Crypto and quantum threat: Europol sounds the alarm and urges Europe to act
The European agency warns of the vulnerability of cryptocurrency wallets and the strategy of collecting encrypted data with a view to future decryption.
Quick Look
Europol has published two reports on the quantum threat, highlighting the vulnerability of cryptocurrency wallets to Shor's algorithm and the risk of mass collection of encrypted data for future decryption (Harvest now, decrypt later).
AI-generated summary
Why It Matters
The development of quantum computing threatens current encryption protocols, including RSA and elliptic curves.
The present has a long memory. On Wednesday October 7, Europol published two reports on the quantum threat. The first concerns wallets, the second concerns data already stolen while waiting for power to arrive.
The key points of this article:
Europol considers public key cryptography to be truly threatened, with wallets being the main point of exposure.
NIST plans to retire traditional public-key cryptography by 2035, with current configurations deprecated as early as 2030.
The migration of all Bitcoin UTXOs would require at least 76 days of cumulative cutoff.
A post-quantum signature occupies approximately 20 KB compared to 72 bytes for an ECDSA.
The blockchain holds, the wallet cracks
The first document, signed by the European Cybercrime Center (EC3), makes a clear distinction. The hash functions that secure the integrity of the blockchain remain largely resilient.
On the other hand, the flaw lies in wallets, those which authorize transactions using public key cryptography. It is Shor's algorithm, published in 1997, which renders RSA, Diffie-Hellman and the elliptic curve ineffective.
In fact, Europol does not fear the collapse of cryptocurrencies. Thus, the report fears a vulnerability targeted at the ownership and control of digital assets.
The calendar remains unclear. The Quantum Threat Timeline Report 2025, built on the opinions of 32 global experts, gives an increasing probability that a quantum computer will break RSA-2048 in 24 hours.
For its part, Google is aiming for a fault-tolerant machine by 2029, a horizon that the document considers uncertain. The answer is therefore organizational rather than technological.
On the one hand, Europol recommends incremental updates and account abstraction of the ERC-4337 standard, which replaces traditional accounts with smart contracts. On the other hand, the adoption of algorithms standardized by NIST in 2024, FIPS 203 (CRYSTALS-Kyber) and FIPS 204 (CRYSTALS-Dilithium).
The problem? The size. A hash-based signature like XMSS occupies around 20 KB compared to 72 bytes for an ECDSA, enough to saturate already constrained blocks.
Thus, a study cited by the report estimates the migration of all UTXOs at a minimum of 76 days of continuous outage. Such a cut is untenable, and the project would be spread over 300 days, reserving 25% of each block. Indeed, Taproot, adopted in 2021 with Schnorr signatures, provides no quantum resistance and remains under 1% usage.
“Harvest now, decrypt later”, collection before power
The second report, developed with UC3M as part of the Advisory Group Research and Development, no longer talks about blockchain but about data. An attacker stores encrypted elements today without being able to read them, betting that a quantum computer will allow it later.
This threat does not require any quantum computer today. It mainly concerns data that retains value over time, government communications, investigation files and the identities of informants.
Companies are rated medium to high risk for their trade secrets. Individuals remain low to medium, except for their medical records, already broken by the Oracle cyberattack of 2025. On the one hand, the theory is sound. On the other hand, practice depends on the configurations. Technical analysis shows that TLS, SSH and OpenPGP storage are vulnerable, but not to the same degree.
Europol is not aware of a proven and documented HNDL case. However, groups like REvil and Clop already collect exfiltrated data before encryption to resell it or launch extortion later. Long-term intention is difficult to prove, behavior is observable.
Open Questions
- When will a quantum computer capable of breaking RSA-2048 actually be available?
- What will be the real impact on the liquidity of the cryptocurrency market during a migration?







