Google's Quantum AI team published a whitepaper on March 31, 2026, demonstrating that breaking the elliptic curve cryptography (ECDSA-256) underpinning Bitcoin, Ethereum, and most blockchain networks could require 20x fewer quantum resources than estimated in 2019 — specifically fewer than 500,00...
"I've stopped thinking about post-quantum as a hurdle that we have to overcome, and I think of it more as an opportunity. It's an opportunity for Ethereum to stand out as the very first global computer that is quantum-safe." — Justin Drake, Ethereum Foundation Researcher
Google's Quantum AI team published a whitepaper on March 31, 2026, demonstrating that breaking the elliptic curve cryptography (ECDSA-256) underpinning Bitcoin, Ethereum, and most blockchain networks could require 20x fewer quantum resources than estimated in 2019 — specifically fewer than 500,000 physical qubits. The paper models a real-time transaction hijacking attack with a 41% success rate against Bitcoin's 10-minute block confirmation window, and identifies approximately 6.9 million BTC (~32% of circulating supply) sitting in wallets with exposed public keys.
No cryptographically relevant quantum computer exists today. Google's own Willow chip operates at 105 qubits, roughly 5,000x short of the threshold described in the paper. Conservative estimates place a viable threat 10 to 15 years out. But the paper, co-authored by Ethereum Foundation researcher Justin Drake, Stanford cryptographer Dan Boneh, and six Google Quantum AI researchers led by Ryan Babbush and Hartmut Neven, has compressed timelines enough to trigger concrete protocol-level responses across the industry. Sui, Ethereum, and Bitcoin have all initiated formal post-quantum migration work in 2026.
Prior estimates, based on unoptimized implementations of Shor's algorithm, suggested that breaking ECDSA-256 would require tens of millions of physical qubits. Google's March 2026 paper, titled "Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly," revised that figure downward to fewer than 500,000 physical qubits and approximately 1,200 logical qubits with tens of millions of quantum gate operations.
The paper's attack model is specific. It describes a scenario in which a sufficiently advanced quantum computer intercepts a pending Bitcoin transaction, extracts the private key from the exposed public key during the 10-minute block confirmation window, and submits a competing transaction. The modeled success rate: 41%. For Ethereum, with its shorter ~12-second block time, the window is narrower but the same vulnerability class applies to externally owned accounts using ECDSA signatures.
Google simultaneously announced an internal deadline to migrate its own infrastructure to post-quantum cryptography by 2029, lending institutional weight to the timeline acceleration.
A separate concern compounds the threat. Western intelligence agencies and national cybersecurity authorities have documented "harvest now, decrypt later" (HNDL) strategies, where adversaries systematically intercept and archive encrypted data to decrypt retroactively once quantum hardware matures. A September 2025 Federal Reserve study flagged distributed ledgers as particularly vulnerable to HNDL because their transaction histories are public, permanent, and cryptographically dependent.
Glassnode data as of May 20, 2026, measures 6.04 million BTC (30.2% of supply) with on-chain public key exposure. Separate analysis from Ark Invest and Unchained estimates roughly 35% of Bitcoin's total outstanding supply sits in theoretically vulnerable address types.
The exposure stratifies into two tiers. According to the "Quantum Horizon" research paper, approximately 2.3 million BTC are both quantum-vulnerable and dormant — they have not moved in at least five years. These coins are effectively irreversible losses in a quantum-capable future, as the key holders may be deceased, have lost access, or are otherwise unable to migrate. The remaining ~3.7 million BTC are migratable if holders act before a cryptographically relevant quantum computer (CRQC) materializes.
At current prices (~$76,000 per BTC as of August 21, 2026), the 6.04 million exposed BTC represent approximately $459 billion in at-risk value. The 2.3 million irreversibly exposed coins alone represent roughly $175 billion.
Ethereum faces a parallel problem. Every externally owned account (EOA) on Ethereum uses ECDSA for transaction signing. Vitalik Buterin identified four vulnerable components in a February 26, 2026, blog post: consensus signatures, data availability, externally owned accounts, and zero-knowledge proofs.
Sui became the first major Layer 1 to integrate NIST-approved quantum-resistant signature schemes in August 2026. The network will support two post-quantum schemes: ML-DSA-65 (lattice-based) for native account authentication, and SLH-DSA-SHA2-128s (hash-based) for high-value smart contract vaults.
Quantum-safe vaults are targeted for mainnet deployment by year-end 2026. Native ML-DSA-65 account authentication is planned for testnet by late 2026 and mainnet by Q1 2027. Existing account holders can migrate to quantum-safe keys without changing wallet addresses or generating new seed phrases.
The Ethereum Foundation formally established a Post-Quantum (PQ) team on January 23, 2026, led by Thomas Coratger, marking what Drake called "an inflection in the Ethereum Foundation's long-term quantum strategy." The team's mandate falls within the "Strawmap" framework — an experimental but structured L1 upgrade roadmap introduced after a January 2026 Ethereum Foundation workshop.
Buterin's published roadmap targets approximately seven network upgrades over four years, with hard forks at six-month intervals. The Glamsterdam upgrade, scheduled for H1 2026, is listed as a near-term milestone. The full quantum-resistance package — incorporating six signature schemes, 13 EVM precompiles, and recursive STARK aggregation — is targeted under the ETH2030 upgrade timeline. The Foundation allocated a $1 million research prize for post-quantum cryptography contributions.
Buterin stated in his February 2026 roadmap: "Ethereum will be quantum-safe. Ethereum will put users' privacy first." Quantum resistance and privacy, both absent from the 2023 roadmap, now lead the plan.
Bitcoin's response centers on two proposals. BIP-360, published February 11, 2026, and authored by Hunter Beast (MARA), Ethan Heilman, and Isabel Foxen Duke, introduces the network's first quantum-resistant address type. Originally titled Pay-to-Quantum-Resistant-Hash (P2QRH) and later renamed Pay-to-Merkle-Root (P2MR), it has been merged into Bitcoin's official BIP repository.
BIP-361, published April 14, 2026, addresses the harder problem: what to do with the 6+ million BTC already sitting in vulnerable addresses. The proposal outlines a multi-year phase-out of legacy ECDSA and Schnorr signatures, requiring holders to migrate coins to new quantum-resistant addresses. Unmigrated coins would eventually be frozen — including an estimated 1.1 million BTC widely attributed to Satoshi Nakamoto.
The Bitcoin community has not reached consensus on either proposal. The debate over whether protecting Bitcoin from future quantum attacks justifies restricting access to dormant coins — including potentially Satoshi's — remains unresolved.
NIST finalized three core post-quantum cryptographic standards in August 2024: FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, digital signatures), and FIPS 205 (SLH-DSA, hash-based signatures). A fourth algorithm, HQC, was selected for standardization in 2025.
Federal mandates now require adoption of these standards by 2030 for U.S. government systems. The United Kingdom, European Union, and Australia have published their own migration roadmaps with target deadlines between 2030 and 2035. NIST finalized 2026 technical requirements for post-quantum infrastructure migration in a supplementary guidance document.
The blockchain sector operates without a central authority capable of mandating timelines. Each protocol must achieve social consensus — a process that, as Bitcoin's BIP-361 debate illustrates, can take years even when the technical threat is well-documented.
The quantum-resistant cryptocurrency sector has reached $9.6 billion in market capitalization with daily trading volumes exceeding $1.5 billion, according to CoinGecko category data. Quantum-resistant or quantum-aware tokens saw notable short-term price movements following the Google paper's publication in March 2026: Quantum Resistant Ledger (QRL) rose approximately 50%, and Cellframe gained roughly 40%.
The category includes protocols with varying degrees of actual quantum resistance. QRL, built from inception with hash-based cryptography, represents the most direct implementation. Zcash, Starknet, and Nervos Network are included in the category due to their advanced cryptographic foundations, though none is fully quantum-resistant in its current deployed state.
The category remains a fraction of the total crypto market. At $9.6 billion, it represents approximately 0.37% of the $2.56 trillion total crypto market capitalization.
Kostas Chalkias, co-founder and chief cryptographer of Mysten Labs (Sui), announced on August 10, 2026, a personal initiative to mass-produce quantum-safe hardware wallet cards at a target retail price below $10. Chalkias has leased a dedicated factory to manufacture what he calls the "Quantum 2FA Sui card," using NFC with a one-to-two-second quantum signature time.
The announcement followed a security breach affecting Coldcard hardware wallets. "What happened to Coldcard will NEVER happen to my people," Chalkias wrote. He indicated that cards may be sponsored for users who cannot afford them.
The project operates outside Mysten Labs' corporate structure. If production targets are met, it would represent the first mass-market quantum-safe hardware wallet, addressing a gap between the protocol-level upgrades now underway and the end-user hardware that must ultimately execute quantum-resistant signatures.
The quantum threat to blockchain networks is not imminent. It is, however, closer than previously estimated, and the gap between "theoretical risk" and "protocol-level response" is closing. The March 2026 Google paper did not announce a new quantum computer. It announced that the existing mathematical attack surface is smaller than believed — and that the resource ceiling for exploitation is falling. Three of the paper's co-authors work directly on blockchain protocols.
The industry response splits into three timelines. Sui is targeting mainnet-grade quantum resistance within six months. Ethereum has committed to a four-year migration. Bitcoin, constrained by its governance model and the politically charged question of frozen coins, has no consensus timeline.
The economic stakes are defined by the 6 million BTC with exposed public keys. If a CRQC materializes before migration completes, those coins — and the addresses holding them — become the largest honeypot in financial history. The race is not against a quantum computer. It is against the entropy of decentralized governance.