Europol Says Quantum Threat Centers on Crypto Wallet Keys
Two reports recommend phased post-quantum upgrades and warn that encrypted information collected today could face future decryption risks.

Europol released two reports Oct. 7 warning that quantum computing could expose cryptocurrency wallet keys and encrypted information, prompting early preparation across the industry for post-quantum cryptography.
A report by Europol’s European Cybercrime Centre on cryptocurrency security identifies the cryptographic keys that control wallets and authorize transactions as the main exposure point. A sufficiently powerful quantum computer could derive a private key from a publicly exposed public key, potentially allowing an attacker to move funds without the owner’s permission.
Hash functions that support blockchain integrity are comparatively more resistant to quantum attacks. That distinction places the focus of quantum preparation on wallet security and key management rather than treating the blockchain network itself as the sole point of failure.
The reports recommend improving wallet security and key management through a phased transition to quantum-resistant cryptography. Blockchain developers, wallet providers, policymakers and users all have a role, while coordination across decentralized networks will be required. Developers and wallet providers will need to coordinate protocol and wallet upgrades and explain future migration requirements to users.
A second report, “Harvest Now, Decrypt Later,” was developed jointly by Europol and Carlos III University of Madrid. It examines the risk that attackers collect and store encrypted information now, then attempt to decrypt it when more advanced computing capabilities become available.
Quantum computers are not needed during the collection stage. The risk is most relevant to information that must remain confidential for many years, including government communications, intellectual property, medical records and law-enforcement files.
There is no clear evidence that the tactic is being systematically exploited at scale. Large storage, processing and technical requirements make high-value information with lasting sensitivity the most plausible target.
The timing of practical quantum capabilities remains uncertain, but both reports recommend beginning preparations before a specific deadline emerges. Organizations should identify systems that rely on cryptography, assess which information requires long-term protection and plan upgrades in phases.
The reports recommend cryptographic agility, allowing systems to replace encryption algorithms as security requirements change. For crypto networks, that preparation includes coordinated work on protocols and wallets, along with clear communication about future upgrades and migration requirements.