Crypto’s Quantum Risk Begins With Wallet Keys, Says Europol

Europol says quantum computing could eventually turn exposed wallet keys into a route for theft, leaving crypto networks years to prepare for a security migration.
Key Takeaways
- Europol flags wallet keys as crypto’s main quantum risk.
- Exposed public keys could endanger funds in the future.
- Wallet and network upgrades need long-term planning.
- Today’s scams and key theft remain the immediate threat.
Europol puts wallet keys at the centre of the risk
Europol published two reports on October 7 examining how quantum computing could affect cryptocurrencies and sensitive encrypted data. The agency separates the risk to wallet signatures from the wider question of blockchain integrity, directing attention to the cryptographic keys that authorise transfers.
Its European Cybercrime Centre report on quantum computing and cryptocurrencies identifies wallet keys as the main point of exposure. A sufficiently capable quantum computer could derive a private key from an exposed public key, potentially giving an attacker the authority needed to sign and broadcast a transaction.
The idea is easier to understand through the way a wallet works today. A public address lets other people send assets to a wallet and verify its transactions. The private key or recovery phrase gives the holder control over that wallet. Today’s computers cannot realistically work backwards from public transaction information and obtain the private key needed to sign a transfer. Europol’s concern is that quantum computing could eventually change that calculation.
The agency also draws an important line between wallet signatures and the rest of a blockchain. Europol says hash functions protecting important parts of blockchain integrity are comparatively more resistant to quantum attacks. Its warning therefore centres on the systems that prove ownership and authorise transfers, where a compromised key can immediately give someone control over assets.
A fuller explanation of the mechanics appears in our guide to how quantum computers could threaten crypto wallet security. The key point for readers is simple: Europol is focused on who can approve a transfer, not on a sudden collapse of every blockchain record.
Changing crypto security will take longer than a software update
Quantum hardware capable of carrying out this kind of attack has not reached the necessary scale. Europol says the timeline remains uncertain, yet it sees little value in waiting for a precise date. “Adapting systems and coordinating security upgrades will take time,” the agency wrote in its October 7 announcement.
The scale of the migration explains that urgency. Replacing a signature method affects far more than the underlying blockchain code. A secure transition depends on developers, validators, wallet makers, exchanges, custodians and users moving in a compatible order.
- Developers need to select quantum-resistant signature methods and test them against existing software and security assumptions.
- Networks need their validators, miners or node operators to run compatible code and agree on any required rule changes.
- Wallet providers and custodians need to support new keys, signing formats and migration tools.
- Users need clear instructions if funds eventually have to move to a new address or a different signing system.
Europol calls this ability “crypto-agility.” It means having a safe route from an older security method to a stronger one without interrupting access to funds or leaving holders behind. That process needs to be designed well before a threat becomes urgent, especially on decentralised networks where no single company can force every participant to upgrade.
Current wallet crime shows why key control already matters
Quantum computing would create a new route to wallet control, but the crypto industry already deals with the same end result every day. Criminals use phishing, malware, impersonation, compromised platforms and physical coercion to obtain recovery phrases, private keys or access to accounts that can approve transfers.
Recent Chainalysis research estimated that $3.4 billion was stolen across crypto during 2025. The firm also identified roughly 158,000 individual wallet-compromise incidents affecting about 80,000 victims, involving an estimated $713 million in stolen value.
That research describes present-day theft, not quantum attacks. It still gives Europol’s warning practical context: private-key control already determines whether an attacker can move crypto assets. A future quantum-capable attack would seek the same authority through a weakness in public-key cryptography instead of a stolen seed phrase or a fraudulent support message.
Europol’s warning calls for long-term preparation while users and service providers continue to defend against the threats causing losses today. Quantum-resistant signatures would not eliminate phishing, exchange breaches, poor password practices or unsafe storage of recovery phrases.
The second report looks beyond coins to data that must stay private
Wallet keys are one part of Europol’s warning. Its second report, Harvest Now, Decrypt Later, turns to information that attackers can collect today and attempt to decrypt later when more capable quantum computing becomes available.
The greatest concern involves information that must remain confidential for many years: government communications, intellectual property, medical records and identity data. An attacker does not need a quantum computer while collecting the material. They need storage capacity, an expectation that the information will remain valuable and the ability to wait for better computing tools.
For crypto companies, this risk sits alongside the assets they hold. Exchanges, custodians and wallet providers can store identity documents, account details, support messages, internal communications and transaction-related records outside the blockchain. The agency says there is no clear evidence that this approach is being systematically used at scale, but it still recommends reviewing the encryption and key-management systems that protect long-lived data.
That creates two separate preparation jobs. Networks and wallet providers need an eventual route to stronger transaction signatures. Companies holding customer records also need to examine whether their data can remain confidential over the full period in which it has value.
Preparation needs to be visible without creating panic
For users, the useful response starts with ordinary wallet security rather than a rushed move based on a future threat. A legitimate network or wallet migration would come through official releases, documented software updates and clear instructions from the service a person already uses.
Unsolicited messages claiming that a wallet needs an immediate “quantum-safe” upgrade deserve caution, particularly when they ask for a recovery phrase, private key or connection to an unfamiliar application. Scammers routinely use technical language and urgency to create opportunities for theft; quantum computing gives them another subject to exploit.
What credible preparation looks like
Networks: Public research, testing and a clear route for adopting stronger cryptography.
Wallet providers and custodians: Strong key protection today, plus a documented way to support future migrations.
Users: Established wallet software, offline recovery-phrase storage and careful verification of every upgrade request.
The clearest sign of progress will be practical work that users can inspect: published technical proposals, compatible wallet releases, independent reviews and migration guidance that does not demand blind trust. A promise that a product is “quantum-proof” offers far less value without those details.
Europol’s warning is an engineering deadline without a date
No one can say when quantum computers will be able to threaten wallet cryptography at scale. Europol’s argument does not depend on predicting that date. It rests on the time required to agree on stronger standards, test them on live networks and move users safely to new signing systems.
Crypto’s quantum challenge therefore begins with preparation, not with a sudden attack. Wallet keys sit at the centre because they determine who can move assets. Building a credible way to protect that authority before quantum hardware becomes capable will matter far more than guessing the year when the threat first becomes real.
This article is for informational purposes only and does not constitute cybersecurity, financial or investment advice. Quantum-computing capabilities, security standards and wallet software may change as research develops.









