Invest2 publishersAlso reported elsewhere3 min readPublished
Europol tells crypto holders to move exposed wallet keys before quantum computers can break them
Europol named wallet keys as crypto's main quantum exposure, a risk that covers the 6.04 million bitcoin Glassnode counts with public keys already on-chain. Its report says those coins can be protected only by moving them before an attack, so the length of the migration queue sets the deadline for custodians.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Europol's cybercrime centre found the hash functions that link blocks and secure mining largely quantum-safe, calling the effort to break a 256-bit hash "astronomically high with foreseeable technology."
- A 2024 study the report cites puts migrating every unspent bitcoin output at 76 days of cumulative downtime, or roughly 300 days if the work took 25% of each block.
- NIST-standardised post-quantum signatures are 10 to 120 times larger than Bitcoin's ECDSA signatures, and the report warns they would crowd blocks and raise fees.
- Nine firms, BlackRock, Coinbase and Strategy among them, committed $15 million between them in July to fund three years of Bitcoin security research, with quantum defences part of the remit.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Custodians holding coins at exposed addresses have to set a migration start date before any attack is credible, since Europol says those outputs cannot be secured after the fact.
- constraint A migration taking a quarter of each block leaves ordinary bitcoin payments three quarters of the network's capacity for about ten months.
- cost Holders pay for the move in transaction fees on far larger signatures, and the bill grows if they all try to move in the same few months.
"Cryptocurrencies will not collapse due to quantum computing," the report concludes [5]. The danger it describes is narrower. A powerful enough machine could work out a private key from a public key already visible on-chain and spend the coins [3]. The report pairs moves by individual owners with a phased transition to quantum-resistant cryptography and better key management [6].
For a custodian, the figure to plan around is how long the move takes. At full blocks, the floor in the 2024 study is 76 days [10]. Give migration a quarter of each block and 76 divided by 0.25 is 304 days [20], close to the study's own figure of roughly 300. IBM's roadmap targets a fault-tolerant quantum computer by 2029 [11], and Microsoft expects scalable quantum computing in the same year [13]. To finish before such a machine exists, a migration has to start at least 304 days earlier, and that assumes the queue moves in order [20].
This could go differently in three ways. The first is a late machine: taken at face value, the surveyed experts put the odds that nobody breaks RSA-2048 within a day this decade at 51% to 72% [22]. That survey measured RSA, though. Google research in March and an AI-assisted competition in September both lowered the resources thought necessary to attack the elliptic-curve cryptography Bitcoin uses [14]. The second is an orderly start at a quarter of each block. The third is a late scramble toward the full-block floor, where migrations compete with every other transaction for space and post-quantum signatures push fees up [9].
I think the evidence supports starting custody migration plans now. The queue can be measured today and the attack date cannot. The case against rests on the survey's majority outcome: anyone who moves early pays fees for protection they may not need for ten years [22]. My view would weaken if a signature design sharply cut the block space each migrated output uses, or if estimates of what it costs to attack elliptic curves stopped falling [14].
Industry money so far is easy to size. The July pledge comes to $5 million a year [23], or about $556,000 per firm per year if the nine split it evenly [24]. Decrypt's report does not give the split. Coinbase's quantum advisory council urged developers in June to start migration work, and Ripple and the Stellar Development Foundation have published migration roadmaps [15].
For payments, the report rates real-time interception, which it calls a "just-in-time" attack, as a more immediate quantum risk than decrypting recorded data later [17]. Its companion study, on attackers who harvest encrypted data now to decrypt it later, found "currently no clear evidence" that the technique is being exploited systematically at scale [18].
What to watch
- Whether Bitcoin developers settle on a post-quantum signature scheme compact enough to cut the 76-day full-block migration floor.
- Any further cut in the resources estimated to break elliptic-curve keys, after Google's March research and September's AI-assisted competition.
- EU member states' post-quantum migration strategies, which the NIS Cooperation Group wants adopted by the end of 2026, and whether they reach crypto custodians.