Europol Urges Crypto Firms to Prepare for Future Quantum Threats

Daily Feed
Europol Urges Crypto Firms to Prepare for Future Quantum Threats

Europol urges crypto firms to prepare for future quantum threats

Europol is urging cryptocurrency firms and other organizations to prepare for a possible quantum threat in the future. The agency is not warning that today’s machines can break crypto wallets. No one knows when that capability might arrive, and migrating decentralized networks and existing funds could be difficult.

  • Wallet signatures and exposed public keys are the main concern.
  • No publicly demonstrated quantum computer is known to steal crypto at scale.
  • Europol recommends phased preparation and clear migration plans.
  • Bitcoin’s post-quantum proposal remains a draft.

In two reports published on Oct. 7, Europol examined quantum risks to cryptocurrency wallets and the separate possibility that attackers could store encrypted information now and decrypt it later. The agency does not claim that quantum computers can break cryptocurrency security today. Its warning concerns a capability that may emerge in the future, and the time it could take to prepare.

Why wallet signatures matter

Many blockchains use public-key cryptography to confirm that a transaction was authorized by the holder of a private key. The public key helps verify a digital signature. The private key creates the signature and controls the funds.

A sufficiently capable quantum computer could, in theory, use an exposed public key to derive its corresponding private key. An attacker could then sign unauthorized transactions. Europol identifies digital signatures and wallet authorization keys as the main concern.

How much of a public key is exposed depends on the address type and how it is used. For example, a Bitcoin address that hashes a public key generally reveals that key when the funds are spent. Other output types can put public-key information on-chain from the start. Reusing an address can also leave a key exposed after an earlier spend. Wallets do not all face the same level of exposure.

Europol says blockchain hash functions are comparatively resistant to quantum attacks. That does not make hashes immune. Some quantum algorithms can reduce the security margin of hash-based systems. But the main concern for potential wallet theft is breaking public-key signature systems, not simply “switching off” every part of a blockchain.

Wallet theft and stored data are different risks

No publicly demonstrated quantum computer is known to derive cryptocurrency private keys at the scale needed to steal assets protected by modern blockchain signature systems. No one knows when such a machine might arrive. Europol’s warning is about preparation, not evidence of an active wave of quantum-powered theft.

A separate Europol report, developed with University Carlos III of Madrid, examines “harvest now, decrypt later.” In this scenario, attackers collect encrypted information they cannot read today and keep it in case future computing systems can decrypt it.

Government communications, medical records, intellectual property and law-enforcement files may remain sensitive for years. Their exposure depends on the encryption protocols, configurations and key-management practices used to protect them. Europol says it found no clear evidence of systematic, large-scale harvest-now-decrypt-later activity. Collecting and retaining data at that scale would require substantial resources.

Preparing for a migration

Europol recommends preparing in stages. That includes testing post-quantum cryptography, improving wallet and key-management practices, coordinating upgrades and explaining clearly to users what a migration will require. In separate migration-planning guidance for financial services, the agency recommends ranking systems by their cryptographic vulnerability, exposure and importance.

The U.S. National Institute of Standards and Technology (NIST) finalized three post-quantum standards in August 2024:

  • FIPS 203, ML-KEM: a standard for establishing shared cryptographic secrets, derived from CRYSTALS-Kyber. It is not a digital-signature scheme for authorizing blockchain transactions.
  • FIPS 204, ML-DSA: a digital-signature standard derived from CRYSTALS-Dilithium.
  • FIPS 205, SLH-DSA: a hash-based digital-signature standard derived from SPHINCS+.

NIST says organizations should begin moving to quantum-resistant systems. Its planned transition would deprecate and eventually remove quantum-vulnerable algorithms from NIST standards by 2035, with higher-risk systems expected to move sooner. In March 2025, NIST selected HQC for standardization as another key-establishment algorithm. FALCON is in development as a separate digital-signature standard.

These standards are building blocks, not a universal upgrade that can be dropped into every wallet and blockchain. Networks and service providers still need to decide what to support, update their infrastructure and make the transition without creating new security or usability problems.

Bitcoin’s technical proposal and the question of unmoved funds

Draft Bitcoin Improvement Proposal BIP-361 proposes a planned move away from legacy ECDSA and Schnorr signatures after a post-quantum Bitcoin output type becomes available. In practical terms, it outlines a path to new signature protections. The proposal remains a draft and has not been activated on Bitcoin.

Even if the community agrees on a technical path, existing funds would remain a challenge. Holders would need to move their bitcoin into outputs protected by the new system. Some may be unable to act, unaware of the change or unwilling to move their funds. That raises a difficult policy question: what, if anything, should happen to coins whose owners do not migrate them? No answer has been settled.

Ledger CTO Charles Guillemet has argued that safely migrating wallets and existing funds could be Bitcoin’s hardest quantum-readiness problem. The challenge goes beyond cryptography. It also involves coordination, user education and decisions about dormant coins, a concern raised in a Bitcoin quantum-migration plan that would freeze legacy funds.

Some companies are already preparing. BitGo and Silence Laboratories tested post-quantum multiparty computation (MPC) signing in an institutional custody workflow using ML-DSA. The post-quantum signature scheme addresses the potential quantum threat. MPC describes how signing is distributed across multiple parties or components. BitGo has also introduced controls for supported institutional Bitcoin wallets, including tools to assess public-key exposure, consolidate outputs and help clients move funds considered more exposed in a future quantum scenario.

Coinbase has reportedly been designing custody infrastructure that can support different post-quantum signature schemes, since, as Bitcoin developers have not selected a final replacement. Galaxy Digital established a $5 million program to fund Bitcoin research into quantum-resistant signatures, migration tools and security audits.

Other networks are exploring different designs. Sui plans to offer optional quantum-safe authentication using NIST-approved signature schemes and is targeting native post-quantum accounts for mainnet in 2027. Monad researchers have proposed separating account addresses from authentication keys, which could let users change keys without giving up the same address. The proposal is still under development.

Key questions about quantum threats to crypto

  • Can today’s quantum computers break cryptocurrency wallets?

    No publicly demonstrated machine is known to derive private keys at the scale needed to steal assets protected by modern blockchain signatures.

  • Which wallet protections are most exposed?

    Digital signatures are the main concern, especially when public keys are exposed. The level of exposure depends on the address type and how it is used.

  • Is “harvest now, decrypt later” happening at scale?

    Europol says it found no clear evidence of systematic, large-scale activity. Information collected today could still matter if future systems can decrypt it.

  • Has Bitcoin chosen a post-quantum signature scheme?

    No. BIP-361 is a draft, and Bitcoin has not activated a post-quantum output type or selected a final replacement.

  • Why is moving funds a challenge?

    A migration may require coordinated changes by developers, wallet providers and custodians, along with action from individual holders. Dormant funds raise unresolved questions about what happens when owners do not move their coins.

The practical next step is preparation: assess which keys and data are exposed, test suitable alternatives and make migration requirements clear before a deadline becomes urgent. Quantum risk is no reason to panic. But uncertain timing is no excuse to assume decentralized systems can upgrade overnight.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog