New research has sharply lowered the estimated resources needed for quantum attacks on Bitcoin and Ethereum, turning post-quantum security from a distant concern into a pressing issue for blockchain developers and users.
Recent research has forced the crypto industry to take the quantum threat seriously. In 2026, scientists cut the estimated resources needed for a key quantum attack on Bitcoin and Ethereum's elliptic-curve cryptography by 86% in just two months. Quantum computers still can't break these networks today, but the shift from theory to practical planning is clear.
For anyone holding crypto or building blockchain infrastructure, the question is no longer if quantum computers will threaten digital assets, but whether networks can switch to quantum-resistant cryptography before the risk becomes real. If migration falls behind quantum progress, attackers could eventually forge digital signatures, approve unauthorized transactions, or decrypt sensitive data collected now for future use.
- Protocol Analyst
Recent studies have made the quantum risk more concrete. In September 2026, IonQ published a resource estimate suggesting that a future 20,000-physical-qubit fault-tolerant quantum computer could, under its model, break Bitcoin's secp256k1 cryptography in about 26 days. This isn't a working attack, but it puts a timeline on what might be possible if quantum hardware advances as expected.
Ethereum's developers are not waiting for a crisis. The Ethereum Foundation has set December 2029 as a target for making Ethereum's core protocol quantum-resistant, covering execution, consensus, and data layers. The roadmap includes staged upgrades for key registration, signature verification, and consensus mechanisms, with outside expert review planned from January 2027. Still, this is an engineering goal, not a guaranteed finish date, and full resistance across all protocol layers will require more milestones after the initial Hegotá upgrade.
Despite the urgency, a Reuters investigation found that none of the top 20 blockchains had implemented post-quantum cryptography as of 2026. The industry is still in the preparation phase. Bitcoin developers are working on BIP-360 and BIP-361, which define a quantum-resistant address format and a migration timeline that would eventually block new transactions to legacy address types. This signals a move toward proactive defense.
- Fidelity Digital Assets, Research & Insights
Bitcoin, Ethereum, and other major blockchains still rely on public-key cryptography that quantum computers could eventually break. The real risk isn't an immediate exploit, but that attackers could capture encrypted data or exposed public keys now and decrypt or forge signatures once quantum machines mature.
How PQC changes crypto security
Post-quantum cryptography (PQC) refers to algorithms designed to withstand attacks from both classical and quantum computers. PQC is about building defenses using new mathematical constructions that remain secure even if quantum computers become practical.
The National Institute of Standards and Technology (NIST) has finalized three PQC standards: ML-KEM for key exchange, and ML-DSA and SLH-DSA for digital signatures. These standards, released in August 2024, are now ready for implementation. NIST is urging organizations to start migrating systems that depend on quantum-vulnerable cryptography and is advancing additional algorithms for broader use cases.
For blockchain networks, adopting PQC is not a simple software update. Wallets, transaction formats, consensus mechanisms, smart contracts, exchanges, and hardware wallets may all need changes. Migration will take years of testing, coordination, and infrastructure overhaul to make sure new cryptographic systems are deployed safely and without disrupting network operations.
What crypto users need to know
For most individual users, quantum computing is not an immediate emergency. The more pressing issue is whether the networks, wallets, and exchanges they use have credible plans for cryptographic upgrades. Claims that a particular token or wallet is already "quantum-proof" should be viewed skeptically, since true quantum resistance depends on the underlying cryptographic system and its implementation, not just a marketing label.
Users may eventually see new wallet formats, signature schemes, or asset-migration procedures as networks introduce post-quantum protections. The industry is focusing less on predicting an exact "Q-Day" and more on whether migration can be completed before quantum computers become a practical threat.
According to an earlier breakdown, the push for tokenization and infrastructure upgrades is already changing how financial systems approach blockchain security and long-term planning.
In August 2024, NIST finalized its first three post-quantum cryptography standards after an eight-year project. By May 2026, nine more digital-signature candidates had advanced to the third round of NIST's standardization process, reflecting the need for multiple algorithms to address different applications and performance requirements.
If quantum migration falls behind, risks include compromised digital signatures, unauthorized transactions, and emergency upgrades that could disrupt blockchain operations. How severe these risks become depends on how quickly users and networks can move to safer cryptographic schemes.
For now, the industry's focus is on preparation, not panic. The latest research does not show that Bitcoin or Ethereum has been broken, but it does make clear that the time for theoretical debate is over. The challenge is building cryptographic agility and migration plans strong enough to handle the next era of computing power.
In 2026, IonQ's estimate that a 20,000-qubit quantum computer could break Bitcoin's secp256k1 cryptography in 26 days under its model marked a shift in the perceived timeline for quantum risk. NIST's release of ML-KEM, ML-DSA, and SLH-DSA as federal standards in August 2024 gave organizations the first official tools to begin migration. Ethereum's December 2029 target for quantum resistance at the protocol level shows that major networks are treating the threat as a practical infrastructure challenge, not a distant possibility.
Post-quantum cryptography is not about using quantum computers to secure data, but about defending against them. PQC algorithms are designed to resist both classical and quantum attacks, but their adoption requires careful planning, compatibility testing, and coordination across the entire blockchain ecosystem. As migration efforts pick up speed, the industry's ability to adapt will determine whether digital assets stay secure in a quantum future.
Quantum-resistant cryptography is fundamentally different from simply increasing key sizes or tweaking existing algorithms. PQC relies on mathematical problems that are believed to be hard for both classical and quantum computers, such as lattice-based, hash-based, code-based, or multivariate constructions. These new algorithms often come with trade-offs in performance, signature size, and compatibility, requiring careful integration into existing systems. For blockchain networks, the transition to PQC is a multi-year process that demands coordination among developers, wallet providers, exchanges, and users. The success of this migration will shape the security and resilience of digital assets for years to come.