The quantum threat to cryptocurrency cryptography accelerated on three fronts in September 2026. On September 3, the G7 Cybersecurity Working Group and CISA published a joint advisory urging immediate migration to post-quantum cryptography. On September 8, the U.S. Commerce Department finalized $...
The quantum threat to cryptocurrency cryptography accelerated on three fronts in September 2026. On September 3, the G7 Cybersecurity Working Group and CISA published a joint advisory urging immediate migration to post-quantum cryptography. On September 8, the U.S. Commerce Department finalized $300 million in CHIPS Act grants to Rigetti, D-Wave, and Quantinuum — $100 million each — with the federal government taking minority equity stakes. On September 10, Eigen Labs published results from the ecdsa.fail challenge showing that researchers and AI agents reduced a key quantum attack resource benchmark for Bitcoin's secp256k1 curve by 86%.
Roughly 6.7 to 6.9 million BTC — approximately 34% of circulating supply — sit in addresses with public keys exposed on-chain, according to estimates from Google Quantum AI, Coinbase's advisory board, and Glassnode. Of that total, approximately 2.3 million BTC are dormant and cannot be migrated because private keys are presumed lost. No quantum computer in 2026 can exploit these vulnerabilities. Google's Willow chip carries 105 qubits; a credible attack requires an estimated 500,000 physical qubits or more. But the gap is narrowing faster than the industry's migration plans.
On September 8, the U.S. Department of Commerce signed definitive agreements with three quantum computing companies under the CHIPS and Science Act:
| Company | Award | Use of Funds | |---------|-------|-------------| | D-Wave | $100M | 100,000-qubit annealing system; 10,000-qubit gate-model system with 100 logical qubits | | Rigetti | $100M | Miniaturized readout electronics; expanded cryogenic capacity; high-connectivity chip fabrication | | Quantinuum | $100M | 300mm wafer fabrication of ion traps (with GlobalFoundries); laser/optical components (with Monarch Quantum) |
The grants are structured as R&D awards with milestone-based disbursements and non-controlling federal equity stakes. Shares of all three companies rose on the news: Rigetti +7.4% to $16.33, D-Wave +5.4% to $17.48, Quantinuum +3.9% to $51.56.
This follows the G7 Cybersecurity Working Group's September 3 publication, jointly released with CISA, titled Preparing for the Post-Quantum Era: A Call to Action. The document urges governments and regulated institutions to begin post-quantum cryptography transitions immediately, citing active "harvest now, decrypt later" campaigns by state-level adversaries. The G7 advisory does not mention cryptocurrency or blockchain by name but applies directly to the elliptic curve cryptography (ECDSA over secp256k1) securing Bitcoin, Ethereum, and most other chains.
Eigen Labs launched the ecdsa.fail challenge in late May 2026, creating a public scoreboard where researchers and AI agents compete to optimize quantum circuits for attacking secp256k1 — the elliptic curve underlying Bitcoin and Ethereum transaction signatures.
The results, published September 10, are significant:
More than 100 participants contributed to the challenge. The reductions are in circuit optimization for one component of a full quantum attack — they do not represent a complete end-to-end break. But they compress the theoretical timeline by reducing the hardware requirements for the attack's most computationally intensive step.
Separately, Google Quantum AI's March 2026 whitepaper estimated that breaking ECDSA-256 could require fewer than 500,000 physical qubits — roughly 20 times fewer than Google's own 2019 estimate. The paper modeled a real-time transaction hijacking attack achieving a 41% success rate against Bitcoin's 10-minute block confirmation window.
Google's current Willow processor carries 105 qubits. The gap between 105 and 500,000 is large — but in 2019, the gap was between 54 qubits (Google's Sycamore) and millions. The resource floor keeps dropping.
Not all Bitcoin is equally vulnerable. The risk concentrates in addresses where public keys are already exposed on-chain — either through legacy pay-to-public-key (P2PK) formats used in Bitcoin's early years, or through addresses that have previously sent transactions, which exposes the public key in the spending script.
Estimates of exposed supply as of mid-2026:
| Source | Exposed BTC | % of Supply | |--------|------------|-------------| | Google Quantum AI | 6.9M | ~33% | | Coinbase Advisory Board | ~7.0M | ~33% | | Glassnode (May 2026) | 6.04M | ~29% | | BlockEden analysis | 6.7M | ~32% |
Of this total, approximately 2.3 million BTC are classified as irreversibly at risk — dormant for more than five years, with private keys presumed lost. This includes an estimated 1.7 million BTC in Satoshi-era wallets, valued at over $100 billion at current prices. These coins cannot migrate to quantum-safe addresses because no one holds the keys.
The remaining 4.6 million exposed BTC could theoretically be moved to quantum-safe address types — if those types exist and if holders act before a cryptographically relevant quantum computer (CRQC) arrives. Most credible estimates place a CRQC 10 to 15 years out, with conservative projections extending to 20–40 years.
Bitcoin's approach to post-quantum migration is defined by two proposals:
BIP-360 (Pay-to-Merkle-Root / P2MR), introduced February 2026, creates a new address type that never exposes public keys on-chain — not even when spending. This eliminates the quantum attack surface for future transactions but does nothing for already-exposed addresses.
BIP-361 (Post Quantum Migration and Legacy Signature Sunset), proposed April 2026, outlines a three-phase sunset plan:
Neither BIP has reached consensus. The proposal to freeze coins is politically contentious within Bitcoin's governance culture. BIP-361's supporters argue it converts quantum security into a private economic incentive — users who migrate protect their own wealth. Critics argue that freezing $100+ billion in lost coins amounts to a supply-side confiscation by protocol diktat.
Ethereum's approach differs structurally. In February 2026, Vitalik Buterin published a roadmap identifying four cryptographic layers requiring post-quantum upgrades:
EIP-8052, now in draft, creates a precompiled contract for verifying Falcon-512 signatures within the EVM. Falcon's 666-byte signatures are compact enough for blockchain use. EIP-8141 would allow accounts to switch signature schemes without changing addresses — a migration path unavailable on Bitcoin.
The Ethereum Foundation in March 2026 launched a post-quantum security coordination hub involving more than 10 client teams. Ethereum's stated target is December 2029 for quantum resistance — three years out. Unlike Bitcoin, Ethereum's governance model allows coordinated protocol upgrades through hard forks managed by a known set of core developers and the Ethereum Foundation.
NIST's FALCON-based standard (FN-DSA / FIPS 206) remains in draft, with final publication expected late 2026 or early 2027. Ethereum's reliance on a not-yet-finalized standard introduces dependency risk.
Solana has taken a different path: deploying an experimental quantum-resistant vault using Winternitz One-Time Signatures (W-OTS). The vault generates a new cryptographic keypair for each transaction, using truncated Keccak-256 hashing with 224-bit preimage resistance.
As of April 2026, fewer than 300 accounts on Solana's mainnet-beta used the Winternitz vault. The scheme requires a new address for every transaction, creating significant UX friction. It is positioned as a temporary cold-storage tool, not a protocol-level migration.
Solana's longer-term roadmap centers on adopting Falcon once NIST finalizes FIPS 206, but no concrete EIP-equivalent proposal or timeline has been published.
The entire blockchain industry's post-quantum migration ultimately depends on NIST-standardized algorithms. Three standards were finalized on August 13, 2024:
| Standard | Algorithm | Type | Signature/Key Size | |----------|-----------|------|-------------------| | FIPS 203 | ML-KEM | Key Encapsulation | 800–1,568 bytes | | FIPS 204 | ML-DSA | Digital Signature | 2,420–4,595 bytes | | FIPS 205 | SLH-DSA | Digital Signature (hash-based) | 7,856–49,856 bytes |
A fourth standard, FN-DSA (FIPS 206), based on FALCON, remains in draft. This is the algorithm Ethereum's EIP-8052 targets. HQC was selected in March 2025 as a backup key encapsulation mechanism.
The signature size issue is non-trivial for blockchains. ML-DSA signatures at 2,420+ bytes are roughly 35× larger than current ECDSA signatures (approximately 70 bytes). Falcon-512 at 666 bytes is the most compact option but is not yet finalized. Larger signatures mean higher on-chain data costs, increased block sizes, or reduced throughput — direct economic consequences for every chain.
The quantum threat to cryptocurrency has not materialized and will not materialize for years. But three developments in September 2026 — the G7's explicit advisory, the $300 million federal hardware investment, and the ecdsa.fail benchmark reductions — collectively compressed the perceived timeline. The "harvest now, decrypt later" attack vector identified by the G7 means that data intercepted today becomes vulnerable retroactively once quantum hardware matures.
The blockchain industry's response is fragmented. Ethereum has a roadmap and a deadline. Bitcoin has proposals and a debate. Solana has a prototype and fewer than 300 users. The NIST standards underpinning all migration plans are partially finalized. The cost of migrating — in larger signatures, higher fees, and governance friction — remains unquantified.
What the data shows: the resource requirements for a quantum attack are falling faster than the industry is building defenses. That gap defines the risk.