← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Crypto's Post-Quantum Arms Race Begins

Zephyra|February 17, 2026|BPF
EXECUTIVE SUMMARY

The quantum threat to blockchain is no longer a theoretical debate confined to academic papers. In January 2026, the Ethereum Foundation elevated post-quantum security to a top strategic priority and formed a dedicated team. On February 11, Bitcoin's BIP 360 — a quantum-resistant output type — wa...

"Quantum computing is moving from theory into engineering. That changes the timeline, and it means we need to prepare." — Thomas Coratger, Lead, Ethereum Foundation Post-Quantum Team

Executive Summary

The quantum threat to blockchain is no longer a theoretical debate confined to academic papers. In January 2026, the Ethereum Foundation elevated post-quantum security to a top strategic priority and formed a dedicated team. On February 11, Bitcoin's BIP 360 — a quantum-resistant output type — was merged into the official BIP repository. Algorand has already broadcast the world's first post-quantum mainnet transaction. XRP Ledger is running quantum-safe consensus on its AlphaNet. Solana is testing CRYSTALS-Dilithium signatures on a public testnet with a potential mainnet vote before year-end.

This is no longer about whether blockchains will migrate to post-quantum cryptography (PQC). The question is who moves first, who pays the highest cost, and who gets left behind. The chains that solve the engineering trade-offs — 40x larger signatures, 50% throughput degradation, 2-3x higher fees — without breaking their user experience will define the next era of digital asset infrastructure. Those that delay face a compressed timeline and coordination chaos when the threat signals become unambiguous.

For investors and institutions, the quantum migration represents a multi-billion-dollar infrastructure upgrade cycle that will reshape competitive dynamics across every major Layer 1 ecosystem. This report maps the threat landscape, the engineering responses, and the economic consequences.

Table of Contents

  1. The Threat: How Real, How Soon?
  2. The $550 Billion Exposure Map
  3. The Arms Race: Chain-by-Chain Migration Status
  4. The Engineering Tax: What Quantum Safety Actually Costs
  5. Harvest Now, Decrypt Later: The Silent Risk
  6. Investment Implications
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Threat: How Real, How Soon?

The current quantum computing landscape is defined by a stark gap between capability and threat threshold. Google's Willow chip, unveiled in December 2024, operates with 105 qubits. Microsoft's Majorana 1, announced in February 2025, introduced a topological architecture that the company claims offers a "clear path to fit a million qubits on a single chip" — though this claim has drawn significant scientific skepticism, with physicists noting the announcement came via press release without publicly shared data.

The cryptographic threat threshold for blockchain is well understood. University of Sussex researchers estimate that breaking Bitcoin's ECDSA encryption within one day would require approximately 13 million error-corrected qubits. CoinShares, in a February 2026 report, framed this gap plainly: breaking Bitcoin's secp256k1 curve would require fault-tolerant quantum computers roughly 100,000 times more powerful than today's machines.

So the threat is not imminent — but the trajectory is accelerating. Vitalik Buterin has publicly estimated a 20% probability that quantum computers capable of breaking modern cryptography could emerge before 2030. NIST's transition roadmap calls for deprecating all quantum-vulnerable algorithms by 2035, with high-risk systems transitioning much earlier. The U.S. government has ordered federal agencies to be "quantum-resistant" by that same deadline.

The crypto industry, which secures over $2 trillion in assets with the very elliptic curve cryptography that quantum computers would break, cannot afford to be the last to move.

The $550 Billion Exposure Map

Not all blockchain assets face equal quantum risk. The most vulnerable are Bitcoin addresses using the original Pay-to-Public-Key (P2PK) format from 2009, where the public key is directly visible on-chain. According to Deloitte's analysis, approximately 4.5 million BTC — worth roughly $550 billion at recent prices — sits in these exposed addresses, including Satoshi Nakamoto's estimated 1.1 million BTC.

However, CoinShares pushes back hard on the headline risk. Their February 2026 report argues that while approximately 1.6 million BTC (roughly 8% of total supply) sits in older P2PK addresses, only around 10,200 BTC is concentrated enough that its theft could cause "appreciable market disruption." The firm's conclusion: quantum risk to Bitcoin is "long-dated and manageable."

For modern Bitcoin addresses using Pay-to-Public-Key-Hash (P2PKH) or Pay-to-Taproot (P2TR), the public key is only revealed at the moment of spending. This means an attacker would need to break the cryptography in real-time during the brief window between transaction broadcast and confirmation — a far harder task, even for a future quantum computer.

Ethereum faces a different exposure profile. Every Ethereum account's public key is derived and visible after the first outbound transaction, making the entire network's address space theoretically vulnerable once a sufficiently powerful quantum computer exists.

The Arms Race: Chain-by-Chain Migration Status

The industry's response has been uneven but accelerating. Here is where the major ecosystems stand as of February 2026:

Bitcoin: BIP 360 and the Governance Bottleneck

On February 11, 2026, BIP 360 was merged into the official Bitcoin Improvement Proposals repository. Co-authored by Hunter Beast (MARA), Ethan Hellman, and Foxen Duke, the proposal introduces Pay-to-Merkle-Root (P2MR) — a new output type that removes the quantum-vulnerable keypath spend from Taproot while preserving script-path functionality. P2MR addresses would begin with "bc1z."

Critically, a merge into the BIP repository does not signal endorsement or activation. Bitcoin's governance process — slow, conservative, and consensus-driven — means deployment could take years. Bitcoin Core developers have publicly warned that upgrading the network's cryptography could take 5-10 years. For a network securing $1.3 trillion in value, that timeline is both prudent and terrifying.

Ethereum: $2 Million in Bounties and a Throughput Problem

The Ethereum Foundation formed a dedicated post-quantum team in January 2026, led by Thomas Coratger, with $2 million in research prizes to harden hash-based primitives. The team is running biweekly developer sessions on PQ transactions and multi-client post-quantum consensus test networks.

The centerpiece of Ethereum's strategy is leanVM, a minimalist zero-knowledge proof virtual machine optimized for hash-based quantum-resistant signatures. But Ethereum faces a brutal engineering trade-off: ML-DSA (CRYSTALS-Dilithium) signatures are approximately 2,420 bytes versus 65 bytes for ECDSA — a 37x increase. At Ethereum's calldata pricing, a single PQ signature would consume roughly 38,720 gas versus approximately 1,040 gas for ECDSA. Testnet implementations show 52-57% throughput degradation.

Convincing Ethereum's decentralized community to accept a 50% capacity hit and 2-3x fee increase is an enormous governance challenge. Experts estimate this transition could take 10-15 years through normal governance processes.

Algorand: First Mover on Mainnet

Algorand holds the distinction of broadcasting the world's first post-quantum transaction on a major Layer 1 mainnet on November 3, 2025. The transaction used Falcon-1024, a lattice-based signature scheme selected by NIST for standardization. Algorand's state proofs already use Falcon-1024 to verify every 256 rounds, meaning the ledger's integrity layer is already quantum-secure.

The roadmap includes adding Falcon verification to the Algorand Virtual Machine so dApps and multisig wallets can adopt PQC with just two SDK updates rather than a full protocol fork. This pragmatic approach — quantum-ready opt-in rather than mandatory migration — may prove the template for the industry.

Solana: Racing Firedancer and Dilithium

In December 2025, the Solana Foundation partnered with security firm Project Eleven to open a public testnet replacing every Ed25519 signature with CRYSTALS-Dilithium. High-value wallets can already create dual keypairs (Ed25519 plus Dilithium) in Phantom and Ledger developer builds. Firedancer — Jump Crypto's independent validator client shipping in 2026 — already supports multiple signature backends.

The activation mechanism is elegant: when at least 10% of stake votes with post-quantum keys, the foundation will propose an on-chain referendum to lock a cut-over date. If the vote passes and end-to-end Dilithium support in Solana Pay arrives before December 2026, Solana will demonstrate that high-performance chains can harden for the quantum threat without sacrificing speed.

XRP Ledger: Quantum Consensus on AlphaNet

In December 2025, XRPL Labs integrated ML-DSA quantum-safe signatures into its AlphaNet, replacing elliptic curve signatures with 2,420-byte Dilithium proofs. The implementation extends beyond transactions to validator consensus itself — vote signing now uses post-quantum schemes. The AlphaNet pilot is generating critical data on whether the 38x signature size increase can maintain transaction throughput under real-world conditions.

The Engineering Tax: What Quantum Safety Actually Costs

The economic cost of post-quantum migration is substantial and unevenly distributed. The core challenge: every major PQC signature scheme produces dramatically larger signatures than the elliptic curve cryptography it replaces.

| Metric | ECDSA (Current) | ML-DSA (Dilithium) | Falcon-1024 | Increase Factor | |---|---|---|---|---| | Signature Size | 64-65 bytes | ~2,420 bytes | ~1,280 bytes | 20-38x | | Verification Speed | Baseline | ~1.5-2x slower | ~1.2x slower | Variable | | Throughput Impact | Baseline | 52-57% degradation | ~30% degradation | Significant |

For Ethereum, where calldata costs dominate transaction fees, this translates to a direct 2-3x increase in user costs. For Bitcoin, BIP 360's P2MR outputs will incur "slightly higher transaction fees due to additional witness data." For high-throughput chains like Solana, the bandwidth increase of propagating 38x larger signatures across thousands of validators creates novel engineering challenges.

This is not a one-time upgrade cost. It is a permanent increase in the per-transaction resource footprint of every quantum-safe blockchain. The chains that solve signature aggregation, compression, and proof batching most efficiently will capture the economic advantage.

Harvest Now, Decrypt Later: The Silent Risk

The most underappreciated quantum risk to blockchain is not the future breaking of cryptographic keys — it is the present harvesting of encrypted data. The "harvest now, decrypt later" (HNDL) attack vector involves adversaries collecting encrypted blockchain data today with the expectation of decrypting it once quantum computers reach sufficient capability.

The U.S. Federal Reserve published a dedicated research paper on this exact scenario for distributed ledger networks in 2025, warning that even after successful PQC migration protects future transactions, the privacy of previously recorded transactions remains permanently vulnerable.

For blockchains — which are, by design, permanent and publicly accessible records — this creates an irreversible exposure. Every transaction ever broadcast on a transparent chain is available for harvesting. Privacy-focused chains and zero-knowledge systems have a structural advantage here: their data is already encrypted or hidden at the protocol level.

Europol's Quantum-Safe Financial Forum has warned banks to begin inventorying vulnerable cryptographic keys immediately. The blockchain industry, which operates entirely on public ledgers, faces arguably greater exposure than traditional finance.

Investment Implications

The quantum migration creates several distinct investment themes:

Infrastructure winners. The chains that achieve quantum safety first — without destroying their user economics — will attract institutional capital seeking regulatory-grade security. Algorand's first-mover status on mainnet PQC is a competitive moat that the market has not yet priced.

The governance premium. Chains with faster governance mechanisms (Solana's stake-weighted voting, Algorand's opt-in approach) hold a structural advantage over Bitcoin's multi-year consensus process and Ethereum's decentralized coordination challenge.

The compression race. Signature aggregation, ZK-proof batching, and PQC-optimized compression will become critical infrastructure. Projects solving the 38x signature bloat problem will unlock enormous value.

Privacy chains as quantum hedges. Zero-knowledge systems and privacy-preserving chains offer inherent protection against HNDL attacks, a structural advantage that will compound as quantum timelines compress.

Key Takeaways

  • The quantum threat is real but not imminent. Breaking Bitcoin's ECDSA would require quantum computers 100,000x more powerful than today's. Expert consensus places the timeline at 10-20 years, with Vitalik Buterin estimating a 20% chance before 2030.

  • The migration is already underway. BIP 360 is in Bitcoin's repository. Ethereum has a funded PQ team. Algorand has mainnet PQC. Solana is testing Dilithium. XRPL has quantum consensus on AlphaNet. The race is real.

  • The engineering costs are brutal. Post-quantum signatures are 20-38x larger, causing 50%+ throughput degradation and 2-3x fee increases. Solving this trade-off is the defining infrastructure challenge of the next cycle.

  • "Harvest now, decrypt later" is the silent risk. Public blockchain data is permanently available for collection. The Fed has published research on this exact threat. Privacy-preserving systems hold a structural advantage.

  • Only 10,200 BTC faces concentrated theft risk. CoinShares' analysis debunks the $550 billion vulnerability headline. The realistic market-moving quantum theft risk is orders of magnitude smaller.

Conclusion

The post-quantum migration is the largest coordinated infrastructure upgrade in blockchain history. It will take years, cost billions in aggregate, and permanently alter the economic profile of every chain that undertakes it. The engineering is hard — 38x larger signatures break assumptions baked into every layer of the stack, from consensus to wallets to block explorers.

But the alternative is existential. A blockchain that cannot resist quantum attack is a blockchain that cannot secure institutional capital, meet regulatory requirements, or fulfill its core value proposition of trustless, immutable record-keeping.

The winners of this transition will be the chains that move deliberately but decisively — investing in PQC research, testing on public networks, and building governance mechanisms that can execute a migration without fragmenting their communities. The losers will be those who dismiss the threat as "decades away" until the timeline compresses and they are forced into emergency upgrades under duress.

The quantum clock is ticking. The smart money is already moving.

Sources & References

  1. CoinShares: Quantum Computing Threat to Bitcoin Is 'Manageable' — CoinShares report on Bitcoin quantum risk assessment, Feb 2026
  2. CoinShares: Only 10,200 BTC Face Real Quantum Risk — The Block coverage of concentrated BTC exposure, Feb 2026
  3. Ethereum Foundation Elevates Post-Quantum Security to Top Strategic Priority — Ethereum PQ team formation, Jan 2026
  4. Ethereum Foundation Forms Post-Quantum Security Team — The Block on $1M research prize, Jan 2026
  5. Quantum Threat Gets Real: Ethereum Foundation Prioritizes Security with leanVM and PQ Signatures — CoinDesk on Ethereum's PQ engineering, Feb 2026
  6. Bitcoin Advances Toward Quantum Resistance With BIP 360 — Bitcoin Magazine on BIP 360 merge, Feb 2026
  7. BIP-360 Lands in the Official Bitcoin BIPs Repository — BIP 360 technical analysis
  8. Algorand: Technical Brief on Quantum-Resistant Transactions with Falcon Signatures — Algorand's Falcon-1024 mainnet implementation
  9. Solana, Aptos Move to Harden Blockchains Against Future Quantum Attacks — Decrypt on Solana's Dilithium testnet
  10. XRPL Flips to Quantum-Safe Signatures — CryptoSlate on XRPL AlphaNet PQC integration
  11. Ethereum's Massive Fee Shock: Post-Quantum Signatures Are 40x Larger — CryptoSlate analysis of PQC fee impact
  12. Federal Reserve: "Harvest Now Decrypt Later" — Examining Post-Quantum Cryptography Risks for DLT — Federal Reserve research paper on HNDL risks
  13. NIST Releases First 3 Finalized Post-Quantum Encryption Standards — NIST PQC standardization, Aug 2024
  14. Microsoft Unveils Majorana 1 Quantum Processor — Microsoft topological qubit announcement
  15. Vitalik Buterin Warns 20% Quantum Risk by 2030 — CCN on Buterin's quantum probability estimate