On July 2, 2026, Swiss-registered QoreChain settled the first end-to-end post-quantum-secured transaction on a live public blockchain mainnet — a 1,000 QOR transfer verified using all three NIST-standardized post-quantum algorithms. The event lands amid accelerating timelines: a January 2026 Citi...
"For years, the response to our thesis was that it was too early. Today that argument stops being theoretical." — Liviu Epure, Founder and CTO, QoreChain
On July 2, 2026, Swiss-registered QoreChain settled the first end-to-end post-quantum-secured transaction on a live public blockchain mainnet — a 1,000 QOR transfer verified using all three NIST-standardized post-quantum algorithms. The event lands amid accelerating timelines: a January 2026 Citi Institute report pegged the economic risk of a "Q-Day" cryptographic break at $2.0–$3.3 trillion in U.S. GDP alone, while Google researchers cut the estimated qubit requirement to crack 256-bit elliptic-curve cryptography by 20x, bringing the threshold below 500,000 physical qubits.
The crypto industry is now in a three-front migration. Bitcoin merged BIP-360 in February 2026, introducing quantum-resistant P2MR addresses. Ethereum's Foundation stood up a dedicated post-quantum team and published Vitalik Buterin's "Strawmap" roadmap targeting quantum-safe infrastructure by roughly 2029. And at least one Layer 1 — QoreChain — has shipped a full NIST-compliant stack to production. According to the Citi report, approximately 25% of Bitcoin's supply, 65% of Ethereum's, and effectively all of Solana's are currently quantum-exposed. The clock is no longer hypothetical.
Transaction hash: 4E49D57F86FEC8851CDC34811B4C80FDB24F4C253ABE15D25C05B7A27F2B7F1F. Network: qorechain-vladi (EVM Chain ID 9801). Date: July 2, 2026.
The transfer of 1,000 QOR to a Keplr wallet-generated address used three NIST-standardized algorithms across the full cryptographic path:
Performance benchmarks reported by QoreChain: Dilithium-5 verification completes in approximately 53 microseconds, signing in approximately 110 microseconds. Mean block time: 1.376 seconds. Tested throughput capacity: approximately 64,000 transactions per second, with 40 concurrent transactions confirmed in a single block.
The distinction from prior "quantum-safe" claims is scope. Most projects replace only the signature algorithm while leaving key exchange and hashing on classical cryptography. QoreChain disabled classical fallback entirely, applying post-quantum primitives to signature, key encapsulation, and state functions simultaneously.
QoreChain operates as a Cosmos SDK v0.53 chain with a triple-VM runtime supporting EVM, CosmWasm, and SVM execution environments. The QoreChain Association is registered in Rolle, Switzerland (CHE-484.963.998), and holds a FINMA no-action letter classifying QOR as a utility token.
"Being first is not the point. Being ready is. The institutions with the most to lose in the quantum transition cannot adopt infrastructure that is experimental or non-standard," said Tilak Patel, QoreChain's President and CEO.
The Citi Institute's January 2026 report, "Quantum Threat: The Trillion-Dollar Security Race Is On," provides the clearest institutional framing of the risk:
For blockchains specifically, the exposure is structural. According to the Citi analysis:
| Chain | Estimated Quantum-Exposed Supply | Dollar Exposure (approx.) | |-------|----------------------------------|---------------------------| | Bitcoin | ~25% (~4.5–6.7M BTC) | $500–600B | | Ethereum | ~65%+ | Not specified | | Solana | "Effectively total" | Not specified |
The exposure arises from addresses whose public keys have been revealed on-chain — a precondition for Shor's algorithm to derive the corresponding private key. Bitcoin's UTXO model partially mitigates this for unused addresses, but any address that has sent a transaction exposes its public key permanently.
Google's March 2026 research reduced the estimated resource requirement to break 256-bit elliptic-curve cryptography to fewer than 1,200 logical qubits and under 500,000 physical qubits, with runtimes measured in minutes on a future fault-tolerant quantum computer. This represents a roughly 20x reduction from prior estimates and compresses the practical timeline from "decades" to a range measured in years.
Google's current Willow processor operates at 105 qubits with 99.97% single-qubit gate fidelity. The company has set an internal 2029 deadline to migrate its own systems to post-quantum cryptography. In March 2026, Google added neutral-atom hardware as a second modality alongside superconducting qubits, signaling an acceleration path to higher qubit counts.
A Federal Reserve research paper titled "Harvest Now, Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks" identifies the core asymmetry: blockchains are immutable public ledgers. Unlike traditional databases, blockchain transaction histories cannot be deleted, retroactively encrypted, or redacted.
The "Harvest Now, Decrypt Later" (HNDL) attack vector is well-documented by the NSA, CISA, and NIST. Adversaries collect encrypted data and on-chain transaction records today, storing them for future decryption once cryptographically relevant quantum computers become available. For blockchains, this creates a compounding problem: every block added to the chain prior to quantum-safe migration becomes permanently vulnerable, regardless of when migration eventually occurs.
The practical implication: even if Bitcoin completes its quantum migration by 2028, any transaction signed with ECDSA before that date remains exposed indefinitely. The public key revealed in those transactions is baked into the chain's history. A future quantum computer could derive the private key and, without additional protocol-level protections, sweep funds from addresses that received coins after the last outgoing transaction.
This is why BIP-361 proposes a sunset mechanism — a hard deadline after which legacy signature types are no longer honored — and why QoreChain's approach of launching with post-quantum cryptography from genesis avoids the problem entirely.
Bitcoin's migration is proceeding in two stages:
BIP-360 (merged February 11, 2026): Introduces Pay-to-Merkle-Root (P2MR), a new address type using the bc1z prefix. P2MR hides public keys from the chain, removing the quantum-vulnerable spending path for newly created outputs. BTQ Technologies deployed the first working implementation on Bitcoin Quantum testnet v0.3.0 in March 2026.
BIP-361 (published April 14, 2026): Formally titled "Post Quantum Migration and Legacy Signature Sunset," this proposal establishes a mechanism for handling existing quantum-exposed coins. The core design sets a deadline by which holders must migrate funds to quantum-resistant addresses. After the deadline, the network would stop honoring spends from legacy signature types, effectively orphaning unmigrated funds.
BIP-361 is contentious. It requires consensus on an immutability trade-off — locking out holders who fail to migrate in time, whether due to lost access, custodial delays, or simple inaction. Satoshi Nakamoto's estimated 1.1 million BTC, untouched since 2010, would be permanently frozen under this scheme unless the protocol includes an exemption mechanism.
Neither BIP-360 nor BIP-361 has been activated on Bitcoin's mainnet. The testnet implementation is functional but requires broader node adoption and a soft fork activation to take effect.
Ethereum's quantum migration is more complex due to its reliance on BLS signatures for validator consensus:
Strawmap (February 2026): Vitalik Buterin published a "strawman roadmap" identifying four areas of Ethereum's cryptography requiring post-quantum upgrades: consensus signatures, account-level signatures, data availability proofs, and ZK-proof systems. The Ethereum Foundation simultaneously established a dedicated post-quantum team and announced a $1 million prize for advances in quantum-resistant cryptography.
BLS Vulnerability: Ethereum's proof-of-stake consensus aggregates hundreds of thousands of validator signatures using BLS, which relies on elliptic-curve pairings. A quantum computer could break BLS, compromising consensus integrity. The planned replacement is leanXMSS, a hash-based signature scheme considered quantum-safe because it depends only on hash function security.
Lean Ethereum (July 4, 2026): Buterin's most recent roadmap iteration proposes recursive STARK verification to replace transaction re-execution, quantum-resistant hash-based signatures, one- or two-round finality, and multidimensional gas pricing. The scope spans three to four years of incremental upgrades, with structured fork milestones targeting core post-quantum infrastructure completion around 2029.
EIP-8141 is under consideration for the Hegotá hard fork (second half of 2026) and would allow individual accounts to opt into quantum-safe signature schemes voluntarily, without requiring a network-wide migration.
Ethereum's account model offers one structural advantage: individual accounts can adopt quantum-resistant verification logic independently. This contrasts with Bitcoin's script-level constraints, which require protocol-level changes for new address types.
NIST finalized three post-quantum cryptography standards on August 13, 2024:
| Standard | Algorithm | Purpose | |----------|-----------|---------| | FIPS 203 | ML-KEM (CRYSTALS-Kyber) | Key encapsulation mechanism | | FIPS 204 | ML-DSA (CRYSTALS-Dilithium) | Digital signatures | | FIPS 205 | SLH-DSA (SPHINCS+) | Hash-based digital signatures |
HQC, a code-based backup algorithm, was selected on March 11, 2025, with a draft standard expected in early 2026 and finalization in 2027.
U.S. federal agencies face a 2030 deadline to migrate to post-quantum cryptography. Full adoption across government systems is targeted for 2035. European coordinated strategies are required by end of 2026, with high-risk system transitions mandated by 2030.
The path from standard to deployment is not straightforward:
Signature bloat: Dilithium-5 signatures are 4,627 bytes versus ECDSA's 72 bytes — a 64x increase. For high-throughput chains processing thousands of transactions per second, this inflates bandwidth, storage, and verification costs materially.
Backward compatibility: Chains with years of transaction history cannot retroactively protect exposed public keys. Migration protects future transactions but leaves historical state permanently vulnerable to HNDL attacks.
Ecosystem coordination: Wallets, hardware signers, exchanges, custodians, and smart contracts all must be updated. A chain can adopt post-quantum signatures at the protocol level, but if major exchanges still generate legacy addresses, the migration's impact is diluted.
Performance overhead: While individual Dilithium operations are fast (53 μs verification), the aggregate impact at network scale — multiplied across millions of daily transactions, mempool processing, and state validation — remains undertested in production environments with real economic activity.
Consensus risk: BIP-361's sunset mechanism and Ethereum's validator signature migration both require network-wide coordination on timelines and handling of non-migrated assets. These are governance decisions as much as technical ones.
The quantum threat to blockchain infrastructure has shifted from theoretical concern to active engineering problem. The data — Citi's trillion-dollar risk assessment, Google's 20x reduction in qubit requirements, the Federal Reserve's HNDL research — establishes a credible timeline measured in years, not decades. QoreChain's mainnet transaction demonstrates that full NIST-compliant post-quantum cryptography is deployable today on production infrastructure, though the network is nascent and lacks the economic activity of established chains.
The harder question is not whether the technology works but whether the industry's largest networks — Bitcoin at $1.2 trillion market cap, Ethereum at $300 billion — can coordinate migrations at scale before the threat materializes. Bitcoin's BIP-360 and Ethereum's Strawmap are substantive first steps, but neither is close to mainnet activation. The Harvest Now, Decrypt Later vector means the migration clock started years ago, and every additional block settled on classical cryptography adds to the permanently exposed surface.
The institutions Citi's report warns about — the banks, custodians, and clearinghouses integrating blockchain into financial infrastructure — are now evaluating quantum readiness as a procurement criterion. Whether that demand flows to quantum-native chains like QoreChain, to migrated incumbents, or to entirely new architectures remains an open question. What is no longer open is whether the problem is real.