MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Regulation / Europol Says 6.9 Million Bitcoin Sit in Wallets Exposed to Future Quantum Attacks
Regulation

Europol Says 6.9 Million Bitcoin Sit in Wallets Exposed to Future Quantum Attacks

By MABOnChain Desk · Published · Updated · 4 min read

Editorial digital-art illustration of a colossal golden quantum computer looming over a dark vault of glowing Bitcoin coins and cracked skeleton keys dissolving into digital particles, a hooded guard figure with a shield in the foreground, deep navy and cyan palette with amber gold accents

Published October 7, 2026, 21:15 UTC. Based on Europol's published reports, with reporting from CoinDesk, Decrypt, Crypto Briefing and crypto.news.

Europol published two reports on Wednesday identifying cryptocurrency wallets, not blockchains, as the primary point of exposure to future quantum-computing attacks. The European Union's law enforcement agency said a sufficiently powerful quantum computer could work backward from an exposed public key to derive the private key that authorizes spending, letting an attacker move funds without the owner's consent.

The 6.9 million exposed bitcoins

Roughly 6.9 million bitcoin sit in addresses whose public keys are already visible on chain, including early pay-to-public-key outputs and long-dormant holdings from Bitcoin's earliest days, Europol said. Blockchain analytics firm Glassnode estimated in May that 6.04 million BTC, or 30.2 percent of the issued supply, has already had its public key exposed, Decrypt reported. Crypto Briefing, citing CryptoQuant estimates, put the value of the exposed stash at around $586 billion.

Why wallets, not blockchains

Europol drew a distinction the agency says is often lost in warnings about quantum computing. The hash functions that help secure a blockchain's history, including bitcoin mining, remain far more resistant to quantum attacks than the public-key cryptography used to control wallets. Breaking a 256-bit hash would still take what the report calls an astronomically high number of operations with foreseeable technology, Decrypt reported. "Cryptocurrencies will not collapse due to quantum computing," Europol said, concluding that "proactive adaptation, rather than systemic collapse, is the most likely outcome." Quantum computers capable of carrying out such attacks do not exist yet, and Europol did not predict when they will, CoinDesk reported.

The migration math is the hard part

For wallets whose public keys are already visible on chain, there is no retroactive fix. "The only solution is pre-emptive migration," the report says, with owners moving funds to new wallets before any attack, according to Decrypt. That makes the challenge a coordination problem across a global decentralized network rather than a purely technical one.

NIST-standardized post-quantum signatures run 10 to 120 times larger than the ECDSA signatures Bitcoin uses today, and a 2024 study cited by Europol estimated that migrating every unspent transaction output to a quantum-safe format would require at least 76 days of cumulative network block space, or roughly 300 days if the work took up 25 percent of each block. Bitcoin researchers and institutions increasingly see 2029 as the point by which credible quantum-resistant migration plans need to be in place, CoinDesk reported. IBM's roadmap targets a fault-tolerant quantum computer by 2029, and a 2025 survey of 32 experts put the odds of a machine breaking RSA-2048 encryption within 24 hours in the next decade at 28 to 49 percent, Decrypt reported.

"Harvest now, decrypt later"

The second report, developed with Spain's University Carlos III of Madrid, examines attackers who collect encrypted data today to decrypt it later. It found widely used protocols such as TLS, SSH and OpenPGP susceptible, with risk varying by configuration and key management, Decrypt reported. There is "currently no clear evidence" the technique is being systematically exploited at scale, the report says. For payments, the crypto report says real-time interception poses the more immediate quantum risk, describing a "just-in-time" attack in which a quantum computer derives a private key during the short window between a transaction exposing its public key and that transaction being confirmed.

Industry and the EU timeline

Europol urged the industry to begin a phased transition now through wallet upgrades, post-quantum cryptography and coordination among developers, miners, exchanges and users, CoinDesk reported. Coinbase's quantum advisory council urged developers in June to begin post-quantum migration work, while Ripple and the Stellar Development Foundation have published migration roadmaps, Decrypt reported. In July, nine firms including BlackRock, Coinbase and Strategy pledged a combined $15 million over three years for Bitcoin security research, including quantum defenses. A draft Bitcoin proposal, BIP-361, sketches a planned migration away from legacy ECDSA and Schnorr signatures once a post-quantum output type becomes available, crypto.news reported.

On the policy side, the EU's NIS Cooperation Group has recommended that member states adopt a post-quantum migration strategy by the end of 2026, Decrypt reported. The U.S. National Institute of Standards and Technology has proposed deprecating the most common public-key configurations by 2030 and phasing out classical public-key cryptography by 2035. Europol recommends a European Commission-led working group, including Europol, the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, to brief policymakers regularly.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Regulation

Jury Finds Uranium Finance Hacker Guilty in $55 Million DeFi Theft

October 7, 2026 · 4 min read

A Manhattan federal jury convicted Maryland cybersecurity consultant Jonathan Spalletta of stealing nearly $55 million from the Uranium Finance exchange in April 2021, Bloomberg reported. He faces up to 20 years on the money-laundering count, with sentencing set for February 16, 2027.