On Wednesday, 7 October 2026, the European Cybercrime Centre, Europol, noted that quantum computing is unlikely to undermine Bitcoin. An estimated 6 million to 6.9 million BTC, about 30% of the supply, might need migration from addresses with exposed public keys.
The risk relies on a quantum computer powerful enough to derive private keys from visible public keys.
Europol’s reports distinguish the blockchain’s hashing layer from the cryptography used by wallets. Bitcoin’s SHA-256-based hashing is comparatively resistant to quantum attacks. Wallets relying on exposed public-key cryptography are the primary point of concern.

If a capable quantum computer were developed, it could theoretically use an exposed public key to derive its matching private key and authorize a transaction without the owner’s approval. Public-key visibility is not itself a private-key compromise, and Europol’s assessment does not establish an active or present-day method for quantum theft.
Wallet Migration, Not the Blockchain, Is Bitcoin’s Real Quantum Challenge
JUST IN: Europol warns Bitcoin & crypto wallet keys face quantum risk.
• Only exposed public keys are at risk
• No timeline projected
• Nothing new—no reason to panic
Do not reuse addresses! pic.twitter.com/Ig9gB0ZN2X
— Bitcoin Archive (@BitcoinArchive) October 7, 2026
Europol recommends phased adoption of post-quantum cryptography and proactive migration to safer wallets. That makes wallet security and key management central to Bitcoin quantum risk, alongside protocol-level planning; the distinction also matters to holders choosing between direct custody and fund exposure, as explored in Bitcoin self-custody and ETF security trade-offs.
A separate Glassnode analysis estimates 6.04 million BTC, or 30.2% of the issued supply, is exposed at rest under its methodology. It divides that estimate into 1.92 million BTC of structural exposure and 4.12 million BTC associated with operational practices such as address or key reuse. These are supplementary estimates, not a count of coins presently hackable, and they use a distinct analysis from Europol’s broader range.
You’re Still Early: 10 AI Agent Coins That Could Win Big Next Bullrun
Europol and The Quantum Risk: The Market Impact
The primary significance for investors is not an immediate Bitcoin price signal. Europol’s assessment provides no measured market reaction; instead, it highlights a future migration burden for individual holders, exchanges, custodians, wallet providers, and Bitcoin developers.
Bitcoin has no central IT department that can impose a mandatory wallet update, so migration would require coordination across a decentralized network. Europol estimates that processing all Bitcoin unspent transaction outputs, or UTXOs, could take more than 76 days of cumulative processing time under certain assumptions.
The figure is not a countdown or a prediction of when quantum attacks will become feasible. It does show why migration planning cannot be left until a threat is operational: users and custodians would need to move relevant funds before a capable machine arrives. A past wallet security breach illustrates the difference between a present-day incident and this conditional, future-facing risk.
Glassnode’s structural and operational categories add a useful distinction to the migration question. Some exposed balances reflect address-management behavior, while others sit in output types that reveal public keys by design. The categories do not establish that every coin can be moved: inactive or inaccessible holdings may pose a more difficult coordination problem.
For now, Europol’s recommendation is phased post-quantum adoption paired with wallet upgrades, not an assumption that Bitcoin is on the verge of failure.
Don’t Miss: ICOBench Experts Call the Next 1000x Crypto Coins for 2027
