The quantum clock is ticking — and for the first time, blockchain's biggest protocols are acting like it. On February 19, 2026, the inaugural Quantum Summit at ETHDenver convened cryptographers, protocol engineers, and institutional stakeholders for the industry's first dedicated reckoning with p...
"Elliptic curves are going to die." — Vitalik Buterin, Co-Founder, Ethereum
The quantum clock is ticking — and for the first time, blockchain's biggest protocols are acting like it. On February 19, 2026, the inaugural Quantum Summit at ETHDenver convened cryptographers, protocol engineers, and institutional stakeholders for the industry's first dedicated reckoning with post-quantum cryptography (PQC). Days earlier, BIP 360 was formally merged into Bitcoin's official improvement proposal repository. Ethereum's Foundation has committed $2 million to a dedicated post-quantum team. Solana has demonstrated quantum-resistant signatures at full throughput on testnet.
This is no longer a theoretical exercise. With Google's Willow chip hitting 105 qubits, NIST finalizing three PQC standards, and the U.S. National Security Agency mandating quantum-safe systems by 2030, the question has shifted from whether blockchains must upgrade their cryptographic foundations to which protocols will finish first — and what happens to those that don't.
This comparative analysis examines how the three largest smart-contract ecosystems — Bitcoin, Ethereum, and Solana — are approaching the post-quantum migration, evaluates the economic assets at risk, and assesses whether the industry's current pace matches the threat timeline.
Every major blockchain relies on elliptic curve cryptography (ECC) — specifically ECDSA for Bitcoin and Ed25519 for Ethereum and Solana — to generate the public-private key pairs that secure wallets and sign transactions. A sufficiently powerful quantum computer running Shor's algorithm could derive private keys from exposed public keys, enabling theft of funds from any address whose public key is visible on-chain.
This is not a brute-force attack on hashing. SHA-256 and Keccak-256, used in mining and state commitments, face only a quadratic speedup from Grover's algorithm — manageable by doubling key lengths. The existential threat is to digital signatures specifically.
Today's quantum hardware is nowhere near capable. Google's Willow processor operates at 105 qubits. University of Sussex researchers estimate that breaking Bitcoin's ECDSA encryption in a single day would require approximately 13 million qubits. But the trajectory of error correction and qubit scaling — Willow demonstrated below-threshold quantum error correction for the first time — means the gap is closing faster than linear extrapolation suggests.
"Q-Day" — the moment a quantum computer can break production-grade elliptic curve cryptography — remains the subject of fierce debate. The estimates span a wide range:
What unifies all timelines is the "harvest now, decrypt later" risk. Nation-state adversaries are already cataloguing encrypted blockchain traffic today, banking on future quantum capability to decrypt it. The NSA's CNSA 2.0 framework mandates quantum-safe federal systems by 2030. NIST plans to deprecate elliptic curve cryptography in federal systems by the mid-2030s.
For blockchains, the migration window is not Q-Day minus today. It is Q-Day minus the years required to achieve consensus, test, deploy, and migrate billions in assets to new cryptographic schemes.
Status: Proposal merged into BIP repository. No activation timeline.
BIP 360 introduces Pay-to-Merkle-Root (P2MR), a new output type designed to support quantum-resistant script trees while maintaining backward compatibility with existing Tapscript infrastructure. The proposal disables key-path spending and commits only to the script path, eliminating the attack surface where public keys are directly exposed.
The technical design is sound. The coordination challenge is immense. Bitcoin's governance model — deliberately slow, consensus-driven, and resistant to top-down directives — means BIP 360 faces years of review, testing, and political negotiation before activation.
Key challenge: An estimated 1.6 million BTC sits in legacy P2PK (pay-to-public-key) addresses where public keys are permanently exposed on-chain. CoinShares' February 2026 analysis argues only about 10,200 BTC in these addresses is large enough to create "appreciable market disruption" if stolen. But a separate Chaincode Labs study estimates 20–50% of circulating Bitcoin addresses may be vulnerable due to reused public keys, representing roughly 6.26 million BTC — between $650 billion and $750 billion in exposure.
The discrepancy matters. It reflects a deeper uncertainty about how many users will actually migrate to quantum-safe address formats voluntarily — and what happens to dormant coins in Satoshi-era wallets that cannot be moved.
Status: Dedicated PQ team formed. Multi-client devnets running. Roadmap forthcoming.
In January 2026, the Ethereum Foundation elevated post-quantum security to a top strategic priority, forming a dedicated team led by cryptographic engineer Thomas Coratger with $2 million in funding. The allocation breaks into two initiatives: a $1 million Poseidon Prize targeting the Poseidon hash function used in zero-knowledge proof systems, and a $1 million program focused on post-quantum cryptographic proximity problems.
Multiple teams — Zeam, Ream Labs, PierTwo, Gean client, and Ethlambda — are already collaborating with established consensus clients Lighthouse, Grandine, and Prysm on multi-client post-quantum development networks.
Buterin has framed the goal as passing a "walkaway test": the protocol must remain safe and functional indefinitely, even if core developers stop shipping upgrades. This philosophical commitment to long-term cryptographic durability aligns with Ethereum's broader roadmap emphasis on protocol ossification.
Key advantage: Ethereum's account-based model and active upgrade governance (hard forks via EIPs) make migration mechanically simpler than Bitcoin's UTXO model. The Foundation can coordinate client teams directly.
Key risk: Ethereum's complexity — smart contracts, ERC-20 tokens, DeFi protocols, Layer 2 rollups — means the migration surface area is vastly larger. Every contract storing value with ECDSA-signed authorizations needs upgrading or wrapping.
Status: Quantum-resistant signatures tested on public testnet at full throughput.
Solana may be the furthest along operationally. In December 2025, the Solana Foundation partnered with security firm Project Eleven to open a public testnet replacing every Ed25519 signature with CRYSTALS-Dilithium, a NIST-approved lattice-based scheme (FIPS 204). Benchmarks on that network held approximately 3,000 transactions per second — matching Solana's mainnet throughput — demonstrating that larger post-quantum keys do not necessarily degrade performance.
The rollout plan is staged: high-value wallets can already create dual keypairs (Ed25519 plus Dilithium) in developer builds of Phantom and Ledger. Validators will opt in on mainnet-beta, while Firedancer — the Jump Crypto client shipping in 2026 — already supports multiple signature backends, ensuring consensus does not depend on a single codebase.
Key advantage: Solana's validator-coordinated governance and relatively young address space (no legacy P2PK equivalent) make migration logistically simpler. The chain has fewer years of dormant, unmovable coins.
Key target: End-to-end Dilithium support in Solana Pay before December 2026, which would make Solana the first major chain with production quantum-resistant payments.
| Dimension | Bitcoin | Ethereum | Solana | |---|---|---|---| | PQC Proposal | BIP 360 (P2MR) | Multi-client devnets | CRYSTALS-Dilithium testnet | | Stage | Proposal merged | R&D / devnet | Public testnet | | Dedicated Funding | Community-driven | $2M (Ethereum Foundation) | Foundation + Project Eleven | | Governance Speed | Slow (BIP consensus) | Moderate (EIP hard forks) | Fast (validator vote) | | Legacy Exposure | 1.6M–6.26M BTC in vulnerable addresses | All ECDSA accounts + smart contracts | Minimal (young chain) | | Throughput Impact | Unknown (no testnet) | Under evaluation | None demonstrated (3K TPS maintained) | | Target Timeline | No activation date | Multi-year transition | December 2026 (Solana Pay) |
The quantum threat is not equally distributed across chains.
Bitcoin carries the heaviest legacy burden. CoinShares' conservative estimate identifies 1.6 million BTC (approximately $160 billion at current prices) in P2PK addresses with permanently exposed public keys. Chaincode Labs' upper-bound estimate — 6.26 million BTC — would represent over $600 billion. Even the conservative figure exceeds the total value locked in all of DeFi.
Ethereum's exposure is more diffuse but potentially larger in aggregate. Every externally-owned account (EOA) that has ever sent a transaction has its public key exposed in the transaction signature. The entire DeFi stack — $90+ billion in TVL across lending protocols, AMMs, and bridges — relies on ECDSA-signed approvals.
Solana's exposure is structurally lower. The chain launched in 2020, has no legacy address format with permanently exposed keys, and its address space is dominated by active wallets that can be migrated.
The asymmetry is stark: the oldest, most valuable chains face the largest migration challenges, while newer chains can move faster precisely because they have less to protect.
The quantum threat timeline has compressed. Metaculus moved its estimate from 2052 to 2034. The NSA mandates quantum-safe federal systems by 2030. The blockchain industry's migration window is shorter than most participants realize.
All three major ecosystems are now actively building PQC solutions, but at dramatically different speeds. Solana has demonstrated production-equivalent throughput with quantum-resistant signatures. Bitcoin has not yet tested its proposal on any network.
Legacy exposure creates an unequal risk distribution. Bitcoin's P2PK addresses represent a permanent, unmovable vulnerability. Ethereum's smart contract surface area creates migration complexity no other chain faces. Solana's youth is, paradoxically, its greatest security advantage.
The "harvest now, decrypt later" threat is already active. Nation-states cataloguing on-chain transactions today can retroactively break privacy and steal funds once quantum capability arrives. This makes the threat timeline effectively now, not Q-Day.
Governance speed is the binding constraint. The cryptographic solutions exist (NIST finalized three PQC standards in 2024). The bottleneck is coordination: achieving consensus to deploy them across decentralized networks with billions in live assets.
The inaugural Quantum Summit at ETHDenver marks a symbolic inflection point: the blockchain industry's transition from quantum denial to quantum preparation. But symbolism does not equal readiness. Of the three major ecosystems, only Solana has demonstrated quantum-resistant operations at production scale. Ethereum has committed institutional resources and formed dedicated teams. Bitcoin — the chain with the most to lose — remains in the proposal stage, constrained by the same deliberate governance that makes it resilient to hasty changes.
The irony is structural. Bitcoin's conservative governance, its greatest defense against human-initiated attacks, may prove its greatest vulnerability against a computational one. The protocols that move fastest to adopt post-quantum cryptography will not just protect their users — they will capture the narrative of cryptographic leadership at a moment when institutional capital is actively evaluating which chains are built to last beyond the current cryptographic epoch.
The migration is not optional. The only variable is whether it happens proactively or in crisis.