HomeWeb 3Quantum and wallet keys: Europol says the risk is exposed keys, and...

Quantum and wallet keys: Europol says the risk is exposed keys, and Ethereum researchers urge a careful move

The quantum threat to cryptocurrencies is a threat to wallet keys that have already been exposed, not to blockchains themselves. That is the central finding of a report published on 7 October 2026 by Europol’s European Cybercrime Centre (EC3) [1][2][3]. Europol says quantum computers capable of such attacks do not exist yet, does not predict when they will, and urges a phased upgrade starting now [2].

On the same day, Ethereum researcher Justin Drake called on the industry to prepare for “bunker mode”, arguing that fast-moving AI-assisted mathematics could one day weaken the elliptic-curve cryptography that protects wallets. Vitalik Buterin backed taking the risk seriously while explicitly advising against a scramble [4].

Europol’s report is confirmed official analysis. Drake’s and Buterin’s posts are opinion and risk assessment. Nobody in these sources has shown that today’s wallet cryptography has been broken. No investment advice follows.

What does Europol say the real risk is?

Confirmed (Europol report, as published and reported). Europol’s publication page describes the report, Quantum Computing and Cryptocurrencies – Bridging technical expertise and decision-making, as an EC3 analysis that “pinpoints genuine risks, recommends mitigation strategies, and addresses misconceptions” [1].

Its core distinction, as reported by CoinDesk and Decrypt [2][3]:

  • Wallets are the weak point. A wallet uses a private key to authorise transactions and a public key that the network uses to verify them. A sufficiently powerful quantum computer could derive the private key from an exposed public key and spend the funds. Europol calls wallets “the primary point of exposure to quantum threats” [3].
  • Blockchains’ hash functions are far sturdier. The hash functions that link blocks and underpin bitcoin mining remain largely quantum-resistant; Decrypt quotes the report describing the work needed to break a 256-bit hash as “astronomically high with foreseeable technology” [3].
  • No collapse. “Cryptocurrencies will not collapse due to quantum computing,” Europol says, and “proactive adaptation, rather than systemic collapse, is the most likely outcome” [2][3].

In plain terms: the risk is not that someone rewrites bitcoin’s history. It is that, one day, someone could take coins from addresses whose public keys are already visible on-chain.

How much bitcoin is exposed?

CoinDesk, reporting on the Europol report, says roughly 6.9 million bitcoin sit in addresses with exposed public keys, including early “Satoshi-era” pay-to-public-key outputs and many long-dormant holdings [2].

A different estimate circulates too. Decrypt cites blockchain analytics firm Glassnode, which estimated in May that 6.04 million BTC, or 30.2% of issued supply, had already had its public key exposed [3]. The two figures come from different sources and dates; TSN could not open the report PDF to check which figure Europol itself uses, so treat both as estimates.

The important point is the same either way. Europol says exposed keys cannot be made safe retroactively: for those wallets, “the only solution is pre-emptive migration”, meaning owners move funds to new addresses before any attack [2][3].

Why is upgrading bitcoin hard?

Europol’s answer, as reported, is mostly about coordination and capacity rather than missing cryptography [2][3]:

  • Bigger signatures. NIST-standardised post-quantum signatures can be 10 to 120 times larger than the ECDSA signatures bitcoin uses now, which the report says could crowd block space, raise fees and slow confirmations [2][3].
  • Migration time. Europol cites a 2024 study estimating that converting every unspent bitcoin output (UTXO) to a quantum-resistant format would take at least 76 days of cumulative block space, or about 300 days if a quarter of each block were reserved for the job [2][3].
  • A transaction-time risk. Decrypt reports the report also describes a “just-in-time” attack, in which a quantum computer derives a private key in the short window between a transaction revealing its public key and that transaction being confirmed [3].

Europol’s recommendation is a phased transition now, through wallet upgrades, post-quantum cryptography and coordination among developers, miners, exchanges and users [2]. It also proposes a European Commission-led working group, including Europol, the EU cybersecurity agency ENISA and the EU Anti-Money Laundering Authority, to brief policymakers [3].

A companion Europol report on “harvest now, decrypt later”, produced with Spain’s Universidad Carlos III de Madrid, found “currently no clear evidence” that that technique is being systematically exploited at scale [3].

What is “bunker mode”?

Opinion (researcher posts, as reported). Justin Drake, an Ethereum researcher, urged the industry on 7 October to prepare for “bunker mode” because AI could eventually make it possible to break ECDSA, the elliptic-curve signature scheme used to secure wallets [4]. His concern is not quantum hardware but mathematics: rapid AI-assisted progress that could overturn hardness assumptions people have relied on.

“Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen,” Drake wrote, adding that elliptic curves carry “rich structure”, whereas “hashes are designed to minimize algebraic structure” [4].

His recommendation is a gradual one: “set in motion a controlled mass migration of assets to fresh addresses,” with large and sophisticated holders moving first, and moving any remaining funds to a new address after signing a transaction [4]. He also warned that “a rushed migration would do more harm than good” [4].

What did Vitalik Buterin add?

Opinion. Buterin backed the caution, not a panic. “I don’t recommend anyone scramble to move their funds to new wallets today,” he wrote. “But we should take the risks to cryptography from AI-accelerated math seriously” [4].

He went further than Drake on one point, warning that lattice-based cryptography, a leading family of quantum-resistant schemes, could also take “serious hits from the next two years of AI math”, and said this is a major reason Ethereum’s roadmap has been moving in a “hash-only” direction [4].

On practical steps: “If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea.” And a warning about the cure: “I personally have lost more money in botched migrations than I have lost in all hacks combined” [4].

Dragonfly’s Haseeb Qureshi called Drake’s post “a very sober call”, writing that “the risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions” [4].

Update, 8 October 2026 (Starknet)

Opinion, not a decision. The “bunker mode” idea has spread beyond Ethereum’s own researchers. On 8 October Eli Ben-Sasson, chief executive of StarkWare, the company behind the Starknet network, posted a thread on X asking: “Starknet becoming an L1 for post-quantum agility: good idea or bad idea?” [8]

Starknet is a “layer 2”: a network that runs on top of Ethereum and relies on it for final security. Ben-Sasson’s argument is that a layer 2 can be only as quantum-safe as the chain beneath it. Starknet, he says, already has “an active migration roadmap” to post-quantum security, “but as an L2, Starknet relies on the security of its L1, Ethereum” [8]. If Ethereum does not move fast enough, “We’re considering multiple options, including becoming an L1”, meaning its own base chain. The advantage, he writes, would be “control over the network’s security migrations, rather than having to wait for Ethereum or Bitcoin to move first” [8].

He echoes Drake’s concern about AI as well as quantum computers, calling for “bunker mode” and saying AI “may bring quantum threats even closer than most people expect” [8]. He also makes three timing claims: that Ethereum is targeting full quantum resistance at its base layer by the end of 2029, that Bitcoin has made no such commitment, and that “Starknet could get there by 2027” [8]. These are his statements; TSN has not checked them against Ethereum’s or Starknet’s published plans.

Ben-Sasson framed the thread as a question linked to a conference talk, not an announcement. No change to Starknet’s design or governance has been decided, and the 2027 date refers to quantum resistance, not to a move to layer 1.

Where Europol and the researchers agree, and where they differ

  • Agree: the weak point is the exposed public key, and the defence is moving funds to fresh, unexposed addresses, carefully and in phases [2][3][4].
  • Differ on the driver: Europol’s report is about quantum computers [2]. Drake and Buterin are worried about AI-driven mathematics, which could in principle arrive by a different route [4].
  • Differ on what is “safe”: Europol treats hashes as robust and post-quantum signatures as the upgrade path [3]. Buterin cautions that even some post-quantum schemes may weaken, favouring hash-based designs [4].

For institutions, TSN’s earlier coverage of Project Eleven’s Strongpoint custody platform covers the same theme from the custody side: controls built to survive a change of signature scheme.

Update, 8 October 2026

Two US government sources published timing signals the same week, and both need reading carefully.

On 7 October DARPA moved four more companies into the final, hands-on stage of its Quantum Benchmarking Initiative. Its programme lead said DARPA “increasingly expect[s] that someone will build a utility-scale quantum computer by 2033” [5]. That is a forecast, not a commitment. “Utility-scale” means a machine whose computing value exceeds its cost [5]; it is not the same as a machine able to derive wallet keys, and DARPA does not claim that.

On 6 October the US Government Accountability Office published an audit finding that none of 24 major federal agencies had fully prepared to move to post-quantum encryption [6]. GAO wrote that a machine able to break today’s encryption could arrive as soon as the 2030s, while noting that experts put the chance of one within ten years as low [6][7].

Neither source gives a Q-Day date. Both point the same way as Europol: the move to new cryptography takes years, so preparation starts before the threat arrives.

What this does not prove

  • That any wallet cryptography has been broken. Europol says capable quantum computers do not yet exist [2]. Drake and Buterin describe a risk, not a demonstrated break [4].
  • When Q-Day, or an AI-driven break, might arrive. Europol did not predict a date [2]; Buterin’s “next two years” remark concerns lattice security, not a forecast that wallets will be drained [4]. DARPA’s 2033 expectation is about useful machines, not key-breaking ones [5].
  • The precise number of exposed coins. CoinDesk reports about 6.9 million BTC; Glassnode’s May estimate was 6.04 million [2][3]. TSN did not verify either against chain data.
  • That users should move funds today. Buterin explicitly says he does not recommend scrambling; Drake warns against a rushed migration [4].
  • That the bitcoin or Ethereum protocols have agreed upgrade paths. Europol stresses coordination as the main challenge [2].
  • Any price effect or investment conclusion. TSN is not offering investment advice.
  • That Starknet will leave Ethereum. StarkWare’s chief executive says becoming an L1 is one option under consideration; no decision has been announced [8].

The Bottom Line

Europol’s message is calm and specific: quantum computing threatens exposed wallet keys, not the blockchains themselves, and the sensible response is a phased upgrade that starts now [1][2][3]. Drake and Buterin add a second, more speculative worry: that AI-assisted maths could pressure today’s cryptography from another direction, which is a reason for careful preparation, not panic [4].

Both point to the same habit: keep funds in addresses whose public keys have not been revealed, and plan migrations rather than rush them.

Related on TSN: Project Eleven Strongpoint: post-quantum custody with Zcash Foundation as partner (https://tsnmedia.org/project-eleven-strongpoint-zcash-foundation/).

Sources

  1. Europol, “Quantum computing and cryptocurrencies – Bridging technical expertise and decision-making,” publication page, 7 October 2026 (page is JavaScript-rendered; summary text read via search index; report PDF not retrieved). https://www.europol.europa.eu/publications-events/publications/quantum-computing-and-cryptocurrencies
  2. Olivier Acuna, “Quantum computers threaten exposed private keys rather than blockchains, Europol warns,” CoinDesk, 7 October 2026. https://www.coindesk.com/tech/2026/10/07/quantum-computers-threaten-exposed-private-keys-rather-than-blockchains-europol-warns
  3. Decrypt Agent, “Europol Warns Crypto Wallets Are ‘Primary Risk’ for Quantum Attacks,” Decrypt, 7 October 2026. https://decrypt.co/380268/europol-warns-crypto-wallets-are-primary-risk-for-quantum-attacks
  4. Felix Ng, “Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances,” Cointelegraph, 8 October 2026. https://cointelegraph.com/news/justin-drake-urges-crypto-bunker-mode-as-ai-could-break-wallet-security-within-months
  5. Drew Jolly, “Atom Computing, Diraq, IBM and IonQ Advance to DARPA QBI Stage C,” HPCwire, 7 October 2026. https://www.hpcwire.com/2026/10/07/atom-computing-diraq-ibm-and-ionq-advance-to-darpa-qbi-stage-c/
  6. Madison Alder, “Work needed to fortify systems against quantum threats, watchdog says,” FedScoop, 7 October 2026 (on GAO-27-108740; gao.gov blocked our fetch). https://fedscoop.com/agencies-behind-fortifying-systems-against-quantum-threats-watchdog-says/
  7. “US Cryptographic Inventory Audit: One of 24 Complete,” PostQuantum.com, 6 October 2026 (summary of GAO-27-108740’s threat section). https://postquantum.com/security-pqc/us-cryptographic-inventory-audit/
  8. Eli Ben-Sasson (@EliBenSasson), “Starknet becoming an L1 for post-quantum agility: good idea or bad idea?…,” thread on X, 8 October 2026, 09:19–09:20 BST. https://x.com/EliBenSasson/status/2108110129572741426

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.