Europol Says Wallets Are the Quantum Weak Point, Not the Blockchain. The Distinction Matters.

CryptoShakti
By -
0

Key takeaways

  • Europol has described crypto wallets, rather than blockchains themselves, as the primary area of quantum risk.
  • The distinction is technical. Hash functions are relatively resistant to quantum attack; the elliptic-curve signatures that prove ownership of coins are not.
  • An address is normally a hash of a public key, so funds in an address that has never spent reveal no public key at all. Spending from it publishes the key permanently.
  • That makes address reuse the practical exposure, and it means cold storage does not help if the public key is already on-chain.
  • Migration is the genuinely hard problem: it requires both a protocol change and every holder individually moving funds. Coins whose keys are lost can never be moved at all.

Europol has published a warning describing cryptocurrency wallets as the primary area of risk from future quantum computing. It is a carefully worded claim, and the wording is the interesting part: wallets, specifically. Not blockchains, not mining, not exchanges.

That is not a rhetorical choice. It follows from how the cryptography is actually arranged, and the arrangement is worth understanding because it determines which risks are real now and which are decades away.

Two kinds of cryptography, two very different exposures

A blockchain like Bitcoin leans on two distinct cryptographic primitives, and they do not fail in the same way.

The first is hashing. SHA-256 is what mining grinds against and what turns a public key into an address. The best known quantum attack on a hash function is Grover's algorithm, which gives roughly a square-root speedup. That is a real improvement but not a break; it is the kind of thing you answer by using a longer output, and SHA-256 already has considerable margin.

The second is digital signatures. Proving you own a coin means producing an elliptic-curve signature - ECDSA over the secp256k1 curve, for Bitcoin and Ethereum alike. Its security rests on the difficulty of recovering a private key from a public key. Shor's algorithm, on a sufficiently large and sufficiently reliable quantum computer, solves that problem directly rather than approximately.

So the asymmetry is stark. Mining would get somewhat more efficient. Ownership itself would stop being provable only by the owner. That is why the warning points at wallets.

Why an unspent address is in a better position

Here is the detail that most coverage skips, and it changes the picture considerably.

In the common Bitcoin address formats, the address is not your public key. It is a hash of your public key. While an address has only ever received funds, the public key behind it has never been broadcast to anyone. An attacker with a working quantum computer would face a hash, not a curve point, and the hash is the resistant half.

The moment you spend from that address, the signature you publish exposes the public key, and it is on a public ledger permanently. There is no taking it back. If you send the change to the same address and keep using it - address reuse - then the balance sitting there is sitting behind a key that the whole world now has a copy of.

Ethereum's model differs in a way that matters. Externally owned accounts are designed to be reused: one address, used repeatedly, indefinitely. After an account's first outgoing transaction its public key is public, and that is true of essentially every active account on the network. Some newer Bitcoin output types also commit to a public key directly rather than to a hash of one.

The part that breaks a common assumption

A lot of people reason that their holdings are safe because the keys are offline, on a hardware device or on paper, disconnected from everything.

Against ordinary attackers that reasoning is sound and important. Against this particular one it does nothing. The attack does not need to reach your device. It needs your public key, and if you have ever spent from that address, your public key is already published on a ledger that is replicated worldwide and cannot be edited. Air-gapping protects the secret you are holding; it cannot retract the thing you already broadcast.

This is also why the risk is not symmetrical across holders. Someone who has never spent from an address is in a materially different position from someone who has used the same address for years, and neither of them chose that position deliberately.

Why migration is the hard problem

Post-quantum signature schemes exist and are being standardised. In the abstract, a chain can adopt one. In practice the difficulty is not inventing the replacement but completing the move.

It takes two things at once. The protocol has to support the new scheme, which is a coordinated consensus change on a system with no one in charge. And then every single holder has to individually move funds into addresses of the new type - which is not a protocol action at all but millions of separate human decisions, each requiring the holder to still have their keys and still be paying attention.

Which leaves the part nobody has a clean answer for. A very large quantity of coin has not moved in many years. Some of those keys are lost, some of those owners are dead, some are simply gone. Those coins cannot be migrated by anyone, ever, and if their public keys are exposed they stay exposed. Any proposal to do something about them on their owners' behalf runs straight into the question of whether a network can confiscate or freeze coins it does not like the position of, which is a question about what the system is for rather than about cryptography.

What is actually known about timing

It is worth being plain here: nothing that exists today is remotely close. Breaking secp256k1 requires a large fault-tolerant machine with error correction at a scale that current hardware is many orders of magnitude away from, and estimates of when that arrives vary enormously depending on who is estimating and what they are selling.

That uncertainty is exactly why a law enforcement body is writing about it now rather than later. The threat has an unusual shape: an adversary can record encrypted or signed material today and attack it whenever the capability arrives. For data, that is the harvest-now-decrypt-later problem. For a public blockchain, the recording step is already done and was done by design, because publishing everything permanently is the whole point of the structure.

The practical reading

None of this is a reason for alarm about holdings and it is not a statement about any asset's prospects. It is a reason to understand the exposure accurately rather than vaguely.

Modern wallet software has generated a fresh address per transaction for years precisely because address reuse is bad for privacy, and the same habit happens to limit key exposure. Understanding that an address which has spent is different from one which has not, and that offline storage does not undo a published key, is most of the useful knowledge here. The rest is a migration problem that the networks will have to solve in public, slowly, and with a long tail they cannot reach.

Education, not investment advice.

Frequently asked questions

Could a quantum computer break Bitcoin today?

No. Breaking the elliptic-curve signatures Bitcoin uses would need a large fault-tolerant quantum computer with extensive error correction, and existing hardware is many orders of magnitude short of that. The concern is about preparing for a capability that does not yet exist.

Why are wallets the risk rather than the blockchain?

Because the two use different cryptography with different exposures. Hash functions, which mining and address generation rely on, face only a square-root speedup from quantum attack and retain margin. Elliptic-curve signatures, which prove ownership, could be solved directly. Ownership is the weak point, not the ledger or the mining.

Does keeping my keys offline protect me from this?

Not from this specific attack. It needs your public key, not your device. If you have ever spent from an address, the public key is already published permanently on-chain. Air-gapping protects the secret you still hold; it cannot retract what was already broadcast.

What does address reuse have to do with it?

An address is normally a hash of a public key, so an address that has only received funds has never revealed the key behind it. Spending publishes that key forever. If you keep using the same address afterwards, the balance there sits behind a key everyone can now read.

Is Ethereum in a different position from Bitcoin?

Somewhat. Ethereum's externally owned accounts are designed for repeated use at a single address, so after an account's first outgoing transaction its public key is public — and that applies to essentially every active account. Bitcoin's common formats hash the key, so unspent addresses reveal nothing.

Can the networks just upgrade to quantum-resistant signatures?

Adopting a new scheme is the easier half. The hard half is that every holder must then individually move funds into the new address type, which needs them to still have their keys and still be paying attention. Coins whose keys are lost can never be moved by anyone, and that tail has no technical fix.


Not financial advice. Crypto assets are volatile and unregulated in many jurisdictions. In India, gains are taxed at 30% with 1% TDS on transfers. Do your own research and never invest money you cannot afford to lose.

Editorial note: Crypto Shakti uses an AI-assisted research and drafting workflow. Every article is grounded in the linked primary sources and live market data captured at publication time.

Post a Comment

0 Comments

Post a Comment (0)

#buttons=(Ok, Go it!) #days=(20)

Our website uses cookies to enhance your experience. Check Out
Ok, Go it!