Photo: Rafael Minguet Delgado / Pexels
Europol says quantum computing wonāt break Bitcoin, but some wallets are exposed
The EU police agency's cybercrime unit says blockchains hold up against quantum attacks, while roughly 30% of Bitcoin sits in addresses with exposed public keys.
Europe’s top police agency has weighed in on crypto’s favorite doomsday scenario. Its verdict: the sky is not falling.
On October 7, 2026, Europol’s European Cybercrime Centre (EC3) published two reports on how quantum computing could affect crypto and encrypted data. The key finding was blunt.
“Cryptocurrencies will not collapse due to quantum computing.”
Still, “will not collapse” is not the same as “nothing to worry about.” The reports draw a sharp line between the blockchain itself and the wallets people use to hold their coins.
What Europol actually found
The primary report carries a title only a policy committee could love: “Quantum Computing and Cryptocurrencies ā Bridging Technical Expertise and Decision-Making.”
Its core argument splits crypto security into two layers. The vault is the blockchain. Europol says its integrity holds because it relies on hash functions, such as Bitcoin’s SHA-256, which the agency describes as largely resistant to quantum attacks. The report calls wallets built on public-key cryptography the “primary point of exposure.”
The concern is specific. A sufficiently powerful quantum computer could work backward from an exposed public key, derive the matching private key, and then sign transactions the owner never approved.
The 30% problem
The most striking figure in the report: approximately 6 to 6.9 million BTC sit in addresses whose public keys have already been exposed. Europol pegs that at roughly 30% of Bitcoin’s supply.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
According to Europol, the only real protection is moving those funds to safe wallets before a capable quantum machine arrives. Exposed keys cannot be secured retroactively.
The agency recommends a phased adoption of post-quantum cryptography, or PQC, paired with wallet upgrades. PQC refers to encryption schemes designed to hold up even against quantum computers.
Easier said than migrated
Europol flags coordination as a central challenge. Bitcoin has no IT department that can push a mandatory update and call it a day.
The report estimates that migrating all Bitcoin unspent transaction outputs, known as UTXOs, could require more than 76 days of cumulative processing time under certain assumptions.
The reports also build on earlier Europol assessments of quantum technology published in 2023. The new work narrows that broader lens to what quantum risk means for digital assets specifically, while the companion report addresses the wider threat to encrypted data.
What this means for holders and builders
For investors, the issue is less whether Bitcoin as a network survives quantum computing and more whether a specific holder’s coins sit in a vulnerable address. Holders with exposed public keys face a risk that cannot be patched later. Under Europol’s analysis, the remedy is proactive migration, which shifts much of the responsibility from the protocol to individual users.
The thorniest question involves coins whose owners never act. If roughly 30% of supply sits in exposed addresses, and protection depends on owners moving funds themselves, it is not obvious how every one of those coins gets secured.
If a full migration could take more than 76 days of processing, waiting until quantum machines are ready would leave very little room for error.