The U.S. Department of Commerce on May 21, 2026, committed $2.013 billion in CHIPS Act incentives across nine quantum computing companies, with IBM receiving $1 billion to build the nation's first dedicated quantum wafer foundry. The investment arrives as a Caltech-Oratomic paper published March ...
"The gap is not technical. The gap is entirely coordination, urgency, and willingness to accept the costs." — Alex Pruden, CEO, Project Eleven
The U.S. Department of Commerce on May 21, 2026, committed $2.013 billion in CHIPS Act incentives across nine quantum computing companies, with IBM receiving $1 billion to build the nation's first dedicated quantum wafer foundry. The investment arrives as a Caltech-Oratomic paper published March 30 demonstrated that elliptic curve cryptography — the signature scheme protecting Bitcoin, Ethereum, and the majority of blockchain assets — could fall to a quantum computer with as few as 9,988 physical qubits, down from prior estimates in the tens of millions.
The three largest blockchain networks are now racing, at different speeds, to retrofit post-quantum cryptography (PQC) into live production systems. Ethereum created a dedicated PQ team in January 2026. Solana aligned its two core developer teams on the Falcon signature scheme in April. Bitcoin, whose governance model lacks a coordinating foundation, has published BIP-360 and BIP-361 — the latter proposing to freeze an estimated 6.2–6.9 million BTC ($500 billion) in quantum-vulnerable addresses if holders fail to migrate. The comparative readiness of these three networks reveals sharp differences in governance speed, technical tradeoff tolerance, and economic risk exposure.
The Commerce Department's $2.013 billion allocation spans two manufacturing initiatives and seven technology developers pursuing six distinct qubit architectures: superconducting (IBM, Rigetti), trapped-ion (Quantinuum), neutral atom (Atom Computing, Infleqtion), photonic (PsiQuantum), annealing (D-Wave), and silicon spin (Diraq).
Allocation breakdown:
| Recipient | Amount | Technology | |-----------|--------|------------| | IBM (Anderon foundry) | $1.0B | Superconducting — quantum wafer fabrication | | GlobalFoundries | $375M | Quantum chip manufacturing support | | Quantinuum | $100M | Trapped-ion | | PsiQuantum | $100M | Photonic | | Atom Computing | $100M | Neutral atom | | Rigetti | $100M | Superconducting | | Infleqtion | $100M | Neutral atom | | D-Wave | $100M | Quantum annealing | | Diraq | $38M | Silicon spin |
IBM is matching its federal award dollar-for-dollar with $1 billion in cash, intellectual property, and staff. IBM CEO Arvind Krishna stated that "Anderon will be well-positioned to fuel America's fast-growing quantum technology industry." The Commerce Department will take equity stakes in all nine companies, a condition of each award. Commerce Secretary Howard Lutnick characterized the investments as targeting "thousands of high-paying American jobs."
IBM has separately committed to delivering large-scale fault-tolerant quantum computers by 2029.
Three research milestones in 2026 have compressed the estimated qubit requirement for breaking 256-bit elliptic curve cryptography (the scheme securing ECDSA-based blockchains):
Google (March 2026): Published a refined implementation of Shor's algorithm requiring 20x fewer resources than prior art. New threshold: under 500,000 physical qubits, down from prior estimates of 10–20 million.
Caltech-Oratomic (March 30, 2026): Demonstrated in a paper submitted to arXiv that ECC could be broken with 9,988 reconfigurable atomic qubits — though requiring approximately 1,000 days of continuous computation. At 26,000 qubits, the same attack completes in one day.
Google Q-Day probability estimate: Google researchers separately assessed at least a 10% chance of a cryptographically relevant quantum computer (CRQC) emerging by 2032.
Project Eleven's 110-page report, published May 9, 2026, synthesized these findings and concluded that "Q-Day is more likely to occur than not by 2033." The firm estimates the window at 2030–2033.
For context, IBM's current largest processor (Willow) operates at 105 physical qubits. The gap between 105 and 10,000 is large but narrowing. IBM's roadmap targets 100,000+ qubits by the early 2030s.
On April 24, 2026, Project Eleven awarded its Q-Day Prize — 1 BTC — to independent researcher Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible IBM quantum hardware. The result represents a 512x jump from the previous public demonstration of a 6-bit key break in September 2025.
Bitcoin's actual key space is 256 bits. A 15-bit break does not constitute a direct threat. However, the demonstration confirmed that Shor's algorithm-based attacks on real ECC implementations are executable on commodity cloud-accessible quantum hardware today, without requiring access to national laboratory equipment.
"The resource requirements for this type of attack keep dropping, and the barrier to running it in practice is dropping with them," Pruden stated.
Bitcoin's post-quantum defense centers on two proposals:
BIP-360 (Pay-to-Merkle-Root / P2MR): Introduces a new address type that never exposes a public key, even during spending. This eliminates the quantum attack surface for new addresses. BIP-360 was formally assigned on February 11, 2026, and entered testnet via BTQ Technologies. The proposal has six co-authors including Casa CTO Jameson Lopp.
BIP-361 (Legacy Address Freeze): Proposes a three-phase soft fork timeline:
BIP-361 targets an estimated 6.2–6.9 million BTC with exposed public keys, worth approximately $500 billion at current prices. This includes all P2PK outputs from Bitcoin's first two years — including an estimated 1.1 million BTC attributed to Satoshi Nakamoto — and every address that has ever sent a transaction.
The proposal has generated sharp opposition. Critics argue it violates Bitcoin's foundational property-rights ethos by confiscating coins from holders who may be unable to migrate (deceased holders, lost keys, long-term cold storage without monitoring). No coordinating body exists to mandate or accelerate a Bitcoin-wide upgrade. Bitcoin advocate Nic Carter stated: "Elliptic curve cryptography is on the brink of obsolescence. Whether it's 3 or 10 years, it's over."
The governance challenge is structural. Bitcoin has no foundation, no funded research team, and no formal roadmap. Migration depends entirely on voluntary miner and node operator adoption of soft-fork proposals.
The Ethereum Foundation took a different approach by creating a dedicated Post-Quantum Security team in January 2026, led by Thomas Coratger. The team is developing leanVM, specialized software designed to compress multiple post-quantum cryptographic approvals into a single blockchain-compatible proof.
"Quantum computing is moving from theory into engineering. That changes the timeline, and it means we need to prepare," Coratger stated.
The core technical challenge: Ethereum's current system efficiently bundles thousands of validator attestations using BLS signatures. Post-quantum alternatives (lattice-based or hash-based schemes) produce significantly larger signatures — ranging from 1,300 bytes (Falcon) to 8,000+ bytes (SPHINCS+) — versus 48 bytes for BLS. At Ethereum's scale of approximately 1 million active validators, the bandwidth and storage implications are substantial.
Ethereum's roadmap includes:
Solana's two core developer teams — Anza and Jump Crypto's Firedancer — aligned in April 2026 on adopting Falcon, a NIST-standardized lattice-based signature scheme, as the primary post-quantum primitive.
Solana's challenge is architectural. The network processes approximately 4,000 transactions per second with sub-400ms finality. Falcon signatures are roughly 5x larger than Ed25519 signatures currently used. Early internal testing confirmed that integrating PQ signatures adds measurable latency to transaction processing.
The Solana Foundation's position: "Any eventual migration would be manageable and unlikely to significantly impact performance." The migration strategy is phased — new wallets first, existing wallets later.
An existing quantum-resistant prototype, Blueshift's "Winternitz Vault," has operated on Solana for over two years using hash-based one-time signatures. Google Quantum AI has cited this implementation.
| Factor | Bitcoin | Ethereum | Solana | |--------|---------|----------|--------| | Coordinating body | None | Ethereum Foundation | Solana Foundation | | Dedicated PQ team | No | Yes (Jan 2026) | Aligned developer teams | | PQ signature scheme | P2MR (BIP-360, custom) | Under evaluation (Falcon, SPHINCS+) | Falcon | | Testnet implementation | Yes (BTQ Technologies) | In development | Winternitz Vault live 2+ years | | Governance mechanism | Soft fork (voluntary) | Hard fork (coordinated) | Validator upgrade | | Target completion | No formal date | ~2029 | No formal date | | Legacy asset risk | ~6.9M BTC ($500B) exposed | All pre-migration accounts | All pre-migration accounts | | Key challenge | No coordinating authority | Signature size at validator scale | Latency impact on throughput |
Project Eleven estimates over $3 trillion in digital assets globally are secured by elliptic curve cryptography vulnerable to quantum attack. The exposure breaks down unevenly:
Bitcoin: 34% of total supply (~6.9M BTC) has exposed public keys on-chain. This includes approximately 1.7 million BTC in legacy P2PK scripts from 2009–2010. Migration requires individual wallet holder action — no protocol-level forced migration exists without BIP-361.
Ethereum: Every account that has ever sent a transaction has its public key exposed. However, Ethereum's account-based model and planned account abstraction (EIP-8141) offer a cleaner migration path than Bitcoin's UTXO model.
Solana: All accounts using Ed25519 signatures expose public keys. Solana's smaller total value locked (~$8B in DeFi) represents lower absolute economic risk but identical cryptographic vulnerability.
The asymmetry matters: Bitcoin carries the largest dollar-denominated exposure, the slowest governance mechanism, and the most contentious proposed solution. Ethereum has the most structured response. Solana has the earliest live prototype but faces the steepest performance tradeoff.
NIST finalized three post-quantum cryptography standards in August 2024 — ML-KEM, ML-DSA, and SLH-DSA — providing the foundational algorithms. Canada mandated PQC compliance for government systems starting April 2026. Google set a 2029 deadline for its own authentication services. The blockchain industry has no equivalent mandate.
The convergence of three developments in 2026 — federal quantum investment at scale, dramatically reduced qubit-threshold estimates, and a live proof-of-concept ECC break on public hardware — has shifted the quantum threat to blockchain cryptography from theoretical to operational planning. The question is no longer whether post-quantum migration is necessary but whether decentralized networks can execute it faster than quantum hardware matures.
Bitcoin faces the sharpest governance challenge: its $500 billion quantum-vulnerable exposure cannot be addressed without either voluntary mass migration by millions of individual holders or a contentious consensus change that would freeze unmigrated coins. Ethereum's centralized research capacity provides faster response capability but introduces its own trust assumptions. Solana's early prototyping offers technical proof but has not resolved the fundamental tension between quantum-resistant signature sizes and high-throughput architecture.
The data suggests that the blockchain industry is approximately 3–7 years away from a credible quantum threat and approximately 3–10 years away from completing the infrastructure changes needed to survive it. The overlap in those ranges defines the risk.