Europol warns encrypted wallets of a quantum threat
crypto.news
56m ago
Ai Focus
The European Police Agency states that in the future, quantum computers may pose a threat to cryptocurrency wallets and long-term encrypted data, and recommends that the encryption industry prepare for the migration to post-quantum cryptography as soon as possible. The agency noted that there is currently no clear evidence indicating that the "collect first, then decrypt" attack has been used on a large-scale and systematic basis.
Helpful
No.Help

The European Police Agency ( Europol ) warns that future quantum computers may pose a threat to cryptocurrency wallets and long-term encrypted data, and urges the crypto industry to begin security preparations before actual attacks become possible.

  • The European Police Agency stated that quantum computers could potentially expose cryptocurrency wallets by deriving private keys from public keys.
  • The European Police Agency recommends phased migration to post-quantum cryptography to enhance wallet security and improve key management practices.
  • NIST has finalized three post-quantum standards and urges organizations to begin the migration as soon as possible.
  • Bitcoin developers are discussing post-quantum migration proposals, while custodian institutions are testing quantum-resistant wallet controls and signatures.
  • The European Police Agency stated that there is no clear evidence indicating that the 'collect first, decrypt later' attack tactic is being used systematically or on a large scale.

On October 7th, the European Police Agency released two reports examining how advancements in quantum computing could impact digital assets and sensitive information. The agency stated that it is still uncertain when a practically useful quantum computer will emerge, but upgrading cryptographic systems in decentralized networks could take several years.

The first report focuses on cryptocurrency wallets, while the second examines the situation where attackers store encrypted information today with the intention of decrypting it in the coming years. Europol has not indicated that current quantum computers are capable of cracking the security of cryptocurrencies yet.

Quantum threats focus on the keys of encrypted wallets

The European Police Agency's cryptocurrency report lists wallet authorization keys as the main potential vulnerability points. Many blockchain systems rely on public key cryptography to prove that the wallet owner has authorized a transaction.

A sufficiently powerful quantum computer could theoretically use the exposed public key to calculate the corresponding private key. The European Police Agency stated that attackers could then sign transactions and transfer assets without permission.

The institution distinguished between digital signatures and blockchain hash functions. Europol stated that the cryptographic hash functions used in important aspects of blockchain security are relatively more resistant to quantum attacks. Therefore, the report focuses on wallet signatures, public key exposure, and key management.

The report does not predict an inevitable collapse of cryptocurrencies. On the contrary, Europol recommends a phased transition to post-quantum cryptography, with blockchain developers, wallet providers, policymakers, and users coordinating future upgrades.

Bitcoin developers are already discussing some of these issues. Draft BIP-361 proposes a planned migration from the older versions of signatures ECDSA and Schnorr to the new post-quantum Bitcoin output types. This proposal is still in draft form and has not yet been implemented on the Bitcoin network.

As previously reported by crypto.news, the relevant Bitcoin proposals have sparked discussions, with the focus on how users can migrate their vulnerable coins and what should be done with the dormant funds that have never been migrated.

Quantum security efforts have entered the field of encrypted wallets.

Some crypto hosting institutions and blockchain developers have begun testing post-quantum systems before actual threats emerge.

BitGo and Silence Laboratories tested post-quantum multi-party computation signatures earlier this year. crypto.news reported that the demonstration used ML-DSA in an institutional-hosted workflow to test how quantum-resistant signatures could be adapted to existing wallet infrastructure.

BitGo subsequently introduced four control measures for its supported institutional Bitcoin wallets. Relevant reports indicate that the company has added tools to measure public key exposure, integrate outputs, and assist users in transferring funds from addresses that are considered more vulnerable in future quantum computing scenarios.

Coinbase is also dealing with similar hosting issues. In September, crypto.news reported that the company was designing infrastructure capable of supporting different post-quantum signature schemes, as Bitcoin developers have not yet selected a final alternative standard.

Other networks are pushing forward with changes at the account level. Sui plans to offer optional quantum security authentication based on the signature scheme approved by NIST, and intends to introduce native post-quantum accounts onto the mainnet in 2027. crypto.news reports that this proposal will allow users to retain their existing recovery information while adopting new authentication methods.

Monad Researchers have proposed to separate blockchain addresses from their authentication keys. Relevant reports indicate that this design would allow for key replacements without users having to give up the same account address. This proposal is still in development.

NIST Standards provide developers with migration options

The recommendations from the European Police Agency came after the National Institute of Standards and Technology (NIST) in the United States finalized the first batch of major post-quantum cryptography standards.

NIST approved FIPS 203, FIPS 204, and FIPS 205 in August 2024. These standards cover quantum-resistant key establishment and digital signatures.

FIPS 203 specifies ML-KEM, which originates from CRYSTALS-Kyber and is used to establish a shared key. FIPS 204 specifies ML-DSA, which originates from CRYSTALS-Dilithium and is used for digital signatures. FIPS 205 uses a hash-based SLH-DSA signature system, which originates from SPHINCS +.

NIST indicates that organizations should immediately begin migrating to quantum-resistant systems. The planned transition will gradually phase out algorithms with quantum vulnerabilities from the NIST standards and ultimately remove them by 2035, while systems with higher risks are expected to migrate even sooner.

The institution is still developing other solutions. HQC was selected in March 2025 as the standardization object for another key establishment algorithm, while FALCON is being developed as a separate digital signature standard.

The European Police Agency had already discussed the migration plan as early as January. A financial services report released by the agency at that time recommended a risk-based transition approach, which involved first identifying vulnerable cryptography, and then prioritizing systems based on the degree of exposure and their importance.

Long-term encrypted data faces another quantum risk

The second report released by Europol on October 7th examined what security researchers refer to as the "collect first, then decrypt" ( harvest now , decrypt later ) risk.

In this scenario, attackers would collect the encrypted information that is currently unreadable and save it, waiting for future computing systems to develop the capability to crack these encryptions.

The European Police Agency stated that the most relevant targets of these threats are information that needs to be kept confidential for several years, including government communications, medical records, intellectual property, and law enforcement documents.

The report was jointly conducted by Europol and the University of Carlos III in Madrid, stating that the actual level of exposure depends on the encryption protocols used to protect data, the configuration settings, and the methods of key management.

The European Police Agency has not found conclusive evidence indicating that the 'collect first, then decrypt' attack is currently being carried out on a systematic and large-scale basis. Collecting and storing large amounts of encrypted information requires considerable storage, processing capabilities, and technical resources.

In the context of this report, it is more likely that information with a long lifespan and high value will become the target. The European Police Agency recommends removing outdated protocols, reducing unnecessary data retention, and testing post-quantum systems before quantum attacks become feasible.

Encrypted migration may take several years.

The timeline remains one of the biggest unknowns among issues related to quantum threats.

Currently, there is no publicly demonstrated quantum computer that is capable of deriving cryptocurrency private keys on the scale protected by modern blockchain signature systems. Therefore, Europol regards this issue as preparatory work, rather than an ongoing cryptocurrency attack.

Migration itself can also be difficult, as decentralized networks require coordination among developers, wallet companies, exchanges, custodian institutions, miners or verifiers, as well as individual asset holders.

Ledger The Chief Technology Officer Charles Guillemet once stated that perhaps the most difficult issue with Bitcoin is how to securely migrate wallets and existing funds after developers reach an agreement on a new signature scheme. crypto.news reports that dormant tokens and users whose assets were not migrated will pose additional technical and governance challenges.

Galaxy Digital has invested funds in this project. Relevant reports indicate that the company established a $5 million project in July to fund Bitcoin research, covering quantum-resistant signatures, migration tools, and security audits.

The advice from Europol calls on encryption projects to first identify exposed assets, improve wallet and key management practices, test quantum alternative solutions, and clearly communicate future migration requirements to users.

Tip
$0
Like
0
Save
0
Views 23
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Goldman Sachs warns that as the AI craze is unlikely to last, Buffett's rules for surviving in the stock market are once again attracting attention
Buffett has never predicted stock market crashes, but as the S&P 500 and the Nasdaq reach new highs and the yield on 10-year U.S. Treasury bonds surpasses 5.3%, the market once again looks back at his advice to hold stocks for the long term, avoid leverage, and not panic and sell. Panmure Liberum warns, however, that the S&P 500 could fall back to 5,000 points by the end of 2027.
Coinpedia
·2026-10-07 23:11:58
7
How much does it actually cost to retire in each state after deducting social security?
Schroders A survey shows that Americans participating in workplace retirement plans believe a comfortable retirement requires an average of $1.2 million. Investopedia Estimates indicate that a single retiree in North Dakota would need about $644,000, while in New Jersey it would be around $1.018 million; the main differences come from housing and local living costs.
Fortune
·2026-10-07 22:49:38
14
$ ORCA rose by 84% due to DAO's assessment of potential credit market acquisitions
Orca DAO has proposed governance initiatives, planning to restructure the use of repurchase and treasury funds, and considering acquiring a Solana DeFi protocol to expand the credit and revenue product line; despite strong opposition from the community, $ORCA has still risen by 84% in the past 7 days.
SolanaFloor
·2026-10-07 22:30:44
15
Report: The AI cybersecurity market is expected to reach $95.25 billion by 2031
According to MarketsandMarkets, the AI cybersecurity market is expected to grow from $31.25 billion in 2026 to $95.25 billion by 2031, with a compound annual growth rate of 25.0% during the forecast period. The report also indicates that threat detection and anomaly detection, OT / IoT, network physical security, automation and orchestration, as well as the needs of small and medium-sized enterprises (SMEs), will drive this growth, with North America accounting for the highest share in 2026.
PR Newswire
·2026-10-07 22:30:40
12
View More