On October 7, 2026, the European police agency Europol published two technical reports that reframe the quantum threat debate across the crypto ecosystem: blockchains themselves will not collapse, but wallets whose public keys are already exposed on-chain remain the structural weak point.
🔑 Key Takeaways
- Europol estimates that 6.9 million BTC (around $586 billion) sit in legacy or reused addresses potentially vulnerable to Shor’s algorithm.
- Hash functions securing blockchain history remain broadly resistant to quantum attacks.
- The reports detail a “Harvest Now, Decrypt Later” (HNDL) strategy in which encrypted data is intercepted today for future decryption.
- The European Commission requires member states to begin the post-quantum transition by the end of 2026.
- The Ethereum Foundation targets 2029 to complete its consensus-layer post-quantum infrastructure.
The Threat Targets Wallets, Not Blockchains
The European Cybercrime Centre (EC3) report, titled Quantum Computing and Cryptocurrencies, draws a distinction often missing from public debate. Hash functions — including those used in bitcoin mining — remain structurally more resistant to quantum attacks than the public-key cryptography that controls wallets. The historical integrity of a blockchain, guaranteed by the cryptographic work of miners, is not the immediate target.
The risk lies in asset ownership. When a bitcoin transaction is broadcast, the sender’s public key becomes visible on-chain. A sufficiently powerful quantum computer could, by running Shor’s algorithm, derive the matching private key and sign unauthorized transactions. According to CryptoQuant estimates cited by Europol, roughly 6.9 million BTC sit in addresses where the public key is already exposed. At the time of writing, this figure was valued at approximately $586 billion.
Europol stresses that already-revealed keys cannot be retroactively secured — a problem fueling a growing community debate over whether to freeze dormant “Satoshi era” holdings as the threat draws closer.

Shor’s Algorithm and the Harvest Now, Decrypt Later Strategy
The reports explain the attack mechanism in accessible terms. Shor’s algorithm, developed in 1994, solves in polynomial time the factoring and discrete logarithm problems that underpin ECDSA (Elliptic Curve Digital Signature Algorithm), the digital signature scheme used by bitcoin and ethereum. With a public key in hand, a malicious actor equipped with a quantum machine of several thousand logical qubits could recover the corresponding private key and transfer the funds.
“Cryptocurrencies will not collapse because of quantum computing. The immediate problem concerns ownership of assets held in wallets, not the ability of a quantum computer to rewrite the bitcoin blockchain.”
Europol, EC3 report
The temporal dimension adds a systemic risk. Europol details the “Harvest Now, Decrypt Later” (HNDL) strategy: state or criminal actors intercept encrypted data today, waiting for a future decryption window. Transactions broadcast on public blockchains, where public keys appear in plaintext after spending, are particularly exposed to this opportunistic collection. The amounts at stake extend well beyond individual users: European financial services are urged to integrate this risk into their threat models before 2030.
Regulatory Timeline and NIST Standards
The institutional response is accelerating on both sides of the Atlantic. The European Commission has set a roadmap requiring member states to begin the transition to post-quantum security measures by the end of 2026. In September 2026, the European Supervisory Authorities (ESA) issued an alert highlighting the risk that a technical breakthrough could precede commercial applications, meaning a security risk could materialize well before quantum computers become common commercial tools.
| Standard | Name | Type | Cryptographic basis |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key encapsulation | Lattice-based |
| FIPS 204 | ML-DSA (Dilithium) | Digital signature | Lattice-based |
| FIPS 205 | SLH-DSA (SPHINCS+) | Stateless signature | Hash functions |
NIST plans to deprecate ECDSA by 2030 and ban it by 2035. Google has set an internal deadline of 2029 to migrate its own systems. IBM stated in July 2025 that it expects quantum computing to generate significant commercial revenue within two to four years, suggesting the threshold of capacity useful for breaking ECDSA is drawing near.
Ethereum’s Structured Response
The Ethereum Foundation is anticipating this transition with a plan published on ethereum.org. In February 2026, Vitalik Buterin identified four areas requiring post-quantum upgrades: BLS signatures on the consensus layer, KZG polynomial commitments for data availability, ECDSA signatures on the execution layer, and zero-knowledge proofs (ZK-proofs) on the application layer.
| Milestone | Goal |
|---|---|
| I | Post-quantum key registry for validators |
| J | Precompilations for post-quantum signature verification |
| L | Post-quantum attestations and real-time proofs via leanVM |
| M | Full post-quantum signature aggregation and secure data commitments |
EIP-8141, scheduled for the Hegotá hard fork in the second half of 2026, introduces account abstraction that will allow each user to migrate individually to a post-quantum scheme without waiting for a global upgrade. STARK proofs, already used by several rollups, offer native resistance since they rely on hash functions rather than elliptic curves. A dedicated team, led by Thomas Coratger, publicly tracks its work at pq.ethereum.org. The ecosystem is further supported by the Poseidon Prize ($1 million) for hash-based cryptographic primitives research, and a second post-quantum research summit scheduled for October 9-12, 2026 in Cambridge.
The Technical Obstacles for Bitcoin
For bitcoin, the difficulty is less algorithmic than social. A 2024 study cited by Europol estimates that converting every unspent transaction output (UTXO) to a post-quantum format would require at least 76 days of cumulative block space. Allocating 25% of each block, the process would stretch to roughly 300 days. New post-quantum signature schemes are also 10 to 120 times larger than current ECDSA signatures, weighing on network throughput and node bandwidth.
The core challenge remains coordination. Persuading a global, decentralized network to adopt a cryptographic format change before vulnerable wallets become exploitable targets demands a level of political and technical consensus unprecedented in the protocol’s history. The bitcoin community remains divided over whether to freeze dormant holdings — and therefore sacrifice the immutability principle — to prevent a massive quantum theft.
Conclusion
Europol’s reports reframe the debate: the quantum threat is not theoretical but an operational risk on a 2029-2030 horizon, carried by the exposure window of public keys already published on-chain. ECDSA, the cryptographic foundation of bitcoin and ethereum, will be deprecated by 2030 under the NIST timeline, imposing a narrow transition window on the two largest networks.
Ethereum appears structurally better prepared, thanks to a public roadmap, a dedicated team, and numbered milestones through 2029. Bitcoin, by contrast, faces a governance challenge where technical urgency collides with the difficulty of amending a conservative protocol. For individual holders, using fresh single-use addresses — avoiding the reuse that exposes the public key — remains the most immediate and accessible precaution available today.
Sources
- CoinDesk — Quantum computers threaten exposed private keys rather than blockchains: Europol warns
- TradingView — Europol Warns Crypto Wallets Are the Weak Spot for Future Quantum Attacks
- Ethereum.org — Quantum Resistance Roadmap
- The QRL — Definitive Guide to Post-Quantum Blockchain Security
- Europol — Prioritising Post-Quantum Cryptography Migration Activities in Financial Services
This article is published for informational and educational purposes. It does not constitute investment advice. Do your own research (DYOR) before making any decisions.

