Europol Urges Early Action to Protect Cryptocurrencies and Sensitive Data from Quantum Threats
Europol is publishing two reports on the security challenges posed by quantum computing, urging organisations, policymakers and the cryptocurrency industry to begin preparing now. The reports examine how future quantum capabilities could undermine the cryptography protecting cryptocurrency wallets and allow attackers to decrypt sensitive information collected years earlier.
The timing of these capabilities remains uncertain. However, this should not be the main concern. Adapting systems and coordinating security upgrades will take time. Therefore, regardless of the nature of the threats that may emerge, crypto-agility should be pursued proactively to ensure that systems can withstand and overcome future threats while remaining secure.
Both reports highlight the need to identify and prioritise threaten assets according to their relevance, and to plan the transition to post-quantum cryptography accordingly, focusing on algorithms designed to withstand attacks from both conventional and quantum computers while ensuring interoperability and coexistence with existing cryptographic systems.
Cryptocurrency wallets are the main point of exposure
Quantum Computing and Cryptocurrencies – Bridging technical expertise and decision-making, produced by Europol’s European Cybercrime Centre, examines the implications for digital assets and challenges predictions that quantum computing will inevitably cause cryptocurrencies to collapse.
The report identifies the cryptographic keys used to control cryptocurrency wallets and authorise transactions as the primary point of exposure. A sufficiently powerful quantum computer could derive a private key from an exposed public key, potentially allowing an attacker to transfer funds without the owner’s permission.
The cryptographic hash functions underpinning important aspects of blockchain integrity are comparatively resistant to quantum attacks. This distinction is central to understanding the threat and directing protective measures where they are most needed.
The report recommends a phased transition to quantum-resistant cryptography, supported by improvements to wallet security and key management. Blockchain developers, wallet providers, policymakers and users all have a role to play. Coordinating upgrades across decentralised networks will be a particular challenge, making early preparation essential.
Encrypted data collected today could be exposed in the future
The second report, Harvest Now, Decrypt Later, jointly developed by Europol and University Carlos III of Madrid (UC3M) as part of the Europol EC3 Advisory Group on Research and Development, examines a different risk: attackers collecting and storing encrypted information today with the intention of decrypting it when more advance computing capabilities become available.
This approach does not require access to a quantum computer at the time the data is collected. It is particularly relevant to information that must remain confidential for many years, including government communications, intellectual property, medical records and law enforcement files.
The report assesses the conditions under which encrypted communications and stored files could become vulnerable. It finds that exposure depends on the protocols, configurations and key management practices used.
There is currently no clear evidence that this technique is being systematically exploited at scale. Significant storage, processing and technical resources would be required, making high-value information with lasting sensitivity the most plausible target. Nevertheless, the potential consequences justify preparations today.
Preparing for the transition
Both reports recommend that organisations identify where cryptography is used, assess which assets and information need long-term protection, and prioritise the systems most exposed to future quantum attacks.
For organisations handling sensitive data, practical measures include removing outdated security protocols, limiting unnecessary data retention, strengthening flexible key management models and testing post-quantum solutions. The transition should be planned in phases prioritising systems, networks and information according to their relevance while taking account of technical dependencies and the need to maintain essential services.
For the cryptocurrency ecosystem, preparation requires coordinated work on protocols and wallets, alongside clear information for users about future upgrades and migration requirements.
Strengthening international cooperation on criminal finances and cryptoassets
These publications complement Europol’s wider work to address evolving risks involving digital assets. On 15–16 September 2026, Europol co-organised the 10th Global Conference on Criminal Finances and Cryptoassets with the Basel Institute on Governance and the United Nations Office on Drugs and Crime, hosted by Luxembourg’s Bureau de gestion des avoirs. The conference provided a forum for public authorities and private-sector specialists to exchange expertise on the criminal misuse of cryptoassets, emerging risks and practical responses, supporting cooperation across borders and sectors.





