Google Quantum AI's March 30 white paper — co-authored with the Ethereum Foundation and Stanford University — demonstrated that breaking 256-bit elliptic curve cryptography (ECC) requires 20x fewer quantum resources than 2019 estimates: fewer than 500,000 physical qubits, executable in minutes. G...
"When Bitcoin was still debating whether to freeze quantum-vulnerable addresses, and Ethereum was still forming research committees, TRON was already taking action." — Justin Sun, Founder, TRON
Google Quantum AI's March 30 white paper — co-authored with the Ethereum Foundation and Stanford University — demonstrated that breaking 256-bit elliptic curve cryptography (ECC) requires 20x fewer quantum resources than 2019 estimates: fewer than 500,000 physical qubits, executable in minutes. Google moved its own post-quantum migration deadline to 2029, six years ahead of NIST's 2035 disallowance target.
The disclosure set off a migration race across the blockchain industry. As of June 10, 2026, at least eight major networks — Stellar, BNB Chain, NEAR, Solana, XRP Ledger, TRON, Cardano, and Ethereum — have published formal post-quantum roadmaps. NEAR deployed ML-DSA signatures on mainnet May 6. BNB Chain completed testnet trials but measured a 40% throughput drop. Bitcoin's BIP-361 proposal to freeze 6.9 million BTC in quantum-vulnerable addresses remains contested. The total value at direct risk: an estimated $145 billion in exposed Bitcoin P2PK addresses alone, within a $2.38 trillion total crypto market cap.
The clock is no longer theoretical. The engineering trade-offs — signature sizes 10–121x larger, throughput losses of 40–90% — are real. The question is whether decentralized governance can execute coordinated cryptographic migration before the threat window opens.
On March 30, 2026, Google Quantum AI published research alongside Ethereum Foundation and Stanford University cryptographers demonstrating that the quantum resources required to break ECDSA-256 — the signature scheme underpinning Bitcoin, Ethereum, and most blockchains — are significantly lower than previous estimates.
The team designed two attack circuits for the Elliptic Curve Discrete Logarithm Problem (ECDLP-256): one using fewer than 1,200 logical qubits and 90 million Toffoli gates, and another using fewer than 1,450 logical qubits and 70 million gates. Both could execute in minutes on a superconducting quantum computer with fewer than 500,000 physical qubits.
Google subsequently moved its internal post-quantum cryptography (PQC) migration deadline from NIST's 2035 timeline to 2029. The NSA targets 2031. Google is now the most aggressive major institution on this timeline.
For context: Google's current Willow chip operates at 105 qubits. IBM's roadmap targets 100,000+ qubits by 2033. The gap between current hardware and the attack threshold is closing, albeit unevenly.
On April 24, Project Eleven awarded a 1 BTC bounty ($78,000) to researcher Giancarlo Lelli for breaking a 15-bit ECC key on publicly accessible quantum hardware — a 512x jump from the prior public demonstration. However, the result was contested: independent reviewers replicated the feat using classical computing methods within hours, underscoring that the current threat remains theoretical rather than operational.
The blockchain industry's quantum vulnerability is concentrated in exposed public keys.
Bitcoin: Approximately 6.9 million BTC are held in addresses where the public key is visible on-chain. Of these, roughly 1.7 million BTC sit in Satoshi-era pay-to-public-key (P2PK) addresses — including an estimated 1.1 million BTC attributed to Satoshi Nakamoto. At current prices, the P2PK exposure alone totals approximately $145 billion, according to CoinDesk analysis.
Ethereum: Vitalik Buterin has identified four distinct cryptographic components vulnerable to quantum attack: consensus-layer BLS signatures, KZG commitments used for data availability, ECDSA signatures on user accounts, and zero-knowledge proof systems used by applications and Layer 2 networks. The entire $600+ billion Ethereum ecosystem operates on these primitives.
Broader market: The total cryptocurrency market cap stands at approximately $2.38 trillion. While not all of this is directly exposed — modern hashed addresses provide partial protection — the systemic risk from a successful attack on any major network would likely cascade across the sector. Some analysts estimate a potential 50% market cap loss if a major network is compromised before migration completes, according to InvestorPlace.
The following tracks the post-quantum status of eight major networks as of June 10, 2026:
NEAR Protocol — Deployed (May 6, 2026) NEAR implemented ML-DSA signatures on mainnet on May 6, making it the first major smart-contract platform to deploy NIST-standardized post-quantum cryptography in production. Details on throughput impact have not been publicly disclosed.
BNB Chain — Testnet Complete (May 14, 2026) BNB Chain published a detailed migration report on May 14 adopting ML-DSA-44 (Dilithium, NIST Level 2) for transaction authentication and pqSTARK aggregation for consensus. Testnet results revealed a 40–50% throughput reduction. Transaction sizes increased from 110 bytes to approximately 2.5 KB. Block sizes grew to approximately 2 MB. Address format and RPC compatibility were maintained.
Stellar — Stage 1 Underway (June 10, 2026) Stellar launched its Quantum Preparedness Plan (QPP) on June 10, a three-stage roadmap. Stage 1 (2026): ML-DSA-44 and ML-DSA-65 signature verification in Soroban smart contracts. Stage 2 (2027): quantum-safe signer types as native options for classic accounts. Stage 3: Ed25519 deprecation, timing contingent on quantum developments. Stellar's architecture separates account identity from signing keys, enabling key rotation without address migration.
Solana — Research Phase (April 2026) Solana's two core development teams — Anza and Jump Crypto's Firedancer — independently selected NIST-standardized Falcon as the preferred post-quantum signature scheme. Early tests with Dilithium on the Solana testnet (December 2025) showed signatures up to 40x larger and network performance approximately 90% slower. No mainnet deployment timeline has been committed. The existing Winternitz vault, deployed experimentally, has fewer than 300 accounts on mainnet-beta.
XRP Ledger — Phase 2 Testing (H1 2026) Ripple published a four-phase roadmap on April 21 targeting full quantum resistance by 2028. Phase 2 (H1 2026): testing NIST-recommended PQC schemes under real XRPL workloads with Project Eleven. Phase 3 (H2 2026): candidate post-quantum signatures alongside existing ECC on Devnet. Phase 4 (2028): production-ready network amendment. Ripple is designing for cryptographic agility, supporting multiple algorithms rather than committing to a single scheme.
TRON — Mainnet Initiative Announced (April 2026) TRON announced plans to deploy NIST-standardized post-quantum signatures on mainnet, claiming first-mover status among large public blockchains. Initial implementation will use hybrid signing — validating both ECDSA and post-quantum signatures simultaneously. No testnet performance data has been published. Signature size increase: 10–121x over ECDSA.
Ethereum — Research Phase (Ongoing) The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026. Buterin proposed EIP-8141, which introduces native account abstraction allowing individual accounts to choose their own signature verification scheme — effectively enabling opt-in quantum-safe migration without a protocol-wide upgrade. EIP-8141 is being considered for the Hegotá hard fork (H2 2026). Full post-quantum infrastructure completion is targeted for approximately 2029.
Cardano — Planning Phase (2026) Cardano's Vision 2026 initiative includes post-quantum security as one of three core strategic pillars, with a focus on lattice-based cryptography. Five Cardano Improvement Proposals covering quantum-safe mechanisms are expected to move into implementation. Founder Charles Hoskinson has stated there is a "more than 50%" probability that commercially viable quantum systems emerge before 2033.
Post-quantum cryptography imposes direct costs on blockchain performance. The fundamental constraint: NIST-standardized post-quantum signatures are dramatically larger than their classical counterparts.
| Scheme | Signature Size | vs. ECDSA (64–70 B) | |--------|---------------|---------------------| | ML-DSA-44 (Dilithium) | ~2.5 KB | ~36x larger | | ML-DSA-65 | ~3.3 KB | ~47x larger | | Falcon-512 | ~666 B | ~10x larger | | Falcon-1024 | ~1.3 KB | ~19x larger |
Falcon offers the smallest signatures but requires constant-time floating-point arithmetic, creating implementation complexity. Dilithium (ML-DSA) is simpler to implement but imposes heavier bandwidth costs.
BNB Chain's testnet data provides the most concrete performance benchmark: a 40–50% throughput reduction, driven primarily by increased transaction and block sizes creating network propagation overhead — not by signature verification latency itself. Solana's early Dilithium tests showed a more severe 90% slowdown, though this was on unoptimized infrastructure.
The governance dimension compounds the engineering challenge. Unlike centralized systems that can mandate upgrades, blockchain migration requires coordinated action across validators, wallet providers, exchanges, DeFi protocols, and end users. Bitcoin's debate over BIP-361 illustrates the friction.
Bitcoin faces a unique problem: it cannot force users to migrate.
On April 14, 2026, a developer coalition including Jameson Lopp submitted BIP-361, proposing a three-phase phase-out of ECDSA and Schnorr signatures. The proposal would ultimately freeze all wallets that have not migrated to quantum-resistant addresses — including Satoshi's estimated 1.1 million BTC.
The proposal is contentious. Freezing addresses contravenes Bitcoin's property-rights ethos. Leaving them unfrozen creates a potential supply shock if a quantum attacker drains dormant wallets.
Alternative approaches are emerging. AmericanFortress proposed a patent-pending scheme using zero-knowledge proofs to secure vulnerable addresses via soft fork without requiring fund migration. Postquant Labs is building on Arch Network to deliver post-quantum protection without any Bitcoin fork.
BIP-360, a related proposal, outlines a broader quantum-resistant address format. Neither BIP-360 nor BIP-361 has achieved consensus.
The impasse highlights a structural tension: networks with stronger governance mechanisms (Stellar's key rotation, Ethereum's account abstraction, Ripple's amendment system) can migrate more cleanly than networks optimized for immutability and minimal governance.
Google's March 2026 white paper compressed the threat timeline. Breaking ECDSA-256 requires 20x fewer quantum resources than 2019 estimates. Google's internal migration deadline is 2029 — six years ahead of NIST's full disallowance date of 2035.
NEAR is the only major network with post-quantum signatures deployed on mainnet. BNB Chain has completed testnet validation. All others remain in research, planning, or early testing phases.
Performance costs are substantial and unavoidable. Post-quantum signatures are 10–121x larger than ECDSA. BNB Chain measured 40–50% throughput loss. Solana measured up to 90% degradation on unoptimized infrastructure.
$145 billion in Bitcoin P2PK addresses is directly exposed. The 6.9 million BTC with visible public keys represents the most concentrated quantum risk in the industry. BIP-361's proposed freeze remains contested.
Governance capacity may matter more than technical readiness. Networks with native key rotation (Stellar, XRP Ledger) or account abstraction (Ethereum's EIP-8141) have architectural advantages over networks where migration requires user-initiated action.
The migration window is 3–9 years. Google targets 2029. NIST targets 2035. Current quantum hardware (105 qubits) remains orders of magnitude below the attack threshold (500,000 physical qubits). The risk is not immediate, but migration timelines measured in years make early action rational.
The post-quantum migration is the largest coordinated cryptographic upgrade in blockchain history. It requires replacing the signature schemes that secure every transaction, every wallet, and every smart contract across networks holding $2.38 trillion in value.
The industry's response has been uneven. NEAR deployed. BNB Chain tested. Stellar, Ripple, and Ethereum have published structured roadmaps. Solana and Cardano remain in research phases. Bitcoin is stuck in governance debate.
The technical constraints are clear: larger signatures, slower throughput, complex migrations. The threat timeline is narrowing but not immediate. The networks that move first accept performance penalties today to avoid existential risk later.
No blockchain has solved the full problem. The race is underway, but no one has crossed the finish line.