Europol published two reports on Wednesday, 7 October, warning that quantum computing poses a growing threat to the public-key cryptography underpinning crypto wallets and much of Europe's encrypted data, and calling for migration strategies to begin now rather than once quantum machines capable of breaking current systems actually exist.
The first report was produced by Europol's European Cybercrime Centre (EC3). The second was developed with UC3M, within the agency's Advisory Group Research and Development. Together they lay out why algorithms widely used today, including RSA, Diffie-Hellman and elliptic curve cryptography, are at risk from Shor's algorithm, a mathematical method published in 1997 that, once run on a sufficiently powerful quantum computer, could break them.
The timeline is not abstract. NIST, the US standards body, has set a schedule to deprecate classical public-key cryptography configurations by 2030 and remove them entirely by 2035. Google has stated an internal target of 2029 for building a fault-tolerant quantum computer. NIST already standardized two post-quantum algorithms in 2024, FIPS 203 (CRYSTALS-Kyber) and FIPS 204 (CRYSTALS-Dilithium), giving industry a starting point for migration.
Bitcoin's migration problem
The reports single out Bitcoin to illustrate how disruptive a transition could be. Migrating every existing Bitcoin UTXO to quantum-resistant signatures would require a minimum cumulative network downtime of 76 days if done all at once, according to the analysis. Spreading the migration out while reserving a quarter of each block's capacity for the process would stretch the timeline to around 300 days.
Part of the difficulty is size. A post-quantum, hash-based signature scheme such as XMSS runs to roughly 20 kilobytes, against 72 bytes for a standard ECDSA signature — a jump that strains block space and network design. Taproot, which introduced Schnorr signatures to Bitcoin in 2021, offers a partial path forward, but adoption remains under 1%, leaving the bulk of the network on older, more vulnerable signature schemes.
On the Ethereum side, the reports point to ERC-4337, the account abstraction standard, as a recommended route for wallets to adopt quantum-resistant signing without requiring a wholesale protocol overhaul.
Harvest now, decrypt later
Beyond wallets, the reports flag a broader data-security risk known as Harvest Now, Decrypt Later, in which encrypted data is stolen today with the expectation that it can be decrypted once quantum computers mature. Europol notes that groups such as REvil and Clop have already built business models around exfiltrating data before encryption, for later extortion or resale — a pattern that would extend naturally to a harvest-now strategy. The 2025 cyberattack on Oracle, which exposed medical records, is cited as an example of the kind of breach that could feed such a pipeline. Europol states it has no documented confirmed case of a Harvest Now, Decrypt Later attack to date, but treats the absence of evidence as no reason for delay.
The agency's Quantum Threat Timeline Report 2025, based on the opinions of 32 global experts, underpins much of the urgency in the findings. For European policymakers and infrastructure operators, the message from both reports is the same: migration planning needs to start well before a cryptographically relevant quantum computer actually exists, given how long transitions such as Bitcoin's are likely to take.



