Sources
- Europol: Europol urges early action to protect cryptocurrencies and sensitive data from quantum threats (7 Oct 2026)
- Decrypt: Europol warns crypto wallets are 'primary risk' for quantum attacks (7 Oct 2026)
- NIST: Post-quantum cryptography project and FIPS 203, 204, 205
- BIP 360: Pay-to-Merkle-Root (P2MR)
- Justin Drake on X, 7 Oct 2026
Last reviewed 7 Oct 2026 by Akriti Seth. Originally published 7 Oct 2026.
Key takeaways
- A quantum attack on bitcoin would use a future, very large quantum computer to work out a wallet’s private key from its public key, then spend the coins.
- Only coins whose public key is already visible on the blockchain are directly exposed. Mining and the chain’s hash functions are far harder to attack.
- The main risk is not that the network “breaks” overnight, but that exposed coins must move to safer addresses before such a machine exists.
A quantum attack on bitcoin is a hypothetical attack in which a powerful quantum computer derives a wallet’s private key from its visible public key, letting the attacker spend that wallet’s coins. No existing machine can do this. The risk applies mainly to coins whose public keys are already exposed on-chain.
Here’s how such an attack would work, which coins are most exposed, what developers and regulators are doing, and what you can do as a holder.
Why quantum attacks on bitcoin are in the news
On 7 Oct 2026, Europol, the European Union’s law-enforcement agency, published two reports urging governments and the crypto industry to start preparing for quantum computers capable of breaking today’s encryption. Its crypto report names wallets as “the primary point of exposure”, but concludes that “cryptocurrencies will not collapse due to quantum computing”, as Decrypt reported.
Related: Europol’s quantum report, analysed
The same day, Ethereum Foundation researcher Justin Drake called on the industry to “calmly begin planning” for what he called “bunker mode”: a controlled migration of assets to addresses whose public keys remain hidden.
How does a quantum attack on bitcoin work?
Every bitcoin wallet rests on a pair of keys. Your private key is a secret number that authorises spending. Your public key is derived from it and lets the network check your signature. Today, working backwards from a public key to a private key is practically impossible for ordinary computers.
Related: What a private key is
A quantum computer is a different kind of machine that uses quantum bits, or qubits. In 1994 the mathematician Peter Shor described an algorithm that a large, error-corrected quantum computer could use to solve the kind of maths that protects bitcoin’s signatures, the elliptic-curve scheme behind ECDSA and Schnorr signatures. Run at scale, Shor’s algorithm would turn “practically impossible” into “feasible”.
[DIAGRAM (Illustrative): Left, a private key producing a public key (arrow labelled “easy”). Right, a reverse arrow from public key back to private key labelled “infeasible today; feasible for a large quantum computer”. Below, an address shown as a hash of the public key, with a shield icon marked “hidden until first spend”.]
A toy example. Imagine your address is a sealed envelope with your public key inside. As long as the envelope is sealed, an attacker has nothing to work on. The moment you spend from it, or if your address type prints the key on the outside, the key becomes visible. A future quantum attacker could then try to compute your private key from it.
Hash functions are a different story. They link blocks together and power mining. A quantum computer offers only a limited speed-up against them, and Europol’s report calls the operations needed to break a 256-bit hash “astronomically high with foreseeable technology”. That is why the focus is on wallets, not on the chain itself.
Which bitcoin is most exposed?
Exposure depends on whether your public key is visible on the blockchain. Blockchain analytics firm Glassnode estimated in May that about 6.04 million BTC, or 30.2% of issued supply, sat in outputs whose public key had already been exposed, according to the figures cited by Decrypt.
Coins become exposed in a few common ways:
- Very old address types. The earliest bitcoin outputs, known as pay-to-public-key, put the public key directly on-chain.
- Address reuse. Standard addresses hide the key behind a hash, but once you spend from an address, the key is revealed. Coins left in that address stay exposed.
- Taproot outputs. Taproot, activated in 2021, places a public key in the output itself, so those coins are visible from the start.
There is also a short-window risk. When you broadcast a transaction, your public key becomes visible before the transaction is confirmed. Europol’s report describes a “just-in-time” attack, in which a quantum computer would derive the key within that window. That would require a far faster machine than a long, patient attack on old exposed coins.
How do exposed and hidden keys compare?
| Address situation | Is the public key visible? | Exposure to a future quantum attack |
|---|---|---|
| Pay-to-public-key (early bitcoin) | Yes, always | High: key on-chain permanently |
| Standard address, never spent from | No, hidden behind a hash | Low while unspent |
| Standard address, reused after spending | Yes, after the first spend | High for coins left behind |
| Taproot address | Yes, in the output | High: key visible from the start |
| Any address, transaction in mempool | Briefly, until confirmed | Only to a very fast attacker |
Simplified for beginners. Some script types behave differently.
How close are quantum computers?
Nobody can give a firm date, and you should be wary of anyone who does. Europol’s report cites IBM’s target of building a fault-tolerant quantum computer by 2029, and a 2025 survey in which experts put the odds of breaking RSA-2048 encryption within 24 hours, at some point in the next decade, at 28% to 49%. Research published this year has also lowered estimates of the resources needed to attack the elliptic-curve cryptography bitcoin uses.
For governments, the timetable is already set. The US National Institute of Standards and Technology (NIST) has proposed deprecating today’s most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035, according to Europol. NIST published its first three post-quantum standards, FIPS 203, 204 and 205, in August 2024.
What is being done to protect bitcoin?
Bitcoin has no central authority to switch cryptography, so any change needs broad agreement among developers, miners, businesses and users.
The best-known proposal is BIP 360, now titled Pay-to-Merkle-Root. It describes a Taproot-like output type without the exposed key path. It is a draft soft-fork specification with no activation date, and on its own it does not add post-quantum signatures. Those would come later, and they are bulky: NIST-standardised post-quantum signatures are 10 to 120 times larger than today’s ECDSA signatures, Europol notes.
Size is the practical problem. A 2024 study cited by Europol estimated that moving every unspent bitcoin output to quantum-safe addresses would need at least 76 days of cumulative network downtime, or about 300 days if migration used a quarter of each block. That is why researchers argue for starting early.
Risks and criticisms
Over-hyping the threat. Headlines that say “quantum will break bitcoin” can push people into rushed decisions or scams that sell “quantum-proof” coins and wallets. Europol’s own conclusion is that the system can adapt.
Under-preparing. The opposite risk is waiting too long. Migration needs software, agreement and block space, and all three take time.
What to do about lost or dormant coins. Some exposed coins belong to people who have lost their keys or stopped paying attention. If owners never move them, a future attacker could. Proposals to freeze or phase out spending from vulnerable outputs are controversial, because they cut against the principle that nobody can touch your coins.
Bigger signatures, higher costs. Post-quantum signatures take more space, which could raise fees and slow confirmations, Europol warns.
What you can do as a holder
You don’t need to act in a panic, but good habits help today:
- Avoid address reuse. Use a fresh receiving address for each payment. Most modern wallets do this automatically.
- Know your address type. Check whether your wallet uses Taproot or an older type, and follow your wallet provider’s guidance on any future quantum-safe options.
- Use official software only. When migration tools arrive, get them from your wallet’s official site or app store.
- Keep your seed phrase offline and private. Quantum risk doesn’t change the basics.
Frequently asked questions
Can a quantum computer hack bitcoin today?
No. No publicly known quantum computer is anywhere near the size needed to recover a bitcoin private key. The concern is about future machines.
Would a quantum computer let someone create new bitcoin?
No. Mining and block links rely on hash functions, which Europol describes as largely quantum-resistant. The risk is to individual wallets with visible public keys.
Are my coins at risk if I’ve never reused an address?
Coins in standard addresses that have never sent a transaction keep the public key hidden behind a hash, which is the safer position. Taproot outputs are the exception, because the key is visible from the start.
What is “harvest now, decrypt later”?
It means collecting encrypted data today in the hope of decrypting it once quantum computers are strong enough. Europol’s second report found “currently no clear evidence” that it is being exploited at scale.
Will bitcoin change its cryptography?
Proposals such as BIP 360 exist, but none has been activated and there is no timetable.
Common mistakes
- Buying a token or “quantum-safe wallet” because a promoter says bitcoin is about to be broken.
- Reusing one address for years, leaving its public key exposed with funds still inside.
- Downloading “migration tools” from links in direct messages or search ads instead of official sources.
- Sharing a seed phrase with anyone who claims to be helping you “upgrade” your wallet.
- Assuming the threat is either zero or immediate. It’s neither.
Glossary: what a private key is
Produced by the Crypto Watch Desk newsroom using AI tools. This article is for information only and is not investment advice.
