• Home
  • Industry Blog
  • Beyond Bitcoin: How Other Blockchains Are Preparing for Quantum Computing

Beyond Bitcoin: How Other Blockchains Are Preparing for Quantum Computing

Picture2wolfgang.png
Wolfgang Amadeus VitaleCrypto Protocol Expert
31 Jul 20267 Min

Shor's algorithm would break the elliptic curve cryptography (ECC) behind Bitcoin, given a cryptographically relevant quantum computer (CRQC) powerful and stable enough to run it at the required scale. No such machine exists today, but any reasonable timeline pointing toward one is now measured in years, rather than decades. 

Currently standardized quantum resistant cryptography is available in two families: hash-based and lattice-based cryptography. Not all solutions deploy comfortably on a blockchain, and all major live networks are still at least partially relying on ECC.  

That is Bitcoin's position, and while the specifics vary, it is every other major protocol's position too, because they all sign transactions with schemes that reduce to the same underlying mathematical problem. The destination is common, but the routes are not, and most of them were published for the first time in the first half of this year.

Ethereum's post-quantum program

Bitcoin uses elliptic curve cryptography in only one place: transaction signatures, or in other words, spending coins. For consensus, instead, it relies on the security of hash functions, which is already quantum resistant.  

Ethereum does not have this advantage. ECC is used to secure the whole base layer, from transaction signatures, to consensus, to data availability. Everything must be replaced, which is clearly a challenge, but also an opportunity to rebuild and clear out technical debt Ethereum has carried for years.  

Such a broad upgrade requires long-term planning and coordination. The Ethereum Foundation took the initiative to run a dedicated post-quantum research effort, targeting a hash-based base layer by 2029, eliminating its dependence on ECC. That deadline is aggressive, and it needs to be, because there is not much margin.  

One of the main challenges is signature aggregation at consensus level: hash-based cryptography does not enable direct algebraic aggregation like ECC. Ethereum currently supports hundreds of thousands of validator keys constantly participating in consensus. This is good for decentralization, but impractical without signature aggregation. The plan is to use a hash-based  system to prove and verify the existence of a multitude of valid signatures, rather than directly aggregating them.

How the other major networks are preparing

Solana's two main validator clients, Agave and Firedancer, are independent software implementations of the same protocol. Both teams lean towards Falcon for transaction signatures, a lattice-based scheme whose signatures stay small enough not to slow a fast chain down too much. Alternatives remain under evaluation. For consensus, Anza proposed Quantumglow, a modification of the Alpenglow protocol that keeps fast finality while providing quantum resistance. The Solana Foundation's stated position is that the migration is still years away and the upgrade can be activated when it needs to be. 

Ripple published a four-phase roadmap in April, targeting a quantum-resistant XRP Ledger by 2028 with native post-quantum signatures and testing on a development network later this year. As with Solana, the leading candidate for transaction signatures is lattice-based, specifically ML-DSA, the NIST-standardized digital signature algorithm, but more options are under evaluation. The migration will be simplified by the separation between account identity and operational authorization. This is cryptographic agility: the key that authorizes transactions can be swapped while the balance stays at the same address.  

Cardano's post-quantum work runs together with Midnight, its privacy-focused partner chain, which went live in March leveraging conventional zero-knowledge proofs, the cryptography that lets a network verify a transaction without seeing what is inside. In February, Hoskinson announced Nightstream, a lattice-based replacement for those proofs, built with researchers connected to Microsoft and Stanford. He has said the intention is to carry the results back into Cardano. That is proof-layer work, though, and the signatures that spend ADA are a separate job that just recently started.

What separates the post-quantum migration paths

All these networks will find viable paths towards a post-quantum upgrade. Beyond technical choices, depending on design constraints and architectural differences, what separates them is how accustomed they are to changing the protocol, and their respective governance process.  

The XRP Ledger has a formal amendment process based on validator support thresholds. Cardano can authorize protocol upgrades through onchain governance involving validators, token holders via representatives, and a constitutional committee. Ethereum and Solana have good track records of coordinating upgrades off chain, through developers, client teams, testing and validator adoption. While governance processes can change (Solana recently formalized an onchain process), all these networks are used to coordinate regular, planned protocol changes, including hard forks. 

Bitcoin has no comparable mechanism. While the BIP process is also based on the same offchain social consensus seen on Ethereum and Solana, the network rejects the idea of a more structured coordination with recurring upgrade cycles. Each change must find its own path towards consensus. This friction makes coordinated migration harder, but also limits the ability of any narrower group to redefine Bitcoin’s rules.

Bitcoin

That is a deliberate choice rather than an oversight. Ossification, meaning the protocol should become increasingly difficult to change, is treated within Bitcoin as a value in itself. Quantum risk, as I said on our podcast with Charles Hoskinson, will be the test of that principle. 

And still, agreeing on an upgrade would solve only a part of the problem. The network can find an agreement on a post-quantum migration path, but nobody can force BTC holders to take it. Estimates of lost coins may vary, but roughly one million BTC attributed to Satoshi (5% of the total supply) is widely presumed unlikely to migrate. They form part of a much larger pool of vulnerable BTC: ~7 million coins whose public keys are available on chain. As soon as CRQCs are available, they can be used to start deriving the corresponding private keys, though most of their owners can still move them. Whether they do is the open question. 

We stay close to these developments across protocols so that our clients do not have to. The Quantum Update tracks them monthly.

Related Articles

  • Quantum Research

    Migration Is the Hard Part

    A sufficiently powerful quantum computer running Shor's algorithm could derive private keys from exposed public keys, breaking the elliptic curve cryptography (ECC) that Bitcoin depends on for digital signatures. The preparation window is measured in years, not decades, and the clock is already running.

    16 Jul 20269 Min
  • Quantum Research

    How Close Are We? The Quantum Timeline

    When you hold Bitcoin, what you actually own is knowledge of a private key. Elliptic-curve cryptography (ECC) lets you prove you know it without ever revealing it, using a digital signature and a corresponding public key.

    30 Jun 20269 Min
  • Quantum Research

    The Quantum Threat to Bitcoin: What You Need to Know

    The first thing I want to make very, very clear is that a quantum computer is not a faster version of a classical computer. It is a completely different machine. It works with a fundamentally different unit of information.

    16 Jun 20266 Min

Personal Support, Every Step

Our team of native experts are here to provide you with the tools, insights and support you need.

Opening hours

24/7 online

Monday to Friday: 7am to 7pm

contact@bitcoinsuisse.com

0800 800 008

Call us toll-free from Switzerland

+41 41 660 00 00

Call us from abroad