Six major blockchain networks have published post-quantum cryptography (PQC) migration roadmaps in the past 90 days, triggered by a March 2026 Google Quantum AI paper that slashed the estimated resource cost of breaking elliptic-curve cryptography (ECC-256) by 20x. The paper showed that fewer tha...
"Waiting for it to be urgent is not a good idea." — Coinbase Quantum Advisory Board, Position Paper (April 2026)
Six major blockchain networks have published post-quantum cryptography (PQC) migration roadmaps in the past 90 days, triggered by a March 2026 Google Quantum AI paper that slashed the estimated resource cost of breaking elliptic-curve cryptography (ECC-256) by 20x. The paper showed that fewer than 500,000 physical qubits — down from the team's own 2019 estimate of 20 million — could attack the signature scheme underpinning Bitcoin, Ethereum, Solana, and most other chains. On current hardware trajectories, that threshold may be reachable in the early 2030s.
The stakes are measured in exposed keys. Project Eleven estimates approximately 6.9 million BTC — roughly one-third of total supply, including Satoshi Nakamoto's estimated 1 million BTC — sit in addresses with public keys already visible on-chain, making them the first targets of any cryptographically relevant quantum computer (CRQC). Each network is now racing to deploy NIST-approved signature schemes (FIPS 203, 204, 205), but the migrations differ sharply in complexity, timeline, and performance cost. This report compares the approaches of Bitcoin, Ethereum, Solana, Algorand, NEAR Protocol, and the XRP Ledger.
Google Quantum AI's March 31, 2026 paper compiled two attack circuits against ECC-256: one requiring 1,200 logical qubits and 90 million Toffoli gates, and another requiring 1,450 logical qubits and 70 million Toffoli gates. On a superconducting architecture, the attack could execute in approximately nine minutes using fewer than 500,000 physical qubits.
Current hardware is not there yet. Google's Willow chip operates at 105 qubits. IBM's largest production processor, Heron r3, runs at 156 qubits. IBM's roadmap targets a 4,158-qubit multi-chip system (Kookaburra) by late 2026, and its first fault-tolerant machine by 2029. Atom Computing's 1,225-qubit neutral-atom system represents the current commercial high-water mark. The gap between today's ~1,000-qubit noisy machines and the ~500,000 physical qubits needed for the ECC-256 attack remains large, but the trajectory has accelerated.
A separate milestone arrived in April 2026: an independent researcher broke a 15-bit elliptic-curve key on publicly accessible quantum hardware, winning Project Eleven's Q-Day Prize of 1 BTC. The key size is trivial relative to the 256-bit keys securing live blockchains, but the demonstration confirmed that quantum attacks on elliptic curves are no longer theoretical.
A 50-page Coinbase advisory board report, authored by Stanford's Dan Boneh, Ethereum Foundation's Justin Drake, and Eigen Labs' Sreeram Kannan, concluded in April 2026 that a CRQC is "at least two major engineering leaps away" but that blockchain migrations will themselves take years, making early preparation essential.
The core technical constraint is data bloat. A standard ECDSA signature used in Bitcoin or Ethereum transactions is 64 bytes. The NIST-approved alternatives are substantially larger:
| Scheme | Standard | Signature Size | Public Key Size | |--------|----------|---------------|-----------------| | ECDSA (current) | — | 64 bytes | 33 bytes | | ML-DSA (Dilithium) | FIPS 204 | ~2,420 bytes | ~1,312 bytes | | FN-DSA (Falcon) | FIPS 206 (draft) | ~666 bytes | ~897 bytes | | SLH-DSA (SPHINCS+) | FIPS 205 | ~7,856 bytes | 32 bytes | | leanXMSS (hash-based) | — | ~2,500+ bytes | varies |
ML-DSA signatures are 38x larger than ECDSA. Falcon signatures are roughly 10x larger. Hash-based schemes like SPHINCS+ run to 17,000 bytes or more in some configurations. For networks processing millions of transactions daily, the bandwidth, storage, and throughput implications are non-trivial. This is the central engineering challenge driving divergent migration strategies.
Bitcoin's approach centers on BIP-360, a proposal for a new output type called Pay-to-Merkle-Root (P2MR), authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke. P2MR retains nearly all Taproot (P2TR) functionality but removes the quantum-vulnerable keypath spend.
In March 2026, BTQ Technologies released Bitcoin Quantum testnet v0.3.0 with the first working BIP-360 implementation, including SegWit version 2 outputs and five Dilithium post-quantum signature opcodes in tapscript context. A companion proposal, BIP-361, addresses migration mechanics and legacy signature sunset timelines.
The BIP-360 co-author has publicly stated that Bitcoin may require seven years to complete the upgrade — a timeline that reflects Bitcoin's conservative governance model, the requirement for broad node operator adoption, and the contentious question of what happens to coins in quantum-vulnerable addresses whose owners never migrate. A related proposal from Paradigm, called PACTs (Post-quantum Algebraic Commitment Transactions), published on May 2, 2026, offers Satoshi Nakamoto a mechanism to prove control of early coins without moving them, but it does not solve the migration problem for the broader ecosystem.
The exposed surface is large. Approximately 6.9 million BTC sit in addresses with on-chain public keys, including all Taproot-spent coins (post-2021) and legacy P2PK outputs from Bitcoin's earliest years.
Vitalik Buterin published Ethereum's quantum-resistance roadmap in February 2026, identifying four vulnerability surfaces: validator consensus signatures (currently BLS), the data availability sampling system, user wallet transaction signatures, and certain proof systems used in rollups.
The plan proposes replacing BLS validator signatures with leanXMSS, a hash-based signature scheme. Hash-based signatures derive their security from hash functions alone, which quantum computers weaken but do not fully break. For user wallets, EIP-8141 would enable accounts to switch signature schemes without changing addresses — a critical feature for backwards compatibility.
Buterin's "Strawmap" envisions approximately seven hard forks over four years, with the first two — Glamsterdam and Hegotá — confirmed for 2026. The plan also depends on SNARK-based signature aggregation to manage the larger data footprint of post-quantum signatures at the consensus layer. Without aggregation, Ethereum's beacon chain would face substantial bandwidth increases from validator attestations alone.
Ethereum's approach is the most architecturally ambitious: it requires coordinated changes across both the execution layer and the consensus layer, plus downstream rollup and wallet ecosystem adaptation.
Solana's two core development teams — Anza and Jump Crypto's Firedancer — independently converged on NIST's Falcon signature scheme. Both teams have published initial implementations on GitHub. The Solana Foundation outlined a phased roadmap on April 27, 2026: continued Falcon research, introduction of post-quantum schemes for new wallets, and eventual migration of existing wallets.
Solana faces a specific performance tension. The network's value proposition rests on high throughput and low latency. Falcon signatures, at ~666 bytes, are 10x larger than Ed25519's 64-byte signatures — the smallest quantum-resistant option, but still a meaningful increase for a network processing thousands of transactions per second. A CoinDesk analysis from April 4, 2026 described this as a "harsh tradeoff: security vs. speed."
The Foundation has stated that migration is "well-researched, understood, and ready to deploy" but that no immediate changes are planned because "quantum is still years away." Blueshift's Winternitz Vault, a quantum-resistant primitive, has been live on Solana for over two years and was cited in Google Quantum AI's March paper.
Algorand executed the first post-quantum transaction on a public blockchain mainnet in November 2025, using NIST-selected Falcon signatures. As of May 2026, over 140,000 quantum-resistant transactions have been processed on Algorand's mainnet.
The Coinbase Quantum Advisory Board's April 2026 report named Algorand and Aptos the "most quantum-prepared layer-1 blockchains." Algorand's advantage stems from its early adoption of the FN-DSA (Falcon) standard and a protocol architecture that accommodated larger signature sizes from inception.
Algorand's approach provides a live proof-of-concept that post-quantum signatures can function on a production blockchain without breaking performance. However, Algorand's transaction throughput (approximately 6,000 TPS) and validator set are substantially smaller than Bitcoin's or Ethereum's, limiting the direct comparability of the migration challenge.
NEAR Protocol announced on May 7, 2026 that it will integrate FIPS-204 (ML-DSA) as its first post-quantum signing option, with co-founder Illia Polosukhin confirming a Q2 2026 rollout to testnet. The announcement drove a 14.25% price increase, with trading volume surging 180.59% to $471.8 million.
NEAR's architectural advantage is structural. Its account model treats accounts as containers holding rotatable access keys, decoupled from any single keypair. Migration to a quantum-safe signing standard requires one transaction per user — not a protocol-level fork. This contrasts with Bitcoin and Ethereum, where the migration requires consensus-layer changes affecting every node.
Near One is extending quantum-safe Chain Signatures to 35+ external chains through NEAR's cross-chain infrastructure. The Defuse team is separately integrating quantum-safe Chain Signatures into NEAR Intents, the cross-chain swap protocol. If completed, this would position NEAR as a quantum-safe signing proxy for assets originating on chains that have not yet migrated.
The downstream challenge remains: wallets, APIs, hardware devices, and user workflows must all accommodate ML-DSA's larger key and signature sizes. Near One is coordinating with Ledger and other hardware wallet manufacturers.
Ripple published a four-phase post-quantum roadmap for the XRP Ledger on April 21, 2026:
XRPL's protocol-native key rotation allows users to migrate from vulnerable keys without abandoning accounts — a feature shared with NEAR but absent from Bitcoin's UTXO model.
| Network | Scheme | Status | Migration Complexity | Target Date | Mainnet PQC Txns | |---------|--------|--------|---------------------|-------------|-----------------| | Bitcoin | ML-DSA (BIP-360) | Testnet v0.3.0 | Hard fork required | ~2033 | 0 | | Ethereum | leanXMSS + EIP-8141 | Roadmap published | ~7 hard forks | ~2030 | 0 | | Solana | Falcon | Initial implementation | Phased, no date set | TBD | 0 | | Algorand | Falcon | Live on mainnet | Completed | Done (Nov 2025) | 140,000+ | | NEAR | ML-DSA (FIPS 204) | Q2 2026 testnet | One txn per account | Q2-Q3 2026 | 0 | | XRPL | TBD (NIST candidates) | Phase 2 testing | Network amendment | 2028 | 0 |
Google's March 2026 paper reduced the estimated quantum attack threshold on ECC-256 by 20x to fewer than 500,000 physical qubits, compressing the industry's preparation window.
Algorand is the only network with live post-quantum transactions on mainnet — 140,000+ as of May 2026 — using NIST-selected Falcon signatures.
NEAR's account-key architecture enables per-user migration in a single transaction, avoiding the protocol-level forks required by Bitcoin and Ethereum.
Bitcoin faces the longest migration timeline (~7 years per BIP-360 co-author), complicated by 6.9 million BTC in addresses with exposed public keys.
Ethereum's plan is the most complex, requiring coordinated changes across consensus, execution, rollup, and wallet layers over approximately seven hard forks.
Post-quantum signatures are 10x to 38x larger than current ECDSA/Ed25519 signatures, creating bandwidth and storage costs that disproportionately affect high-throughput chains.
No quantum computer currently exists that can attack live blockchain cryptography. The largest commercial system operates at ~1,225 qubits; the attack requires ~500,000 physical qubits.
The blockchain industry's post-quantum migration is now a live engineering project, not a theoretical discussion. Six networks have published concrete timelines, one has production transactions, and a Coinbase-commissioned panel of leading cryptographers has called for immediate action. The divergence in approaches — from Bitcoin's multi-year consensus process to NEAR's single-transaction key rotation — reflects fundamental architectural differences that will determine which networks can adapt fastest when quantum capability arrives. The data suggests that account-model chains with native key rotation hold a structural advantage over UTXO-based systems in migration speed. Whether that advantage proves decisive depends on a variable no protocol can control: when the first CRQC comes online.