A 15-bit elliptic curve key was broken on publicly accessible quantum hardware in April 2026, a 512x jump from the prior 6-bit record set in September 2025. The milestone, awarded Project Eleven's 1 BTC Q-Day Prize, sits far below the 256-bit threshold protecting $2.5 trillion in ECC-secured digi...
"Q-Day could arrive as early as 2030 and no later than 2033." — Project Eleven, Q-Day Report (May 2026)
A 15-bit elliptic curve key was broken on publicly accessible quantum hardware in April 2026, a 512x jump from the prior 6-bit record set in September 2025. The milestone, awarded Project Eleven's 1 BTC Q-Day Prize, sits far below the 256-bit threshold protecting $2.5 trillion in ECC-secured digital assets. But separate research from Google Quantum AI and a Caltech/Oratomic collaboration has compressed the theoretical qubit requirement for a full 256-bit break from millions down to as few as 10,000 physical qubits under certain architectures. NIST plans to deprecate ECDSA by 2030 and disallow it by 2035. The three largest smart-contract platforms — Bitcoin, Ethereum, and Solana — are now running parallel but structurally distinct post-quantum migration programs.
Bitcoin merged BIP-360 into its official repository on February 11, 2026, introducing a Pay-to-Merkle-Root (P2MR) address type that eliminates the key-path spend quantum computers could eventually exploit. Ethereum published SPHINCS-, a hash-based signature scheme optimized for in-EVM verification at roughly $0.07 per account, on June 12, 2026. Solana released a joint Anza/Firedancer roadmap on April 27, 2026, selecting the Falcon lattice-based scheme, though early tests show quantum-safe signatures are up to 40x larger and reduce throughput by approximately 90%. Each chain faces different tradeoffs. This report compares their approaches, timelines, and structural constraints.
IBM and Google have moved the industry from the Noisy Intermediate-Scale Quantum (NISQ) era into early Fault-Tolerant Quantum Computing (FTQC). Google achieved a 1:100 physical-to-logical qubit ratio in May 2026, a significant improvement from prior requirements. IBM expects its Nighthawk system to demonstrate quantum advantage on a practically relevant computational problem by end of 2026. Global quantum computing investment reached $17.3 billion in 2026, according to industry aggregators.
The cryptographic implications are narrowing. Google Quantum AI published research in March 2026 estimating that breaking 256-bit elliptic curve cryptography — the scheme securing Bitcoin, Ethereum, and Solana account signatures — could require roughly 1,200 logical qubits. A subsequent Caltech/Oratomic paper brought the physical qubit estimate to as low as 10,000 under a neutral-atom architecture. These figures remain theoretical, but they compress the timeline from "decades away" to a window most estimates place between 2029 and 2033.
NIST finalized three post-quantum cryptography standards on August 13, 2024: FIPS 203 (ML-KEM, lattice-based key encapsulation), FIPS 204 (ML-DSA, lattice-based digital signatures), and FIPS 205 (SLH-DSA, hash-based digital signatures, formerly SPHINCS+). The NSA's Commercial National Security Algorithm Suite 2.0 mandates PQC for new national security systems starting in 2027. Google began defaulting to quantum-safe TLS connections in 2026.
Blockchain networks face a compounding problem. Unlike centralized systems that can force-upgrade, decentralized protocols require consensus among thousands of independent operators, wallet providers, and exchanges. The migration window is finite; the governance overhead is not.
Approach: Hash-based, new address type (P2MR) Status: Merged into official repository February 11, 2026 Testnet: BTQ Technologies deployed BIP-360 on Bitcoin Quantum Testnet v0.3.0 in March 2026 Address format: SegWit version 2 outputs with bc1z encoding (bech32m)
BIP-360 introduces Pay-to-Merkle-Root, a quantum-resistant output type that commits directly to the script tree's Merkle root without relying on an internal key or tweak. This preserves Taproot's scripting capabilities while eliminating the key-path spend that Shor's algorithm could target.
The structural problem: BIP-360 protects coins going forward. It does not address the approximately 6.9 million BTC — worth roughly $560 billion at current prices — already sitting in quantum-vulnerable addresses. This includes every P2PK output from Bitcoin's first two years (including Satoshi Nakamoto's estimated 1.1 million BTC), every address that has sent a transaction at least once (revealing the public key in the spending signature), and every P2TR keypath spend made since the 2021 Taproot activation.
The Bitcoin community is split on how to handle legacy exposure. Adam Back, Blockstream CEO, advocates a phased optional upgrade approach, arguing that Taproot already contains structural defenses. Others, including Project Eleven CEO, argue the migration "will be harder than Taproot and needs to start now," noting that Taproot itself took roughly five years and remained opt-in. A "just-in-time" alternative proposes adding a hidden post-quantum fallback spend path to Taproot's existing structure, preserving current efficiency and privacy until a quantum-safe branch is actually needed.
Despite BIP-360's inclusion in the official proposal repository, broader ecosystem adoption remains limited. No major wallet or exchange has announced support for bc1z addresses. The Bitcoin governance model — deliberately slow, consensus-driven, and resistant to forced upgrades — makes rapid migration structurally difficult.
Approach: Multi-layered; hash-based signatures, lattice-based alternatives, account abstraction Status: Post-Quantum Security team formed January 2026; SPHINCS- proposal published June 12, 2026 Cost: Approximately $0.07 per account for SPHINCS- protection Hard fork dependency: SPHINCS- requires no hard fork; broader roadmap targets Hegotá hard fork (H2 2026) and completion by ~2029
Ethereum faces a more complex migration than Bitcoin because its cryptography is embedded in four distinct protocol layers. Vitalik Buterin's February 2026 roadmap identified each:
The SPHINCS- proposal, published by researcher nicocsgy on Ethereum Research on June 12, 2026, offers a stopgap for layer 3 (ECDSA signatures). The scheme replaces standard SHAKE256 with EVM-native KECCAK256, allowing a Solidity implementation without protocol changes or precompiles. The C13 variant requires approximately 127,000 gas with a 3,704-byte signature. At current gas prices, this translates to roughly $0.07 per account upgrade.
The Ethereum Foundation formed a dedicated Post-Quantum Security hub in March 2026, coordinating more than 10 client teams. The structured fork milestones target completion of core post-quantum infrastructure by approximately 2029. Unlike Bitcoin, Ethereum's account abstraction roadmap (EIP-8141 and related proposals) provides a built-in mechanism for users to adopt quantum-resistant schemes individually, without requiring network-wide consensus on a single signature standard.
However, replacing BLS signatures and KZG commitments at the consensus layer is a harder engineering problem. These primitives are deeply embedded in Ethereum's proof-of-stake mechanism and data availability sampling design. No concrete replacement proposals have reached implementation stage for these layers.
Approach: Lattice-based (Falcon) Status: Joint Anza/Jump Crypto Firedancer roadmap published April 27, 2026 Performance impact: Signatures up to 40x larger; ~90% throughput reduction in early tests Migration timeline: Phased; research-first, wallet updates before protocol changes
The Solana Foundation's quantum readiness roadmap, co-authored with Anza and Jump Crypto's Firedancer team, selects Falcon — NIST's lattice-based signature standard (FIPS 204 category) — as the primary post-quantum candidate. The choice reflects Solana's emphasis on compact signatures and high throughput relative to other post-quantum schemes.
The tradeoff is severe. Early tests show quantum-safe signatures are up to 40x larger than current Ed25519 signatures, and network throughput drops by approximately 90%. For a chain whose value proposition centers on sub-second finality and high transaction-per-second capacity, this represents a fundamental architectural tension. The Solana Foundation has stated that any eventual migration "would be manageable and unlikely to significantly impact performance," though the test data cited by CoinDesk's April 2026 report suggests otherwise.
The phased plan starts with continued research and testing, followed by quantum-resistant cryptography for new wallets only if quantum risks materialize as a realistic near-term threat. Full migration of existing wallets would follow only if necessary. The Blueshift Winternitz Vault, already deployed on Solana, was cited in a 2026 Google Quantum AI whitepaper as a leading example of proactive quantum-proofing — though it remains a niche solution rather than a protocol-wide standard.
Solana's governance model allows faster upgrades than Bitcoin's, but the performance regression creates an economic constraint. Validators and applications built around current throughput assumptions would face disruption if Falcon signatures were mandated at the protocol level.
| Dimension | Bitcoin (BIP-360) | Ethereum (SPHINCS-/EIP-8141) | Solana (Falcon) | |---|---|---|---| | Signature scheme | Hash-based (P2MR) | Hash-based (SPHINCS-) + account abstraction | Lattice-based (Falcon) | | NIST alignment | Custom (not direct FIPS mapping) | FIPS 205 derivative (SLH-DSA) | FIPS 204 category (ML-DSA family) | | Hard fork required | Yes (SegWit v2) | No (SPHINCS-); Yes (BLS/KZG replacement) | TBD (phased approach) | | Per-account cost | TBD | ~$0.07 | TBD | | Signature size | TBD | 3,704 bytes (C13) | ~40x current Ed25519 | | Throughput impact | Minimal (new address type) | Minimal (EVM-level) | ~90% reduction (early tests) | | Legacy exposure | 6.9M BTC (~$560B) | All EOAs using ECDSA | All accounts using Ed25519 | | Governance speed | Slow (multi-year consensus) | Medium (Foundation + EIP process) | Fast (Foundation-directed) | | Target completion | No firm date | ~2029 | Phased, no firm date | | Testnet deployment | Yes (March 2026) | Research stage | Research stage |
The three approaches reflect each chain's architectural constraints. Bitcoin's UTXO model allows a clean new address type without modifying existing transaction logic, but cannot retroactively protect spent outputs. Ethereum's account model and smart-contract layer create four separate attack surfaces but also provide account abstraction as a migration vehicle. Solana's performance-first architecture makes any signature size increase a throughput problem.
The timeline is compressing. Google's 1:100 physical-to-logical qubit ratio, achieved May 2026, and theoretical attack estimates as low as 10,000 physical qubits move "Q-Day" estimates into the 2029-2033 window. NIST plans to deprecate ECDSA by 2030.
No chain is quantum-safe today. All three major platforms use elliptic curve cryptography that Shor's algorithm can theoretically break. The question is migration speed, not whether migration is needed.
Bitcoin has the largest legacy exposure. Approximately 6.9 million BTC ($560 billion) sit in addresses with exposed public keys. BIP-360 protects new coins only. The community has no consensus on legacy migration.
Ethereum has the broadest attack surface but the most flexible migration path. Four distinct cryptographic primitives need replacement, but account abstraction enables opt-in upgrades without hard forks for user-facing signatures.
Solana faces the hardest performance tradeoff. A 90% throughput reduction is incompatible with the chain's core value proposition. The phased approach buys time but defers the fundamental engineering problem.
Economic value at risk is measurable. The combined market capitalization secured by ECC across the three chains exceeds $1.5 trillion. Post-quantum migration is not a theoretical exercise — it is infrastructure maintenance on a defined timeline.
The post-quantum migration across Bitcoin, Ethereum, and Solana reveals a structural reality: decentralized networks move slower than the threat environment. Bitcoin's governance model prioritizes stability over speed, leaving $560 billion in legacy exposure without a migration path. Ethereum's multi-layered architecture creates the broadest attack surface but also the most modular upgrade path, with SPHINCS- offering a $0.07-per-account stopgap that requires no protocol changes. Solana's performance constraints make the engineering problem qualitatively different — the chain must solve for speed and security simultaneously, and early data suggests the current candidates cannot deliver both.
NIST's 2030 ECDSA deprecation date provides an external forcing function. Whether blockchain governance mechanisms can coordinate migrations within that window remains the open question. The data suggests that Ethereum's account abstraction model is best positioned for incremental adoption, Bitcoin faces the most politically difficult migration, and Solana must solve a performance problem that no other chain shares at the same scale.