Google Quantum AI published a whitepaper on March 31, 2026, concluding that breaking ECDSA-256 — the signature scheme securing Bitcoin, Ethereum, and most major blockchains — could require fewer than 500,000 physical qubits, a 20x reduction from 2019 estimates. The finding compressed what the ind...
"The quantum threat is no longer a drill. Our research shows breaking elliptic-curve cryptography could require 20 times fewer quantum resources than estimated in 2019." — Craig Gidney, Google Quantum AI Researcher
Google Quantum AI published a whitepaper on March 31, 2026, concluding that breaking ECDSA-256 — the signature scheme securing Bitcoin, Ethereum, and most major blockchains — could require fewer than 500,000 physical qubits, a 20x reduction from 2019 estimates. The finding compressed what the industry assumed was a 15-to-20-year runway into a plausible 3-to-7-year window. IBM's Starling roadmap targets 200 logical qubits by 2029. Citi Institute's January 2026 report estimated a quantum-enabled cyberattack on U.S. financial infrastructure could put $2.0–$3.3 trillion of GDP at risk.
The blockchain industry responded with a burst of post-quantum cryptography (PQC) activity across Q1–Q2 2026. BNB Chain published live testnet results on May 14 showing ML-DSA-44 signatures cut throughput by 40–50%. Ethereum Foundation launched pq.ethereum.org with $2 million in prize funding and 10+ client teams running weekly PQC devnets. Solana's Anza and Firedancer teams converged on Falcon signatures. Bitcoin developers shipped BIP-360 and BIP-361, the first concrete proposals to address ~6.9 million BTC ($483 billion) sitting in wallets with exposed public keys. NEAR deployed FIPS-204 key support. TRON announced — but has not yet documented — a mainnet PQC initiative.
This report compares the post-quantum migration strategies of six major blockchain networks across four dimensions: timeline, technical approach, performance cost, and governance readiness.
On March 31, 2026, Google's Quantum AI team published research demonstrating that the resource requirements to break elliptic-curve cryptography had fallen to fewer than 500,000 physical qubits — roughly 20x less than the team's own 2019 estimate. The paper modeled a real-time transaction hijacking attack against Bitcoin with a 41% success rate within a 10-minute block confirmation window.
No quantum computer currently exists at this scale. IBM's most advanced roadmap targets 200 logical qubits (Starling processor) by 2029. However, the compressed timeline reframed the threat from theoretical to operational planning. According to prediction market data cited by Citi Institute, 39% of experts now expect a "useful" quantum computer by 2030, up from single digits just two years prior. The Global Risk Institute places the probability of quantum computers breaking public-key encryption at 19–34% by 2034, rising to 60–82% by 2044.
NIST finalized three post-quantum cryptographic standards in August 2024: ML-KEM (key encapsulation), ML-DSA (digital signatures, derived from CRYSTALS-Dilithium), and SLH-DSA (stateless hash-based signatures). The CNSA 2.0 deadline requires U.S. National Security Systems to begin transitioning by January 2027. NIST's broader mandate calls for phasing out quantum-vulnerable algorithms by 2030 and disallowing them entirely by 2035.
| Network | PQC Scheme | Status (May 2026) | Signature Size | Performance Impact | Governance Model | |---------|------------|-------------------|----------------|-------------------|------------------| | Bitcoin | SHRIMPS/P2MR (BIP-360/361) | Draft BIP, testnet | Varies by scheme | Not yet benchmarked | Soft fork required; consensus-heavy | | Ethereum | leanXMSS + EIP-8141 (AA) | Weekly PQC devnets, $2M prizes | ~2.5 KB per sig | 250x compression via leanVM | Foundation-coordinated, multi-client | | BNB Chain | ML-DSA-44 + pqSTARK | Live testnet (May 14) | 2,420 bytes (sig), 1,312 bytes (pubkey) | 40–50% TPS reduction | Centralized; BNB Chain core team | | Solana | Falcon (FN-DSA) | Anza + Firedancer prototyping | ~690 bytes (Falcon-512) | Manageable per Foundation | Foundation-coordinated, two-client | | NEAR | ML-DSA (FIPS-204) | Testnet Q2 2026 | Standard ML-DSA sizes | Not yet disclosed | NearOne-led, account-model advantage | | TRON | Unspecified (announced) | Announcement only (Apr 15) | N/A | N/A | Justin Sun announcement; no TDP filed |
The central engineering challenge of post-quantum migration is data bloat. Classical ECDSA signatures occupy approximately 65 bytes. Post-quantum alternatives range from 690 bytes (Falcon-512) to 2,420 bytes (ML-DSA-44), representing a 10x to 37x increase.
BNB Chain's May 14 testnet report provides the only chain-specific live benchmark data available as of this writing. Key metrics from cross-region testing:
Solana's Foundation stated in its April 27 roadmap that Falcon can protect the network "without causing major performance issues," though it has not published comparable benchmarks. A separate CoinDesk analysis from April 4 reported that early quantum-safe signature tests made Solana's network "roughly 90% slower," though the Foundation disputed this characterization, attributing the figure to unoptimized preliminary testing.
Bitcoin's quantum exposure is structurally different from other chains. Approximately 6.9 million BTC — roughly 32% of total supply, valued at ~$483 billion at current prices — sit in addresses with exposed public keys. This includes early Satoshi-era coins (Pay-to-Public-Key format), any address that has ever broadcast a transaction, and all Taproot (P2TR) outputs since the 2021 upgrade which expose public keys by default.
BIP-360, authored by Hunter Beast, Ethan Heilman, and Isabel Foxen Duke, proposes a new output type called Pay-to-Merkle-Root (P2MR) that removes the quantum-vulnerable keypath spend. Unlike ECDSA, P2MR addresses do not expose public keys even when spending coins. The proposal moved to public testnet implementation by March 2026.
BIP-361, published April 15, 2026, by Jameson Lopp and five co-authors, addresses migration of existing vulnerable coins. The proposal outlines a multi-year schedule: Phase A (after ~160,000 blocks, approximately three years post-activation) would stop accepting new sends to legacy quantum-vulnerable address types. The proposal has generated significant community debate, as freezing legacy addresses would affect coins held by early adopters, estates, and potentially Satoshi Nakamoto's estimated 1.1 million BTC.
Bitcoin's governance model — requiring rough consensus among a decentralized developer community for any soft fork — makes rapid migration structurally difficult. CoinDesk characterized the situation: "Unlike Ethereum, which has a coordinated, well-funded post-quantum migration plan, Bitcoin lacks a unified roadmap, and its anti-centralization culture makes it harder to agree on urgent security upgrades before quantum hardware matures."
Ethereum's migration plan is the most structurally comprehensive among major chains, reflecting both the complexity of its cryptographic surface area and the Foundation's organizational capacity.
Vitalik Buterin published a roadmap in February 2026 identifying four distinct cryptographic layers requiring upgrades:
The Ethereum Foundation launched pq.ethereum.org on March 25, 2026, consolidating roadmaps, specifications, open-source repositories, and a 14-question FAQ. More than 10 client teams — including Lighthouse and Grandine, with Prysm expected to follow — are running weekly post-quantum interoperability devnets. The Foundation allocated $2 million across two prizes: $1 million for the Poseidon Prize (hash function improvements) and $1 million for the Proximity Prize (broader PQC research).
EIP-8141 is the critical near-term deliverable. It enables individual accounts to switch to post-quantum signature schemes via account abstraction, without requiring the entire protocol to upgrade simultaneously. This gives Ethereum a user-level migration path that Bitcoin currently lacks.
The Foundation targets completion of core post-quantum infrastructure by approximately 2029, matching Google's own internal PQC migration deadline.
BNB Chain published its post-quantum migration research report on May 14, 2026, making it the first major EVM chain to release live testnet benchmarks for NIST-standardized PQC algorithms.
The test replaced secp256k1 ECDSA with ML-DSA-44 for transaction signatures and deployed pqSTARK aggregation for validator consensus. Key data points:
The report identified the performance impact as primarily driven by increased data sizes rather than verification speed. The pqSTARK aggregation layer absorbed most of the consensus overhead, suggesting that data availability and bandwidth — not computation — represent the binding constraint for PQC migration on high-throughput chains.
On April 27, 2026, the Solana Foundation published a quantum readiness roadmap co-authored with Anza and Jump Crypto's Firedancer team. Both development teams independently selected Falcon (FN-DSA), a NIST-standardized lattice-based signature scheme, as their preferred PQC solution.
Falcon-512 signatures are approximately 690 bytes — significantly smaller than ML-DSA-44's 2,420 bytes — making it a better fit for Solana's throughput-optimized architecture. The Foundation outlined a three-phase roadmap: (1) continued research and optimization of Falcon implementations, (2) new wallets begin using PQC signatures as the quantum threat materializes, (3) existing wallets migrated to new key pairs.
Solana's existing Winternitz Vault, developed by Blueshift, has been live on mainnet for over two years as a quantum-resistant primitive and was cited by Google Quantum AI in its March 2026 research. However, Winternitz is a one-time signature scheme — impractical for general transaction signing — making Falcon the path forward for full network migration.
The Foundation stated that migration "can happen quickly when conditions demand it" and that "network performance is not expected to take a meaningful hit." NEAR's approach offers a structural advantage: its account-based key rotation model allows users to replace keys with a single transaction, avoiding the UTXO-model complications that complicate Bitcoin's migration.
The regulatory timeline is tightening independently of quantum hardware progress. NIST's CNSA 2.0 mandate requires U.S. National Security Systems to begin PQC transition by January 2027 — seven months away. The broader federal mandate phases out quantum-vulnerable algorithms by 2030 and bans them by 2035.
These deadlines create indirect pressure on blockchain networks that aspire to institutional adoption. The Federal Reserve's May 2026 benchmark of $25 billion in tokenized assets on public blockchains places validator and protocol reliability inside the Fed's financial stability assessment framework. Any chain seeking to custody or settle tokenized securities, deposits, or Treasury instruments will face the same cryptographic standards as traditional financial infrastructure.
Citi Institute's January 2026 report estimated that a quantum-enabled cyberattack disrupting a major U.S. bank's Fedwire access could put $2.0–$3.3 trillion of GDP at risk and trigger a six-month recession. The report characterized the PQC transition as likely to "dwarf Y2K in scale and complexity."
The post-quantum migration across major blockchains reveals a familiar pattern: engineering feasibility is established, but coordination and governance lag behind. The cryptographic tools exist — NIST finalized ML-DSA, ML-KEM, and SLH-DSA in 2024, with Falcon standardization underway. The performance costs are material but not prohibitive: BNB Chain's 40% throughput reduction and Falcon's compact signature size suggest workable tradeoffs for most chain architectures.
The binding constraint is governance. Ethereum's Foundation-coordinated model, with dedicated funding, weekly devnets, and a clear EIP pipeline, positions it furthest along. Solana's dual-client convergence on Falcon suggests rapid deployment capability when triggered. BNB Chain's centralized decision-making enabled the fastest benchmarking but raises questions about validator-level adoption.
Bitcoin remains the outlier. Its decentralized governance, UTXO model, and the politically charged question of freezing legacy addresses (including Satoshi's coins) create a coordination problem that no amount of cryptographic research can resolve. BIP-360 and BIP-361 are technically sound proposals. Whether they achieve activation before quantum hardware reaches critical capability is an open question that depends more on social consensus than on engineering.
The "harvest now, decrypt later" threat identified by Citi means the migration window is not defined by when quantum computers arrive, but by when adversaries begin collecting encrypted blockchain data for future decryption. For networks settling institutional assets under regulatory scrutiny, that window may already be closing.