoin mining, which it said is more resistant to quantum attacks. The agency said “proactive adaptation, rather than systemic collapse, is the most likely outcome.”
Keys already exposed cannot be made safe retroactively, leaving the fate of vulnerable, dormant BTC addresses a contentious question for the Bitcoin community. Researchers and institutions increasingly identify 2029 as a target for having credible quantum-resistant migration plans in place.
Market impact
Europol is urging developers, miners, exchanges and users to begin a phased shift to wallet upgrades and post-quantum cryptography. The challenge is coordinating adoption across a global, decentralized network before vulnerable wallets become targets.
A 2024 study cited by Europol estimated that moving every Bitcoin unspent transaction output to a quantum-resistant format would use at least 76 days of cumulative block space. If 25% of each block were reserved for migration, the process would take about 300 days. Post-quantum signature schemes could also be 10 to 120 times larger than Bitcoin’s current ECDSA signatures, adding a capacity trade-off to the migration.
Frequently asked questions
-
Why does Europol identify Bitcoin wallets, rather than the blockchain, as the main quantum risk?
A powerful quantum computer could derive a private key from an exposed public key and spend the funds. Europol said the cryptography protecting blockchain history and mining is more resistant to quantum attacks.
-
How much Bitcoin is held at addresses with exposed public keys?
About 6.9 million BTC sit at addresses with exposed public keys, including early and long-dormant holdings.
-
Do quantum computers capable of stealing Bitcoin exist now?
No. Europol said computers capable of carrying out such attacks do not exist yet and did not predict when they will.
-
How long could a Bitcoin quantum-resistant migration take?
A 2024 study cited by Europol estimated at least 76 days of cumulative block space to convert every UTXO. Reserving 25% of each block would stretch the process to about 300 days.
-
What trade-off could larger post-quantum signatures create for Bitcoin?
Post-quantum signature schemes could be 10 to 120 times larger than Bitcoin’s current ECDSA signatures, adding a capacity consideration to the migration.
CoinDesk