← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] 00B at Quantum Risk: L1 Migration Race Begins

Zephyra|June 3, 2026|BPF
EXECUTIVE SUMMARY

Google's March 2026 white paper reduced the estimated qubit threshold for breaking blockchain elliptic-curve cryptography by 20x, to fewer than 500,000 physical qubits. Current hardware sits at 1,000–1,225 qubits. The gap is narrowing: global quantum-computing investment reached $17.3 billion in ...

"The rate of research is going to accelerate from here, and we have already seen progress that people didn't expect would come this early." — Illia Polosukhin, Co-founder, NEAR Protocol

Executive Summary

Google's March 2026 white paper reduced the estimated qubit threshold for breaking blockchain elliptic-curve cryptography by 20x, to fewer than 500,000 physical qubits. Current hardware sits at 1,000–1,225 qubits. The gap is narrowing: global quantum-computing investment reached $17.3 billion in 2026, IBM targets verified quantum advantage by year-end, and Citi's May 2026 research note places $350–500 billion in Bitcoin alone at direct quantum risk within the decade.

The response from major Layer 1 protocols is uneven. NEAR Protocol plans to ship FIPS-204 post-quantum signing on testnet by end of Q2 2026. Ethereum has mobilized 10+ client teams on weekly post-quantum interoperability devnets, targeting full migration before 2030. Bitcoin, constrained by its conservative governance model, is mired in a contentious debate over BIP-360 and BIP-361 — proposals that would freeze coins in quantum-vulnerable addresses if holders fail to migrate. Solana, Algorand, and others occupy intermediate positions. This report compares each chain's approach, timelines, and the economic stakes involved.

Table of Contents

  1. The Threat: Google's Revised Estimates
  2. Exposure: $600B in Quantum-Vulnerable Assets
  3. Bitcoin: BIP-360, BIP-361, and the Freeze Debate
  4. Ethereum: Buterin's Four-Front Migration
  5. NEAR: First Mover on FIPS-204
  6. Solana and Algorand: Phased Approaches
  7. AI as Threat Accelerator
  8. Comparative Migration Matrix
  9. Key Takeaways
  10. Conclusion

The Threat: Google's Revised Estimates

On March 31, 2026, Google's Quantum AI team published a paper titled "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities," presenting two optimized circuit variants for running Shor's algorithm against the secp256k1 curve used by Bitcoin, Ethereum, and most blockchains:

  • Variant A: ≤1,200 logical qubits, ≤90 million Toffoli gates
  • Variant B: ≤1,450 logical qubits, ≤70 million Toffoli gates

The paper estimates that breaking ECDSA-256 requires fewer than 500,000 physical qubits — a 20x reduction from 2019 estimates. At sufficient scale, the attack completes in minutes. Google modeled a real-time "on-spend" transaction-hijacking scenario against Bitcoin's 10-minute block confirmation window and found a 41% success rate.

Three papers published in Q1 2026 — from Google, a University of Sussex team, and a Shanghai-based research group — converged on shorter timelines than previously assumed, according to The Quantum Insider. Google itself has set a 2029 internal deadline to migrate its own infrastructure to post-quantum cryptography.

Current hardware remains far from the threshold. Google's Willow chip operates at roughly 1,000 qubits; Atom Computing's neutral-atom machines reach 1,225 qubits; IBM's Flamingo modular systems target 4,000+ qubits. The gap between current capability and the attack threshold spans two to three orders of magnitude, but the trajectory is closing.

Exposure: $600B in Quantum-Vulnerable Assets

The quantum threat is not theoretical in the sense that the attack surface already exists on-chain. The vulnerability depends on public-key exposure: any wallet whose public key is visible on the blockchain is a potential target once quantum hardware matures.

According to Citi's May 2026 research note, 4.5–6.7 million BTC have exposed public keys on-chain, representing $350–500 billion at current prices. Google's own analysis identifies 6.9 million BTC (roughly 32% of circulating supply) in this category. The bank placed the global banking system's total quantum-cryptographic exposure at $3 trillion.

Ethereum's account model is structurally more exposed at the wallet level: every address that has ever sent a transaction has permanently revealed its public key. Solana's architecture exposes 100% of addresses by design, according to security researchers.

Aggregate estimates from multiple research teams place over $600 billion in crypto assets in a quantum-vulnerable state as of mid-2026.

A separate class of risk — "harvest now, decrypt later" — concerns state-level actors who archive encrypted data today for future decryption. This threat is immediate even though the quantum hardware is not.

Bitcoin: BIP-360, BIP-361, and the Freeze Debate

Bitcoin faces the most acute governance challenge. Its conservative upgrade process — requiring broad miner and node-operator consensus for any soft fork — makes rapid migration structurally difficult.

BIP-360 (February 2026): Introduces Pay-to-Merkle-Root (P2MR), a new output type resembling Taproot but removing the quantum-vulnerable key-path spend. BTQ Technologies deployed the first working implementation on Bitcoin Quantum testnet v0.3.0 in March 2026. BIP-360 has been merged into Bitcoin's official BIP repository but has not activated on mainnet.

BIP-361 (April 2026): Published by Jameson Lopp (co-founder, Casa) and five co-authors, BIP-361 proposes a three-phase soft fork:

  • Phase A (~3 years after BIP-360 activation): Blocks wallets from sending funds to legacy address types.
  • Phase B (~2 years after Phase A): Renders all legacy signatures invalid at the consensus layer.
  • Phase C: Coins that did not migrate become permanently frozen.

The proposal would freeze an estimated 1.1 million BTC believed to belong to Satoshi Nakamoto, plus millions of additional dormant coins. As of March 2026, more than 34% of circulating Bitcoin has exposed public keys.

Community response has been sharply divided. Phil Geiger, Head of Business Development at Metaplanet, characterized the proposal as: "We have to steal people's money to prevent their money from being stolen." Lopp himself expressed ambivalence, stating he "dislikes the idea but fears the alternative of quantum theft even more."

Paradigm's PACTs (May 2026): Dan Robinson, General Partner at Paradigm, proposed Public Address-Control Timestamps — zero-knowledge proofs that allow holders to secretly timestamp their knowledge of a private key before quantum computers arrive. If an emergency fork freezes vulnerable addresses, PACT holders could reclaim funds using the pre-quantum proof. The mechanism works offchain and anonymously but does not extend to multisig wallets or complex scripts.

Ethereum: Buterin's Four-Front Migration

Ethereum has taken the most structured approach. In February 2026, Vitalik Buterin published a roadmap identifying four quantum-vulnerable cryptographic components:

  1. Consensus-layer BLS signatures — To be replaced with leanXMSS, a hash-based signature scheme for validators.
  2. Data-availability KZG commitments — Require migration to quantum-safe polynomial commitment schemes.
  3. EOA signatures (ECDSA) — Users will gain signature agility through account abstraction (EIP-8141), allowing individual accounts to switch to post-quantum schemes without a protocol-wide hard fork.
  4. Application-layer ZK proofs (Groth16) — To be replaced with quantum-safe alternatives through "validation frames" that bundle and compress multiple proofs.

The Ethereum Foundation established a Post-Quantum Security team in January 2026. More than 10 client teams run weekly post-quantum interoperability devnets. EIP-8141 is under consideration for inclusion in the Hegotá upgrade (second half of 2026). Full activation is targeted before 2030.

Ethereum's account-abstraction architecture gives it a structural advantage: users can migrate individually rather than waiting for a network-wide consensus event. This contrasts directly with Bitcoin's UTXO model, where migration requires a coordinated soft fork.

NEAR: First Mover on FIPS-204

NEAR Protocol has moved fastest among major L1s. On June 2, 2026, co-founder Illia Polosukhin stated that NEAR plans to deploy post-quantum cryptography by end of Q2 2026.

NEAR selected FIPS-204 (ML-DSA, formerly CRYSTALS-Dilithium), a lattice-based digital signature algorithm standardized by NIST in August 2024. The implementation exploits NEAR's human-readable account model and rotatable access keys: any account holder can rotate to a quantum-safe key in a single transaction with no address migration required.

The v2.13 upgrade, scheduled for June 2026, combines two capabilities: dynamic resharding (automatic scaling of network shards based on transaction demand) and post-quantum cryptographic signing. No other L1 is shipping both simultaneously.

Mainnet deployment will follow security audits and community coordination; no mainnet date has been set. The testnet milestone, if delivered by end of Q2, would make NEAR the first major L1 with a functioning post-quantum signing testnet.

Solana and Algorand: Phased Approaches

Solana: Both of Solana's core client teams (Anza and Firedancer) independently selected FALCON, a NIST-approved lattice-based scheme, for post-quantum security. The Solana Foundation outlined a phased migration plan in April 2026, prioritizing wallet-level upgrades first.

The tradeoff is significant: post-quantum signatures are substantially larger than current Ed25519 signatures, creating throughput and bandwidth costs on a network optimized for speed. According to CoinDesk, the security-vs.-speed tradeoff is the central tension in Solana's quantum readiness plan.

Algorand: Algorand activated FALCON-signed State Proofs on mainnet in September 2022 and completed the first mainnet FALCON-1024 transaction in November 2025. However, individual account signing still uses Ed25519, leaving wallet-level transactions quantum-vulnerable.

The 2026 roadmap includes a consensus module verifying FALCON signatures natively, Ledger hardware firmware updates for larger key sizes, and an on-chain governance vote to enable "quantum-safe accounts" without a hard fork.

AI as Threat Accelerator

A CoinDesk investigation published May 24, 2026, reported that AI is accelerating the quantum threat through three vectors:

  1. Error correction optimization: Machine-learning systems are reducing quantum error rates — the field's largest engineering bottleneck — faster than classical approaches alone.
  2. Materials discovery: AI-driven simulation is accelerating the development of qubit substrates and quantum hardware components.
  3. Automated vulnerability hunting: AI tools are being applied to cryptanalytic research, potentially identifying weaknesses in existing schemes more rapidly.

The convergence creates a compounding effect: AI shortens the timeline to cryptographically relevant quantum computers, while those computers, once available, could be paired with AI to mount more efficient attacks. Multiple security researchers quoted in the piece assessed that the combination could compress previously estimated timelines by 2–5 years.

Comparative Migration Matrix

| Protocol | Algorithm | Status (June 2026) | Migration Model | Governance Constraint | |----------|-----------|--------------------|-----------------|-----------------------| | Bitcoin | P2MR (BIP-360) | Testnet; mainnet soft fork required | Network-wide UTXO migration | High — requires miner/node consensus | | Ethereum | leanXMSS, ML-DSA via EIP-8141 | Weekly devnets; 10+ client teams | Per-account via account abstraction | Medium — EIP process, but individual opt-in | | NEAR | FIPS-204 (ML-DSA) | Testnet by end Q2 2026 | Per-account key rotation | Low — single-transaction key swap | | Solana | FALCON | Phased plan; wallet-first approach | Wallet-level, then protocol | Medium — throughput/bandwidth tradeoff | | Algorand | FALCON-1024 | State Proofs live; account signing pending | On-chain vote for account migration | Low — no hard fork required |

Timeline to full post-quantum protection (estimates):

  • NEAR: Testnet Q2 2026, mainnet TBD (pending audit)
  • Algorand: Partial (State Proofs live), full account migration 2026–2027
  • Ethereum: Full activation targeted before 2030
  • Solana: Phased, no firm mainnet date
  • Bitcoin: Years from activation, pending community consensus

Key Takeaways

  • $600 billion in crypto assets currently sit in quantum-vulnerable addresses, per aggregate research estimates. Citi places Bitcoin-specific exposure at $350–500 billion.
  • Google's March 2026 paper cut the estimated qubit requirement by 20x. The attack surface is known; the timeline is the variable.
  • Governance determines migration speed. NEAR and Algorand can upgrade per-account without hard forks. Ethereum's account abstraction enables individual opt-in. Bitcoin requires a coordinated soft fork that historically takes years.
  • BIP-361's freeze proposal has split the Bitcoin community. Paradigm's PACTs offer a partial alternative but do not cover multisig or complex scripts.
  • AI is compressing timelines. Machine-learning acceleration of quantum error correction and hardware development may shorten the window for preparation by 2–5 years, per security researchers.
  • No chain is fully quantum-safe today. Even NEAR and Algorand, the most advanced, have only partial implementations. The race is between protocol migration speed and quantum hardware maturation.

Conclusion

The post-quantum migration is not a future problem. The attack surfaces exist on-chain today — 6.9 million BTC with exposed public keys, every Ethereum address that has ever transacted, 100% of Solana addresses. What remains uncertain is when quantum hardware reaches the capability threshold, not whether the vulnerability is real.

The economic stakes make this the most consequential infrastructure upgrade in blockchain history. Chains that can migrate per-account without network-wide consensus events — NEAR, Ethereum (via account abstraction), Algorand — hold a structural advantage. Bitcoin's UTXO model and conservative governance create a genuine risk of delayed response.

Google's 2029 internal migration deadline serves as a de facto industry benchmark. Protocols that cannot demonstrate credible post-quantum migration plans by that date face a potential repricing of their security assumptions by institutional allocators, as Citi's report makes explicit.

The data does not support panic. Current quantum hardware is orders of magnitude below the attack threshold. But the data does support urgency. Migration takes years. The window for preparation is finite and, according to multiple research teams, shorter than previously assumed.

Sources & References

  1. Google Quantum AI — "Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly" — Google's March 2026 white paper on ECDSA quantum vulnerability estimates
  2. CoinDesk — "Bitcoin Bulls Scramble for Post-Quantum Protection as Google Drops Bombshell Paper" — Coverage of Google's qubit reduction estimates
  3. The Quantum Insider — "Q-Day Just Got Closer: Three Papers in Three Months" — Analysis of converging quantum threat timelines
  4. CoinDesk — "Bitcoin Faces Outsized Quantum Threat, Citi Says" — Citi's May 2026 research note on Bitcoin quantum exposure
  5. CoinDesk — "Vitalik Buterin Unveils Ethereum Roadmap to Counter Quantum Computing Threat" — Buterin's four-front post-quantum migration plan
  6. CoinDesk — "Ethereum Foundation Prepares for Quantum Threat with New Cryptography Roadmap" — Ethereum Foundation's Post-Quantum Security team and devnets
  7. BloomingBit — "NEAR Founder Says Post-Quantum Cryptography to Roll Out by End of Second Quarter" — Polosukhin's June 2 statement on NEAR's Q2 PQ deployment
  8. CoinDesk — "Solana's Post-Quantum Push Reveals Harsh Tradeoff: Security vs Speed" — Solana's FALCON selection and bandwidth concerns
  9. CoinDesk — "Bitcoin's Quantum Debate Splits as Adam Back Pushes Optional Upgrades Over Forced Freeze" — BIP-361 community debate
  10. Paradigm — "PACTs: Protecting Your Bitcoin From a Quantum Sunset" — Dan Robinson's zero-knowledge timestamp proposal
  11. CoinDesk — "AI Is Speeding Up the Quantum Threat to Crypto, Security Experts Warn" — AI as quantum threat accelerator
  12. Bitcoin.com — "Bitcoin Developers Propose Freezing Coins That Skip Quantum-Safe Migration Under BIP-361" — BIP-361 freeze mechanism details
  13. CryptoTimes — "Solana Foundation Details Phased Plan for Post-Quantum Migration" — Solana's phased post-quantum roadmap
  14. NIST — "FIPS 204: Module-Lattice-Based Digital Signature Standard" — The NIST standard adopted by NEAR Protocol