Summary
- Europol, the law enforcement agency of the European Union, released two reports on Wednesday, urging the cryptocurrency sector and policymakers to take proactive measures against potential quantum computing threats.
- The agency's cybercrime division identified wallet keys as the most significant vulnerability, while noting that the hash functions securing blockchains are mostly resistant to quantum attacks.
- A study referenced by Europol estimates that transitioning all Bitcoin outputs to quantum-safe standards would necessitate at least 76 days of total network downtime.
On Wednesday, Europol released two reports emphasizing the need for the cryptocurrency industry and policymakers to prepare for the emerging threats posed by quantum computers that could undermine common encryption methods.
The first report, Quantum Computing and Cryptocurrencies, produced by Europol's European Cybercrime Centre, highlights cryptocurrency wallets as "the primary point of exposure to quantum threats." These wallets depend on a pair of keys: a private key for authorizing transactions and a public key for network verification.
According to the report, a sufficiently advanced quantum computer could extract a private key from a public key that has been exposed, enabling an unauthorized user to access funds. This scenario is often referred to as Q-Day.
The report indicates that the hash functions used in blockchain technology are generally resistant to quantum threats, as breaking a 256-bit hash would require a number of operations deemed "astronomically high with foreseeable technology."
"Cryptocurrencies will not collapse due to quantum computing," the report concludes, advocating for “proactive defense” strategies to ensure their future security. It suggests a gradual shift to quantum-resistant cryptography and improvements in wallet security and key management.
Wallets with public keys already visible on-chain cannot be retroactively secured. The report states that for these wallets, "the only solution is pre-emptive migration," urging owners to transfer funds to new wallets before any potential attack. Blockchain analytics firm Glassnode estimated in May that 6.04 million BTC, representing 30.2% of the total supply, has had its public key compromised.
Myriad: How high will Bitcoin go? Click to make your prediction.Transitioning Bitcoin to quantum-safe protocols involves significant costs. NIST-standardized post-quantum signatures are 10 to 120 times larger than the current ECDSA signatures used by Bitcoin, potentially overloading block space, increasing fees, and delaying confirmations. A 2024 study estimates that migrating every unspent transaction output would require a minimum of 76 days of cumulative downtime, or around 300 days if the migration occupied 25% of each block's capacity.
The report references IBM's roadmap, aiming for a fault-tolerant quantum computer by 2029, and a 2025 survey in which 32 experts assessed the likelihood of a machine breaking RSA-2048 encryption within the next decade at 28% to 49%.
Similarly, Microsoft anticipates scalable quantum computing by 2029, while research from Google in March and AI-enhanced competition in September both revised down the resource requirements for attacking the elliptic curve cryptography employed by Bitcoin.
Coinbase's quantum advisory council encouraged developers in June to start post-quantum migration efforts immediately, while Ripple and the Stellar Development Foundation have already laid out migration strategies. In July, nine firms, including BlackRock and Coinbase, committed a total of $15 million over three years towards research on Bitcoin security, including defenses against quantum threats.
“Harvest now, decrypt later”
The second report, Harvest Now, Decrypt Later, produced in collaboration with Spain's University Carlos III of Madrid, investigates the tactics used by attackers who collect encrypted data now for future decryption. It identifies widely used protocols like TLS, SSH, and OpenPGP as vulnerable, with risks varying based on configuration and key management.
Currently, the report indicates that there is "no clear evidence" of this method being exploited on a large scale. The resources needed make government communications and sensitive corporate data the most likely targets.
In September, the European Union's three financial regulators highlighted this same threat, warning that a quantum computer capable of breaking encryption could emerge before the technology becomes commercially viable. The EU's NIS Cooperation Group has advised member states to formulate a post-quantum migration strategy by the end of 2026.
For payment systems, the report highlights that real-time interception poses a more immediate quantum risk than retrospective decryption. It describes a potential "just-in-time" attack, where a quantum computer could derive a private key in the brief period between a transaction revealing its public key and the confirmation of that transaction.
Europol suggests establishing a working group led by the European Commission, including Europol, the EU cybersecurity agency ENISA, and the EU Anti-Money Laundering Authority, to regularly update policymakers. The U.S. National Institute of Standards and Technology has proposed phasing out the most commonly used public-key configurations by 2030 and completely eliminating classical public-key cryptography by 2035, as detailed in the second report.