Google's March 2026 whitepaper reduced the estimated quantum resources needed to break 256-bit elliptic curve cryptography by 20x, to fewer than 500,000 physical qubits. The revised estimate places the cryptographically relevant quantum computer (CRQC) arrival window between 2030 and 2033, accord...
"The distributed nature of blockchain networks means that migration to post-quantum cryptography may take the better part of a decade, longer than other centralized systems." — Alex Pruden, CEO, Project Eleven
Google's March 2026 whitepaper reduced the estimated quantum resources needed to break 256-bit elliptic curve cryptography by 20x, to fewer than 500,000 physical qubits. The revised estimate places the cryptographically relevant quantum computer (CRQC) arrival window between 2030 and 2033, according to consensus modeling by Project Eleven, Citi, and NIST. Three major blockchain ecosystems — Bitcoin, Ethereum, and Solana — are now pursuing structurally different migration strategies to post-quantum cryptography (PQC), each reflecting their governance models, technical constraints, and economic incentives.
Citi's May 2026 research identifies 6–7 million BTC ($350–500 billion) in addresses with exposed public keys. The Ethereum Foundation launched pq.ethereum.org with 10+ client teams running weekly PQC devnets. Solana adopted Falcon signatures in April 2026 with both Anza and Firedancer teams independently converging on the same scheme. The quantum-resistant token sector surpassed $9 billion in market capitalization by June 2026, up approximately 50% since Google's disclosure.
Three research papers published between January and March 2026 compressed the quantum threat timeline. Google Quantum AI's March 31 paper demonstrated that Shor's algorithm adapted for ECDLP-256 could theoretically execute with approximately 1,200 logical qubits and 90 million Toffoli gate operations. An alternative circuit configuration uses 1,450 logical qubits and 70 million Toffoli gates. Both represent a 20-fold reduction in required physical qubits compared to 2019 estimates.
The paper models a real-time transaction hijacking attack with a 41% success rate against Bitcoin's 10-minute block confirmation window. Google has set a 2029 internal deadline for migrating its own infrastructure to post-quantum cryptography — one of the most aggressive timelines publicly stated by a major technology firm.
NIST anticipates deprecating ECDSA by 2030 and disallowing it entirely by 2035. Project Eleven's baseline model places "Q-Day" — the date a quantum computer can break secp256k1 in operationally useful timeframes — at 2033, with optimistic and pessimistic bounds at 2030 and 2042.
In April 2026, Project Eleven awarded its 1 BTC Q-Day Prize to researcher Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible quantum hardware. The attack remains far from Bitcoin's 256-bit security, but demonstrates that the attack class is advancing on real hardware, not just in simulation.
CoinDesk reported in May 2026 that AI is accelerating quantum threat timelines by optimizing quantum error correction — one of the field's primary engineering bottlenecks. The "harvest now, decrypt later" strategy, in which state actors stockpile encrypted traffic for future decryption, adds urgency for systems where public keys are permanently visible on-chain.
Bitcoin's migration plan consists of two proposals. BIP-360, published and merged into Bitcoin's official repository on February 11, 2026, introduces Pay-to-Merkle-Root (P2MR), the network's first quantum-resistant output type. BTQ Technologies deployed BIP-360 on Bitcoin Quantum testnet v0.3.0 in March 2026, with 50+ miners, over 100,000 blocks mined, and complete wallet RPC support enabling users to create, fund, sign, and spend P2MR transactions.
BIP-361, titled "Post Quantum Migration and Legacy Signature Sunset," published April 14, 2026, addresses the harder problem: the estimated 6–7 million BTC already sitting in quantum-vulnerable addresses. The proposal outlines a three-phase soft fork:
Neither BIP has reached the adoption threshold for a soft fork. Citi's May 2026 report identifies Bitcoin's slow governance process as its primary quantum vulnerability relative to other chains. Bitcoin's deliberate consensus-seeking model, which took years to activate Taproot, faces a category of threat where speed of adaptation determines survival of economic value.
Project Eleven's CEO stated at Consensus Miami in May 2026 that Bitcoin's post-quantum migration "will be harder than Taproot and needs to start now." The firm's 110-page report argues it may already be too late for an orderly migration given Bitcoin's governance cadence.
Ethereum's strategy differs structurally from Bitcoin's. Rather than a single protocol-wide signature migration, Ethereum plans to use native account abstraction (EIP-8141) to give individual accounts signature agility. Users could switch to quantum-safe signatures without waiting for global protocol changes.
In February 2026, Vitalik Buterin published a roadmap identifying four cryptographic components requiring post-quantum upgrades:
The Ethereum Foundation launched pq.ethereum.org as a central coordination hub, with more than 10 client teams running weekly post-quantum interoperability devnets. EIP-8141 is under consideration for the Hegotá hard fork in H2 2026, with a full L1 target of 2029.
A near-term solution already exists: Ethereum researchers demonstrated in June 2026 that accounts can begin preparing for a post-quantum world today at a cost of approximately $0.07 per account, using existing smart contract infrastructure. This opt-in approach contrasts with Bitcoin's all-or-nothing migration timeline.
The Ethereum Foundation's $30 million funding gap (reported separately) could slow execution, though the multi-client architecture means progress does not depend on a single entity.
Solana's approach prioritizes preserving its low-latency execution profile. In April 2026, the Solana Foundation announced adoption of Falcon, a NIST-approved lattice-based signature scheme, after both Anza and Jump Crypto's Firedancer team independently identified it as the optimal choice.
Falcon was selected because it balances security and efficiency in a way that fits Solana's performance requirements. The Foundation completed an initial implementation requiring no protocol-level changes. The roadmap includes:
Solana had previously introduced a quantum-resistant vault in January 2025 using hash-based WOTS (Winternitz One-Time Signatures) that generate a new cryptographic key per transaction. Early tests confirmed performance tradeoffs, but Falcon's smaller signature sizes make it more compatible with Solana's throughput goals.
The convergence of Anza and Firedancer on the same scheme — independently — provides confidence in the technical direction. If end-to-end Dilithium support in Solana Pay arrives before December 2026, Solana would demonstrate that high-performance chains can harden for quantum threats without sacrificing speed.
Algorand provides the only live production benchmark for post-quantum blockchain transactions. On November 3, 2025, the chain executed the first mainnet transaction signed with NIST-selected Falcon-1024 signatures — a global first for public blockchains.
By early 2026, over 140,000 quantum-resistant transactions had been recorded on Algorand's mainnet. State proofs are already generated every 256 rounds secured by Falcon. The roadmap extends through 2026:
Algorand's implementation demonstrates feasibility but also illustrates the scale gap: 140,000 PQC transactions vs. billions of legacy transactions across major chains. The transition economics favor chains that started with PQC in mind over those retrofitting it.
| Dimension | Bitcoin | Ethereum | Solana | Algorand | |-----------|---------|----------|--------|----------| | PQC Scheme | SHRIMPS/P2MR (BIP-360) | Dilithium + Falcon (multi-component) | Falcon | Falcon-1024 | | Governance Model | BIP + miner/node consensus | EIP + client team coordination | Foundation-directed | Foundation-directed | | Migration Status | Testnet (v0.3.0) | Weekly PQC devnets | Initial implementation complete | 140K+ mainnet transactions | | Estimated Full Migration | 5–8 years post-activation | 2029 (L1 target) | TBD (phased) | Q4 2026 (native accounts) | | Value at Risk | $350–500B (6–7M BTC exposed) | Lower (address reuse less common) | Moderate (Ed25519 keys) | Minimal (early PQC adoption) | | Key Constraint | Governance speed | Multi-component complexity | Performance preservation | Scale/adoption |
Citi's May 2026 report and multiple independent analyses converge on a consistent picture of quantum-era economic exposure:
The "harvest now, decrypt later" risk is structurally different for blockchains than for traditional systems: all transaction data is permanently public. There is no corporate network boundary to breach. Every exposed public key is already "harvested" by default.
The quantum threat to blockchain cryptography has moved from theoretical to engineering-constrained. The question is no longer whether post-quantum migration is necessary but whether decentralized governance models can execute migrations at the pace the threat demands.
Bitcoin's exposure is largest in absolute terms and its governance model is slowest by design. Ethereum's modular approach provides more migration pathways but requires coordinated upgrades across four distinct cryptographic systems. Solana's centralized foundation model enables faster decision-making but the chain has yet to commit to a binding timeline. Algorand provides proof of concept at small scale.
The economic value framework for evaluating these approaches is straightforward: chains that complete PQC migration before Q-Day protect their holders' economic value; chains that do not risk permanent loss. The timeline differential between Google's 2029 internal deadline and Bitcoin's potential 5–8 year migration window represents the core vulnerability. Whether BIP-361's proposed coin-freezing mechanism activates before or after a quantum attack determines whether billions in legacy bitcoin survive the transition or become permanently stranded.