Google's March 2026 white paper reduced the estimated qubit threshold for breaking blockchain elliptic-curve cryptography by 20x, to fewer than 500,000 physical qubits. Current hardware sits at 1,000–1,225 qubits. The gap is narrowing: global quantum-computing investment reached $17.3 billion in ...
"The rate of research is going to accelerate from here, and we have already seen progress that people didn't expect would come this early." — Illia Polosukhin, Co-founder, NEAR Protocol
Google's March 2026 white paper reduced the estimated qubit threshold for breaking blockchain elliptic-curve cryptography by 20x, to fewer than 500,000 physical qubits. Current hardware sits at 1,000–1,225 qubits. The gap is narrowing: global quantum-computing investment reached $17.3 billion in 2026, IBM targets verified quantum advantage by year-end, and Citi's May 2026 research note places $350–500 billion in Bitcoin alone at direct quantum risk within the decade.
The response from major Layer 1 protocols is uneven. NEAR Protocol plans to ship FIPS-204 post-quantum signing on testnet by end of Q2 2026. Ethereum has mobilized 10+ client teams on weekly post-quantum interoperability devnets, targeting full migration before 2030. Bitcoin, constrained by its conservative governance model, is mired in a contentious debate over BIP-360 and BIP-361 — proposals that would freeze coins in quantum-vulnerable addresses if holders fail to migrate. Solana, Algorand, and others occupy intermediate positions. This report compares each chain's approach, timelines, and the economic stakes involved.
On March 31, 2026, Google's Quantum AI team published a paper titled "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities," presenting two optimized circuit variants for running Shor's algorithm against the secp256k1 curve used by Bitcoin, Ethereum, and most blockchains:
The paper estimates that breaking ECDSA-256 requires fewer than 500,000 physical qubits — a 20x reduction from 2019 estimates. At sufficient scale, the attack completes in minutes. Google modeled a real-time "on-spend" transaction-hijacking scenario against Bitcoin's 10-minute block confirmation window and found a 41% success rate.
Three papers published in Q1 2026 — from Google, a University of Sussex team, and a Shanghai-based research group — converged on shorter timelines than previously assumed, according to The Quantum Insider. Google itself has set a 2029 internal deadline to migrate its own infrastructure to post-quantum cryptography.
Current hardware remains far from the threshold. Google's Willow chip operates at roughly 1,000 qubits; Atom Computing's neutral-atom machines reach 1,225 qubits; IBM's Flamingo modular systems target 4,000+ qubits. The gap between current capability and the attack threshold spans two to three orders of magnitude, but the trajectory is closing.
The quantum threat is not theoretical in the sense that the attack surface already exists on-chain. The vulnerability depends on public-key exposure: any wallet whose public key is visible on the blockchain is a potential target once quantum hardware matures.
According to Citi's May 2026 research note, 4.5–6.7 million BTC have exposed public keys on-chain, representing $350–500 billion at current prices. Google's own analysis identifies 6.9 million BTC (roughly 32% of circulating supply) in this category. The bank placed the global banking system's total quantum-cryptographic exposure at $3 trillion.
Ethereum's account model is structurally more exposed at the wallet level: every address that has ever sent a transaction has permanently revealed its public key. Solana's architecture exposes 100% of addresses by design, according to security researchers.
Aggregate estimates from multiple research teams place over $600 billion in crypto assets in a quantum-vulnerable state as of mid-2026.
A separate class of risk — "harvest now, decrypt later" — concerns state-level actors who archive encrypted data today for future decryption. This threat is immediate even though the quantum hardware is not.
Bitcoin faces the most acute governance challenge. Its conservative upgrade process — requiring broad miner and node-operator consensus for any soft fork — makes rapid migration structurally difficult.
BIP-360 (February 2026): Introduces Pay-to-Merkle-Root (P2MR), a new output type resembling Taproot but removing the quantum-vulnerable key-path spend. BTQ Technologies deployed the first working implementation on Bitcoin Quantum testnet v0.3.0 in March 2026. BIP-360 has been merged into Bitcoin's official BIP repository but has not activated on mainnet.
BIP-361 (April 2026): Published by Jameson Lopp (co-founder, Casa) and five co-authors, BIP-361 proposes a three-phase soft fork:
The proposal would freeze an estimated 1.1 million BTC believed to belong to Satoshi Nakamoto, plus millions of additional dormant coins. As of March 2026, more than 34% of circulating Bitcoin has exposed public keys.
Community response has been sharply divided. Phil Geiger, Head of Business Development at Metaplanet, characterized the proposal as: "We have to steal people's money to prevent their money from being stolen." Lopp himself expressed ambivalence, stating he "dislikes the idea but fears the alternative of quantum theft even more."
Paradigm's PACTs (May 2026): Dan Robinson, General Partner at Paradigm, proposed Public Address-Control Timestamps — zero-knowledge proofs that allow holders to secretly timestamp their knowledge of a private key before quantum computers arrive. If an emergency fork freezes vulnerable addresses, PACT holders could reclaim funds using the pre-quantum proof. The mechanism works offchain and anonymously but does not extend to multisig wallets or complex scripts.
Ethereum has taken the most structured approach. In February 2026, Vitalik Buterin published a roadmap identifying four quantum-vulnerable cryptographic components:
The Ethereum Foundation established a Post-Quantum Security team in January 2026. More than 10 client teams run weekly post-quantum interoperability devnets. EIP-8141 is under consideration for inclusion in the Hegotá upgrade (second half of 2026). Full activation is targeted before 2030.
Ethereum's account-abstraction architecture gives it a structural advantage: users can migrate individually rather than waiting for a network-wide consensus event. This contrasts directly with Bitcoin's UTXO model, where migration requires a coordinated soft fork.
NEAR Protocol has moved fastest among major L1s. On June 2, 2026, co-founder Illia Polosukhin stated that NEAR plans to deploy post-quantum cryptography by end of Q2 2026.
NEAR selected FIPS-204 (ML-DSA, formerly CRYSTALS-Dilithium), a lattice-based digital signature algorithm standardized by NIST in August 2024. The implementation exploits NEAR's human-readable account model and rotatable access keys: any account holder can rotate to a quantum-safe key in a single transaction with no address migration required.
The v2.13 upgrade, scheduled for June 2026, combines two capabilities: dynamic resharding (automatic scaling of network shards based on transaction demand) and post-quantum cryptographic signing. No other L1 is shipping both simultaneously.
Mainnet deployment will follow security audits and community coordination; no mainnet date has been set. The testnet milestone, if delivered by end of Q2, would make NEAR the first major L1 with a functioning post-quantum signing testnet.
Solana: Both of Solana's core client teams (Anza and Firedancer) independently selected FALCON, a NIST-approved lattice-based scheme, for post-quantum security. The Solana Foundation outlined a phased migration plan in April 2026, prioritizing wallet-level upgrades first.
The tradeoff is significant: post-quantum signatures are substantially larger than current Ed25519 signatures, creating throughput and bandwidth costs on a network optimized for speed. According to CoinDesk, the security-vs.-speed tradeoff is the central tension in Solana's quantum readiness plan.
Algorand: Algorand activated FALCON-signed State Proofs on mainnet in September 2022 and completed the first mainnet FALCON-1024 transaction in November 2025. However, individual account signing still uses Ed25519, leaving wallet-level transactions quantum-vulnerable.
The 2026 roadmap includes a consensus module verifying FALCON signatures natively, Ledger hardware firmware updates for larger key sizes, and an on-chain governance vote to enable "quantum-safe accounts" without a hard fork.
A CoinDesk investigation published May 24, 2026, reported that AI is accelerating the quantum threat through three vectors:
The convergence creates a compounding effect: AI shortens the timeline to cryptographically relevant quantum computers, while those computers, once available, could be paired with AI to mount more efficient attacks. Multiple security researchers quoted in the piece assessed that the combination could compress previously estimated timelines by 2–5 years.
| Protocol | Algorithm | Status (June 2026) | Migration Model | Governance Constraint | |----------|-----------|--------------------|-----------------|-----------------------| | Bitcoin | P2MR (BIP-360) | Testnet; mainnet soft fork required | Network-wide UTXO migration | High — requires miner/node consensus | | Ethereum | leanXMSS, ML-DSA via EIP-8141 | Weekly devnets; 10+ client teams | Per-account via account abstraction | Medium — EIP process, but individual opt-in | | NEAR | FIPS-204 (ML-DSA) | Testnet by end Q2 2026 | Per-account key rotation | Low — single-transaction key swap | | Solana | FALCON | Phased plan; wallet-first approach | Wallet-level, then protocol | Medium — throughput/bandwidth tradeoff | | Algorand | FALCON-1024 | State Proofs live; account signing pending | On-chain vote for account migration | Low — no hard fork required |
Timeline to full post-quantum protection (estimates):
The post-quantum migration is not a future problem. The attack surfaces exist on-chain today — 6.9 million BTC with exposed public keys, every Ethereum address that has ever transacted, 100% of Solana addresses. What remains uncertain is when quantum hardware reaches the capability threshold, not whether the vulnerability is real.
The economic stakes make this the most consequential infrastructure upgrade in blockchain history. Chains that can migrate per-account without network-wide consensus events — NEAR, Ethereum (via account abstraction), Algorand — hold a structural advantage. Bitcoin's UTXO model and conservative governance create a genuine risk of delayed response.
Google's 2029 internal migration deadline serves as a de facto industry benchmark. Protocols that cannot demonstrate credible post-quantum migration plans by that date face a potential repricing of their security assumptions by institutional allocators, as Citi's report makes explicit.
The data does not support panic. Current quantum hardware is orders of magnitude below the attack threshold. But the data does support urgency. Migration takes years. The window for preparation is finite and, according to multiple research teams, shorter than previously assumed.