“Cryptocurrencies will not collapse due to quantum computing, but their long-term security requires proactive defence,” Europol warned on October 7, summing a pair of reports that, together with a redacted US Government Accountability Office document released October 6, urge immediate and concrete action across government and industry.
US GAO: 89 recommendations, a redacted report, and three core priorities
The US Government Accountability Office (GAO) published a redacted version of a document on October 6 that it says was first sent to agencies in September 2025. The GAO said it has already made 89 recommendations to 23 agencies aimed at accelerating the transition to post-quantum cryptography (PQC). The GAO identified three core areas agencies should address: develop a prioritized inventory of vulnerable cryptography; identify PQC funding needs; and test PQC.
Yet the report also states that “none of the 24 agencies cited in the report have fully addressed all three,” and it traced the incomplete implementation to three specific shortfalls: “(1) cryptography expertise, (2) processes for developing cryptography inventories and identifying funding needed to transition to post-quantum cryptography, and (3) plans to guide post-quantum cryptography testing.” The GAO concluded bluntly: “Until the selected agencies address these weaknesses, they will not be well-positioned to address the threat of CRQCs to cryptography that agencies rely on to protect sensitive information.”
Europol on HNDL: harvest-now, decrypt-later is already a present risk
On October 7 Europol published two reports related to quantum risk. The first examined how encrypted communications and stored files could become vulnerable to “harvest now decrypt later” (HNDL) attacks — the practice of collecting encrypted data today to decrypt it once cryptographically relevant quantum computers (CRQCs) exist. Europol noted that exposure depends on the specific protocols, configurations and key management practices an organization uses, and it flagged that some governments are already rumored to be conducting HNDL operations.
To reduce near-term exposure, Europol urged organizations to upgrade to TLS 1.3 and SSH2, disable legacy protocols, and enforce forward secrecy “as soon as possible.” It also recommended identifying and deleting any unnecessary sensitive data to limit long-term storage, and exploring options for adopting PQC — including hybrid approaches — as they become available.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildEuropol on cryptocurrencies and wallets: phased integration of PQC
Europol’s second study targeted the cryptocurrency ecosystem, warning that quantum computing poses a concrete long-term risk to wallets and cryptographic primitives but stopping short of predicting immediate collapse. As quoted above, Europol wrote: “Cryptocurrencies will not collapse due to quantum computing, but their long-term security requires proactive defence.”
The agency urged blockchain projects to prioritize integration of PQC algorithms into core protocols and to share resources with wallet providers so the providers can implement those changes. For wallet vendors, Europol recommended testing and deploying PQC-enabled wallets and educating users about the risks of CRQCs.
Google’s 2029 projection and the calendar of urgency
The timing question hangs over every technical recommendation. Consensus is divided about when cryptographically relevant quantum computers (CRQCs) will appear, but the reports underscore that the date — “Q-day” — matters in operational terms because those machines will be able to break the crypto that protects much government and corporate information. In March, Google predicted that the date could be as soon as 2029, a projection cited in the same week’s reporting.
That timeline helps explain why both Europol and the GAO emphasize immediate action: inventories and testing take time, protocol upgrades ripple across systems, and wallet and blockchain changes touch distributed ecosystems.
What this means for technologists, agencies, and wallet providers
- Technologists and security teams: Follow Europol’s mitigation checklist now — upgrade to TLS 1.3 and SSH2, disable legacy protocols, enforce forward secrecy, and identify and delete unnecessary sensitive data; begin evaluating hybrid PQC options as they become available.
- Federal agencies and procurement leaders: The GAO’s three priorities — inventories of vulnerable cryptography, identifying PQC funding needs, and conducting PQC testing — remain unfinished tasks across the cited agencies; the GAO specifically called out gaps in cryptography expertise, inventory and funding processes, and testing plans.
- Blockchain projects and wallet providers: Europol urges protocol-level integration of PQC algorithms and resource-sharing with wallet vendors; wallet providers should be testing and preparing PQC-enabled wallets and communicating quantum risks to users.
The two European reports and the GAO’s redacted document together draw a clear line from strategy to operations: inventories, funding plans, testing, protocol upgrades and coordinated implementation across ecosystems. With Google’s projection that Q-day could arrive as soon as 2029, the record in these reports is stark — recommendations are in hand, but the work of filling expertise gaps and completing inventories and tests remains unfinished. Will agencies and ecosystem participants convert those recommendations into completed transitions before quantum cryptanalysis becomes practical? The reports leave that question, and the answer, hanging in plain sight.




