Close-up of a microchip on a circuit board
Crypto

Europol warns quantum risk is wallet theft from exposed keys, not a Bitcoin chain break

The agency estimates about 6.9 million BTC sit at addresses with exposed public keys and urges a phased post-quantum migration.

By Marcus Hale6 min read

Europol said the most plausible quantum-computing threat to crypto is unauthorized spending from wallets whose public keys are already visible on-chain, not rewriting blockchain history. The agency urged the industry to start phased post-quantum migration planning now, while stressing attack-capable quantum machines do not exist yet and offering no timeline.

Key Takeaways

  • Europol framed the quantum threat as a wallet-control problem tied to public-key cryptography, not an imminent failure of hash-function-secured chain history.
  • The agency said quantum computers capable of executing these attacks do not exist yet and it did not offer a forecast for when they might.
  • Roughly 6.9 million BTC are held at addresses with exposed public keys, including early and long-dormant “Satoshi era” holdings.
  • A cited 2024 estimate put a full Bitcoin UTXO migration at at least 76 days of cumulative block space, or about 300 days if 25% of each block were reserved.

Europol’s Quantum Warning Targets Wallet Keys, Not Bitcoin’s Chain History

Europol’s new quantum report draws a line traders should care about. The near-term failure mode is not “Bitcoin gets rewritten.” It is “coins get spent by someone else.”

The agency said cryptocurrency wallets are the primary point of exposure to future quantum attacks because they rely on public-key cryptography. By contrast, Europol described the hash functions that secure blockchain history, including bitcoin mining, as far more resistant to quantum attacks. “Cryptocurrencies will not collapse due to quantum computing,” the report said.

Europol also stripped out the most common source of panic: timing certainty. Quantum computers capable of carrying out the relevant attacks do not exist yet, Europol said, and it did not predict when they will. The report’s base case is a long runway and a messy transition, arguing that “proactive adaptation, rather than systemic collapse, is the most likely outcome.”

Why 6.9M BTC in Exposed Public Keys Keeps the Tail-Risk Narrative Alive

The number that keeps this from being a purely academic debate is 6.9 million BTC. Europol said that amount sits at addresses with exposed public keys, including early pay-to-public-key outputs and many long-dormant holdings.

“Exposed public key” is the operational detail. A public key is considered exposed when it is visible on-chain. Europol’s concern is straightforward: if a sufficiently powerful quantum computer can derive a private key from a public key, it can spend the associated funds. The private key is the credential that authorizes spending. Lose exclusivity over it and ownership becomes a race.

That is why the report repeatedly points back to early Bitcoin-era patterns, often labeled “Satoshi era.” Some of those early address types and spending behaviors leave public keys visible on-chain, and many of the coins tied to them have been dormant for years. Dormant supply is usually treated as structurally illiquid. Quantum changes the framing from “illiquid forever” to “illiquid until it isn’t,” with the counterparty being whoever has the first credible quantum capability.

Europol’s harder statement is that this exposure is not something the network can clean up after the fact. Exposed keys “cannot be made safe retroactively,” the agency said. That constraint is what turns the issue into governance and social coordination, including the report’s reference to ongoing controversy over whether BTC in Satoshi-era wallets should be frozen as the quantum threat approaches.

Migration Math: Block-Space Constraints and 10–120x Larger Signatures

Even if post-quantum cryptography is available, Europol’s report argues the bottleneck is migration capacity and coordination. Bitcoin’s security model is social as much as it is mathematical. Upgrades only matter if the network adopts them.

The report urged a phased transition “now” via wallet upgrades, post-quantum cryptography, and coordination among developers, miners, exchanges, and users. That list is the point. A migration that touches wallet software, custody stacks, exchange infrastructure, and miner policy is not a patch Tuesday.

Europol cited a 2024 study estimating that converting every Bitcoin unspent transaction output (UTXO) to a quantum-resistant format would require at least 76 days of cumulative block space. A UTXO is a spendable chunk of bitcoin. Migrating UTXOs means moving existing coins into new locking scripts or address formats that rely on quantum-resistant assumptions.

The same estimate gets uglier once you price in real-world throughput constraints. Reserving 25% of each block for migration would stretch the process to about 300 days, Europol said. That is a long window where fees, mempool pressure, and user incentives decide whether the plan is feasible or politically dead on arrival.

Signature size is the other constraint Europol highlighted. New post-quantum signature schemes can be 10 to 120 times larger than Bitcoin’s current Elliptic Curve Digital Signature Algorithm (ECDSA) signatures, the report said. ECDSA is the mechanism that proves ownership and authorizes transfers. Inflate signatures by an order of magnitude and block space becomes a policy fight, not a technical footnote.

Signals Traders Should Track as Post-Quantum Planning Moves From Theory to Roadmap

The first signal is formalization. Watch for Bitcoin ecosystem proposals or BIPs that lay out a phased post-quantum migration path, including wallet upgrade expectations and any early timelines attached to them.

The second is surface-area reduction in custody and on-chain behavior. Moves by exchanges and custodians to reduce exposed-public-key patterns matter because they shrink the set of coins that become “first targets” in Europol’s framing.

The third is fee reality. A migration that competes for block space will be fee-sensitive by design. Any serious discussion about reserving block capacity for migration, even informally, is a tell that the ecosystem is moving from research to operational planning.

The fourth is governance escalation around long-dormant exposed outputs. Europol flagged debate over whether to freeze Satoshi-era BTC. If that conversation shifts from forum argument to concrete proposals, it becomes a market-structure issue around supply legitimacy and settlement finality.

My Read: The Market Risk Is a Coordination Shock, Not a Sudden ‘Bitcoin Break’

The threshold that matters is not a quantum breakthrough headline. It is whether the ecosystem can agree on a migration path that fits inside Bitcoin’s block-space budget without turning fees into a permanent tax. Europol’s own numbers make the point: 76 days of cumulative block space is the clean case, and 300 days is the “only 25% of blocks” case. That is a long coordination window.

If credible post-quantum standards emerge but adoption stalls, the setup starts to look structural rather than narrative-driven. The practical risk is a drawn-out repricing of exposed-key coins and custody practices, not a single day where Bitcoin “breaks.”

Sources