Executive Order 14412, signed June 22, 2026, mandates all U.S. federal agencies and contractors migrate to post-quantum cryptography (PQC) by December 31, 2030. NIST IR 8547 schedules the deprecation of RSA-2048 and ECC P-256 by 2030, with full disallowance by 2035. The cryptographic primitives t...
"We treat this as a decade-long structural renovation, not a patch." — Jameson Lopp, BIP-360 co-author, on Bitcoin's post-quantum migration
Executive Order 14412, signed June 22, 2026, mandates all U.S. federal agencies and contractors migrate to post-quantum cryptography (PQC) by December 31, 2030. NIST IR 8547 schedules the deprecation of RSA-2048 and ECC P-256 by 2030, with full disallowance by 2035. The cryptographic primitives that secure an estimated $2.8 trillion in on-chain assets — ECDSA-256 for Bitcoin, secp256k1 for Ethereum, Ed25519 for Solana — are now on a federal countdown.
The blockchain industry's response is uneven. Algorand shipped native Falcon-1024 accounts on mainnet in August 2026, making it the only top-50 chain with live post-quantum signatures. Bitcoin has two formal proposals — BIP-360 and BIP-361 — but no activation timeline. Ethereum launched a dedicated post-quantum security hub at pq.ethereum.org in March 2026 and targets core Layer 1 upgrades by 2029. Solana's early tests show quantum-safe signatures are up to 40x larger and slowed the network by approximately 90%. No cryptographically relevant quantum computer (CRQC) exists today, but Google's March 2026 research reduced the estimated qubit requirement to break ECDSA-256 by 20x, compressing the threat window.
On June 22, 2026, the White House signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks." The order requires federal agencies to transition their most sensitive systems to post-quantum encryption by December 31, 2030, and to post-quantum authentication by December 31, 2031. Federal contractors face the same 2030 deadline under updated Federal Acquisition Regulation requirements.
Within 30 days of signing, each agency must designate a PQC migration lead and begin a cryptographic inventory. The Office of Management and Budget replaced earlier guidance (M-23-02) with M-26-15, a five-phase transition timeline extending to 2035.
Separately, NIST IR 8547 schedules the deprecation of RSA-2048, ECDSA P-256, EdDSA, ECDH, and finite-field Diffie-Hellman by 2030. These algorithms are the public-key infrastructure of today's internet and today's blockchains. Migrating from RSA to ECC provides no protection: both fall to Shor's algorithm on a sufficiently powerful quantum computer. Full disallowance follows by 2035.
NIST finalized three PQC standards in August 2024 — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) — with a fourth, HQC, selected for standardization in March 2025. These standards now serve as the reference implementations for all migration work.
The mandate does not directly apply to decentralized protocols. But it reshapes the environment in which they operate. Custodians, exchanges, banking partners, and institutional allocators — all regulated entities — face binding PQC compliance deadlines. Any blockchain that cannot interoperate with post-quantum infrastructure risks exclusion from regulated capital flows.
No quantum computer in 2026 can break any deployed cryptographic system. Most credible estimates place a cryptographically relevant quantum computer 10 to 15 years away, with conservative estimates extending to 20-40 years. That said, the threat surface is not theoretical.
In March 2026, Google's Quantum AI team published research showing that breaking ECDSA-256 could require 20x fewer quantum resources than estimated in 2019 — specifically fewer than 500,000 physical qubits, or approximately 1,200-1,450 high-quality logical qubits. Google's Willow chip, a 105-qubit superconducting processor, is the first hardware to consistently achieve "below-threshold" error correction, where adding more qubits decreases rather than increases the overall error rate. Google has set a 2029 internal deadline to migrate its own authentication services to PQC.
The "harvest now, decrypt later" (HNDL) attack vector is already active, according to the FBI, CISA, and NIST. State-sponsored actors are collecting encrypted data — financial records, M&A communications, intelligence — with the expectation that future quantum computers will decrypt it. Blockchain data is particularly exposed because transaction histories are public, permanent, and based on the same cryptographic primitives flagged for deprecation.
For Bitcoin specifically, an estimated 6.5 to 6.9 million BTC — roughly 30-34% of circulating supply, worth approximately $500 billion at current prices — sit in addresses with public keys exposed on-chain, according to analysis cross-referenced between Google's whitepaper and on-chain data. Of these, approximately 1.72 million BTC reside in Pay-to-Public-Key (P2PK) outputs from 2009-era addresses, including the majority of coins attributed to Satoshi Nakamoto. An additional 2.3 million BTC are both exposed and dormant, having not moved in at least five years.
Bitcoin's response centers on two proposals merged into the official BIP repository in early 2026.
BIP-360 (published February 11, 2026) introduces Pay-to-Merkle-Root (P2MR), the network's first quantum-resistant address type. P2MR is structurally similar to Taproot (P2TR) with one key difference: the key-path spend is removed, keeping public keys off-chain until spending. A specialized team of 20 experts is working on the standard, according to core contributors.
BIP-361 (published April 2026, co-authored by Jameson Lopp, Pierre-Luc Dallaire-Demers, Christian Papathanasiou, Ian Smith, Joe Ross, and Steve Vaile) proposes a structured sunset of legacy signature types in two phases:
Both proposals are in Draft status. No activation timeline has been set. Bitcoin has no coordinated funding structure, central authority, or agreed migration schedule — a governance gap that stands in contrast to Ethereum's structured approach and the federal sector's binding deadlines.
The Ethereum Foundation formed a dedicated Post-Quantum Security team in January 2026, led by Thomas Coratger. On March 25, 2026, the Foundation launched pq.ethereum.org, a resource hub consolidating the protocol's PQC roadmap, specifications, research papers, EIPs, and a 14-question FAQ.
More than 10 Ethereum client teams run weekly post-quantum interoperability devnets. A $1 million Poseidon Prize targets improvements in hash-based cryptographic primitives. The 2nd Annual PQ Research Retreat is scheduled for October 9-12, 2026, in Cambridge, UK.
Ethereum's migration strategy avoids a single protocol-wide cutoff. Instead, the protocol uses account abstraction — specifically EIP-8141, slated for the Hegotá hard fork — to provide signature agility. EIP-8141 introduces a scheme field in transactions that can carry SECP256K1, P256, or ARBITRARY signatures, allowing users to opt into quantum-resistant signing schemes before the protocol mandates them.
The structured fork milestones target completion of core post-quantum infrastructure by approximately 2029. An academic paper published on the IACR ePrint archive (2026/352) provides a comparative analysis of post-quantum migration paths for both Bitcoin and Ethereum execution layers.
Algorand is the only top-50 blockchain by market capitalization with live post-quantum signatures on mainnet. Native Falcon-1024 accounts went live in August 2026 after the Algorand v5.0.0 upgrade reached the required network approval threshold. Falcon-1024 is one of NIST's selected post-quantum digital signature algorithms.
The implementation protects the entire history of the Algorand chain against quantum retrospective attacks. The protocol's roadmap targets broader quantum resistance — including multisignature wallets and staking support — during 2027.
By selecting a NIST-approved algorithm and deploying it to production, Algorand has set a benchmark that other chains have yet to match. However, Algorand's validator set and transaction volume are materially smaller than Ethereum or Solana, which simplifies deployment logistics.
The Solana Foundation is working with Project Eleven to test quantum-resistant cryptography. Early results, reported in April 2026, expose a fundamental tension: quantum-safe signatures are up to 40x larger than current Ed25519 signatures, and test implementations slowed the network by approximately 90%.
Solana's architecture prioritizes throughput — current theoretical capacity exceeds 65,000 transactions per second. The computational overhead of PQC signatures directly conflicts with this design goal. No timeline for mainnet PQC integration has been announced.
| Chain | PQC Status | Target Date | Approach | |-------|-----------|-------------|----------| | Algorand | Live on mainnet | Aug 2026 (done) | Falcon-1024 native accounts | | Ethereum | Interop devnets running | 2029 | Account abstraction + multi-fork | | Bitcoin | BIP-360/361 in Draft | No date set | P2MR address type + phased sunset | | Solana | Testing with Project Eleven | No date set | TBD (90% slowdown in tests) | | Cardano | Research phase | No date set | TBD | | Polkadot | Research phase | No date set | TBD |
Expert timelines for industry-wide migration cluster in the early 2030s. Chains that start late will finish late — and may face institutional capital exclusion before they finish at all.
The post-quantum migration confronting blockchain networks is not a speculative concern about distant technology. It is a compliance requirement with binding federal deadlines, a research priority for the companies building quantum hardware, and an engineering problem that every major chain must solve on different timescales with different tradeoffs.
The gap between Algorand's live deployment and Bitcoin's governance vacuum illustrates the structural challenge: decentralized networks cannot be patched by executive order. They require consensus — social, technical, and economic — and that consensus takes years to build.
The chains that begin migration now face engineering tradeoffs. The chains that wait face institutional exclusion from a financial system that will, per federal mandate, stop trusting the cryptography they depend on.