Europol Says 6.9 Million Bitcoin (BTC) in Exposed Wallets Face Quantum Risk
Europol flags 6.9 million Bitcoin in addresses with exposed public keys and urges a phased move to quantum-resistant wallet security.
AI SummaryAI
- Europol published two quantum-risk reports on Oct. 7 naming crypto wallets the primary exposure point.
- Europol estimates 6.9 million Bitcoin sits in addresses with publicly visible on-chain keys.
- NIST-standardized post-quantum signatures run 10 to 120 times larger than Bitcoin's ECDSA signatures.
- A cited study estimates a full Bitcoin migration needs at least 76 days of block space.
Europol's Twin Reports Point at Wallet Keys
Europol, the European Union's law enforcement agency, published two reports on Oct. 7 urging the crypto industry to prepare for quantum computers before practical attacks become possible. Its European Cybercrime Centre concludes in the first report, “Quantum Computing and Cryptocurrencies,” that the crypto wallet, not the blockchain itself, is the main point of exposure to future quantum threats. A sufficiently capable quantum machine could, in principle, work backward from an exposed public key to the private key that authorizes spending, allowing funds to be moved without the owner's consent. The agency estimates roughly 6.9 million
Bitcoin (BTC) sits in addresses whose public keys are already visible on-chain, including Satoshi-era coins and long-dormant holdings. Hash functions that secure a chain's history are far more resistant, since breaking a 256-bit hash would take what the report calls an astronomically high number of operations with foreseeable technology. The warning concerns asset ownership rather than the Bitcoin price. Europol framed the timing itself as the core uncertainty: nobody knows when a capable machine arrives, but upgrading cryptographic systems across decentralized networks could take years, and the agency recommends a phased migration to quantum-resistant cryptography alongside stronger wallet security and key management.
76 Days of Block Space for a Full Migration
The harder task is updating the network itself. Exposed keys cannot be made safe retroactively, and the report's remedy for old outputs is pre-emptive migration to fresh addresses before any attack, a path already dividing the
Bitcoin (BTC) community over whether dormant Satoshi-era funds should be frozen or left alone. Migration carries costs of its own: post-quantum signature schemes standardized by NIST run 10 to 120 times larger than the ECDSA signatures Bitcoin uses today, which threatens to overload block space, raise fees and slow confirmations. A 2024 study cited in the document estimates a full conversion of every unspent transaction output needs at least 76 days of block space in total, stretching to about 300 days if a quarter of each block were reserved. Bitcoin's developers are already circling the problem: draft BIP-361 proposes moving away from legacy ECDSA and Schnorr signatures once a post-quantum output type exists, a consensus-level change comparable to a fork that has not been activated. Timing pressure is explicit: IBM targets a fault-tolerant machine by 2029, and a 2025 survey of 32 experts put the odds of breaking RSA-2048 within 24 hours inside the next decade at 28% to 49%.
Custodians and Standards Bodies Move First
The second report, “Harvest Now, Decrypt Later,” produced with Spain's University Carlos III of Madrid, examines attackers who store encrypted data today for decryption years from now; Europol found no clear evidence the technique is being exploited systematically at scale, given the storage and processing it would demand. Preparation on the crypto side is already under way. NIST approved three post-quantum standards, FIPS 203, FIPS 204 and FIPS 205, in August 2024 and has proposed deprecating today's most common public-key configurations by 2030, with classical public-key cryptography phased out by 2035. BitGo and Silence Laboratories tested post-quantum multiparty computation signing with the ML-DSA scheme earlier this year, and BitGo later added institutional wallet controls that measure public-key exposure and consolidate outputs. Coinbase's quantum advisory council urged developers in June to begin post-quantum migration work, and the company is designing custody infrastructure able to support different signature schemes while standards remain unsettled. In July, nine firms including BlackRock, Coinbase and Strategy pledged $15 million over three years for
Bitcoin (BTC) security research, on top of Galaxy Digital's $5 million program for quantum-resistant signature work, and Sui targets optional quantum-safe accounts on mainnet in 2027.
A Coordination Problem, Not a Collapse
COINOTAG's read: Europol's two reports land on the same diagnosis the industry's own researchers reached. The binding constraint is not cryptography but coordination, since any signature migration needs agreement among developers, custodians, miners and holders across a decentralized network, and the 6.9 million BTC exposure sharpens the unresolved question of what happens to dormant coins that never migrate. With IBM and Microsoft both pointing to 2029, the warning moves from distant theory to a scheduling question, and Europol's proposed Commission-led working group, which would include the EU cybersecurity agency ENISA and the bloc's Anti-Money Laundering Authority, would keep the file open on the regulator side.
Primary sources
- framed the timing itself · europol.europa.eu
- report's remedy · europol.europa.eu
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

