The narrative, and the Europol quantum report’s answer
On Wednesday, the European Union’s law-enforcement agency published two reports urging policymakers and the crypto industry to prepare now for quantum computers capable of breaking today’s encryption. The first, from Europol’s European Cybercrime Centre, looks at cryptocurrencies. Its headline conclusion is calmer than most of what you will read about it:
“Cryptocurrencies will not collapse due to quantum computing.”
— Europol, Quantum Computing and Cryptocurrencies, as reported by Decrypt
The popular narrative runs like this: one day a quantum machine arrives, the cryptography under bitcoin fails, and the whole ledger becomes forgeable. It is worth steelmanning. Bitcoin’s signatures use elliptic-curve cryptography, and a large enough fault-tolerant quantum computer running Shor’s algorithm could, in principle, recover a private key from a public key. That is a real mathematical result, not a scare story.

Where it’s true, and where it’s misleading
Europol’s report separates the parts of the system. The hash functions that link blocks and secure mining are largely quantum-resistant, it says, because attacking a 256-bit hash would still take an astronomically high number of operations. The weak point is the wallet: specifically, any wallet whose public key is already visible on-chain.
That distinction does most of the work. Here is the arithmetic as the report and its cited sources lay it out:
- Glassnode estimated in May that about 6.04 million BTC, or 30.2% of issued supply, sit in outputs whose public key is already exposed.
- For those coins, Europol says, “the only solution is pre-emptive migration”: moving them to fresh addresses before an attacker exists.
- Migration has a cost. NIST-standardised post-quantum signatures are 10 to 120 times larger than today’s ECDSA signatures, the report notes.
- A 2024 study it cites estimates at least 76 days of cumulative network downtime to migrate every unspent output, or roughly 300 days if migration used a quarter of each block.
So the narrative is true about the mechanism and misleading about the shape of the risk. The danger is not a single morning when the ledger breaks. It is a long queue of coins that need to move, a block-space budget that limits how fast they can, and a deadline nobody can date precisely. The report cites IBM’s target of a fault-tolerant machine by 2029, and a 2025 expert survey putting the odds of breaking RSA-2048 within 24 hours in the next decade at 28% to 49%.
The second report, on “harvest now, decrypt later” attacks, found no clear evidence of systematic exploitation at scale. Europol wants a European Commission-led working group, including the EU cybersecurity agency ENISA and the new Anti-Money Laundering Authority, to brief policymakers regularly.
Related: EU crypto rules
The base case: “the slow migration”
My base case, which I will call the slow migration, is that this becomes an engineering and coordination problem measured in years, not a cliff. It is more likely than not that bitcoin and Ethereum adopt post-quantum signature schemes well before a cryptographically relevant machine exists, and that the hard question is what to do about exposed coins whose owners never move them.
The debate is already shifting in that direction. Hours after Europol’s release, Ethereum Foundation researcher Justin Drake called on the industry to begin planning calmly for a “bunker mode”, including a controlled mass migration of assets to addresses whose public keys remain hidden behind a hash.
What would change my mind. Three things would make me less relaxed: further sharp cuts in the resource estimates for breaking the elliptic-curve cryptography bitcoin uses, after Google research in March and an AI-assisted competition in September both lowered them; a public, verified quantum hardware result well ahead of current roadmaps; or evidence that developers cannot agree on any migration path for exposed coins.
The bottom line
Europol has done the useful thing a sober institution can do: it has named the weak point precisely. Blockchains are not the target. Old, visible keys are.
The bottom line: the quantum risk to bitcoin is a migration problem with a long fuse, and the sensible time to plan it is before anyone can light it.
— Alasdair
Data and sources as of 7 Oct 2026, 16:30 UTC. Report figures are Europol’s and its cited sources’, as reported by Decrypt; Glassnode’s estimate dates from May 2026.
This article is for information only and is not investment advice.
