Europol identifies 6.9M bitcoin in wallets vulnerable to quantum attacks
Europol says cryptocurrency wallets, not the blockchains underpinning them, are the real target any future quantum computer would need to crack. The warning adds urgency to a long-running debate over how and when networks like bitcoin should adopt post-quantum cryptography.
- About 6.9 million bitcoin sit in addresses with exposed public keys, including long-dormant early wallets.
- Machines capable of deriving private keys from those exposed public keys do not exist yet, Europol said.
- Researchers increasingly treat 2029 as the year credible migration plans toward resistant cryptography must be in place.
- 6.9M bitcoin sitting in wallets with already-exposed public keys
- 2029 year flagged as deadline for migration-readiness planning
- 300 days of block space needed to convert all wallets at 25% allocation
- 10 to 120x larger replacement signatures compared with current ECDSA signatures
Cryptocurrency wallets, rather than the blockchains that record transactions, are the primary point of exposure to future quantum-computing attacks, Europol said in a report published Wednesday, according to CoinDesk. The European Union’s law enforcement agency said machines powerful enough to break current wallet encryption do not exist yet, and it declined to predict when they might. Still, Europol’s European Cybercrime Centre urged the industry to begin a phased shift toward resistant security now, before any such machine arrives.
6.9 million bitcoin sit in wallets with exposed public keys
The agency’s Quantum Computing and Cryptocurrencies report found that roughly 6.9 million bitcoin sit in addresses whose public keys are already visible onchain. That group includes early pay-to-public-key outputs from bitcoin’s first years and many addresses that have sat untouched for over a decade.
A sufficiently powerful machine could use an exposed public key to derive its matching private key and move the funds. Europol said those keys cannot be secured retroactively once exposed, a problem it called central to the debate over whether so-called “Satoshi-era” wallets should eventually be frozen.
The report drew a distinction it said is often lost in such warnings: the hash functions securing bitcoin’s transaction history and mining process are far more resistant to attack than the public-key cryptography, known as ECDSA, that controls spending from wallets. Europol wrote that “cryptocurrencies will not collapse due to quantum computing,” framing the risk as one of asset ownership rather than network integrity.
Converting bitcoin’s wallets could take up to 300 days of block space
Fixing the problem networkwide is harder than finding replacement cryptography, Europol said. The agency cited a 2024 study estimating that converting every bitcoin unspent transaction output, or UTXO, to a resistant format would require at least 76 days of cumulative block space.
Reserving 25% of each block for that migration, the same study found, would stretch the process to about 300 days, nearly a year of dedicated capacity on a network that otherwise processes ordinary transactions. New replacement signature schemes now being tested are 10 to 120 times larger than bitcoin’s current Elliptic Curve Digital Signature Algorithm signatures, according to the report.
2029 emerges as the informal deadline for migration plans
Bitcoin researchers and institutions increasingly point to 2029 as the year by which credible migration plans need to be in place, according to the report. IBM said in July it expects the technology to generate significant commercial revenue within the next two to four years, a timeline that overlaps with that window.
Europol said the larger obstacle is not technical but coordination: persuading a decentralized network of developers, miners, exchanges and users to adopt new standards before exposed wallets become active targets. The agency concluded that “proactive adaptation, rather than systemic collapse, is the most likely outcome,” signaling confidence that the shift is achievable if begun early.
The BlockWest read. Custodians and institutional holders sitting on dormant, exposed-key bitcoin face a planning problem long before any capable machine exists. Waiting for industrywide consensus on migration standards is itself a risk. Firms that move funds into upgraded wallets now will be far less exposed than those that wait for a forced, networkwide deadline to arrive.
Europol’s report leaves unresolved the question dividing bitcoin’s community: whether exposed Satoshi-era wallets should eventually be frozen to prevent theft, or left untouched on principle. With no fixed regulatory deadline and 2029 cited only as a rough planning horizon, that decision rests with developers, miners
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
