Overview
- Europol published two reports Wednesday, October 7, 2026, that name wallet public keys as the main point an attacker could exploit if a quantum computer can derive private keys from public keys.
- A quantum-capable attack would let an attacker use a derived private key to sign transactions and move funds, while the hash functions that secure block linkage are described as largely resistant to foreseeable quantum resources.
- Europol and blockchain analysts estimate roughly 6 to 7 million bitcoin are held in addresses with exposed public keys that would remain vulnerable unless their owners move funds to new, quantum‑safe wallets.
- The agency cites a 2024 study showing network-wide migration is hard and slow, with an estimated minimum of 76 days of cumulative block work or about 300 days if migration uses 25% of block capacity, and it warns that post‑quantum signatures are much larger and will raise coordination, fee, and block‑space challenges.
- Europol found no clear evidence that attackers are systematically harvesting encrypted data now for future decryption, but it calls for immediate planning, key‑management improvements, and industry tests of post‑quantum schemes so custodians, exchanges, developers, and users can begin a staged migration.