Europol flags $502 billion in Bitcoin vulnerable to quantum computer theft
Europol said Wednesday that Bitcoin wallets with exposed public keys have no cryptographic fix once quantum computers become powerful enough to break them, a narrow but concrete warning aimed at individual holders rather than the blockchain itself. The agency’s cybercrime unit puts a figure on that exposure: roughly $502 billion in BTC already shows the public key an attacker would need, held in reused addresses, exchange custody and early wallet formats.
- Glassnode counted 6.04 million BTC exposed as of May, equal to 30.2% of all bitcoin ever issued.
- Quantum-resistant signatures run 10 to 120 times larger than today’s, which Europol warns could clog blocks and push up fees.
- A full migration to quantum-safe wallets would need at least 76 days of Bitcoin’s entire network capacity, one study Europol cites found.
- 30.2% share of all bitcoin supply Glassnode flags as quantum-exposed
- $502B value of exposed BTC at bitcoin’s roughly $83,050 price
- 300 days network capacity needed to spread a full wallet migration
Every Bitcoin wallet runs on two linked codes: a public key that anyone can see on the blockchain, and a private key that authorizes spending. Europol’s cybercrime unit said a sufficiently powerful quantum computer could work backward from an exposed public key to derive the private one, letting an attacker drain the wallet, according to a report first detailed by BeInCrypto. The hashing that chains Bitcoin’s blocks together is far harder to break, Europol’s report found, so the threat sits with individual holders rather than the network’s consensus layer.
Glassnode Counts 6.04 Million Exposed Bitcoin, 30.2% of Supply
Analytics firm Glassnode found that 6.04 million BTC carried an exposed public key as of May, equal to 30.2% of all coins issued. At bitcoin’s price near $83,050, that stash is worth approximately $502 billion, a sum comparable to the market capitalization of a major global bank.
Most standard Bitcoin addresses show only a scrambled fingerprint of the public key, not the key itself, so those coins are not counted as exposed. That protection disappears the moment an address sends a transaction, which reveals the public key and strips cover from any coins left behind at that address.
Exchange-held coins land in the exposed group more often than self-custodied ones, Glassnode found, because platforms tend to reuse deposit addresses across many transactions.
Taproot, the address format Bitcoin added in 2021, and Satoshi Nakamoto’s earliest coins both show the public key by default rather than a hashed version of it, putting both the newest and oldest corners of the network at risk.
Europol Rejects Claims That Quantum Computing Breaks Crypto Outright
Europol’s warning is deliberately narrow. The agency rejects broader claims that quantum computing will collapse cryptocurrency, framing the risk instead as falling on holders who have exposed their keys, not on the protocol as a whole.
Once a public key is exposed, it remains permanently vulnerable to future quantum decryption.
Europol, cybercrime unit report
A second Europol report describes a tactic called harvest-now-decrypt-later, where an attacker copies encrypted data or exposed public keys today and waits for quantum machines capable of cracking them later. Europol said it found no clear evidence this is happening at scale against crypto holdings, but the strategy means exposure recorded today could still be exploited years from now even if no quantum attack exists yet.
Wallet Migration Would Need 76 to 300 Days of Network Capacity
Europol’s cited research estimates that migrating all exposed coins to quantum-safe wallets would consume at least 76 days of Bitcoin’s entire transaction capacity if done all at once. Spreading that migration across a quarter of every block instead stretches the timeline to roughly 300 days, a tradeoff between network congestion and migration speed.
Europol set no date for when a quantum computer capable of this attack might exist. It argues that upgrading a network with no central operator takes years, and noted that some Bitcoin developers already back proposals to freeze coins in vulnerable wallets ahead of any attack.
The larger signature sizes Europol flags, up to 120 times current size, raise the same engineering tension already visible in other parts of crypto infrastructure, where security upgrades compete with throughput. The Ethereum Foundation’s recent proposal for native transaction assertions addresses a related signing-failure risk, while Bitcoin’s own node software has moved incrementally on security, as in Core Lightning’s v26.06.9 release earlier this year.
The CCS read. Custodians and exchanges carry more of this exposure than retail holders who never reuse addresses, since pooled deposit wallets are precisely the reused, always-public-key-visible structures Glassnode flags. Institutional custody providers should treat key rotation and address hygiene as a near-term operational item, not a theoretical one tied to a quantum computer that does not yet exist.
Europol has not set a timeline for when migration standards or network-level freezes might be proposed to Bitcoin’s developer community, leaving custodians and exchanges to decide on their own whether to rotate exposed addresses before any quantum capability materializes.