Europol released two quantum computing reports today. Their conclusion in a nutshell: quantum computing won’t break encryption, but wallets are the weakest link.

1️⃣ The risk lies in wallets, not the blockchain.

A report by Europol’s European Cybercrime Centre (EC3) says that, in theory, a sufficiently powerful quantum computer could derive private keys from public keys that have already been exposed, then transfer assets without authorization—what people commonly call Q-Day. Hash functions that link blocks and support mining, on the other hand, should largely hold up.

2️⃣ Addresses whose public keys are already on-chain can’t be fixed after the fact.

The report’s message is straightforward: the only option is to migrate early, moving funds to new wallets before an attack occurs. Decrypt cites a May estimate from Glassnode that the public keys of about 6.04 million $BTC (30.2% of the issued supply) have been exposed.

3️⃣ Upgrading isn’t free.

NIST-standardized post-quantum signatures are 10 to 120 times larger than the ECDSA signatures Bitcoin currently uses. In other words: more congestion in blocks, higher fees, and slower confirmations. The report also cites a 2024 study estimating that migrating all UTXOs would require at least 76 days of cumulative network downtime.

4️⃣ The second report is about “harvest now, decrypt later.”

First, stockpile encrypted data, then crack it once quantum technology matures. There’s currently no clear evidence that this tactic is being used systematically on a large scale. Government communications and corporate secrets are considered the most likely targets.

My take:

The fact that law enforcement agencies are publishing quantum reports themselves is a signal in its own right. This has moved from a meme in tech circles to a policy agenda.

But no one can give a timeline for when Q-Day will arrive, so don’t get swept up by headlines about a “quantum apocalypse.”

There are really only two things ordinary people can do: avoid reusing the same address to receive funds; and keep an eye out for future quantum-resistant migration options for old addresses and long-dormant wallets. Leave the debate over how to fit signatures 10 to 120 times larger into blocks to the $BTC developers.

Just filtering, not educating.

Sources: Europol’s official website (published October 7), Decrypt.

This is not investment advice.