# QRL Hub — full text (English)

> Every content page of QRL Hub, an independent educational resource on the quantum threat to cryptocurrency and QRL (the quantum-resistant blockchain). Not the official QRL project (https://theqrl.org). Available in 21 languages at /<lang>/<page>.md.

# QRL Hub | Quantum-Safe Crypto & the Quantum Threat to Bitcoin

> QRL is the first quantum-resistant blockchain (live since 2018). Learn why quantum computers threaten Bitcoin and Ethereum, when Q-Day arrives, and how QRL and QRL 2.0 keep crypto quantum-safe.

- Language: en
- Canonical URL: https://qrlhub.com/en
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## The quantum-safe future of crypto starts here

Quantum computers will break the cryptography behind Bitcoin, Ethereum, and nearly all of crypto. QRL has been post-quantum since 2018, and QRL 2.0 brings that protection to EVM smart contracts.

Explore QRL 2.0

Understand the Quantum Threat

🟢 UPDATED AUGUST 23, 2026

Educational content • Community maintained

### Quantum-Safe Cryptocurrency: $QRL

Post-Quantum Security

- Live mainnet since <strong>2018</strong>, post-quantum from day one
- Core today: <strong>QRL 1.x</strong> (XMSS hash-based signatures)
- Next: <strong>QRL 2.0</strong> (EVM smart contracts, quantum-safe)

Official Project

Official Site

## Developers & Community

### Documentation

Explore resources and join the ecosystem.

### GitHub

Explore resources and join the ecosystem.

### Community

Explore resources and join the ecosystem.

## The QRL Story

- 2016: a cancer surgeon saw the quantum threat the crypto world refused to see.
- 2018: QRL launched the world's first quantum-resistant blockchain.
- 2026: eight years of continuous, exception-free operation, still the most established quantum-safe chain in production.
- QRL 2.0 adds full EVM smart-contract support without giving up post-quantum security.
- Bitcoin has only partial proposals, and Ethereum's roadmap reaches just its base layer by 2029. QRL users have been protected since day one.

Read the Origin Story

⚡ SINCE 2018

## The clock is real, and shorter than most people think

The stakes

- A quantum computer breaks the elliptic-curve signatures (ECDSA, Ed25519) behind Bitcoin, Ethereum, and most of crypto, deriving a private key from a public one.
- Credible "Q-Day" estimates now cluster around <strong>2030</strong>, and the hardware bar keeps falling.
- March 2026: Google Quantum AI showed breaking Bitcoin may take far fewer qubits than once believed. Google set itself a <strong>2029</strong> deadline, and Microsoft's Majorana 2 targets a scalable machine in the same window.
- The attack itself keeps getting cheaper: the public <strong>ECDSA.fail</strong> leaderboard now runs <strong>60.9% leaner</strong> than Google's benchmark circuit, and it is still falling.
- NIST, the NSA, the EU, and the Federal Reserve have all issued migrate-now guidance.
- "Harvest now, decrypt later": keys exposed today can be recorded and cracked the moment the hardware arrives.

## Quantum News

See the Latest Developments

- <strong>Google Quantum AI</strong> (Mar 30, 2026, with the Ethereum Foundation and Stanford): breaking Bitcoin needs <strong>20x fewer qubits</strong> than estimated, under 500,000 physical, deriving a key in <strong>~9 minutes</strong>, inside Bitcoin's confirmation window.
- <strong>ECDSA.fail</strong> (Eigen Labs): a public leaderboard where solvers shrink the attack on Bitcoin's curve, now at <strong>915,947 Toffoli gates x 1,278 logical qubits</strong> and <strong>60.9% ahead</strong> of Google's benchmark, with the low-qubit record down to <strong>813</strong>. Snapshot as of Aug 23, 2026; the board moves week to week.
- <strong>Reuters (July 2026):</strong> no top-20 blockchain has post-quantum protection live on mainnet. Tron's new NIST signatures run on a test network only; making the live network safe still needs it switched on plus every holder moving their coins by hand.
- <strong>Quantinuum</strong> went public on Nasdaq with a <strong>$1.68B IPO</strong>; <strong>QuEra</strong> holds the verified record of <strong>96 logical qubits</strong>.
- <strong>~6.9 million BTC</strong> (including ~1.7M Satoshi-era coins) still sit in permanently exposed addresses.

## The migration is the slow part, not the computer

Why Bitcoin and Ethereum cannot simply fix it

Why Bitcoin and Ethereum cannot simply fix it:

- <strong>Patching a live, trillion-dollar chain is not a software update.</strong> A base-layer fix is not the same as being safe.
- <strong>Bitcoin:</strong> ~190 million UTXOs at ~7 TPS is close to a year of blocks doing nothing but migrating, realistically far longer.
- <strong>Bitcoin's dead coins:</strong> lost and Satoshi-era holdings (hundreds of billions) have no owner to move them and stay exposed forever.
- <strong>Bitcoin's proposals fall short:</strong> BIP-360 covers only new, unspent addresses; BIP-361 (freeze or migrate old coins) is still a draft with no date.
- <strong>Ethereum</strong> is the best-positioned major, but its roadmap only reaches the <strong>base layer</strong> around 2029.
- <strong>Ethereum's catch:</strong> account abstraction is the mechanism, not the migration. Hundreds of millions of accounts, every signature-checking contract, bridges, and L2s still have to move, voluntarily, and immutable contracts cannot simply be patched.
- <strong>Even the fastest mover proves the point:</strong> Tron put NIST post-quantum signatures on its test network in June 2026, but that is only step one. The live network still has to switch them on, and then every holder has to move their coins to a new protected address by hand, which no one can force.
- <strong>The bar:</strong> being safe means the <strong>entire stack</strong> migrates before Q-Day. As of July 2026, no top-20 chain has post-quantum protection live on mainnet, which is exactly what QRL was built to avoid.

## Tough Questions

- <strong>"Quantum is 20+ years away?"</strong> Google just set a 2029 deadline and started migrating.
- <strong>"Won't BIP-360 fix Bitcoin?"</strong> Only new addresses, one of two attack types. The <strong>~$470 billion</strong> already exposed stays exposed, forever.
- <strong>"Won't Ethereum's roadmap fix it?"</strong> Base layer only. Hundreds of millions of accounts, contracts, bridges, and L2s still have to migrate on top.
- <strong>"Why target crypto?"</strong> Because blockchain keys are <strong>public and permanent</strong>. The Federal Reserve already warned you.
- <strong>"Can I build or stake on QRL today?"</strong> Yes. QRL 2.0's Testnet V2 is live for smart contracts and staking right now.

See All FAQs

🔥 TOUGH QUESTIONS

## QRL 2.0

- A fully post-quantum EVM chain, quantum-safe from genesis, not bolted on later.
- Port your Ethereum contracts with minimal changes, often just <strong>a few lines</strong>.
- Post-quantum signatures built in from genesis: no migration, no emergency hard fork, no scramble.
- <strong>Testnet V2 is live</strong> (launched March 31, 2026); the cryptographic core has now been cleared by <strong>two independent firms</strong>, Halborn and Trail of Bits, and the full audit program is past the <strong>halfway mark</strong>.
- Launch prep is visible in the open (per QRL's weekly updates): nightly automated end-to-end tests of the full network, genesis parameters being finalized, and the 64-byte address migration (NIST Level 5) complete across the stack.
- Early builders get first-mover advantage on a chain that was never cryptographically vulnerable.

Explore QRL 2.0

🟢 TESTNET LIVE

## Quantum-safe from genesis, proven for eight years

What sets QRL apart

### Post-quantum from block zero

Every transaction signed with hash-based XMSS since 2018. Nothing to migrate, because no key was ever exposed.

### A proven track record

Eight years of continuous, exception-free public mainnet since June 2018, plus multiple independent security audits.

### NIST-aligned cryptography

XMSS is standardized in NIST SP 800-208 and RFC 8391. QRL 2.0 moves to ML-DSA-87 (NIST FIPS 204), with Falcon and ML-KEM on the networking layer.

### Genuinely open source

MIT-licensed core, no field-of-use restrictions, open for anyone to audit, build on, or fork.

### Crypto-agile by design

Already upgraded its signature scheme across the whole stack to a higher security level in about two weeks, no contentious fork, so it can adopt new standards without an emergency.

### Independently validated

QRL 2.0's cryptographic core has been cleared by two independent firms: Halborn (April 2026, all 13 findings Informational and resolved) and Trail of Bits (published August 2026, 15 findings: one High, four Low, ten Informational, all resolved). The remaining protocol components are still under audit, with roughly 50% of the program fully complete and remediated.

### Recognized

Named as already post-quantum secure in Google's March 2026 quantum whitepaper.

## Post-quantum smart contracts, EVM-compatible

QRL 2.0 in depth

- <strong>EVM-compatible:</strong> a Solidity-superset contract language on a post-quantum EVM, so Ethereum developers port over with minimal changes.
- <strong>Proof-of-Stake:</strong> energy-efficient consensus, post-quantum throughout.
- <strong>NIST-standard signing:</strong> ML-DSA-87 (FIPS 204), with crypto-agility built in.
- <strong>Live on testnet:</strong> Testnet V2 public since March 31, 2026. Deploy contracts and stake today.
- <strong>Benchmarked and audited:</strong> testnet throughput in Ethereum's range despite far larger post-quantum signatures; the cryptographic core cleared by both Halborn and Trail of Bits, all findings resolved. Roughly half of the full audit program is already complete and remediated; mainnet follows on completion.
- <strong>Migration path in preparation:</strong> the QRL 1.x tooling stack was refreshed across the board in July-August 2026 (wallet, CLI, core library, offline wallet generator), readying the path for existing holders.

Explore QRL 2.0

## A ready home for crypto's post-quantum future

The vision

- When the migration scramble hits, projects need somewhere already safe to go.
- QRL 2.0 is built for it: <strong>EVM-compatible</strong> to port into, and <strong>post-quantum by default</strong> so nothing is left to migrate once you arrive.
- QRL does not need to replace Ethereum. The goal is to be the proven, audited, post-quantum EVM destination while the rest of the industry is still mid-migration.
- A chain that was quantum-safe from its first block is how the long-term future of decentralized finance gets secured.

## Start here

- [Explore QRL 2.0](/zond)
- [Understand the quantum threat](/news)
- [Read the FAQ](/faq)
- [Read the origin story](/story)

Official project

theqrl.org


---

# The QRL Story | The First Quantum-Resistant Blockchain (2018)

> How Dr. Peter Waterland built QRL, the world's first quantum-resistant blockchain, live since June 2018 with NIST-approved XMSS cryptography - and how QRL 2.0 (Project Zond) brings quantum-safe, EVM-friendly smart contracts while Bitcoin and Ethereum race to retrofit security.

- Language: en
- Canonical URL: https://qrlhub.com/en/story
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## The QRL Story

The First Line of Defense in Blockchain's Quantum Age

## A Vision Born from Foresight

- In 2016, while the cryptocurrency world celebrated Bitcoin's rise and Ethereum's smart contract revolution, a cancer surgeon named Dr. Peter Waterland was contemplating a different kind of threat - one that could unravel the entire blockchain ecosystem.
- Dr. Waterland had been involved in cryptocurrency since 2012, buying Bitcoin heavily in early 2013 and later exploring Ethereum in 2016. But as he delved deeper into quantum computing research, he made a startling discovery: the elliptic curve cryptography (ECDSA) securing Bitcoin, Ethereum, and virtually every blockchain was completely vulnerable to quantum computers.
- This realization sparked an urgent question: What would happen when quantum computers arrived?
- The answer was clear - and alarming. Without quantum-resistant cryptography, the foundations of blockchain technology would crumble, exposing trillions of dollars in digital assets to theft and rendering decentralized systems insecure.
- Rather than wait for the inevitable crisis, Dr. Waterland decided to act. In August 2016, he began designing the Quantum Resistant Ledger (QRL) - the world's first blockchain built from the ground up to withstand quantum attacks.

## The Quantum Threat: An Existential Risk

### The Vulnerability of Modern Blockchains

Today, Bitcoin, Ethereum, and the overwhelming majority of the cryptocurrency market (roughly $2.5 trillion combined) rely on cryptographic algorithms that quantum computers will be able to break:

- Bitcoin and Ethereum: Protected by ECDSA-secp256k1, which Shor's algorithm breaks; Google Quantum AI's March 2026 whitepaper puts the attack at roughly 1,200 to 1,450 logical qubits and fewer than 500,000 physical qubits - a ~20x reduction from earlier estimates
- Cardano and Solana: Use EdDSA, requiring similar quantum computing power to compromise
- Roughly 6.9 million BTC sit in addresses with exposed public keys, and over 270 million Ethereum accounts would need individual migration to quantum-resistant addresses

The threat isn't theoretical anymore. Through 2026, Google set a 2029 Q-Day migration deadline, NIST's roadmap called for deprecating current encryption by 2030, QuEra demonstrated a record 96 error-corrected logical qubits, and in April 2026 a researcher publicly broke a 15-bit elliptic curve key on accessible quantum hardware - a 512-fold improvement over the previous public demonstration just seven months earlier. Ethereum researcher Justin Drake now puts the odds of a quantum computer recovering a Bitcoin private key from an exposed public key by 2032 at 10% or more.

Even the incumbents have started reacting: Bitcoin's quantum-resistant address proposal BIP-360 was merged in February 2026 (mainnet activation still unscheduled), and Ethereum formed a dedicated Post-Quantum Security team in January 2026. These are the first steps of migrations expected to take many years - protection QRL users have had since day one.

### The "Harvest Now, Decrypt Later" Danger

A Federal Reserve study published in late 2025 warns of an even more insidious threat: adversaries are already collecting encrypted blockchain data today, waiting for quantum computers powerful enough to decrypt it tomorrow.

- Past transactions can never be retroactively secured
- Privacy protections are already compromised
- The blockchain's immutability - its greatest strength - becomes its greatest weakness

## QRL: Eight Years Ahead of the Curve

### The First Quantum-Resistant Blockchain

On June 26, 2018, QRL launched its mainnet - becoming the world's first fully operational quantum-resistant blockchain. In June 2026, the network passed its eighth anniversary of continuous operation.

This wasn't a rushed response to hype. QRL spent:

- 2016-2017: Research, whitepaper development, and cryptographer consultations
- Two full years of testing before mainnet launch
- Multiple external security audits by firms including Red4Sec, X41 D-Sec, and most recently Halborn (2026), which found zero cryptographic vulnerabilities

QRL's achievement: Eight years of proven quantum security while others are just beginning to plan their migrations.

### The XMSS Advantage

QRL uses the eXtended Merkle Signature Scheme (XMSS) - a hash-based signature system that is:

- NIST-approved and standardized in NIST SP 800-208 (October 2020)
- IETF-specified in RFC 8391 (May 2018)
- Forward-secure: Previous signatures remain valid even if secret keys are compromised
- Minimal security assumptions: Relies only on hash functions, which are fundamentally quantum-resistant

### What Makes XMSS Quantum-Resistant?

Unlike ECDSA (which relies on elliptic curve problems that Shor's algorithm can solve), XMSS uses:

- Hash-based cryptography: Built on hash functions like SHA-256
- No vulnerable mathematical structures: Quantum computers offer no advantage against secure hash functions
- Proven security dating back to 1979: Hash-based signatures are the oldest and most well-understood post-quantum approach

### Building Right from Genesis Block

QRL didn't need to retrofit quantum security - it was designed quantum-resistant from the very first block:

- No migration required for existing users
- No vulnerable past transactions waiting to be decrypted
- Extensible address format supporting future cryptographic upgrades
- Crypto-agility built in: Can upgrade to new quantum-resistant algorithms as they emerge

### Proven Track Record

While others discuss theoretical implementations, QRL has:

- Eight years of mainnet operation (since June 2018)
- Multiple external security audits confirming its quantum resistance
- Active user base with desktop, mobile, and web wallets
- Ledger hardware wallet support (Nano X/S+)
- Real-world transaction history proving the technology works

## QRL 2.0: The Next Chapter

### From Quantum-Safe Money to Quantum-Safe Smart Contracts

QRL 1.x proved that a quantum-resistant blockchain works. QRL 2.0 (codenamed Project Zond) extends that security to the rest of Web3: a Proof-of-Stake Layer-1 that gives Ethereum developers a quantum-safe home without asking them to start over. Google's March 2026 quantum research paper specifically highlighted QRL as a presently post-quantum secure blockchain.

What QRL 2.0 delivers:

- Hyperion: A post-quantum smart contract language derived from Solidity - most valid Solidity code is already valid Hyperion, so porting Ethereum contracts often takes just a few lines of changes
- QRVM: An EVM-derived execution environment that runs Hyperion contracts, preserving the tools and workflows Ethereum developers already know
- NIST-standardized cryptography from genesis: ML-DSA-87 (Dilithium 5) signatures integrated across the entire stack, with SLH-DSA (SPHINCS+) and other algorithms addable post-mainnet through its crypto-agile address model
- Energy-efficient Proof-of-Stake consensus, replacing QRL 1.x's Proof-of-Work
- Familiar tooling: A MetaMask-like web3 wallet, Web3 API, block explorers, and a Remix-derived IDE

This wasn't rushed either. The development arc has been deliberate and public: devnet pre-release in 2022, beta testnet in 2024, Testnet V1 in 2025, and the audit-ready Testnet V2 launched on March 31, 2026.

### Where QRL 2.0 Stands Today

- Testnet V2 is live and open to everyone - developers are deploying smart contracts and staking on it right now. Halborn's audit of QRL's post-quantum cryptography libraries came back clean, with zero vulnerabilities found, and as of mid-2026 half of the comprehensive third-party audits are fully complete and remediated. Mainnet launches once the full audit process is done - eight years of refusing to ship security shortcuts, and that standard isn't changing at the finish line.
- For existing holders, the move from QRL 1.x is being designed as an automated, trustless claim process - a planned, orderly upgrade between two quantum-secure systems, not the emergency migration facing every ECDSA-based chain.

## Why QRL Matters Now More Than Ever

### The First-Mover Advantage in Security

In blockchain, being first often means network effects and adoption. But in quantum resistance, being first means something more important: survival.

QRL offers:

- Immediate security: No waiting for upgrades or migrations
- Proven technology: Eight years of real-world operation
- Future-ready infrastructure: QRL 2.0 brings quantum-safe, EVM-friendly smart contracts, live on its audit-ready public testnet today
- Migration pathway: A destination for assets fleeing vulnerable chains

### The Choice is Yours

- The quantum threat is real. The timeline is accelerating. The solution exists.
- QRL offers an alternative: A blockchain that never needs quantum migration because it was quantum-secure from day one.

Get Your QRL: Eight Years of Quantum Security. A Lifetime of Value Protection.

## Ready to Learn More?

Explore the Quantum Resistant Ledger and discover how it's protecting the future of blockchain.


---

# QRL FAQ | Buying QRL, Quantum Safety, QRL 2.0 & Building on Zond

> Straight answers about QRL: how and where to buy it, why it is quantum-safe, how XMSS and ML-DSA work, the quantum threat to Bitcoin and Ethereum, staking and mining, and how to build on QRL 2.0 (Zond).

- Language: en
- Canonical URL: https://qrlhub.com/en/faq
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## QRL Frequently Asked Questions

Learn about Quantum Resistant Ledger

## 1. Where do I get QRL?

QRL operates on its own blockchain and is NOT an ERC20 token. Only buy from exchanges listed on the official markets page to ensure you're getting genuine QRL. As of 2026, QRL is not available on Tier 1 exchanges and is mostly traded in the QRL/USDT pair (MEXC currently has the highest QRL volume). You can send USDT from your preferred exchange to any exchange listed on the official markets page to buy QRL.

Easy steps:

- Create a wallet: Visit [wallet.theqrl.org](https://wallet.theqrl.org), or download "QRL Mobile" by Volt Development (available for Android and iOS)
- Keep your wallet safe: Backup your wallet file, mnemonic phrase, and hexseed. Only share your QRL wallet address (never share your wallet file, passphrase, mnemonic, or hexseed)
- Buy QRL from an exchange: Purchase QRL from an exchange available in your location at [theqrl.org/markets](https://theqrl.org/markets).
- Withdraw to your wallet: After purchasing, it is recommended to withdraw your QRL from the exchange to your own wallet address for maximum security
- You're done! Your funds are now quantum-safe and under your control - no urgent migration needed, no complex setup required

## 2. How can I explore the QRL blockchain and view transactions?

You can explore the QRL blockchain using the official QRL Block Explorer at [https://explorer.theqrl.org/](https://explorer.theqrl.org/). The explorer provides comprehensive blockchain data including:

- Real-time Block Information: QRL mines one block per minute consistently, and you can browse through all blocks to see individual transactions
- Rich List: View the top wallet holders at [https://explorer.theqrl.org/richlist](https://explorer.theqrl.org/richlist). The first wallet (Q..f240) belongs to the QRL Foundation, and the second (Q..c016) to MEXC exchange, currently the highest volume exchange for QRL
- Transaction History: Browse through blocks to examine all transactions on the network
- Wallet Balance Lookup: You can view any wallet's balance by using this format: [https://explorer.theqrl.org/a/Q010500b8601fb018af63f22b31854f649f32249ffd7c2e887d80694b458bd18ee6ca9f9806c016](https://explorer.theqrl.org/a/Q010500b8601fb018af63f22b31854f649f32249ffd7c2e887d80694b458bd18ee6ca9f9806c016), where the last part is the wallet address
- Network Statistics: Monitor the health and activity of the QRL network in real-time. The network has operated since 2018 with roughly 900 active nodes globally

The block explorer is an essential tool for transparency, allowing anyone to verify transactions and understand the distribution of QRL tokens across the network.

## 3. Isn't quantum computing still decades away?

Not anymore. Breakthroughs through 2026 keep compressing the timeline:

- Google Quantum AI (March 2026): a landmark whitepaper cut the Bitcoin attack to roughly 1,200 logical qubits and under 500,000 physical qubits - about 20x lower than estimates from five years ago - warned that cryptographic migrations must begin without delay, and set a 2029 target for a useful error-corrected machine
- Iceberg Quantum (Feb 2026): new QLDPC-based architectures showed RSA-2048 can be broken with under 100,000 physical qubits, a 10x reduction; if similar techniques apply to ECDSA, the Bitcoin threshold drops further
- QuEra (Jan 2026): demonstrated a record 96 error-corrected logical qubits; Quantinuum's Helios reached 48 logical qubits at an industry-leading 2:1 encoding ratio
- Microsoft + Atom Computing: the Magne system (50 logical qubits from ~1,200 physical) is slated to be operational by early 2027
- US Department of Energy (April 2026): launched a Grand Challenge targeting a fault-tolerant machine by 2028; DARPA's Quantum Benchmarking Initiative advanced 11 companies toward utility-scale machines by 2033
- Roadmaps are converging on the threshold: IonQ targets 1,600 logical qubits by 2028; IBM targets 200 by 2029 (Starling) and 2,000 by 2033 (Blue Jay) - at or beyond the ~1,200 logical qubit attack level
- Google Willow (Dec 2024): first scalable error correction, since confirmed by four independent teams; Nature (Feb 2026) reported the research consensus shifting from "decades" to "within a decade"
- Timeline estimates range from aggressive ([Quantum Doom Clock](https://quantumdoomclock.com/): 2028) to conservative (institutional: 2035); expert surveys put a 20-33% probability of crypto breaking by 2030

The exact date is debatable. What's certain: "Harvest Now, Decrypt Later" attacks are happening TODAY. QRL has been quantum-resistant since 2018 - already protected, regardless of timeline.

## 4. Why would quantum computers target Bitcoin when banks have way more money?

Because it's not about how much money; it's about how easy it is to steal:

- Bitcoin advertises its targets publicly: Every vulnerable address and transaction is visible on the blockchain forever. Banks keep accounts and security details private
- Hundreds of billions sitting defenseless RIGHT NOW: about 34% of Bitcoin (6.5 to 6.9 million BTC, including ~1.7 million Satoshi-era coins whose early P2PK public keys have been exposed on-chain for over seventeen years) can never be protected. Attackers are already downloading this data today
- The attack is fast: per Google's March 2026 whitepaper, a 1,200-logical-qubit machine could derive a private key in roughly nine minutes - about the time it takes Bitcoin to confirm a single block
- Bitcoin theft is permanent and untraceable: Once stolen Bitcoin moves, it's gone forever. Nobody can freeze it, reverse it, or recover it. Banks have fraud detection, account freezes, transaction reversals, FDIC insurance, and law enforcement
- Banks are upgrading, Bitcoin can't agree on a plan: Cloudflare protects 50%+ of web traffic with quantum-safe cryptography NOW. JPMorgan deployed it in 2024. Apple secured iMessage. Banks upgrade in months. Bitcoin needs years to coordinate 10,900+ nodes, and every major upgrade causes civil war
- The attack window is closing for banks, wide open for Bitcoin: Banks will finish upgrading before quantum computers arrive. Bitcoin hasn't even agreed on which solution to use

Bottom line: Attackers go for easy money, not big money. Bitcoin is a $500B buffet with no locks, no alarms, and no police. Banks are fortified vaults.

## 5. Can't existing blockchains just upgrade?

In theory, yes. In practice, extremely difficult, and a base-layer fix is not the same as being safe:

- Bitcoin: BIP-360 (on testnet) protects only new addresses, and only while coins sit unspent; the public key is still exposed in the mempool on every spend, and it does nothing for the ~$470 billion already in exposed addresses. BIP-361, the proposal to freeze or migrate those coins, is still a draft with no activation date. Even moving the rest is enormous: Bitcoin's ~190 million UTXOs, at the chain's ceiling of ~7 transactions per second, would take roughly a year of blocks doing nothing but migration, and every migration spend briefly re-exposes the key.
- And even success is painful: a 2026 study in the Journal of the British Blockchain Association modeled Bitcoin's post-quantum transition directly - throughput drops 52-57%, fees rise 2-3x, and storage requirements expand dramatically, all without any user-facing benefit.
- Ethereum: its roadmap reaches the base layer by 2029 at the earliest, but that is only the protocol. Hundreds of millions of accounts, the entire smart-contract and DeFi stack, bridges, and Layer-2s still have to migrate on top, much of it voluntary and composably dependent. A 2029 base layer is a milestone, not safety.
- Both face: getting millions of users to each move their own coins, political fights over how to do it (see Bitcoin's SegWit debate), much larger signatures, no retroactive protection for past transactions, and a race against NIST's deadlines (ECDSA deprecated by 2030, prohibited by 2035).

QRL's advantage: already quantum-secure since 2018, with nothing to migrate before Q-Day. Upgrades like QRL 2.0 happen on QRL's timeline, not under emergency pressure.

## 6. Why QRL, and not one of the chains promising to add quantum safety later?

QRL is the most established quantum-resistant blockchain in production, operating continuously since 2018 with multiple independent security audits (Red4Sec and X41 D-Sec audited QRL 1.x in 2018; Halborn's April 2026 audit of QRL 2.0's post-quantum cryptography found zero vulnerabilities). Every claim below is verifiable on-chain or in public documents:

- Proven track record: Nearly eight years of reliable, exception-free operation make QRL the most battle-tested quantum-resistant network
- QRL 2.0: Testnet V2 launched March 31, 2026 as the audit-ready, code-frozen public testnet, enabling smart contracts, DeFi, and NFTs, all with quantum resistance built in. Independent audits were roughly 50% complete and fully remediated as of mid-2026, with mainnet contingent on their successful completion
- External validation: Google Quantum AI's March 2026 research paper specifically highlighted QRL as a presently post-quantum secure blockchain
- Ecosystem advantage: Any token created on QRL 2.0 automatically inherits quantum resistance
- The migration gap: no major chain has completed a post-quantum migration, and hardware roadmaps cross the attack threshold in a 2028-2031 window. Retrofitting a live chain means a hard technical upgrade plus coordinating millions of users to move their coins; QRL never has to make that migration, because it started quantum-safe

The position is easy to state and easy to check: QRL is the most established post-quantum blockchain, secure from its first block in 2018, and with QRL 2.0 it is set to become the first EVM smart-contract platform that is post-quantum from day one. Every other major chain still has its migration ahead of it.

Like any cryptocurrency, QRL is volatile, has limited exchange availability, and depends on future adoption that is not guaranteed. This is educational content, not investment advice - never invest more than you can afford to lose.

## 7. Why does QRL support multiple signature algorithms?

QRL uses NIST-approved post-quantum signature algorithms and is architected for cryptographic diversity and defense-in-depth against quantum threats:

- Current QRL Mainnet uses XMSS (hash-based) - standardized in NIST SP 800-208 and RFC 8391, built on hash-function security studied since 1979. XMSS is stateful, requiring careful tracking of one-time signatures
- QRL 2.0 launches with ML-DSA-87 (formerly CRYSTALS-Dilithium 5, lattice-based) - NIST-standardized in FIPS 204, stateless with unlimited signatures, and fully integrated across the stack (go-qrllib, go-qrl, qrysm, and the staking deposit contracts)
- SLH-DSA (formerly SPHINCS+, hash-based, FIPS 205) follows post-mainnet - to meet the accelerated launch window, the team prioritized ML-DSA for full NIST compliance at launch and rescheduled SLH-DSA integration to after mainnet release
- The key differences are their cryptographic foundations: hash-based (XMSS, SLH-DSA) versus lattice-based (ML-DSA). This diversity means if one cryptographic assumption is ever compromised, the other provides backup protection

## 8. Isn't XMSS limited by the number of signatures?

Yes, but it's manageable with proper planning:

### When creating a wallet, you choose your tree height, which determines the number of one-time signatures (OTS):

- Tree height 10: 1,024 signatures (light usage) - each outgoing transaction requiring a signature
- Tree height 14: 16,384 signatures (moderate usage)
- Tree height 18: 262,144 signatures (heavy usage)

### Plan ahead with slave transactions:

- Slave transactions link new wallets to your current wallet
- These slave wallets must be set up BEFORE you run out of signatures
- Once set up, slave OTS don't count against your master key's limit

### What if signatures run out?

- The wallet becomes permanently read-only - you can receive QRL but never spend it
- Your funds are locked forever with no recovery option

Choose an appropriate tree height for your usage. If needed, set up slave transactions. This effectively gives you unlimited transactions. On QRL 2.0, this limitation disappears entirely: ML-DSA is stateless and supports unlimited signatures per address.

## 9. Why should I trust QRL?

Track record:

- Nearly eight years of continuous, exception-free mainnet operation (since June 2018)
- Multiple external security audits: Red4Sec and X41 D-Sec (2018) for QRL 1.x; Halborn (April 2026) for QRL 2.0's cryptography, finding zero vulnerabilities; further independent audits of QRL 2.0 underway ahead of mainnet
- Open-source code available for review at [github.com/theQRL](https://github.com/theQRL)
- NIST-approved cryptography (XMSS per SP 800-208 today; ML-DSA per FIPS 204 on QRL 2.0)
- Independently recognized: cited in Google Quantum AI's March 2026 research paper as a presently post-quantum secure blockchain, and rated fully quantum-ready by independent quantum-readiness assessments
- Active development and transparent communication
- Member of Linux Foundation Post-Quantum Cryptography Alliance

## 10. How does QRL compare to Bitcoin and Ethereum?

- Feature
- Bitcoin/Ethereum
- QRL

- Quantum Resistant
- No
- Yes

- Security Basis
- Elliptic curve math
- Hash-based (1.x) / NIST post-quantum lattice (2.0)

- Quantum Risk
- Broken by Shor's algorithm
- Secure against quantum computers

- Migration Needed
- Yes (complex, years)
- No

- Smart Contracts
- Yes (quantum-vulnerable)
- Yes, quantum-safe (QRL 2.0)

- Standardization
- Mature (but vulnerable)
- NIST-standardized cryptography

## 11. How does the QRL 2.0 hard fork compare to a potential Bitcoin hard fork for post-quantum cryptography?

A hard fork means migrating to another blockchain. Let's compare how BTC and QRL differ in their approach:

### Migration Timeline:

- QRL: You can take your sweet time migrating. Your old wallet is already quantum safe, so there's no need to hurry.
- BTC: If you don't migrate, unmigrated wallets become quantum bounties. At least 10-15% of the supply won't be migrated regardless and will become bounties flooding the market.

### Destination Clarity:

- QRL: The destination (QRL 2.0) is agreed upon, built, live on an audit-ready public testnet since March 2026, and undergoing independent security audits.
- BTC: The destination is up in the air. People can't agree, and there's no solid plan approved by all miners, wallet holders, and stakeholders.

### Urgency Level:

- QRL: No hurry - migrate at your convenience.
- BTC: Migrate by 2028/2030 or face total destruction of value.

The key difference is that QRL users have the luxury of time and certainty, while Bitcoin faces a high-stakes race against quantum computing advances with no consensus on the solution.

## 12. Will there be two separate QRL coins after the QRL 2.0 upgrade, or just one?

There will only be ONE QRL. After QRL 2.0 launches, you'll migrate your QRL from the old chain to the new QRL 2.0 chain - but it's the same coin, just on a better blockchain. The QRL 2.0 chain is still called QRL; "QRL 2.0" (also known as "Zond") is just the name of the upgrade.

### How migration works:

- One-way transfer - You move your QRL from the old chain to QRL 2.0 (not a "split" or "fork" creating two coins)
- No deadline pressure - Migrate at your own pace since the old QRL chain is already quantum-safe
- Same value, better features - Your QRL keeps its value and name, but now you get smart contracts, DeFi, staking, and improved algorithms
- Old chain sunset - Eventually, the old chain will stop receiving updates, and exchanges will only list QRL 2.0 QRL

Migrate when ready (no rush), move your QRL to the QRL 2.0 chain for continued transactions and new features, and enjoy having one unified QRL on a superior blockchain.

## 13. What makes hash-based signatures special?

Unlike elliptic curve cryptography, hash-based signatures:

- Rely only on secure hash functions (like SHA-256)
- Have no mathematical structures vulnerable to quantum algorithms
- Have been studied and proven secure since 1979
- Require only basic security assumptions
- Offer forward security (past signatures remain valid even if keys are compromised)

## 14. Can I use QRL for smart contracts?

Yes, through QRL 2.0:

- EVM-friendly quantum-resistant blockchain: contracts run on the QRVM (Quantum Resistant Virtual Machine), an execution environment forked from the Ethereum Virtual Machine
- Supports smart contracts in Hyperion, a post-quantum superset of Solidity: most valid Solidity code is also valid Hyperion, with NIST-approved post-quantum cryptographic primitives layered on top
- Easy migration for Ethereum developers: familiar Web3 API and tooling, with contract ports often needing only a few lines changed
- Currently on an independently audited public testnet (Testnet V2, live since March 31, 2026, deployed from code-frozen repositories); mainnet follows completion of the external audits

## 15. What if a better quantum-resistant algorithm is developed?

QRL is designed for this:

- Crypto-agility built into the architecture
- Extensible address format (3-byte cryptographic descriptors on QRL 2.0) supports future upgrades
- Can adopt new NIST-approved algorithms as they emerge - SLH-DSA (SPHINCS+) is already scheduled for integration after the QRL 2.0 mainnet launch
- Migration to QRL 2.0 is a planned, orderly process - not an emergency response to quantum threats
- Unlike other blockchains scrambling to retrofit security, QRL controls its upgrade timeline

## 16. I'm a developer. How do I start building on QRL 2.0?

QRL 2.0 Testnet V2 is live and open to everyone:

- Read the docs: Start at [test-zond.theqrl.org](https://test-zond.theqrl.org) for node setup, wallet creation, and smart contract guides
- Run the clients: QRL 2.0 mirrors Ethereum's architecture with an execution client (go-qrl) and a consensus/beacon client (qrysm). Binaries are available for Windows, Linux, and macOS, and you can also spin up a full private testnet locally
- Create a wallet: Generate an ML-DSA account via the CLI or the zond-web3-wallet Chrome extension, which supports Argon2id encryption, multi-account management, QRC20 tokens, and 30+ JSON-RPC methods
- Get testnet funds: Request testnet QRL in the official [QRL Discord](https://theqrl.org/discord)
- Write and deploy contracts: Use Hyperion (most valid Solidity is valid Hyperion) compiled for the QRVM. A full example deployment workflow lives at [github.com/theQRL/qrl-contract-example](https://github.com/theQRL/qrl-contract-example), and Vortex IDE (a Remix fork) support is on the roadmap
- Use familiar Web3 tooling: QRL-adapted forks of web3.js and wallet.js are available, and the go-qrl JSON-RPC API documents the standard methods (getProof, createAccessList, feeHistory, filters, logs, and more), plus 25+ documented beacon chain endpoints

## 17. How is developing on QRL 2.0 different from Ethereum?

QRL 2.0 deliberately parallels Ethereum, so most of your knowledge transfers directly. The differences reflect deliberate post-quantum security trade-offs:

- Block time: 60 seconds per block (vs ~12 seconds on Ethereum), reflecting the computational overhead of post-quantum cryptography
- Signatures and addresses: accounts use ML-DSA-87 signatures, which are larger than ECDSA. Addresses use a QRL-specific format with a "Q" prefix and 3-byte cryptographic descriptors instead of Ethereum's 0x format
- Naming: token standards are QRC (e.g., QRC20 instead of ERC20), and denominations are QRL/Planck/Shor instead of ETH/Gwei/Wei
- Language: contracts are written in Hyperion, a superset of Solidity - existing Solidity contracts typically port with minimal changes, often just a few lines
- Tooling: you'll need QRL-adapted tooling (compiler, web3.js/wallet.js forks) to compile and deploy, though the modifications to standard Ethereum workflows are minimal
- Consensus: proof-of-stake from genesis, with slashing and whistleblower rewards built in

## 18. Can I stake QRL and earn rewards?

Yes - on QRL 2.0. The current QRL 1.x mainnet is proof-of-work (mined), but QRL 2.0 runs proof-of-stake:

- You can practice as a validator today on Testnet V2 using testnet funds, staking via a deposit contract and CLI (similar to Ethereum's model)
- Validator hardware requirements are modest compared to mining, making participation accessible
- Slashing penalties and whistleblower rewards keep validators honest
- Once QRL 2.0 mainnet is live and you've migrated, staking becomes a way for holders to earn rewards while securing the network

Final mainnet staking parameters (minimum stake, reward rates) will be confirmed at QRL 2.0 mainnet launch. Check [test-zond.theqrl.org](https://test-zond.theqrl.org) and the official Discord for current values rather than relying on older blog posts.

## 19. Can I mine QRL today?

- Yes. The current QRL 1.x mainnet uses proof-of-work with the RandomX algorithm (the same CPU-friendly algorithm as Monero), so you can mine with an ordinary CPU - no ASICs required. You can mine solo via your own node or join a mining pool; see [docs.theqrl.org](https://docs.theqrl.org/) for setup guides.

## 20. How exactly will the migration from QRL 1.x to QRL 2.0 work?

The broad design, as described by the team (final details will be published at mainnet launch):

- A snapshot of QRL 1.x balances is taken
- A migration smart contract on QRL 2.0 lets holders make a user-initiated claim of their coins on the new chain
- The process is one-way and can be done at your own pace - because QRL 1.x is already quantum-safe, there is no security deadline forcing you to rush
- Coins held on exchanges are expected to be migrated by the exchanges themselves, as is standard for chain upgrades

Scammers exploit migration events. Follow only official channels ([theqrl.org](https://theqrl.org), the official Discord, @QRLedger on X) for migration instructions. No legitimate process will ever ask for your mnemonic, hexseed, or private keys.

## 21. I have old QRL ERC20 tokens on Ethereum. Are they still valid?

No. The ERC20 QRL token (contract 0x697b...b97F) was only a placeholder used before the mainnet launched. It was migrated 1:1 to native QRL via a burn process starting in 2018, and that migration window has long since closed. Genuine QRL exists only on the QRL blockchain (addresses starting with "Q"). Anyone selling you "QRL" as an Ethereum token today is selling a worthless placeholder or running a scam. Always verify markets via [theqrl.org/markets](https://theqrl.org/markets).

## 22. Does QRL work with hardware wallets?

- Yes. QRL has official Ledger support (Nano X and Nano S Plus) via the QRL Ledger app, usable with the official web wallet at [wallet.theqrl.org](https://wallet.theqrl.org). Your private keys stay on the device while still using quantum-resistant XMSS signatures. Because XMSS is stateful, the Ledger app tracks your one-time signature index for you - follow the official documentation when setting up.

## 23. Is anything about QRL NOT quantum-resistant?

- Everything that controls funds and consensus is post-quantum secure. All native addresses are XMSS-based by default, and no classical (ECDSA-style) account type even exists on QRL.
- The one classical component is the peer-to-peer networking layer, which uses classical cryptography for node identity. This cannot be used to steal funds, forge transactions, or attack consensus; at worst, a quantum adversary could attempt network-level nuisance attacks (eclipse or denial-of-service). ML-KEM (NIST's post-quantum key encapsulation standard, FIPS 203) integration for the P2P layer is in development.
- Independent quantum-readiness assessments rate QRL's production mainnet as fully quantum-ready, with no current quantum-critical vulnerabilities identified.

## 24. Is Bitcoin safe from quantum computers?

Not permanently. Bitcoin's ECDSA signatures can be broken by a large enough quantum computer running Shor's algorithm, which would expose any address whose public key is visible on-chain, including reused addresses and every pending transaction. Roughly 6 to 7 million BTC currently sit in quantum-vulnerable addresses. Google's March 2026 whitepaper put the attack at roughly 1,200 logical qubits, able to derive a private key in about nine minutes. Bitcoin works fine today, but it has no quantum-safe signature scheme live on mainnet, and "Harvest Now, Decrypt Later" attacks mean exposed keys are already being recorded for future decryption. QRL has used quantum-resistant XMSS signatures since 2018.

## 25. Is Ethereum safe from quantum computers?

No, not yet. Ethereum also relies on ECDSA (secp256k1) signatures, which a cryptographically relevant quantum computer could break to forge transactions and drain accounts. Vitalik Buterin has proposed an emergency post-quantum hard fork, the roadmap reaches the base layer by 2029 at the earliest, and account abstraction may ease a future migration, but no quantum-safe signature scheme is live on Ethereum mainnet today and the approach remains unproven at scale. QRL was built quantum-resistant from genesis in 2018.

## 26. What is the best quantum-resistant cryptocurrency?

QRL (Quantum Resistant Ledger) is the longest-running quantum-safe blockchain, live since 2018 and built from the ground up on NIST-recommended XMSS hash-based signatures instead of the vulnerable ECDSA used by Bitcoin and Ethereum. Unlike projects retrofitting post-quantum cryptography under deadline pressure, QRL has been quantum-resistant since genesis, and QRL 2.0 adds an EVM-compatible, quantum-safe smart contract platform, live on an audited public testnet since March 2026. That track record - validated by independent audits and cited in Google Quantum AI's 2026 research - is why QRL is widely considered the most established quantum-proof cryptocurrency.

## 27. When will quantum computers be able to break Bitcoin (Q-Day)?

Estimates for "Q-Day" range from 2028 to 2035. In March 2026, Google Quantum AI cut the estimated cost of breaking Bitcoin to roughly 1,200 logical qubits and under 500,000 physical qubits, and set a 2029 target for cryptographically relevant quantum computing; IonQ's roadmap targets 1,600 logical qubits by 2028, IBM targets 2,000 by 2033, and the Quantum Doom Clock points to 2028, while conservative institutional estimates cluster around 2030 to 2035. Expert surveys put a 20 to 33 percent chance of today's encryption being broken by 2030. The verified state of the art (QuEra's 96 error-corrected logical qubits, January 2026) remains well below the threshold, so the exact date is uncertain - but "Harvest Now, Decrypt Later" harvesting is happening now, which is why quantum-safe options like QRL matter today.

## 28. Where can I follow QRL development or get help?

The official channels and resources:

- Official site: [theqrl.org](https://theqrl.org) - blog, roadmap, and markets
- Documentation: [docs.theqrl.org](https://docs.theqrl.org) for QRL 1.x; [test-zond.theqrl.org](https://test-zond.theqrl.org) for QRL 2.0
- Source code: [github.com/theQRL](https://github.com/theQRL) - all core repositories are open source, with six core QRL 2.0 repos code-frozen since February 2026 for the audit process
- Community: [Discord](https://theqrl.org/discord) (the most active channel, including testnet fund requests and developer support), [Reddit r/QRL](https://www.reddit.com/r/QRL/), [Telegram](https://t.me/QRLedgerOfficial), and [@QRLedger on X](https://x.com/qrledger)

Team members will never DM you first, and no legitimate support will ever ask for your mnemonic, hexseed, wallet file, or private keys.

## Ready to Get Started?

Join the quantum-resistant future with QRL today.


---

# QRL 2.0 (Zond) | Testnet V2 Live, Audits 50% Complete, Quantum-Safe EVM

> QRL 2.0 (Zond) Testnet V2 is live - deploy smart contracts and stake today. Security audits ~50% complete ahead of mainnet. EVM-compatible Proof-of-Stake blockchain with NIST-approved ML-DSA-87 (Dilithium) at Security Level 5. Build quantum-resistant DeFi, NFTs, and dApps with an easy Ethereum migration path.

- Language: en
- Canonical URL: https://qrlhub.com/en/zond
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## QRL 2.0

The Future of Quantum-Resistant Smart Contracts

## What is QRL 2.0?

QRL 2.0 (also known as QRL Zond) is QRL's next-generation quantum-resistant blockchain - an EVM-compatible Layer-1 engineered for the post-quantum era. It represents the evolution of QRL from Proof-of-Work to Proof-of-Stake, bringing smart contract capabilities to the world's first quantum-resistant blockchain.

As of March 31, 2026, [QRL 2.0 Testnet V2 is live](https://www.theqrl.org/press/qrl-launches-testnet-v2-for-its-postquantum-evmfriendly-blockchain/): a public proof-of-stake network where developers can deploy smart contracts today and users can stake immediately. Mainnet follows once external audits are complete.

QRL 2.0 is being independently audited before mainnet, and its cryptographic core has now been cleared by two independent firms. [Halborn](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/)'s review of the post-quantum cryptography libraries (April 3, 2026) found no cryptographic vulnerabilities, with all 13 findings rated Informational, the lowest severity. On August 4, 2026, [Trail of Bits published its security assessment of go-qrllib](https://www.theqrl.org/press/qrl-announces-trail-of-bits-publication-of-security-assessment-of-its-cryptographic-heart-with-all-findings-resolved/), QRL's core post-quantum cryptography library: 15 findings (one High, four Low, ten Informational), all resolved after remediation and re-review. The findings concerned the robustness of the library's exported API and supporting controls rather than the correctness of its cryptographic primitives; the report appears in Trail of Bits' [official publications repository](https://github.com/trailofbits/publications). The remaining protocol components (consensus, node, VM, wallets) are still under audit; per [QRL's weekly updates](https://www.theqrl.org/weekly/), roughly 50% of the audit program is fully complete, including all necessary remediation. Mainnet launch is gated on the successful completion of these audits.

### Core Features

Ethereum Virtual Machine (EVM) compatible

Port Ethereum contracts with minimal changes

Proof-of-Stake consensus

Energy-efficient consensus replacing the current PoW model

Smart contracts via Hyperion

A post-quantum superset of Solidity, where most valid Solidity is also valid Hyperion

NIST-approved cryptography

ML-DSA-87 (Dilithium) for signatures, targeting full NIST Security Level 5

Crypto-agility

New NIST-approved post-quantum algorithms can be added through an address-descriptor model, without a contentious hard fork

Built for developers

Familiar Web3 tooling, seamless migration path

## Why QRL 2.0 Matters

### The Quantum Threat is Accelerating

The threat of quantum computers breaking encryption has shifted from "decades away" to a near-term concern. Industry experts now project cryptographically relevant quantum computers (CRQCs) could emerge as early as 2027-2033. The most significant recent developments:

- A [Google Quantum AI whitepaper (March 30, 2026)](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf), co-authored with the Ethereum Foundation and Stanford, cut the estimated cost of a Bitcoin attack to roughly 1,200-1,450 logical qubits and fewer than 500,000 physical qubits - about a 20x reduction - and warned that cryptographic migration needs to begin without delay. The same paper identified QRL as a presently post-quantum-secure blockchain.
- A [Caltech/Oratomic paper (March 31, 2026)](https://arxiv.org/pdf/2603.28627) showed the same class of attack could run on as few as ~10,000-26,000 neutral-atom qubits using high-rate qLDPC codes.
- A [EUROCRYPT 2026 paper](https://eprint.iacr.org/2026/280) pushed the minimum logical-qubit requirement for 256-bit elliptic curves down to 1,098.
- QuEra demonstrated a [verified record of 96 logical qubits (Nature)](https://www.nature.com/articles/s41586-025-09848-5), the largest verified logical-qubit count to date.
- [NIST](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf), the [NSA](https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF), and the U.S. [Federal Reserve](https://www.federalreserve.gov/econres/feds/harvest-now-decrypt-later-examining-post-quantum-cryptography-and-the-data-privacy-risks-for-distributed-ledger-networks.htm) have all issued formal warnings; the EU's DORA regulation (effective January 2025) and U.S. federal mandates require migration readiness by 2035.

Legacy blockchains face a monumental migration task - complex technical hurdles, performance trade-offs, and the challenge of user consensus. Bitcoin's own draft proposals ([BIP-360](https://bip360.org/bip360.html), [BIP-361](https://www.bip361.org/)) protect only newly created coins or rely on freezing legacy ones, and have no activation timeline. QRL 2.0 is built quantum-ready from genesis instead.

### A Safe Haven for the Ethereum Ecosystem

The EVM ecosystem represents over $300 billion in value, with hundreds of billions more across EVM-compatible chains like Polygon, Arbitrum, Optimism, BNB Chain, and Avalanche - all currently secured by quantum-vulnerable ECDSA signatures. QRL 2.0's pitch to that ecosystem is straightforward:

- ERC-20 tokens can be replicated on quantum-resistant infrastructure (as QRC-20)
- DeFi protocols can deploy before quantum threats materialize
- NFTs and digital assets secured against future attacks
- A familiar migration target for EVM developers and institutions seeking long-term security

QRL 2.0's differentiator is that it is fully post-quantum from genesis: post-quantum cryptography secures the chain end to end, not as an optional or partial add-on layered onto an otherwise ECDSA-based network. That, paired with an EVM-familiar toolchain and the longest track record of any post-quantum-native chain, is the core of the pitch to the EVM ecosystem.

## Technical Architecture

### Two-Layer Design

QRL 2.0's architecture mirrors Ethereum's post-Merge design:

#### Execution Layer (go-qrl/gqrl)

- Monitors newly broadcasted transactions
- Processes them through the Quantum Resistant Virtual Machine (QRVM), an EVM-friendly VM forked from the EVM
- Maintains the current state and database

#### Consensus Layer (qrysm)

- Executes the Proof-of-Stake consensus algorithm
- Coordinates validators across the network
- Ensures reliability and integrity of network operations

### Post-Quantum Cryptography

QRL 2.0 is built on NIST-approved post-quantum standards, using a crypto-agile, defense-in-depth model rather than a single algorithm:

#### ML-DSA-87 ([Dilithium](https://cryptojedi.org/papers/dilithium-20170627.pdf)) - Primary signatures

- Lattice-based signatures ([NIST FIPS 204](https://csrc.nist.gov/projects/post-quantum-cryptography))
- Unlimited signatures per address
- Smaller signatures and fast verification
- Required for staking validators
- Full NIST compliance at launch

#### SLH-DSA / SPHINCS+ - Hash-based option

- Hash-based signatures ([NIST FIPS 205](https://csrc.nist.gov/projects/post-quantum-cryptography))
- Conservative security assumptions, based only on hash functions
- Recognized at the wallet-descriptor level (canonical ML-DSA-87 and SPHINCS+-256s descriptors), with integration continuing toward and after mainnet
- Provides cryptographic diversity if a lattice assumption is ever weakened

#### Falcon-1024 and ML-KEM - Network (P2P) layer

- Falcon-1024 (FN-DSA) signatures have been [added in go-qrllib](https://www.theqrl.org/weekly/2026-july-10/), with [ML-KEM](https://eprint.iacr.org/2017/634.pdf) (FIPS 203) key encapsulation implementation underway, to secure the peer-to-peer networking layer
- This hardens node-to-node communication against quantum attack, in addition to the transaction-signing layer

#### XMSS (Stateful) - Legacy / QRL 1.x

- Hash-based signatures ([XMSS](https://datatracker.ietf.org/doc/draft-irtf-cfrg-xmss-hash-based-signatures/)) securing the original 2018 mainnet
- Uses one-time keys (requires OTS index tracking), limited signatures per wallet

#### Cryptographic Agility

- New NIST-approved algorithms can be adopted as standards evolve
- The address descriptor identifies which scheme an account uses
- If one algorithm is compromised, others remain secure
- No emergency hard fork needed when new algorithms emerge

This multi-algorithm approach provides defense in depth - not relying on a single cryptographic assumption.

Crypto-agility is not only a design claim; it has been demonstrated in practice. During the testnet phase, QRL 2.0's address format was expanded from its original 24-byte representation to 48 bytes, and then to 64 bytes to reach [full NIST Security Level 5](https://www.theqrl.org/weekly/2026-may-15/) - each change rolling out across the entire repository set (go-qrllib, qrysm, go-qrl, Hyperion, qrvmone, and the wallet libraries) within roughly two weeks, rather than requiring a contentious chain split. Because each account's descriptor records which signature scheme it uses, QRL 2.0 can adopt future NIST-approved post-quantum algorithms (such as [SLH-DSA/SPHINCS+ and others](https://www.theqrl.org/roadmap/), already recognized at the descriptor level) as they are standardized - without an emergency hard fork.

### Address Format

QRL 2.0 uses a distinctive "Q" prefix address format. During Testnet V2 the format is being upgraded from a 48-byte to a 64-byte address to provide complete NIST Security Level 5 (a network reset accompanies this change on the testnet):

- Larger internal representation than Ethereum's 20 bytes, to eliminate ambiguity and reach the highest NIST security level
- Includes a cryptographic descriptor that differentiates between signature schemes
- EIP-55-style checksums implemented in the wallet libraries for safer address handling
- Network uses QRL/Planck/Shor denominations (replacing ETH nomenclature)

### EVM Compatibility

Key breakthrough: developers can port Ethereum smart contracts to QRL 2.0 with minimal modifications. Hyperion is a post-quantum superset of Solidity in which most valid Solidity is also valid Hyperion, with NIST-approved post-quantum primitives layered on top. The QRVM executes these contracts. Hyperion is open source.

#### What this means for developers:

- Write Solidity-style code as you would on Ethereum
- Use familiar tools: web3.js, Hardhat, Remix-style IDEs (Vortex)
- Deploy with minimal changes - often just the pragma line
- QRL-adapted tooling is required to compile and deploy Hyperion contracts, but the changes to existing Ethereum tooling are minimal

### Network Parameters

QRL prioritizes security over raw speed, with some differences from Ethereum. These parameters reflect the computational overhead of post-quantum cryptography and may continue to be adjusted before mainnet.

Block time

60 seconds

12 seconds

Epoch size

128 slots (~128 minutes)

32 slots (~6.4 minutes)

Layer 1 throughput

~15 TPS (Testnet V2 stress test)

~15-30 TPS

Block size

Larger (higher bandwidth/disk requirements)

Standard

Testnet V2 has been [stress-tested at approximately 952 transactions per block](https://www.theqrl.org/weekly/2026-april-24/) (21,000 gas per transaction), which at a 60-second block time is roughly 15 transactions per second on Layer 1. For comparison, [Ethereum's base layer](https://chainspect.app/chain/ethereum) has historically processed about 15-30 TPS. As on Ethereum, higher throughput is expected to come primarily from Layer 2s rather than the base chain.

## Development Timeline

### In Progress (as of [late August 2026](https://www.theqrl.org/weekly/2026-august-21/))

#### External and internal audits

- With the Trail of Bits report on the cryptographic core published (all findings resolved), audits of the remaining protocol components (consensus, node, VM, wallets) continue; roughly [50% of the program is fully complete and remediated](https://www.theqrl.org/weekly/), and mainnet is contingent on successful completion. Remediation has been continuous and fast, with findings fixed within days: web3.js phased remediation is complete and the web wallet is in phase 2. (Progress percentages are the team's estimates and may adjust as final reviews and remediation complete.)

#### Launch preparation

- Nightly automated end-to-end tests of the full QRL 2.0 network are now running (new qrl-tests repo), and genesis parameters are being finalized, with the deposit contract configured at block 0 ([weekly updates](https://www.theqrl.org/weekly/))

#### Falcon-1024 (P2P layer)

- [Added in go-qrllib](https://www.theqrl.org/weekly/2026-july-10/); network-layer integration continuing

#### ML-KEM (P2P layer)

- Key-encapsulation implementation underway for the networking layer

#### Developer tooling

- A [Hardhat-like tool is being developed](https://www.theqrl.org/weekly/2026-july-03/) for QRL 2.0 along with its documentation; plus the Zond Web3 Wallet (Chrome extension, Argon2id encryption, multi-account, QRC-20 support), Vortex IDE, block explorers (execution + consensus), and the Testnet V2 faucet

#### Hyperion/qrvmc

- Test coverage expanding for Hyperion, with qrvmc under review to stay aligned with Hyperion changes

#### Supply-chain hardening

- CI/CD pipelines reviewed and strengthened following industry supply-chain incidents (no substantive issues found)

### Completed

#### Trail of Bits Security Assessment Published

August 4, 2026

- Trail of Bits published its independent security assessment of go-qrllib, QRL's core post-quantum cryptography library: 15 findings (one High, four Low, ten Informational), all resolved after remediation and re-review. The findings concerned the robustness of the exported API and supporting controls rather than the correctness of the cryptographic primitives ([announcement](https://www.theqrl.org/press/qrl-announces-trail-of-bits-publication-of-security-assessment-of-its-cryptographic-heart-with-all-findings-resolved/) · [publications repo](https://github.com/trailofbits/publications))

#### 64-byte Address Migration Complete (NIST Level 5)

August 2026

- The 64-byte address migration to full NIST Security Level 5 is complete across the stack, and the QRVM connector was sealed at v2.0.0; the 1.x tooling stack was also refreshed for the migration path (qrl-wallet v1.9.1-beta, qrl-cli v1.11.0, qrllib v1.2.6, offline wallet generator v3 format) ([weekly updates](https://www.theqrl.org/weekly/))

#### Eight Years of Continuous Operation

June 2026

- QRL marked [eight years of continuous, exception-free mainnet operation](https://www.theqrl.org/blog/celebrating-8-years/) since the 2018 launch - a track record no other post-quantum-native chain can match

#### Halborn Audit Complete

April 3, 2026

- Independent audit of QRL's two post-quantum signature libraries found no cryptographic vulnerabilities; all 13 findings rated Informational and since resolved; core signing, verification, and key-generation logic validated as correct ([announcement](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/) · [full report](https://www.halborn.com/audits/qrl-quantum-resistant-ledger/qrl-quantum-resistant-ledger-37d3f1))

#### QRL 2.0 Testnet V2 Released

March 31, 2026

- Public PoS network live with Hyperion and the QRVM; smart-contract deployment and staking available; decentralized (smart-contract-based) migration path for QRL 1.x holders ([press release](https://www.theqrl.org/press/qrl-launches-testnet-v2-for-its-postquantum-evmfriendly-blockchain/))

#### Code Freeze

February 2026

- Code freeze completed across all relevant repositories in preparation for audit; 100% code coverage achieved across essential cryptographic libraries

#### Cryptography & Address Updates

August 2025

- ML-DSA-87 integration completed across the stack (go-qrllib, go-qrl, qrysm, deposit contracts)

#### ETHDenver Showcase

February 2025

- BUIDL Testnet Preview unveiled; strong developer interest

#### Testnet V1 Launch

Early 2025

- Most stable testnet to date; full EVM compatibility demonstrated; new "Q" prefix address format rolled out

#### Beta-Testnet Launch

January 2024

- Expanded testing with community developers; Web3 API compatibility confirmed

#### Public Devnet Pre-release

December 2022

- Zond Virtual Machine testing; Hyperion Solidity fork introduced

#### QRL Mainnet Launch

June 2018

- World's first full-featured quantum-resistant blockchain; XMSS signatures from genesis block; later audited by [X41 D-Sec and Red4Sec](https://github.com/theQRL/audits)

## For Current QRL Holders

Your current QRL is quantum-safe and will remain so. Migration from current QRL mainnet to QRL 2.0 is being designed as a decentralized, smart-contract-based process - not an emergency migration:

### Snapshot

At a predetermined block height, a final snapshot of the PoW chain captures all balances

### Migration Contract

A smart contract on QRL 2.0 mainnet holds the snapshot balance data

### User-Initiated Claim

Using a simple UI, provide your new QRL 2.0 address and sign with your existing XMSS address

### Automated Transfer

The contract verifies your signature and transfers your full balance

Because the original QRL chain is already quantum-safe, holders can migrate at their own pace. Details will be finalized as mainnet approaches.

## Use Cases

### DeFi Protocols

Lending platforms, DEXs, yield farming, and stablecoins secured against quantum threats from day one.

### NFT Platforms

Mint and trade digital assets with long-term security for provenance and ownership.

### Decentralized Identity

Self-sovereign identity protected against quantum decryption of personal data.

### Trustless Governance

Tamper-proof voting systems and DAO infrastructure with quantum-resistant integrity.

### Enterprise Applications

Supply chain tracking, document authentication, and business logic secured for the quantum era.

## For Developers

### Getting Started Today

#### Testnet Access

- Public Testnet V2 live at test-zond.theqrl.org
- Staking available on the testnet now
- Test tokens available via the Testnet V2 faucet (initial release) and community members
- Documentation available, with beginner-friendly guides being added during the audit/stress-test period

#### Development Tools

- Zond Web3 Wallet: Chrome extension (similar to MetaMask)
- Vortex IDE: Fork of Remix for QRL 2.0 development
- Hyperion compiler: Solidity-compatible with post-quantum extensions (open source)
- Web3.js libraries work with minimal changes

#### Migration from Ethereum

For most contracts, the only required change is the pragma line:

pragma solidity ^0.8.0;

pragma hyperion ^0.8.0;

- Port Ethereum contracts with minimal code changes
- Migration guides and tutorials available
- Community support channels

### Why Build on QRL 2.0 Now?

#### First-Mover Advantage

- Be early to the quantum-resistant ecosystem
- Establish presence before mass migration from vulnerable chains
- Direct support from the development team during the testnet phase

#### Quantum-Secure from Genesis

- Your dApps and users' assets are protected from day one
- No scrambling to migrate when quantum threats materialize
- Unlike chains racing against deadlines, QRL controls its own timeline

### Development Resources

- [Documentation](https://test-zond.theqrl.org/testnet)
- [GitHub](https://github.com/theQRL)
- [Discussions](https://github.com/orgs/theQRL/discussions)

## Community Projects

The QRL 2.0 ecosystem is growing with community-built tools:

- [QRL 2.0 Token Generator](https://qrl-zond.com)
- [Zond Web Wallet](https://myqrlwallet.com)
- [Zond Scan](https://zondscan.com)

Note: Community projects are under active development and may experience instability.

## The QRL 2.0 Ecosystem

### Infrastructure

#### Wallets

- Desktop, mobile, and web wallets
- Hardware wallet support planned
- Multi-signature capabilities

#### Block Explorer

- Full transaction history
- Contract verification
- Network statistics

#### Developer Tools

- Comprehensive APIs
- Testing frameworks
- Documentation
- Code examples

### Community

#### Discord & Telegram

- Active developer channels
- Technical support
- Community discussions

#### GitHub

- Open-source code
- Issue tracking
- Contribution guidelines

#### Developer Grants

- Funding for ecosystem projects
- Technical support
- Marketing assistance

## Current Development Status (August 2026)

### Post-Testnet V2: On the Road to Mainnet

QRL 2.0 Testnet V2 has been live since March 31, 2026, and the project is now in the audit-and-hardening phase that precedes mainnet. The cryptographic core has been cleared by two independent firms: the [Halborn audit](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/) (April 3, 2026) returned no vulnerabilities, and [Trail of Bits published its go-qrllib assessment](https://www.theqrl.org/press/qrl-announces-trail-of-bits-publication-of-security-assessment-of-its-cryptographic-heart-with-all-findings-resolved/) on August 4, 2026 with all findings resolved. Roughly 50% of the broader audit program is fully complete and remediated.

#### What's happening now:

- **Testnet V2 live** — Smart-contract deployment and staking available on a public PoS network
- **Cryptographic core cleared twice** — Halborn found no cryptographic vulnerabilities (all 13 findings Informational, resolved); Trail of Bits' published assessment of go-qrllib reported 15 findings (one High, four Low, ten Informational), all resolved
- **Audits ~50% complete** — Half of the rigorous third-party audits are fully completed including remediation; the remaining protocol components (consensus, node, VM, wallets) are under audit, and mainnet remains gated on full audit completion
- **NIST Security Level 5** — The 64-byte address migration is complete across the stack; the QRVM connector was sealed at v2.0.0
- **Launch preparation** — Nightly automated end-to-end tests of the full network are running (qrl-tests repo); genesis parameters are being finalized, with the deposit contract configured at block 0
- **Migration path in preparation** — The 1.x tooling stack was refreshed in July-August 2026: qrl-wallet v1.9.1-beta (first release since 2022), qrl-cli v1.11.0, qrllib v1.2.6, offline wallet generator v3 format
- **Network-layer PQC** — Falcon-1024 added in go-qrllib; ML-KEM implementation underway for the P2P layer
- **Tooling & docs** — A Hardhat-like tool with documentation in development; wallets, explorers, faucet, and beginner documentation being expanded
The bottom line: with Testnet V2 shipped, the cryptography validated by two independent firms, and audits at the halfway mark, the work now is methodical audit, hardening, and launch preparation - not a race against a quantum deadline. As the team put it at the [eight-year mark](https://www.theqrl.org/blog/celebrating-8-years/): security takes precedence over strict timelines, and that standard isn't changing at the finish line.

### Stay Updated

Follow the latest progress through

QRL Weekly Updates

https://www.theqrl.org/weekly/

- short, accessible reports published every week showing what the team has accomplished.

## Roadmap

### Strategic Approach

Given the accelerating quantum timeline and systemic risk facing the EVM ecosystem, QRL has prioritized speed, reliability, and full NIST compliance:

- Streamlined algorithm implementation: ML-DSA-87 (Dilithium) for full NIST compliance at launch, with the crypto-agile address model allowing additional signature schemes (SLH-DSA/SPHINCS+) to be integrated over time without an emergency hard fork
- Audit-gated mainnet: Rather than committing to a fixed launch date, mainnet timing follows the completion of external audits

Completed - Testnet V2 & Cryptography Audits (Q1-Q3 2026)

- [Testnet V2 released](https://www.theqrl.org/press/qrl-launches-testnet-v2-for-its-postquantum-evmfriendly-blockchain/) (March 31, 2026)
- [Halborn cryptographic-library audit complete](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/) (April 3, 2026)
- [Trail of Bits go-qrllib assessment published, all findings resolved](https://www.theqrl.org/press/qrl-announces-trail-of-bits-publication-of-security-assessment-of-its-cryptographic-heart-with-all-findings-resolved/) (August 4, 2026)
- 64-byte address migration (NIST Level 5) complete across the stack; QRVM connector sealed at v2.0.0 (August 2026)
- Code freeze across all relevant repositories

In Progress - Hardening & Full Audit (~50% complete)

- Audits of the remaining protocol components (consensus, node, VM, wallets) across multiple firms - [roughly 50% of the program fully complete and remediated](https://www.theqrl.org/weekly/)
- Nightly automated end-to-end tests of the full network (qrl-tests repo); genesis parameters being finalized, deposit contract configured at block 0
- Falcon-1024 (added in go-qrllib) and ML-KEM for the P2P layer
- Hardhat-like developer tool with documentation
- Tooling, documentation, and stress testing

Next - Mainnet Launch (TBD, contingent on audit completion)

- QRL 2.0 mainnet release once audits are successfully completed
- Decentralized migration for current QRL holders
- Developer onboarding programs and Vortex IDE support

Post-Mainnet - Continued Enhancement

- Further SLH-DSA (SPHINCS+) integration
- Additional post-quantum algorithm support
- Layer 2 integrations and cross-chain bridges

Growth & Ecosystem Expansion

- Project migrations from Ethereum and other EVM chains
- Institutional partnerships and enterprise adoption
- Quantum-resistant DeFi, NFT, and dApp infrastructure

## Join the Quantum-Resistant Future

The quantum threat to blockchain is real and accelerating. With QRL 2.0, we're not just anticipating the challenge - we're building and shipping the solution.

For developers

Build on proven quantum-resistant technology today, on a live testnet.

For projects

Plan your migration before quantum computers arrive.

For users

Access DeFi, NFTs, and dApps with confidence in long-term security.

The future is quantum-resistant. The future is QRL 2.0.

Live and available now

https://test-zond.theqrl.org

https://test-zond.theqrl.org/testnet

Discord

github.com/theQRL


---

# Qubit Tracker 2026: How Close Are Quantum Computers to Breaking Bitcoin?

> 96 logical qubits exist; ~800-1,400 break Bitcoin. Tracking 2026 qubit counts, the Google, Oratomic and ecdsa.fail attack benchmarks, and which roadmaps cross the line in 2028-2030.

- Language: en
- Canonical URL: https://qrlhub.com/en/qubits
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## The Qubit Gap: 96 Logical Qubits Exist. ~800-1,400 Break Bitcoin.

Where quantum hardware stands today, what it takes to break Bitcoin/Ethereum signatures, and which roadmaps cross that line.

## ⚡ At a Glance

- 96 — Verified logical qubits, the world record (QuEra, Nature, Jan 2026)
- 60.9% — How far the [ecdsa.fail](https://www.ecdsa.fail/) frontier now runs ahead of Google's benchmark on the combined qubits x gates metric (retrieved Aug 23, 2026). Known designs span roughly 800-1,400 logical qubits, trading width against gate count
- 2028-30 — When major roadmaps (IonQ, Infleqtion, IBM, Oratomic) cross the threshold
the gap is a single order of magnitude (~8-13x, depending on how a circuit trades qubit width against gate count), it is closing on every front at once (qubit counts, error rates, error-correction codes, and the attack circuits themselves), and no major chain's migration is on track to finish before the first roadmap crossings.

## 📏 The Gap

Logical (error-corrected) qubits are the count that matters for Shor's algorithm, but a circuit is defined by two numbers at once: how many qubits it needs and how many gate operations it runs. A design can spend more of one to save the other, so the threshold below is a band, not a single figure. Log scale: each tick is 10x the last.

- **IBM**: 1-2
- **Infleqtion**: 12
- **Quantinuum**: 94*
- **QuEra**: 96
- **🔴 BREAKS BITCOIN (~800-1,400, gate cost varies)**: 813
- **🟡 ~2-hour attack (6,500)**: 6500
- Attack
- Logical Qubits
- Physical Qubits (est.)
- Status

- ECDSA-256 (Bitcoin/Ethereum)
- 813 min, at ~1.16B Toffolis (ecdsa.fail) → 1,278 at the best score → 1,200-1,450 (Google)
- <500,000 (superconducting, Google) / ~10,000-26,000 (neutral atom, Oratomic)
- 🔴 Approaching fast

- RSA-2048
- 4,000-6,190
- <100,000 (qLDPC) to 8M (surface code)
- 🟡 Timeline compressed

- SHA-256 mining (Grover's)
- >8,000
- Tens of millions
- 🟢 Lower priority

*Quantinuum's 94 is postselected; QuEra's 96 is the verified error-corrected record. Both use low code distance, while attack circuits need distance ≥25, so quality must scale too, not just count ([a16z, Dec 2025](https://a16zcrypto.com/posts/article/quantum-computing-misconceptions-realities-blockchains-planning-migrations/)).

## 🗓️ The Timeline: Roadmaps vs. the Threshold

Logical-qubit roadmaps vs. the ~800-1,400 attack threshold

2026

- 96 logical verified (QuEra world record)
- Quantinuum 94 beyond break-even
- ecdsa.fail frontier reaches 60.9% ahead of Google on the combined qubits x gates metric (Aug)

2027

- QuEra targets 100 logical / 10,000 physical
- PsiQuantum 1M+ photonic-qubit sites (2027-28)

2028

- 🔴 US DOE target (first fault-tolerant QC)
- IonQ 1,600 logical (accelerated roadmap)

2029

- 🔴 Google's own migration deadline ("Q-Day possible")
- IBM Starling (200 logical)

2030

- Quantinuum Apollo (fully fault-tolerant)
- Infleqtion (1,000 logical)
- IonQ 8,000 logical
- Oratomic + Monarch (thousands of logical qubits "by end of decade")

2033

- IBM Blue Jay (2,000 logical, above every ECDSA threshold)

How to read it:

solid demonstrations sit at 2026; everything after is a company target. Roadmaps slip, but five independent efforts on three different hardware platforms cross the red band in a 2028-2031 window, and both Google and the US DOE have put official deadlines inside it.

## 🎯 The Three Benchmarks That Set the Bar

Three independent 2026 results define what it takes to steal a Bitcoin/Ethereum key. All three slashed prior estimates, and the bar keeps falling.

### 1. Google Quantum AI whitepaper (superconducting, Mar 30, 2026)

- 1,425 logical qubits x 2.1M Toffoli gates (benchmark circuit); 1,200-1,450 across designs
- <500,000 physical qubits; derives a key in ~9 minutes, inside Bitcoin's confirmation window (~18-23 min full attack), validated by a zero-knowledge proof
- A ~20x reduction vs. prior estimates. Google set itself a 2029 migration deadline
- [Whitepaper →](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf)

### 2. Oratomic (neutral atom; paper Mar 31, 2026, company scaling since)

- Shor's algorithm at cryptographic scale with ~10,000-26,000 physical atomic qubits in ~10 days, using high-rate qLDPC codes on reconfigurable atom arrays: roughly 100x below prior estimates for the platform ([Cain et al., arXiv:2603.28627](https://arxiv.org/pdf/2603.28627))
- High-rate codes need as few as 3-4 physical qubits per logical qubit (vs. hundreds for surface codes); movable atoms provide the long-range connectivity these codes require
- The company, not just the paper: Pasadena-based Caltech/Harvard spin-out (CEO Dolev Bluvstein; co-founders include Manuel Endres and John Preskill). Raised a $300M Series A (July 2026) co-led by ARCH, Spark Capital, and Khosla Ventures; Vinod Khosla called it his firm's largest initial investment yet, likening it to OpenAI
- Skipping NISQ entirely to build fault-tolerant machines directly; core components demonstrated, including 6,000+ atom arrays. Partnership with Monarch Quantum (Apr 2026) targets thousands of error-corrected logical qubits by the end of the decade
- [oratomic.com →](https://www.oratomic.com/)

### 3. ecdsa.fail (open challenge, live leaderboard, by Eigen Labs)

- Public arena where solvers shrink the secp256k1 Shor circuit, scored by qubits x Toffoli gates (lower is better)
- Current frontier: 915,947 Toffolis x 1,278 logical qubits (score 1.17B), which is 60.9% ahead of Google's benchmark circuit. A separate low-qubit record stands at 813 logical qubits, under the 835 of a July academic design ([arXiv:2607.13816](https://arxiv.org/abs/2607.13816))
- The open board has now overtaken the best private result: doubleAI's WarpSpeed circuit, certified by a zero-knowledge proof at a score of 1.20B, led when it was published on August 15, 2026, and the public frontier passed it about a week later. The board has taken 493 promoted submissions from 125 solvers
- Not a live exploit: it tracks the algorithmic floor falling in real time, in public. The hardware bar drops even when no new hardware ships
- <strong>These numbers are a snapshot, not a live feed.</strong> They were read from the leaderboard on August 23, 2026 and change often, sometimes several times a week. For the current frontier, check [ecdsa.fail](https://www.ecdsa.fail/) directly
- [See the live leaderboard →](https://www.ecdsa.fail/)

## 🖥️ Hardware Today

The players that matter most for the crypto timeline. Logical qubits shown as now / roadmap target.

- Company
- Tech
- Physical
- Logical (now / target)
- Target

- QuEra
- Neutral atom
- 448 (demo)
- 96 / 100
- 2026-27

- Quantinuum
- Trapped ion
- 98 (Helios)
- 94* / fully fault-tolerant (Apollo)
- 2030

- Infleqtion
- Neutral atom
- 1,600
- 12 / 1,000
- 2030

- IonQ
- Trapped ion
- 256 (6th-gen)
- 0 / 1,600 → 8,000
- 2028 / 2030

- IBM
- Superconducting
- 156 (Heron)
- 1-2 / 200 → 2,000
- 2029 / 2033

- Google
- Superconducting
- 105 (Willow)
- below-threshold / useful FT machine
- 2029

- Oratomic
- Neutral atom
- building (6,000+ atom arrays demonstrated by founders)
- 0 / thousands (with Monarch)
- ~2030

- PsiQuantum
- Photonic
- building
- 0 / 100+ (1M+ physical)
- 2027-28

- Atom Computing
- Neutral atom
- 1,180
- none yet / 50 (Magne)
- late 2026

- USTC (China)
- Superconducting
- 107
- below-threshold / scaling
- TBD

- Microsoft
- Topological
- Majorana 1
- R&D (first readout, Feb 2026)
- "years not decades"

*Postselected, beyond break-even. D-Wave (annealing) is excluded: annealing cannot run Shor's algorithm.

## 💥 What This Means for Crypto

- ~6.9M BTC (~$470B) sits in addresses with already-exposed public keys (P2PK, reused, Taproot) that no future upgrade can protect. Includes Satoshi's ~1M BTC, exposed since 2009.
- Harvest Now, Decrypt Later is already happening. The Federal Reserve confirmed adversaries are recording blockchain data today for future decryption. Harvested data cannot be un-harvested.
- Every spend is a window. Google's whitepaper estimates ~41% theft probability for an on-spend attack during the ~10-minute mempool window.
- The defenses aren't deployed. Bitcoin: BIP-360 merged into the BIP repository (Feb 2026), BTQ testnet live, but no mainnet date. Ethereum: base-layer fix targeted ~2029; accounts, contracts, bridges, and L2s must still migrate on top.
- The migration is the slow part. Bitcoin's ~190M UTXOs at ~7 TPS is roughly a year of blocks doing nothing but migrating. The deadlines above are the schedule it has to beat.

Already protected:

[Quantum Resistant Ledger (QRL)](/story) has been quantum-safe since 2018 using XMSS signatures. See [QRL 2.0 (Zond)](/zond) and [QRL FAQs](/faq).

### What should you do?

- Never reuse addresses: each spend permanently exposes your public key.
- Track the fixes: BIP-360 (Bitcoin), Glamsterdam/Hegota (Ethereum).
- Consider quantum-resistant alternatives like [QRL](/story) / [QRL 2.0](/zond).
- Stay informed via the [Quantum News](/news) page.

## ⚠️ Caveats

- Code distance is the hidden gap. Today's records (QuEra's 96 at distance 4) are far below the distance ≥25 needed to run Shor's end-to-end. Count and quality must scale, but records doubled in about a year, and both are scaling.
- Roadmaps slip. Every target above is a company projection. The picture is the convergence, not any single date.
- Conservative views exist (Adam Back: 20-40 years) but are increasingly outliers; expert consensus now clusters on 2030-2035, with official targets (DOE 2028, Google 2029) inside this decade.

## 📖 Mini Glossary

- Term
- Meaning

### Physical qubit

The actual hardware qubit. Error-prone (~1-in-100 to 1-in-10,000 per operation).

### Logical qubit

One reliable qubit built from many physical qubits via error correction. The unit Shor's algorithm needs.

### Code distance

How strong the error correction is. Records today: distance 4. Attacks need: ≥25.

### qLDPC codes

New error-correction family cutting physical-qubit overhead ~10x (or to 3-4:1, per Oratomic) vs. surface codes.

### CRQC

Cryptographically Relevant Quantum Computer: one that can run Shor's on real keys. None exist yet.

### Q-Day

The day a CRQC breaks deployed public-key crypto. Google: possible by 2029.

### HNDL

Harvest Now, Decrypt Later: record encrypted/public-key data today, crack it later. Confirmed ongoing.

## Sources

- [Google Quantum AI whitepaper (Mar 2026)](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf)
- [Cain et al. / Oratomic, arXiv:2603.28627](https://arxiv.org/pdf/2603.28627)
- [oratomic.com](https://www.oratomic.com/)
- [ecdsa.fail live leaderboard (Eigen Labs), figures retrieved August 23, 2026](https://www.ecdsa.fail/)
- [arXiv:2607.13816 (835-qubit secp256k1 circuit, Jul 2026)](https://arxiv.org/abs/2607.13816)
- [Kim et al., ePrint 2026/106](https://eprint.iacr.org/2026/106)
- [Chevignard et al., ePrint 2026/280 (EUROCRYPT 2026)](https://eprint.iacr.org/2026/280)
- [Roetteler et al. 2017](https://eprint.iacr.org/2017/598.pdf)
- [QuEra, Nature (Jan 2026)](https://www.nature.com/articles/s41586-025-09848-5)
- [IBM roadmap](https://www.ibm.com/roadmaps/quantum/)
- [IonQ roadmap](https://ionq.com/roadmap)
- [Quantinuum roadmap](https://www.quantinuum.com/press-releases/quantinuum-unveils-accelerated-roadmap-to-achieve-universal-fault-tolerant-quantum-computing-by-2030)
- [a16z analysis](https://a16zcrypto.com/posts/article/quantum-computing-misconceptions-realities-blockchains-planning-migrations/)

- [Quantum News](/news)
August 23, 2026


---

# QRL Ecosystem | Wallets, Explorers, Nodes & Developer Tools

> The tools, wallets, explorers, nodes, mining pools, and community projects of the Quantum Resistant Ledger, for both QRL 1.x and QRL 2.0 (Project Zond).

- Language: en
- Canonical URL: https://qrlhub.com/en/ecosystem
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## The QRL Ecosystem

Tools, wallets, explorers, nodes, and projects across the Quantum Resistant Ledger, for both the current QRL 1.x mainnet and QRL 2.0.

Last updated: July 14, 2026

## Official Core (QRL 1.x, current mainnet)

The proof-of-work mainnet, live since June 2018, secured by XMSS hash-based signatures.

- **QRL Website** — The official project home: downloads, blog, roadmap. — [theqrl.org](https://theqrl.org) (✅ Active)
- **QRL Documentation** — Guides for wallets, nodes, mining, and the API. Start here for almost anything. — [docs.theqrl.org](https://docs.theqrl.org) (✅ Active)
- **QRL Web Wallet** — Create and use a QRL wallet in your browser. Keys are generated locally via WebAssembly and never leave your machine. Also available as a desktop app (Windows/macOS/Linux) with Ledger Nano X / S Plus support. — [wallet.theqrl.org](https://wallet.theqrl.org) (✅ Active)
- **QRL Mobile Wallet** — iOS and Android wallet, developed by third-party provider Volt Development. — [theqrl.org downloads](https://theqrl.org) (✅ Active)
- **Ledger Nano app** — Hardware wallet support for QRL (Nano X / S Plus). Keeps keys offline and tracks your OTS key index for you. Note: the legacy Nano S requires v1.x firmware. — [Ledger guide](https://docs.theqrl.org/use/wallet/ledger/overview/) (✅ Active)
- **QRL Node** — The Python reference node implementation. Run it to support the network, solo mine, or serve your own wallet or explorer. — [github.com/theQRL/QRL](https://github.com/theQRL/QRL) (✅ Active)
- **qrl-cli** — Command-line tool for wallets, transactions, and on-chain functions, handy for scripting and automation. — [theqrl.org/features/qrl-cli](https://www.theqrl.org/features/qrl-cli/) (✅ Active)
- **QRL API docs** — Protocol and gRPC API reference for developers building against the 1.x chain. — [api.theqrl.org](https://api.theqrl.org) (✅ Active)
## QRL 2.0 (Project Zond)

The next-generation, EVM-compatible, proof-of-stake chain using NIST-standardized ML-DSA-87 signatures. Testnet V2 is live (launched March 31, 2026); mainnet follows completion of external audits.

- **QRL 2.0 Testnet docs** — The official getting-started hub: install a node, create a wallet, get testnet funds, deploy contracts, stake. — [test-zond.theqrl.org](https://test-zond.theqrl.org) (✅ Active (Testnet V2))
- **Zond Web3 Wallet** — Browser-extension wallet (MetaMask-style) for QRL 2.0. Creates accounts, signs transactions, and exposes APIs for dApps. Argon2id encryption, multi-account, QRC20 token support. — [github.com/theQRL/qrl-web3-wallet](https://github.com/theQRL/qrl-web3-wallet) (✅ Active)
- **go-qrl & Qrysm** — The QRL 2.0 node software: go-qrl is the execution client (a post-quantum fork of go-ethereum) and Qrysm the consensus client. — [github.com/theQRL](https://github.com/theQRL) (✅ Active)
- **Hyperion** — QRL's quantum-resistant fork of Solidity. Most Ethereum contracts port with only minor changes. — [test-zond.theqrl.org](https://test-zond.theqrl.org) (✅ Active)
- **web3.js / wallet.js for QRL** — JavaScript libraries for building dApps and wallet integrations on QRL 2.0. Code-frozen for audit as of Feb 2026. — [github.com/theQRL](https://github.com/theQRL) (✅ Active)
- **qrl-contract-example** — A minimal, working example of deploying and calling a smart contract on the Zond testnet, and the fastest way to learn by doing. — [github.com/theQRL/qrl-contract-example](https://github.com/theQRL/qrl-contract-example) (✅ Active)
- **dApp connection example** — Demonstrates how a web dApp connects to the Zond Web3 Wallet extension (EIP-6963 style). — [github.com/theQRL/zond-web3-wallet-dapp-example](https://github.com/theQRL/zond-web3-wallet-dapp-example) (✅ Active)
- **Vortex IDE** — A Remix IDE fork for writing and deploying Hyperion contracts in the browser. — [testnet docs](https://test-zond.theqrl.org) (🧪 In development)
- **Testnet funds** — Testnet QRL is available via the faucet or by request in the official Discord. — [theqrl.org/discord](https://theqrl.org/discord) (✅ Active)
## Explorers & Analytics

- **QRL Explorer (official)** — Block explorer for the 1.x mainnet: blocks, transactions, addresses, tokens. Also exposes a simple JSON API (emission, reward, mining stats). — [explorer.theqrl.org](https://explorer.theqrl.org) (✅ Active)
- **QuantaScan (community)** — Analytics for the QRL blockchain: rich list, block size and time charts, network stats. — [quantascan.io](https://quantascan.io) (✅ Active)
- **ZondScan (community)** — Fast, modern explorer for the QRL 2.0 testnet by DigitalGuards: transactions, blocks, smart contracts, validators, plus a free, no-API-key REST API. Open source (Next.js and Go). — [zondscan.com](https://zondscan.com) · [GitHub](https://github.com/DigitalGuards/zondscan) (✅ Active)
## Mining (QRL 1.x)

QRL 1.x uses the RandomX (rx/0) CPU-friendly algorithm (the same family as Monero), so standard miners like XMRig work. There is no official pool; the ones below are independent. Mining ends when QRL 2.0 mainnet (proof-of-stake) replaces the proof-of-work chain, so factor that into any hardware plans.

- **Official mining docs** — Overview of solo vs. pool mining and miner configuration. — [docs.theqrl.org/mining](https://docs.theqrl.org/mining/pools/) (✅ Active)
- **HeroMiners** — The largest QRL pool by hashrate. PPS+ and PROP payouts, pool and solo modes. — [qrl.herominers.com](https://qrl.herominers.com) (✅ Active)
- **MiningOcean** — Independent QRL pool, PROP payouts. — [qrl.miningocean.org](https://qrl.miningocean.org) (✅ Active)
- **Pool comparison** — Live list of known QRL pools with fees and hashrate distribution. Check here for decentralization's sake before picking a pool. — [miningpoolstats.stream/quantumrl](https://miningpoolstats.stream/quantumrl) (✅ Active)
## Community Projects & Tools

Independent, community-built projects. Not audited by the QRL team.

- **ZondScan (DigitalGuards)** — QRL 2.0 explorer and free API; see the Explorers section above. Open source and actively developed. — [zondscan.com](https://zondscan.com) (✅ Active)
- **qrl-helpers** — Community helper scripts for setting up and using QRL and Project Zond nodes. — [github.com/theqrl-community/qrl-helpers](https://github.com/theqrl-community/qrl-helpers) (✅ Maintained (updated Dec 2025))
## Support

For questions, help, and testnet funds, the official QRL Discord is the place to go. It is the most active community channel, with the core team and experienced community members present: [theqrl.org/discord](https://theqrl.org/discord)

## Suggest a project

Know of an active QRL tool or project that belongs here? Post it in the QRL Discord. This page is not fed automatically: showing up on Discord does not add you here. The team reads the Discord from time to time and updates this list by hand.

Status: ✅ Active · 🧪 Testnet / in development


---

# Quantum Threat to Crypto: Latest News & Q-Day Timeline 2026

> Latest quantum-computing breakthroughs and what they mean for Bitcoin and Ethereum: Q-Day timelines, logical-qubit milestones, BIP-360/361, Tron's post-quantum testnet, the ECDSA.fail challenge, and why crypto has not finished migrating. QRL is quantum-safe since 2018.

- Language: en
- Canonical URL: https://qrlhub.com/en/news
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## Quantum Threat to Cryptocurrency: 2026 News & Developments

### The Quantum Threat: From Theory to Timeline

The state of play:

- Error correction is proven - four independent teams on three continents have done it. Scaling is now engineering, not physics.
- Google's 2026 whitepaper puts a Bitcoin attack at under 500,000 physical qubits, and Google has set its own Q-Day deadline of 2029. Microsoft's Majorana 2 puts its scalable-machine target in the same 2029 window.
- A Caltech/Oratomic result shows a 10,000-26,000 qubit neutral-atom machine - a scale already built in the lab - could do it in days.
- The attack itself keeps getting cheaper: the public ECDSA.fail leaderboard is now 60.9% leaner than Google's benchmark on the combined qubit-Toffoli metric (915,947 Toffolis x 1,278 logical qubits), it has overtaken the best privately held circuit, and its low-qubit record has fallen to 813 logical qubits (leaderboard snapshot, Aug 23, 2026; ECDSA.fail carries the live figures).
- The timeline is hardening fast: the US Department of Energy is targeting a fault-tolerant machine by 2028, and Quantinuum, now public on Nasdaq after a $1.68 billion June IPO, a fully fault-tolerant system by 2030.
- The deadlines are official: NIST deprecates today's encryption in 2030 and bans it by 2035; NIST, the NSA, and the Federal Reserve have all issued formal warnings.
- The hardware is accelerating faster than expected, while the chains with the most at stake have barely started to migrate.

Error correction has been proven by four independent teams on three continents; scaling is now engineering, not physics. Google's 2026 whitepaper put a Bitcoin attack at under 500,000 physical qubits, and Google set its own Q-Day deadline of 2029; Microsoft's Majorana 2 puts its scalable-machine target in the same 2029 window. A Caltech/Oratomic result showed a neutral-atom machine of roughly 10,000 to 26,000 qubits, a scale already built in the lab, could do it in days. The attack itself keeps getting cheaper: the public ECDSA.fail leaderboard is now 60.9% leaner than Google's benchmark on the combined qubit-Toffoli metric (915,947 Toffolis x 1,278 logical qubits), it has overtaken the best privately held circuit, and its low-qubit record has fallen to 813 logical qubits (leaderboard snapshot, Aug 23, 2026). The timeline is hardening: the US Department of Energy is targeting a fault-tolerant machine by 2028 and Quantinuum, now public on Nasdaq after a $1.68 billion June IPO, a fully fault-tolerant system by 2030, while NIST deprecates today's encryption in 2030 and bans it by 2035. NIST, the NSA, and the Federal Reserve have all warned formally. The hardware is accelerating faster than expected, while the chains with the most at stake have barely started to migrate.

Quantum computers that can steal Bitcoin are no longer a theoretical future problem. They are an engineering problem on a measurable timeline - and no top-20 blockchain has post-quantum protection live on mainnet.

Quantum computers that can steal Bitcoin are no longer a theoretical future problem. They are an engineering problem on a measurable timeline - and no top-20 blockchain has post-quantum protection live on mainnet.

Quantum Resistant Ledger (QRL)

/story

has been quantum-safe since 2018 using XMSS signatures - the protection Bitcoin and Ethereum are still planning. See

QRL 2.0 (Zond)

/zond

and

QRL FAQs

/faq

.

## Breaking News: April - August 2026

### The Open Leaderboard Passes 60% Ahead of Google, and Overtakes the Best Private Circuit

August 22, 2026

The ECDSA.fail frontier reached 60.9% ahead of Google's benchmark circuit, with a best score of 1,170,580,266 (915,947 Toffoli gates on 1,278 logical qubits). A separate low-qubit record now stands at 813 logical qubits, below the 835 of the July academic design that held the previous width record. The board has drawn 493 promoted submissions from 125 solvers.

Two things are worth noting. The open, public frontier has now passed the best privately held result: doubleAI's WarpSpeed circuit scored 1.20 billion when published on August 15 with a zero-knowledge proof instead of open code, and the public board overtook it about a week later. And Eigen Labs has generalized the format into [Yukon](https://www.yukon.org/), a platform for running the same open "autoresearch" competitions on other technical problems. The algorithmic cost of Q-Day is being driven down in public, faster than any single lab has managed in private, while the coins the attack targets remain unmigrated.

- [ECDSA.fail](https://www.ecdsa.fail/)
- [Yukon (Eigen Labs)](https://www.yukon.org/)

### The Record for the Cheapest Quantum Attack on Bitcoin's Curve Goes Private, Proved Without Showing the Circuit

August 15, 2026

doubleAI announced that WarpSpeed, its AI research system, designed a quantum circuit for breaking secp256k1 - the exact curve securing Bitcoin and Ethereum - using 993,181 Toffoli gates on 1,205 logical qubits, a combined spacetime score of 1.20 billion. That is roughly 2.5x more efficient than Google's published benchmark and about 19% ahead of the best entry on the public ECDSA.fail leaderboard, whose own frontier has meanwhile pushed past 50% ahead of Google at 1,154 logical qubits x 1.29 million Toffolis. Citing security concerns, doubleAI did not open-source the circuit: it published a zero-knowledge proof certifying that the design passes the challenge's full validation suite instead.

What was new here was not that software designed the circuit, which is true of the leaderboard entries as well, but that the result was sealed: for the first time the leading design was not public, only attested by cryptography. The algorithmic cost of Q-Day keeps falling on and off the leaderboard, while the coins the attack targets remain unmigrated.

Update, August 22, 2026: the open ECDSA.fail leaderboard overtook this circuit, retaking the frontier at a score of 1.17 billion.

- [Quantum Zeitgeist](https://quantumzeitgeist.com/quantum-encryption-cracking-cost-warpspeeds/)
- [ECDSA.fail](https://www.ecdsa.fail/)

### The Qubit Floor for Breaking Bitcoin's Curve Drops to 835, a Third Lower in Three Months

July 15, 2026

A team spanning four Chinese research institutions posted a space-efficient quantum algorithm for elliptic-curve discrete logarithms that needs just 835 logical qubits for a 256-bit curve like secp256k1 - the lowest width yet reported, well under the previous floors of 1,098 (Chevignard et al.) and 1,175 (Google's low-qubit design). The same group's April preprint stood at 1,333; three months of optimization removed roughly a third of that. The design trades width for gates, spending far more Toffolis, so it does not lead the combined qubit-Toffoli metric - but it lowers the minimum machine size that could ever run the attack, and that floor is still falling. Fewer qubits needed means the hardware roadmaps have less distance to cover.

- [arXiv:2607.13816](https://arxiv.org/abs/2607.13816)

### Reuters: The Industry Is Planning, Not Protected. No Top-20 Chain Has Shipped Post-Quantum Cryptography

July 9, 2026

A Reuters-sourced industry survey captured the state of play: crypto firms are drafting post-quantum plans, citing Google's 2029 estimate for encryption-breaking quantum machines, yet no top-20 blockchain has post-quantum algorithms live on mainnet. Ethereum's target remains 2029 for the base layer, and Algorand says post-quantum accounts arrive later this year. Roughly a year after Q-Day warnings went mainstream, the gap between roadmaps and shipped protection is the story.

- [The Daily Hodl](https://dailyhodl.com/2026/07/09/quantum-computing-threat-prompts-crypto-firms-to-prepare-post-quantum-defenses/)

### Tron Puts NIST Post-Quantum Signatures on Its Nile Test Network, but the Hard Part Is Still Ahead

June 30, 2026

Tron deployed GreatVoyage-v4.8.2-PQ1-build1 on its Nile testnet, adding end-to-end support for two NIST-standardized signature schemes, FN-DSA-512 (Falcon) and ML-DSA-44 (Dilithium), across transactions, block production, P2P handshakes, and smart-contract verification via new TVM precompiles. It is the most complete post-quantum deployment yet by a major incumbent chain, and it delivers on the Q2 testnet pledge Justin Sun made in April.

But this is only the first of two steps, and it shows why upgrading a live chain is so hard. Step one is technical: get the new signatures working and switch them on for the real network. Even that is a heavy lift, because post-quantum signatures are far bigger than the ones used today, so wallets, exchanges, and every piece of infrastructure have to be reworked to handle them, and on Tron the block producers still have to vote the change onto the main network. Step two is the harder one, and no upgrade can do it for you: every existing holder has to move their coins from an old, exposed address to a new protected one, by hand. Anyone who does not move, including lost and dormant coins, stays exposed for good. So far Tron has done part of step one, on a test network only. A working test feature is not a protected network. QRL users have had this protection, across the whole system, since 2018.

- [Crypto Briefing](https://cryptobriefing.com/tron-post-quantum-signatures-testnet/)
- [Cryptopolitan](https://www.cryptopolitan.com/tron-network-quantum-resistant-sign/)

### StarkWare Publishes a Post-Quantum Roadmap for Starknet

June 30, 2026

StarkWare released a multi-phase plan to move Starknet's cryptography to post-quantum standards, leaning on the native quantum resistance of its STARK proof system. Phase 1 targets Falcon-512 signatures and BLAKE2 hashing for new on-chain activity by July 2026, and later phases cover migrating existing deployments and external dependencies, aligned with Ethereum's own timeline. Another major Layer-2 now treats the migration as a scheduled engineering program, and it is another reminder that L2 protection ultimately depends on the L1 underneath it migrating too.

- [Quantum Computing Report](https://quantumcomputingreport.com/news/)

### QRL Marks Eight Years of Quantum-Safe Mainnet; QRL 2.0 Audits Reach the Halfway Mark

June 26, 2026

The QRL Foundation marked eight years of continuous post-quantum mainnet operation, with every transaction signed by hash-based XMSS since June 2018, and reported that the QRL 2.0 (Project Zond) audit program is now 50% fully complete and remediated, following the clean Halborn cryptography audit in April. Mainnet launch remains contingent on the successful completion of the full audit pipeline. While incumbents test their first post-quantum signatures, the chain that never needed a migration is finishing the reviews for its second post-quantum generation.

- [theqrl.org](https://www.theqrl.org/blog/celebrating-8-years/)

### Quantinuum's $1.68 Billion Nasdaq IPO Prices Quantum's Timeline Into Public Markets

June 5, 2026

Quantinuum closed an upsized IPO at $60 per share, raising $1.68 billion in gross proceeds and listing on Nasdaq as QNT. Days earlier it demonstrated, with Microsoft, logical qubits performing roughly 800x better than the underlying physical error rates, and mid-June brought an HPC and AI integration deal with HPE. Public markets are now underwriting the fault-tolerance race at scale, and that kind of capital compresses timelines. Quantinuum's own roadmap targets a fully fault-tolerant system by 2030, squarely inside the window that matters for exposed crypto keys.

- [Quantinuum](https://www.quantinuum.com/press-releases/quantinuum-and-microsoft-announce-new-era-in-quantum-computing-with-breakthrough-demonstration-of-reliable-qubits)

### ECDSA.fail: A Public Leaderboard, With AI in the Race, Is Shrinking the Quantum Attack on Bitcoin's Curve

June 2, 2026

Eigen Labs launched ECDSA.fail, an open challenge asking one question: can you break ECDSA? Researchers, and increasingly AI research agents, compete to shrink the quantum circuit for attacking secp256k1, the exact curve securing Bitcoin and Ethereum, scored by the product of logical qubits and Toffoli gates against Google's benchmark circuit. Submissions are automatically verified, and the crowd pulled far ahead of Google's construction: by late June the leading circuit was down to roughly 1,152 logical qubits and about 1.32 million Toffoli gates, some 49% leaner than Google's benchmark on the combined qubit-Toffoli metric, with dozens of compounding micro-optimizations rolling in. Analysts tracking the challenge note the leading qubit constant has fallen from roughly 9n toward 4.355n.

This is a benchmark, not a live exploit: no hardware exists to run these circuits today. But it makes the trend measurable in public, in real time. The algorithmic cost of Q-Day is a falling number on a leaderboard, being pushed down by open competition and AI, while the hardware curve rises to meet it. Only the hardware side of the equation still protects unmigrated coins.

- [ECDSA.fail](https://www.ecdsa.fail/)
- [Challenge repository](https://github.com/ecdsafail/ecdsafail-challenge)

### Microsoft Unveils Majorana 2 and Halves Its Timeline to a Scalable Quantum Computer by 2029

June 2, 2026

Microsoft unveiled Majorana 2, a topological qubit it says is roughly 1,000x more reliable than its predecessor, holding quantum information for about 20 seconds rather than microseconds. On that strength Microsoft now expects a scalable quantum computer by 2029, halving its previous timeline and putting another major lab's target in the same 2029-2030 window as Google.

- [Microsoft](https://news.microsoft.com/source/features/innovation/majorana-2-microsoft-discovery-agentic-ai/)

### New Paper Publishes Quantum Circuits for Attacking Bitcoin and Ethereum's Exact Curve

June 1, 2026

A new paper from Schrottenloher gives public quantum circuits for attacking secp256k1, the exact curve securing Bitcoin and Ethereum, matching recent work that cut the attack's qubit and gate cost by two to three times. The algorithmic cost of the attack keeps falling alongside the hardware progress.

- [arXiv](https://arxiv.org/abs/2606.02235)

### U.S. Department of Energy Issues RFI for a 2028 Fault-Tolerant Quantum Computer

May 15, 2026

The DOE issued an RFI for a fault-tolerant system of 150-250 logical qubits by 2028. A national government is now treating an error-corrected machine as something to buy, not a distant research goal.

- [Quantum Computing Report](https://quantumcomputingreport.com/news/)

### IonQ Opens Boulder Quantum R&D Laboratory

May 15, 2026

IonQ opened a 22,000-square-foot R&D lab in Boulder for semiconductor ion-trap chips, with its first system expected by late 2026. Its roadmap projects a cryptographically relevant quantum computer as early as 2028.

- [Quantum Computing Report](https://quantumcomputingreport.com/news/)

### Q-CTRL and IBM Demonstrate a 3,000x Speedup on 120 Qubits

May 6, 2026

Q-CTRL and IBM reported a 3,000x speedup on a 120-qubit Fermi-Hubbard simulation using runtime error suppression. Today's pre-fault-tolerant hardware is already reaching beyond classical computers.

- [Quantum Computing Report](https://quantumcomputingreport.com/news/)

### Bitcoin's BIP-361 Brings the "Freeze or Steal" Dilemma Into Focus

April 14, 2026

Bitcoin developers published BIP-361, "Post Quantum Migration and Legacy Signature Sunset," in the official repository on April 14, 2026. Its three phases would stop payments to vulnerable addresses (~3 years after activation), invalidate legacy ECDSA/Schnorr signatures (~5 years), and, in a still-research phase, let owners reclaim frozen coins with a zero-knowledge proof of their seed phrase.

It exists because BIP-360 protects only new coins, leaving ~34% of all BTC (6.5 to 6.9 million, including ~1.7 million Satoshi-era coins) permanently exposed. That is the freeze-or-steal dilemma: freezing lost coins offends Bitcoin's core promise, but leaving them makes them quantum bounties. And BIP-361 is still a draft with no activation timeline; a co-author estimates full migration at about seven years once consensus forms, which it has not.

- [BIP-361 specification](https://www.bip361.org/)
- [news.bitcoin.com](https://news.bitcoin.com/bitcoin-developers-propose-freezing-coins-that-skip-quantum-safe-migration-under-bip-361/)

### Tron Pledges a Post-Quantum Mainnet as the Incumbent Race Accelerates

April 14, 2026

Justin Sun said Tron will put NIST post-quantum signatures on mainnet, targeting a Q2 2026 testnet and Q3 2026 mainnet, and billed it as the "first major public blockchain" to do so. As of mid-April it was only an announcement, with no formal on-chain proposal or technical spec, and the "world's first" claim overlooks QRL, post-quantum since 2018. Others are moving too: Solana has PQ signatures on testnet, and Coinbase formed a quantum advisory board in January. The race shows both the urgency and the difficulty of retrofitting a live chain with millions of legacy addresses. (Update: the testnet pledge was delivered on June 30; see above.)

- [The Block](https://www.theblock.co/post/397572/justin-sun-says-tron-launching-post-quantum-upgrade-plan)
- [Unchained](https://unchainedcrypto.com/justin-sun-says-tron-will-be-first-major-blockchain-to-deploy-post-quantum-cryptography/)

### Independent Audit Finds No Vulnerabilities in QRL's Post-Quantum Cryptography

April 3, 2026

An independent Halborn audit of QRL's two NIST post-quantum signature libraries found no cryptographic vulnerabilities; all 13 findings were Informational and have been resolved. It followed the March 31 QRL 2.0 Testnet V2 launch (Hyperion plus the QRVM). Google's March 30 whitepaper had already named QRL as presently post-quantum-secure.

- [Halborn audit announcement](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/)
- [full report](https://www.halborn.com/audits/qrl-quantum-resistant-ledger/qrl-quantum-resistant-ledger-37d3f1)

### The Whole Migration Picture (July 2026)

"A fix exists" is not the same as "safe." A chain is safe only when its whole stack, the base protocol, every account, and the contracts, bridges, and value on top, is migrated before Q-Day. Here is what today's fixes actually cover:

- Fix
- Protects
- Does not protect

- Bitcoin BIP-360 (P2MR)
- new addresses, coins at rest
- coins on spend (the key still appears in the mempool when you move them); any existing coin

- Bitcoin BIP-361
- proposes freezing or migrating legacy coins
- draft only, no activation date; freezing lost coins is contested

- Ethereum by 2029
- the base protocol (validator signatures, KZG, ZK proofs)
- accounts, smart contracts, bridges, Layer-2s

- Tron testnet (June 2026)
- new PQ signature types, on testnet only
- switching it on for the real network (still needs a network vote); every holder moving their own coins; wallet and exchange support

- QRL since 2018
- the entire stack, from genesis
- nothing left to migrate

- Bitcoin: the migration dwarfs the fix. BIP-360 covers only new addresses, and only at rest; the instant you spend, the public key is exposed in the mempool. Existing coins are worse off: about 34% of all BTC (6.5 to 6.9 million, including ~1.7 million Satoshi-era coins) already have exposed keys that no upgrade can hide. And the scale is brutal: moving Bitcoin's ~190 million UTXOs at the network's ceiling of ~7 transactions per second would take roughly a year of blocks doing nothing but migration, and multi-year in practice. Every migration transaction briefly exposes its own key while it waits to confirm.
- Ethereum: the base layer is the easy part. The 2029 target covers the protocol only. The value sits above it: hundreds of millions of ECDSA accounts, the whole smart-contract and DeFi stack, bridges, and Layer-2s, each with its own cryptography and its own upgrade path. Many contracts are immutable and cannot be patched in place; they must be redeployed and their liquidity moved. Because DeFi is composable, one protocol depends on tokens, oracles, bridges, and an L2 that must all migrate together. No one can mandate it: it is voluntary coordination across hundreds of millions of accounts and thousands of independent teams (per-account wallet agility, via EIP-8141, is still only proposed for late 2026). A 2029 base layer is a milestone, not safety.
- QRL was post-quantum from its 2018 genesis (XMSS) and carries that into EVM smart contracts with ML-DSA-87, now on an independently audited public testnet. There is nothing to migrate before Q-Day.
- The throughline of 2026: the chains with the most at stake face the hardest migrations, while the protection they are racing toward has been live on QRL for years.

## References

### July - August 2026

- [ECDSA.fail Challenge (Eigen Labs)](https://www.ecdsa.fail/)
- [Yukon (Eigen Labs)](https://www.yukon.org/)
- [ECDSA.fail Challenge Repository (GitHub)](https://github.com/ecdsafail/ecdsafail-challenge)
- [WarpSpeed AI Cuts Quantum Encryption Cracking Cost (Quantum Zeitgeist)](https://quantumzeitgeist.com/quantum-encryption-cracking-cost-warpspeeds/)
- [Space-Efficient Point Addition for ECDLP (arXiv:2607.13816)](https://arxiv.org/abs/2607.13816)

### June - July 2026

- [Tron Nile Testnet Post-Quantum Signature Upgrade (Crypto Briefing)](https://cryptobriefing.com/tron-post-quantum-signatures-testnet/)
- [Tron Activates Quantum-Resistant Signatures on Nile Testnet (Cryptopolitan)](https://www.cryptopolitan.com/tron-network-quantum-resistant-sign/)
- [QRL: Eight Years of Building the Quantum-Safe Future (theqrl.org)](https://www.theqrl.org/blog/celebrating-8-years/)
- [Quantinuum IPO and Reliable Logical Qubits Demonstration (Quantinuum)](https://www.quantinuum.com/press-releases/quantinuum-and-microsoft-announce-new-era-in-quantum-computing-with-breakthrough-demonstration-of-reliable-qubits)
- [Microsoft Majorana 2 (Microsoft)](https://news.microsoft.com/source/features/innovation/majorana-2-microsoft-discovery-agentic-ai/)
- [Schrottenloher: Quantum Circuits for secp256k1 (arXiv)](https://arxiv.org/abs/2606.02235)
- [StarkWare Post-Quantum Roadmap for Starknet (Quantum Computing Report)](https://quantumcomputingreport.com/news/)
- [Crypto Firms Prepare Post-Quantum Defenses (The Daily Hodl / Reuters)](https://dailyhodl.com/2026/07/09/quantum-computing-threat-prompts-crypto-firms-to-prepare-post-quantum-defenses/)

### Bitcoin Vulnerability Analysis

- [Google Quantum AI Whitepaper 2026: Comprehensive Bitcoin + Ethereum quantum threat analysis](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf)
- [Kim et al. 2026: New Quantum Circuits for ECDLP (ePrint 2026/106)](https://eprint.iacr.org/2026/106)
- [Strike 2026: PQC Signatures Alone Cannot Support Coherent Bitcoin Migration (Zenodo)](https://zenodo.org/records/18526451)
- [Quantum Attacks on Bitcoin (Aggarwal et al., 2017)](https://arxiv.org/abs/1710.10377)
- [Breaking ECC with Quantum Computing (Webber et al.)](https://www.schneier.com/blog/archives/2022/02/breaking-245-bit-elliptic-curve-encryption-with-a-quantum-computer.html)
- [Bitcoin Address Vulnerability Analysis (Project Eleven)](https://blog.projecteleven.com/posts/quantum-vulnerability-of-bitcoin-addresses)
- [River Learn: Will Quantum Computing Break Bitcoin?](https://river.com/learn/will-quantum-computing-break-bitcoin/)

### Government Standards & Warnings

- [NIST IR 8547 - Transition Timeline](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf)
- [White House NSM-10](https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/)
- [NSA CNSA 2.0](https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)
- [NIST Post-Quantum Cryptography Standards](https://csrc.nist.gov/projects/post-quantum-cryptography)
- [Federal Reserve Quantum Warning (October 2025)](https://www.federalreserve.gov/econres/feds/harvest-now-decrypt-later-examining-post-quantum-cryptography-and-the-data-privacy-risks-for-distributed-ledger-networks.htm)

### Company Roadmaps

- [IonQ Accelerated Roadmap](https://ionq.com/blog/ionqs-accelerated-roadmap-turning-quantum-ambition-into-reality)
- [IonQ 99.99% Two-Qubit Gate Fidelity (October 2025)](https://www.ionq.com/news/ionq-achieves-landmark-result-setting-new-world-record-in-quantum-computing)
- [Infleqtion Sqale Roadmap](https://infleqtion.com/quantum-computing/)
- [Infleqtion First Shor's Algorithm on Logical Qubits (September 2025)](https://infleqtion.com/infleqtion-unveils-new-architecture-to-accelerate-its-quantum-computing-roadmap-to-achieve-1000-logical-qubits-by-2030/)
- [IBM Quantum Roadmap](https://www.ibm.com/roadmaps/quantum/)
- [Quantinuum Skinny Logic - Helios 98-Qubit Result](https://www.quantinuum.com/)
- [Oratomic (Caltech spin-out)](https://arxiv.org/pdf/2603.28627)

## Breaking News: March 2026

The 2025 Nobel Prize validated quantum computing as established science. In 2026, the industry has shifted from "Quantum Advantage" to "QuOps" (error-free Quantum Operations) as the definitive metric for progress, reflecting a mature understanding that value comes from sustained operations, not raw qubit counts.

March 2026 marked the shift from quantum research to quantum urgency. Back-to-back on March 30 and 31, Google Quantum AI cut the Bitcoin attack threshold to under 500,000 physical qubits with a 9-minute on-spend window, and Caltech/Oratomic showed the same attack on ~10,000 neutral-atom qubits, collapsing the old assumptions that millions of qubits are needed and that neutral-atom machines are too slow. Quantinuum's Skinny Logic, the EUROCRYPT paper (1,098 logical qubits), PsiQuantum's first utility-scale facility, $1.5 billion in new government funding, and a first quantum Turing Award rounded out the month. On defence, BIP-360 reached testnet with no mainnet timeline and no help for coins already exposed. The hardware is accelerating; the migration is not.

### Google Quantum AI Publishes Cryptocurrency Whitepaper

March 30, 2026

Google Quantum AI's whitepaper - co-authored with Justin Drake (Ethereum Foundation) and Dan Boneh (Stanford) - is the most authoritative assessment of the quantum threat to cryptocurrency to date. Its headline result: Shor's algorithm against Bitcoin's ECDSA-256 now needs only ~1,200-1,450 logical qubits and fewer than 500,000 physical qubits, a 20x cut over prior estimates. With precomputation, the attack completes in roughly 9 minutes - inside Bitcoin's average block time.

The paper introduces a new attack taxonomy (On-Spend, At-Rest, On-Setup) and sharpens the 'burn or steal' dilemma facing the ~1.7 million BTC locked in P2PK addresses - permanently exposed coins that no fork can migrate. Google verified its findings with a zero-knowledge proof, so the resource estimates can be checked without releasing the attack circuits.

- [Google Quantum AI Whitepaper](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf)

### Caltech/Oratomic Show Shor's Algorithm Needs Only ~10,000 Physical Qubits

March 31, 2026

A Caltech-led paper, alongside the spin-out Oratomic, shows Shor's algorithm against ECC-256 can run on as few as ~10,000 reconfigurable atomic qubits - or ~26,000 in parallel mode for a roughly 10-day run. That is about 100x below prior neutral-atom estimates and two orders of magnitude under the ~1 million qubits typically cited for surface codes.

The breakthrough comes from high-rate qLDPC codes with ~30% encoding (about 1 logical qubit per 3.5 physical), paired with neutral-atom hardware that already runs at 6,100 coherent qubits today. Combined with Google's whitepaper - which needs only ~1,200 logical qubits - the two results sketch a credible CRQC that is far smaller and far closer in time than any prior analysis suggested.

- [Cain et al., arXiv:2603.28627](https://arxiv.org/pdf/2603.28627)

### Google Officially Warns Q-Day Could Arrive as Early as 2029

March 25, 2026

Google has set its first public timeline for post-quantum migration. VP of Security Engineering Heather Adkins and Senior Cryptology Engineer Sophie Schmieg warn that a cryptographically relevant quantum computer capable of breaking RSA and elliptic curve cryptography could exist as early as 2029. Google is already integrating ML-DSA into Android 17 and has proposed Merkle Tree Certificates to keep post-quantum signature overhead manageable in web PKI.

The world's most widely-used mobile OS and browser are now on a defined PQC schedule. Bitcoin and Ethereum still have no equivalent plan, and the gap is widening by the month.

- [Google Security Blog](https://security.googleblog.com/)
- [Google Android 17](https://android.googleblog.com/)

### Quantinuum "Skinny Logic" Achieves Record 2:1 Physical-to-Logical Qubit Ratio

March 2026

Quantinuum's Skinny Logic initiative, demonstrated on its 98-qubit Helios trapped-ion processor, achieved 48 error-corrected logical qubits from 98 physical qubits - a 2:1 ratio. For comparison, surface codes (the dominant approach) typically require 500:1 to 1,000:1. Logical qubits outperformed their physical counterparts by 10 to 100x.

Why This Matters for Crypto: The Google whitepaper now sets the minimum attack threshold at ~1,200 logical qubits. The Oratomic paper shows this can be achieved with ~10,000-26,000 physical qubits using high-rate qLDPC codes. The Skinny Logic result is a separate approach (trapped-ion + modified surface codes) reaching 2:1, showing that the qubit overhead reduction is occurring across multiple hardware platforms simultaneously.

- [Quantinuum Blog](https://www.quantinuum.com/)

### Google Expands into Neutral-Atom Quantum Computing

March 2026

Google Quantum AI appointed Dr. Adam Kaufman (JILA Fellow, University of Colorado Boulder) to lead a new neutral-atom quantum computing team - a second hardware modality alongside its superconducting program. Neutral-atom arrays already exist at 10,000 qubits with reconfigurable "any-to-any" connectivity.

Why This Matters: Google's dual-modality strategy directly hedges the fast-clock vs. slow-clock uncertainty outlined in its own whitepaper. Neutral-atom platforms scale efficiently in the "space dimension." Google's cryptocurrency whitepaper notes that slow-clock (neutral-atom/ion-trap) CRQCs will be able to launch at-rest attacks even before on-spend attacks become feasible - and the Oratomic paper published the same week demonstrates this path is more accessible than previously thought.

- [Google Quantum AI Blog](https://quantumai.google/)

### PsiQuantum Breaks Ground on World's First 1-Million-Qubit Facility

March 2026

PsiQuantum began construction at the Illinois Quantum and Microelectronics Park in Chicago - the first utility-scale quantum computing construction project in history. The facility is designed for a 1 million-qubit quantum supercomputer, funded with $1 billion from NVIDIA, BlackRock, and state partners.

This is no longer a lab experiment. Industrial-scale quantum infrastructure is being built now. PsiQuantum uses standard semiconductor fabs, giving quantum the same manufacturing economics as classical chips.

- [PsiQuantum](https://psiquantum.com/)

### BIP-360 Goes Live on Bitcoin Testnet

March 19, 2026

BTQ Technologies launched Bitcoin Quantum testnet v0.3.0 on March 19, 2026, the first working implementation of BIP-360 (Pay-to-Merkle-Root, P2MR), with 50+ miners and 100,000+ blocks. P2MR was merged into Bitcoin's BIP repository on February 11, 2026.

What it fixes is narrow. P2MR removes Taproot's key-path so a public key is no longer written on-chain, but only for new addresses, and only against At-Rest attacks (harvesting keys that already sit permanent on-chain, with no time pressure). The key still appears in the mempool on every spend, so On-Spend exposure is untouched, left to a future post-quantum-signature proposal.

And that is the easy part. P2MR does nothing for the ~$470 billion already in exposed addresses (all P2PK, all Taproot, every reused address), and migrating the rest is its own ordeal: Bitcoin's ~190 million UTXOs, at the chain's ceiling of ~7 transactions per second, would take roughly a year of blocks doing nothing but migration, multi-year in practice, and each migration spend briefly re-exposes the very key it is trying to protect. BIP-360 has no mainnet activation date, and SegWit and Taproot each took 7 to 8 years to adopt.

- [BIP-360 specification](https://bip360.org/bip360.html)
- [BTQ press release](https://www.prnewswire.com/news-releases/btq-technologies-announces-first-deployment-of-bip-360-on-bitcoin-quantum-testnet-v0-3-0--302718592.html)
- [Bitcoin Magazine](https://bitcoinmagazine.com/news/btq-deploys-first-bip-360-quantum)
- [Project Eleven vulnerability breakdown](https://blog.projecteleven.com/posts/quantum-vulnerability-of-bitcoin-addresses)
- [Google Quantum AI Whitepaper](https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf)

### New Paper Reduces ECC Attack to 1,098 Logical Qubits (EUROCRYPT 2026)

March 26, 2026

A paper by Chevignard, Fouque, and Schrottenloher accepted at EUROCRYPT 2026 (ePrint 2026/280) demonstrates a space-optimised Shor's algorithm requiring only 1,098 logical qubits for 256-bit elliptic curve discrete logarithm - down from the previous minimum of 2,124. The method uses a Residue Number System and Legendre symbol compression to avoid modular inversion, achieving 3.12n + o(n) total qubits for an n-bit curve.

Important trade-off: This qubit-minimised result requires 22 independent runs and approximately 2^38.10 Toffoli gates each - a massively higher gate count than depth-optimised approaches. For early fault-tolerant hardware where logical qubits are the bottleneck, this provides a path to attacking ECC on smaller systems. For hardware where gate count is the bottleneck, Google's ~1,200-1,450 qubit / 18-23 minute approach remains more practical.

- [ePrint 2026/280](https://eprint.iacr.org/2026/280)
- [Quantum Computing Report](https://quantumcomputingreport.com/resource-estimates-for-quantum-discrete-logarithm-computations-on-256-bit-elliptic-curves/)

### Turing Award Goes to Quantum Cryptography Founders for First Time

March 18, 2026

The ACM A.M. Turing Award - computing's highest honour - was awarded for the first time to quantum science. Charles H. Bennett (IBM Research) and Gilles Brassard (University of Montreal) share the $1 million prize for their foundational work on quantum information science, including the BB84 quantum key distribution protocol (1984) and quantum teleportation (1993).

Bennett and Brassard invented the quantum-safe cryptographic primitives that are now the backbone of post-quantum defence. Brassard himself noted the urgency of "harvest now, decrypt later" attacks at the award announcement.

- [ACM Turing Award](https://www.acm.org/media-center/2026/march/turing-award-2025)
- [Nature](https://www.nature.com/articles/d41586-026-00818-z)

### Raccoon-G - First Post-Quantum Wallet with Full BIP32 HD Derivation

March 2026

Researchers published the first post-quantum construction to recover full BIP32 hierarchical deterministic (HD) wallet functionality. Standard NIST PQC schemes (ML-DSA) destroy the linearity needed for non-hardened BIP32 derivation. Raccoon-G uses Gaussian-distributed secrets and full unrounded public keys to preserve it, with security proved under standard lattice assumptions. Trade-off: larger keys (~16 KB public key vs. 33 bytes for secp256k1).

- [Raccoon-G preprint](https://eprint.iacr.org/)

### Circle (USDC) Releases Q-Day Roadmap for Blockchains

March 2026

Circle, issuer of USDC, published a detailed quantum preparation roadmap treating the entire blockchain stack as at risk. Key transitions: TLS 1.3 migration to X25519MLKEM768; replace elliptic curve SNARKs with quantum-resistant STARKs. U.S. and EU are expected to mandate PQC for critical infrastructure by 2030.

For Crypto: The first major stablecoin issuer has set a public timeline. 2030 regulatory mandates will compress the entire DeFi ecosystem's migration window.

- [Circle Research](https://circle.com/research)

### Intel Heracles - FHE Chip Delivers 5,547x Speedup for Encrypted Computation

March 2026

Intel demonstrated the Heracles processor at ISSCC - a 3nm chip for Fully Homomorphic Encryption (FHE), which processes data without decrypting it. Performance: 1,074-5,547x faster than a 24-core Xeon CPU.

FHE makes quantum-safe, privacy-preserving cloud computing production-ready - enabling encrypted-by-default infrastructure even before Q-Day arrives.

- [Intel ISSCC 2026](https://www.isscc.org/)

### IBM Quantum Simulates Real Magnetic Material - Verified Against Physical Lab Data

March 26, 2026

IBM and the DOE's Quantum Science Center used a 50-qubit Heron processor to simulate the magnetic crystal KCuF3, with results verified directly against neutron scattering experiments at Oak Ridge National Laboratory. This is the first time a quantum computer's output has been benchmarked against real physical material data rather than a classical computer.

This demonstrates that current "noisy" quantum hardware is already delivering scientifically reliable results at utility scale - before full fault tolerance is achieved. IBM projects fault-tolerant systems by 2029.

- [IBM press release](https://newsroom.ibm.com/2026-03-26-ibm-quantum-computer-accurately-simulates-real-magnetic-materials,-reproducing-national-laboratory-data)

### Silicon Quantum Processor Achieves Universal Logical Gate Set

March 28, 2026

Researchers at the Shenzhen International Quantum Academy demonstrated a silicon-based quantum processor executing a universal set of logical gate operations, including T-gates and CNOT operations, using five phosphorus donor nuclear spins in an isotopically purified silicon-28 lattice. Published in Nature Nanotechnology, the result validates error-corrected quantum computing on a platform fully compatible with existing CMOS semiconductor manufacturing.

- [The Quantum Insider](https://thequantuminsider.com/2026/03/28/chinese-researchers-demonstrate-logical-operations-on-silicon-quantum-processor/)

### National Quantum Investment Surge

March 2026

Major national quantum investments announced: Karnataka, India ($114M for $20B quantum economy by 2035); Australia NRFC ($20M AUD for SQC atomic-scale semiconductor qubits); USA DOE ($37M for National QIS Research Centers); United Kingdom ($100M for Rigetti hardware development plus £2 billion ProQure program); Europe EC (€75M for EURO-3C quantum infrastructure). PsiQuantum's Chicago facility adds $1 billion - the largest single quantum infrastructure investment to date.

- [Karnataka Quantum Mission](https://it.karnataka.gov.in/)
- [DOE QIS](https://www.energy.gov/science/quantum-information-science)
- [UK ProQure](https://www.gov.uk/)

### Fermilab-MIT Eliminate the Ion Trap Wiring Bottleneck

March 2026

Fermilab and MIT Lincoln Laboratory demonstrated in-vacuum cryoelectronics for ion traps - mounting control chips directly inside the dilution refrigerator, eliminating the cable scaling problem that previously limited trapped-ion systems to dozens of qubits. This opens a credible path to tens of thousands of electrodes.

- [Fermilab](https://www.fnal.gov/)
- [MIT Lincoln Laboratory](https://www.ll.mit.edu/)

### UC Santa Barbara Proposes CN Center - Stable Silicon Defect for Quantum Networking

March 2026

UCSB researchers proposed the CN center silicon defect as a structurally stable telecom-band qubit emitter - solving the fragility problem of T centers caused by hydrogen migration during fabrication. Photonic Inc. is simultaneously exploring deuterium-substituted T centers for improved magnetic field control.

Telecom-band emitters are the foundation of modular quantum architectures that link distributed processors via standard optical fiber.

- [UCSB](https://www.ucsb.edu/)

### Niels Bohr Institute - Real-Time Qubit Monitoring During Computation

March 2026

NBI researchers demonstrated a system that tracks qubit performance fluctuations in real time - down to fractions of a second - enabling dynamic noise correction during long computations. This is a prerequisite for Shor's algorithm, which requires sustained computation over extended periods.

- [Niels Bohr Institute](https://www.nbi.ku.dk/)

### Majorana Replication Controversy (Frolov et al., Science)

March 2026

A team led by Sergey Frolov published replication studies in Science finding that signals previously interpreted as Majorana qubit signatures could be explained by simpler mechanisms when fuller datasets were analysed. The work underwent two years of peer review.

Context: This is separate from QuTech's February 2026 Nature paper demonstrating successful Majorana qubit readout via quantum capacitance, which remains uncontested. The controversy reinforces the value of diverse hardware strategies rather than undermining topological computing overall.

- [Frolov et al., Science](https://www.science.org/)

### Nature Confirms "Vibe Shift" - Usable Quantum Computers Within a Decade

February 4, 2026

A major Nature news feature declares a "vibe shift" in quantum computing: researchers now believe useful quantum computers could arrive within 10 years, not decades. The article cites four teams - Google, Quantinuum, Harvard/QuEra, and USTC in China (Zuchongzhi 3.2) - that have demonstrated below-threshold quantum error correction, meaning logical error rates suppress exponentially as more qubits are added.

Key quotes:
- Dorit Aharonov (Hebrew University): "At this point, I am much more certain that quantum computation will be realized, and that the timeline is much shorter than people thought. We've entered a new era."
- Nathalie de Leon (Princeton): Describes the change as a "vibe shift" - "People are now starting to come around."
- Chao-Yang Lu (USTC): Expects a fault-tolerant quantum computer by 2035.

For Crypto: Four independent teams across three continents have now proven the fundamental physics of error correction works. The remaining challenge is engineering and manufacturing - a challenge with predictable scaling curves and massive investment behind it.

- [Nature](https://www.nature.com/articles/d41586-026-00312-6)

### Iceberg Quantum Pinnacle Architecture Reduces RSA-2048 Breaking Requirement to Under 100,000 Physical Qubits

February 12, 2026

Iceberg Quantum (Sydney-based startup, $6M seed round) published the Pinnacle Architecture, a fault-tolerant quantum computing design using quantum LDPC codes instead of surface codes. Under standard hardware assumptions (physical error rate of 10⁻³, code cycle time of 1 µs, reaction time of 10 µs), the architecture factors RSA-2048 with fewer than 100,000 physical qubits - an order of magnitude below the previous best estimate of ~1 million (Gidney 2025).

How it works: The architecture uses three modular components: (1) Processing Units built from bridged QLDPC code blocks (specifically generalized bicycle codes) that encode 14 logical qubits in ~860 physical qubits at distance 16 - compared to 1 logical qubit in ~511 physical qubits for a surface code at the same distance; (2) Magic Engines that simultaneously produce and consume magic states for a continuous pipeline of T gates; and (3) Memory blocks for efficient qubit storage with parallel read access. A novel technique called Clifford frame cleaning enables flexible parallelism across processing units.

Key numbers for RSA-2048 factoring:
- Minimum qubits config: 97,000 physical qubits, ~1 month runtime
- Faster config: 151,000 physical qubits, ~1 week runtime
- Trapped ions: 3.1 million physical qubits, ~1 month runtime

Why This Matters for Crypto: Previous estimates assumed surface codes requiring ~1 million physical qubits for RSA-2048, placing CRQC capabilities beyond near-term hardware roadmaps. QLDPC codes compress this by 10x. Iceberg is already partnering with PsiQuantum (photonics), Diraq (spin qubits), and IonQ (trapped ions), all of which project systems of this scale within 3-5 years. While these results are based on simulations and theoretical resource estimates (not experimental demonstrations), they fundamentally reset the hardware threshold for cryptographically relevant quantum computing.

Important caveat: The paper does not address ECDSA/secp256k1 directly - the RSA result demonstrates the architecture's efficiency. Applying similar QLDPC-based architectures to elliptic curve cryptanalysis could yield comparable overhead reductions, potentially bringing the physical qubit requirement for Bitcoin key-breaking well below current 8 million estimates.

- [arXiv:2602.11457](https://arxiv.org/abs/2602.11457)
- [The Quantum Insider](https://thequantuminsider.com/2026/02/13/new-architecture-could-cut-quantum-hardware-needed-to-break-rsa-2048-by-tenfold-study-finds/)
- [GlobeNewswire](https://www.globenewswire.com/news-release/2026/02/13/3237814/0/en/Iceberg-Quantum-unveils-breakthrough-in-fault-tolerant-quantum-computing.html)

### QuTech Achieves First-Ever Readout of Majorana Qubits (Nature)

February 11, 2026

Researchers at QuTech (Delft) and ICMM-CSIC (Madrid) demonstrated the first single-shot, real-time readout of quantum information stored in Majorana-based topological qubits, published in Nature. Using quantum capacitance as a global probe, the team distinguished even/odd parity states of a minimal Kitaev chain with parity coherence exceeding one millisecond.

Why This Matters: Topological qubits (Microsoft's primary approach) store information non-locally across Majorana zero modes, making them inherently resistant to local noise - but this same property made reading them a long-standing challenge. This breakthrough solves the readout problem without compromising topological protection, establishing the measurement primitive needed for functional Majorana-based quantum computers.

- [Nature (DOI: 10.1038/s41586-025-09927-7)](https://www.nature.com/articles/s41586-025-09927-7)
- [QuTech](https://qutech.nl/2026/02/12/qutech-demonstrates-real-time-readout-for-majorana-based-qubits/)

### QuTech QARPET Chip Benchmarks 1,058 Spin Qubits at 2 Million Qubits/mm²

February 12, 2026

QuTech (TU Delft) published the QARPET platform (Qubit-Array Research Platform for Engineering and Testing) in Nature Electronics - a crossbar-tiled chip architecture that can host up to 1,058 semiconductor spin qubits in a 23×23 grid, requiring only 53 control lines. The chip achieves a potential density of approximately two million qubits per square millimeter.

Why This Matters: Scaling quantum processors requires understanding statistical qubit properties across large arrays. QARPET brings semiconductor qubit testing in line with traditional chip industry practices, enabling hundreds of qubits to be characterized in a single cooldown. This platform accelerates the path to million-qubit semiconductor quantum computers, which leverage existing CMOS fabrication infrastructure.

- [Nature Electronics (DOI: 10.1038/s41928-026-01569-5)](https://doi.org/10.1038/s41928-026-01569-5)
- [Phys.org](https://phys.org/news/2026-02-carpet-qubits-chip-architecture.html)

### Reed-Muller Codes Enable Full Clifford Group Without Ancilla Qubits

February 12, 2026

Researchers from Osaka, Oxford, and Tokyo demonstrated that high-rate quantum Reed-Muller codes can implement the full logical Clifford group using only transversal and fold-transversal gates - no ancilla qubits required. This is the first such construction for a code family where logical qubits grow nearly linearly with block length.

Why This Matters: This provides another pathway (alongside QLDPC codes) to reduce the overhead of fault-tolerant quantum computing. Eliminating ancilla requirements for Clifford gates means fewer physical qubits needed per logical operation, further compressing the hardware threshold for cryptographically relevant computations.

- [Quantum Zeitgeist](https://quantumzeitgeist.com/quantum-computing-error-correction-breakthrough-unlocks-powerful-minimal-extra/)

### ePrint 2026/106 - Revised ECDSA Attack Estimates (Kim et al.)

February 2026

New research significantly revises the quantum resource estimates for breaking Bitcoin's secp256k1 curve. Kim et al. present optimized quantum circuits for Shor's algorithm on elliptic curves that achieve up to 40% improvement in the qubit-count × depth product compared to all previous work, including Roetteler et al. (2017) and Häner et al. (2020).

The widely-cited "~2,330 logical qubits" was the qubit-minimized design with impractically long runtime. A practical attack (completing in ~2 hours) requires ~6,500 logical qubits and ~8 million physical qubits. Maximum circuit depth of 2^28 is well below NIST's MAXDEPTH constraint of 2^40.

The bottom line: Current quantum hardware (Quantinuum Helios: 98 physical qubits, 48 logical) is still far from this threshold, but company roadmaps targeting utility-scale quantum by 2029-2033 place this within reach in the next decade.

- [ePrint 2026/106](https://eprint.iacr.org/2026/106)

### ETH Zurich Demonstrates First Lattice Surgery on Superconducting Qubits

February 6, 2026

Researchers at ETH Zurich and the Paul Scherrer Institute demonstrated lattice surgery on a 17-qubit superconducting processor - the first time this critical operation has been performed on superconducting qubits. Published in Nature Physics, the team used a distance-three surface code to split a single logical qubit into two entangled logical qubits while continuously correcting bit-flip errors.

Why This Matters: Lattice surgery is the operation for fault-tolerant quantum computing. As researcher Ilya Besedin explains: "One could say that the lattice surgery operation is the operation, and all the others can be constructed from it." This clears a major hurdle for scaling superconducting quantum computers - the dominant architecture pursued by IBM, Google, and USTC - toward fault-tolerant systems capable of running Shor's algorithm.

- [Nature Physics](https://www.nature.com/articles/s41567-025-03090-6)
- [ETH Zurich](https://www.phys.ethz.ch/news-and-events/d-phys-news/2026/01/surgery-for-quantum-bits.html)

### Stanford Cavity-Array Microscope Unlocks Million-Qubit Scaling

February 2, 2026

Stanford researchers published a breakthrough in Nature: a novel optical cavity array that efficiently captures photons from individual atoms, enabling parallel readout of all qubits simultaneously. The team demonstrated a working 40-cavity array and a 500+ cavity prototype, with a clear path to tens of thousands.

Why This Matters: One of the biggest barriers to million-qubit quantum computers has been qubit readout - atoms emit photons too slowly and in all directions. Stanford's microlens-equipped cavities solve this by efficiently funneling light from each atom into a specific direction, even with fewer light bounces. The researchers envision "quantum data centers" where individual quantum computers are linked through cavity-based network interfaces to form quantum supercomputers.

- [ScienceDaily](https://www.sciencedaily.com/releases/2026/02/260201223737.htm)
- [Nature](https://doi.org/10.1038/s41586-025-10035-9)

### Alice & Bob "Elevator Codes" Slash Error Rates 10,000x

January 21, 2026

Alice & Bob, the French cat-qubit quantum computing company (NVIDIA partner), announced "Elevator Codes" - a new error correction technique that achieves a 10,000× lower logical error rate while requiring only ~3× more qubits. The technique works by "moving" logical ancilla qubits up and down during computation to provide additional bit-flip protection.

Why This Matters: Error correction overhead is the single biggest obstacle to building useful quantum computers. Standard approaches require massive numbers of physical qubits per logical qubit. Alice & Bob's cat qubits are naturally protected against one error type (bit-flips); these elevator codes multiply that protection at minimal cost, potentially making useful quantum computers feasible much sooner than expected.

- [Alice & Bob](https://alice-bob.com/newsroom/reducing-quantum-computing-errors-with-new-code/)
- [arXiv:2601.10786](https://arxiv.org/abs/2601.10786)

### Ultra-Fast Photonic Phase Modulator for Quantum Computing (JMU Würzburg)

January 20, 2026

German researchers at Julius Maximilian University of Würzburg developed an ultra-fast, ultra-low-loss optical phase modulator by integrating ferroelectric barium titanate crystals into III-V photonic platforms. Backed by €6.6 million in federal funding, the chip controls light signals at extremely high speeds with almost no losses.

Why This Matters: Quantum photonic circuits require components that combine very high speed with extremely low optical losses - even tiny losses collapse quantum states. This modulator could speed up the transition of quantum photonics from laboratory experiments to practical, large-scale technologies.

- [Interesting Engineering](https://interestingengineering.com/science/new-ultra-fast-photonic-chips)

### USTC Zuchongzhi 3.2 Joins Below-Threshold QEC Club

December 22, 2025

China's University of Science and Technology (USTC) demonstrated fault-tolerant quantum error correction below the surface code threshold using the 107-qubit Zuchongzhi 3.2 processor. Published as an Editors' Suggestion in Physical Review Letters, the team achieved an error suppression factor of Λ = 1.40 using a distance-7 surface code - proving their system operates below the critical error threshold.

The fourth team: This makes USTC the fourth team worldwide (after Google, Quantinuum, and Harvard/QuEra) to achieve below-threshold QEC, and the first outside the United States. Their novel all-microwave leakage suppression architecture suppressed leakage population by a factor of 72×, and it reduces wiring density inside the dilution refrigerator, offering a scalability advantage.

- [Physical Review Letters (Editors' Suggestion)](https://link.aps.org/doi/10.1103/rqkg-dw31)
- [Quantum Computing Report](https://quantumcomputingreport.com/ustcs-zuchongzhi-3-2-achieves-below-threshold-qec-milestone/)

### Ubuntu 26.04 LTS Ships with Post-Quantum Cryptography by Default

February 6, 2026

Ubuntu 26.04 LTS ("Resolute Raccoon," releasing April 23, 2026) will ship with post-quantum cryptography enabled by default in OpenSSH and OpenSSL, using hybrid post-quantum algorithms. This marks the first major Linux distribution to make PQC the default for all encrypted communications.

Why This Matters for Crypto: When the world's most popular server operating system makes PQC the default, it signals that the post-quantum transition is no longer theoretical - it's shipping in production infrastructure. Bitcoin and Ethereum still use quantum-vulnerable ECDSA as their sole signature scheme. The contrast is stark: Linux servers protecting SSH connections with hybrid PQC while billions in crypto remain protected only by secp256k1.

- [PBX Science](https://pbxscience.com/ubuntu-26-04-lts-tpm-encryption-rust-core-and-post-quantum-security-arrive/)

### Los Alamos National Laboratory Establishes Center for Quantum Computing

February 6, 2026

Los Alamos National Laboratory formed a dedicated Center for Quantum Computing, consolidating up to three dozen quantum researchers across national security, algorithms, computer science, and workforce development. The center supports DARPA's Quantum Benchmarking Initiative, the DOE's Quantum Science Center, and NNSA's Beyond Moore's Law project.

- [The Quantum Insider](https://thequantuminsider.com/2026/02/06/los-alamos-forms-quantum-computing-focused-research-center/)

### PQC Signature Upgrades Alone Cannot Support Coherent Bitcoin Migration

February 8, 2026

A new preprint by Michael Strike (Quantum Compliance, LLC) formally demonstrates that post-quantum digital signature algorithms alone are insufficient to support a coherent migration of Bitcoin under its existing protocol semantics. Rather than evaluating specific cryptographic constructions or governance mechanisms, the analysis focuses on structural constraints arising from Bitcoin's definitions of ownership, validity, and consensus as originally specified by Nakamoto.

The core finding: By holding Bitcoin's fundamental assumptions fixed - signature-defined ownership, immutable ledger history, and independent node validation - the paper characterizes a protocol-semantic constraint showing that certain migration objectives cannot be simultaneously satisfied without modifying underlying consensus semantics. The analysis is non-temporal (it does not depend on when a CRQC arrives) and does not propose specific migration mechanisms.

Why This Matters: This formalizes what the practical migration analysis already suggests - that Bitcoin's quantum migration challenge is not merely a cryptographic problem (swap ECDSA for Dilithium) but a fundamental protocol-design problem. Even with perfect PQC algorithms, Bitcoin's ownership model creates migration constraints that cannot be resolved without consensus-level changes. This adds formal rigor to the "defensive downgrade" thesis.

- [Zenodo (DOI: 10.5281/zenodo.18526451)](https://zenodo.org/records/18526451)

### 2026 Timeline Compression Update - Hardware Threshold Collapsing

February 2026

QLDPC codes rewrite the playbook: Iceberg Quantum's Pinnacle Architecture shows RSA-2048 can be broken with under 100,000 physical qubits using QLDPC codes - 10x fewer than surface code estimates. Hardware partners PsiQuantum, Diraq, and IonQ project systems of this scale within 3-5 years.

Four teams below threshold: Google, Quantinuum, Harvard/QuEra, and USTC have all independently demonstrated below-threshold QEC. Two years ago, zero had.

Topological qubits take a leap: QuTech demonstrated the first-ever readout of Majorana qubits via quantum capacitance (Nature), solving a decade-old experimental challenge. Microsoft's topological approach gains credibility.

Lattice surgery demonstrated: ETH Zurich performed the first lattice surgery on superconducting qubits - the critical missing operation for fault-tolerant computing.

Error correction economics transforming: Alice & Bob's Elevator Codes (10,000× error reduction for 3× more qubits), IonQ's Beam Search Decoder (17× error reduction), and Reed-Muller codes eliminating ancilla overhead are changing the cost equation from multiple directions simultaneously.

Million-qubit scaling path visible: Stanford's cavity-array microscope demonstrates parallel qubit readout at scale. QuTech's QARPET benchmarks 1,058 spin qubits at 2M/mm² density. Path to 100,000+ qubits now engineering, not physics.

Infrastructure moving: Ubuntu 26.04 ships PQC by default. Los Alamos consolidates quantum center. PsiQuantum appoints AMD/Xilinx veteran as CEO for deployment phase. DARPA Stage B has 11 companies. 2026 is the year quantum moves from labs to deployment.

### blueqat Unveils Desktop-Scale Silicon Quantum Computer

January 16, 2026

Japanese startup blueqat displayed the first domestically developed semiconductor quantum computer at SEMICON Japan 2025, using single-electron transistors on silicon at 0.3 Kelvin-significantly warmer than superconducting systems.

Why This Matters: Cost under ¥100M (~$670K USD)-1/30th the price of superconducting systems. Power: 1,600W vs. tens of kilowatts. Compatible with standard CMOS manufacturing. Desktop form factor.

The Threat Acceleration: Silicon quantum computing leverages existing semiconductor fabs, potentially achieving "Moore's Law economics"-costs falling with volume, yields improving with iteration. This could dramatically compress timelines to CRQC capabilities. Target: 100 qubits by 2030.

- [EE Times Japan](https://eetimes.itmedia.co.jp/ee/articles/2601/16/news022.html)

### MIT Achieves Scalable Chip-Based Trapped Ion Cooling

January 15, 2026

MIT and Lincoln Laboratory demonstrated polarization-gradient cooling on photonic chips-cooling ions 10x below the Doppler limit in 100 microseconds using integrated nanoscale antennas.

Why This Matters: Traditional trapped-ion systems require bulky external optics, limiting scaling to dozens of ions. Chip-based integration enables thousands of ion sites on a single chip with improved stability. This removes a critical barrier to scaling trapped-ion quantum computers-a leading architecture for achieving the qubit fidelities needed for cryptographic attacks.

- [MIT News](https://news.mit.edu/2026/efficient-cooling-method-could-enable-chip-based-quantum-computers-0115)
- [Light: Science and Applications](https://www.nature.com/articles/s41377-025-02094-4)

### Equal1 Raises $60M for Silicon Quantum Servers

January 15, 2026

Equal1 raised $60M for its Bell-1 silicon quantum server-already shipping to ESA's Space HPC Centre. Rack-mounted, datacenter-ready, no dilution refrigerators required. Uses standard semiconductor manufacturing.

Timeline Compression: Leveraging existing fabs enables semiconductor economics (costs fall with volume). Already in production while other architectures remain in lab. This commercialization path could accelerate CRQC timelines.

- [The Quantum Insider](https://thequantuminsider.com/2026/01/15/equal1-announces-60-million-raise-for-quantum-computer-that-use-existing-semiconductor-manufacturing/)

### Year of Quantum Security (YQS2026) - Threat Declared Operational

January 12, 2026

FBI, CISA, and NIST launched the "Year of Quantum Security 2026" initiative in Washington D.C., declaring the quantum threat has transitioned from theoretical to operational. Federal agencies face mandates to complete cryptographic transitions by 2035-requiring immediate action since infrastructure upgrades take 5-7 years.

The "Harvest Now, Decrypt Later" Crisis: Adversaries are actively intercepting and storing encrypted blockchain transactions today for future quantum decryption. Any data with a shelf life beyond "Q-Day" is effectively compromised now if intercepted.

Critical Math: If Q-Day is 8 years away (2034) and migration takes 5-7 years, organizations starting today are "barely on time." Bitcoin and Ethereum have not begun mandatory migration.

- [The Quantum Insider](https://thequantuminsider.com/2026/01/06/after-a-year-of-quantum-awareness-2026-becomes-the-year-of-quantum-security/)

### Quantinuum Files for $20B+ IPO - The "Netscape Moment"

January 2026

Quantinuum filed confidential IPO registration targeting $20+ billion valuation. Analysts call this quantum's "Netscape moment"-institutional capital now views quantum as commercially viable, not speculative research.

Timeline Acceleration: Public markets provide capital for rapid scaling, talent acquisition, manufacturing. Quantinuum demonstrated 100 reliable logical qubits in 2025 with error rates 800x lower than physical qubits-proof of commercial viability.

### 2026 Timeline Compression: All Barriers Falling Simultaneously

January 2026

Silicon Economics: blueqat ($670K systems), Equal1 (shipping now), Intel/AIST partnerships leverage existing fabs-potential "Moore's Law" scaling for qubits.

Error Correction Solved: 120 QEC papers (2025) vs. 36 (2024). IonQ Beam Search (17x error reduction), Japanese near-theoretical accuracy. Critical bottleneck eliminated.

Commercial Capital: Quantinuum $20B+ IPO, D-Wave $550M acquisition, Equal1 $60M. Research grants → commercial markets = exponential acceleration.

Physics Risk Gone: Google Willow proved below-threshold error correction. Scaling to millions of qubits is now pure engineering.

Expert Consensus Shifting: Conservative "2035+" timelines increasingly questioned. Multiple paths to CRQC validated simultaneously.

### D-Wave Acquires Quantum Circuits for $550M, Targets 2026 Gate-Model Launch

January 7, 2026

D-Wave acquired Quantum Circuits Inc. ($550M: $300M stock, $250M cash), combining annealing and error-corrected gate-model technologies. Dr. Rob Schoelkopf (inventor of transmon and dual-rail qubits, Yale professor) joins to lead gate-model development.

Key Milestone: D-Wave demonstrated "scalable, on-chip cryogenic control" for gate-model qubits-industry-first breakthrough removing a major scaling obstacle. First dual-rail system planned for general availability in 2026.

What This Means: Only company with both annealing (optimization) and gate-model (cryptography-relevant) capabilities. Brings gate-model to market years ahead of previous projections.

- [D-Wave](https://www.dwavequantum.com/company/newsroom/press-release/d-wave-to-acquire-quantum-circuits/)
- [Fast Company](https://www.fastcompany.com/91469364/d-wave-quantum-computing-first-major-breakthrough-of-2026-scalable-technology)

### Quantum Structured Light Reaches Practical Applications

January 6, 2026

International team published comprehensive Nature Photonics review showing quantum structured light has progressed from experimental curiosity to compact chip-based technologies. High-dimensional photons enhance quantum communication security and computing efficiency.

Practical Impact: Holographic quantum microscopes for biological imaging, extremely sensitive quantum sensors now viable. Field reaching turning point for commercial deployment.

- [ScienceDaily](https://www.sciencedaily.com/releases/2026/01/260106001911.htm)

### IonQ Breaks the Decoding Bottleneck

January 8, 2026

IonQ's new Beam Search Decoder achieves 17x reduction in logical error rate and 26x faster runtime, executing in under 1 millisecond on a standard CPU. IonQ estimates three 32-core CPUs could correct 1,000 logical qubits, versus 1,000 FPGA decoders for equivalent superconducting systems.

The QEC Report 2025 identified real-time decoders as the critical remaining bottleneck. IonQ's decoder directly addresses this, de-risking their 2028 roadmap target of 1,600 logical qubits. Their 2030 target of 40,000-80,000 logical qubits would far exceed the ~2,330 threshold.

- [IonQ Blog](https://www.ionq.com/blog/breaking-the-decoding-bottleneck-fast-and-accurate-software-decoding-for-quantum-ldpc-codes)
- [arXiv:2512.07057](https://arxiv.org/abs/2512.07057)

### Japanese Team Achieves Error Correction Near Theoretical Limit

January 6, 2026

University of Tokyo researchers published a breakthrough in npj Quantum Information demonstrating error correction approaching the "hashing bound", the theoretical maximum. The method maintains accuracy even as system size grows, removing a major obstacle to scaling quantum computers to the sizes needed for cryptographic attacks.

- [npj Quantum Information](https://www.nature.com/articles/s41534-025-01090-1)
- [Phys.org](https://phys.org/news/2026-01-error-technology-quantum-real-world.html)

### Nature Physics Proves Efficient Fault-Tolerant Quantum Computing

January 5, 2026

A Nature Physics paper from University of Tokyo proves fault-tolerant quantum computation can achieve constant space overhead and polylogarithmic time overhead simultaneously, meaning qubit requirements don't scale exponentially with problem difficulty. This strengthens the theoretical foundation for practical cryptographic attacks at the scale needed.

- [Nature Physics](https://www.nature.com/articles/s41567-025-03102-5)
- [Phys.org](https://phys.org/news/2026-01-fault-tolerant-quantum-protocol-efficiently.html)

### D-Wave Solves Scalability Bottleneck

January 5, 2026

D-Wave announced the industry's first scalable, on-chip cryogenic control for gate-model qubits, solving the problem where control-line complexity previously scaled unmanageably with qubit count. D-Wave's stock has risen from under $1 to nearly $31 over two years.

- [Fast Company](https://www.fastcompany.com/91469364/d-wave-quantum-computing-first-major-breakthrough-of-2026-scalable-technology)

### Nobel Prize Validates Quantum Computing

October 2025

The 2025 Nobel Prize in Physics went to John Clarke (UC Berkeley), Michel Devoret (Yale/Google Quantum AI), and John Martinis (UCSB/Qolab) for demonstrating macroscopic quantum tunneling in superconducting circuits, the foundation of today's quantum processors. Martinis led Google's quantum supremacy demonstration. The Nobel committee explicitly cited "quantum computers" as an application.

- [Nobel Prize Press Release](https://www.nobelprize.org/prizes/physics/2025/press-release/)

### Silicon Qubits Hit 99.9% Fidelity

December 17, 2025

Silicon Quantum Computing (Sydney) published an 11-qubit processor in Nature achieving 99.99% single-qubit and 99.90% two-qubit gate fidelities, crossing the threshold for practical error correction. Coherence times reached 660 milliseconds. Silicon qubits can leverage existing semiconductor manufacturing, enabling industrial-scale production.

- [Nature](https://www.nature.com/articles/s41586-025-09827-w)

### Scalable Optical Modulator for Trapped-Ion Systems

December 11, 2025

University of Colorado and Sandia Labs published a CMOS-fabricated optical phase modulator in Nature Communications, 80x more power-efficient than alternatives. This removes a scaling barrier for trapped-ion systems (IonQ, Quantinuum), enabling mass-producible control hardware for their high-fidelity qubits.

- [Nature Communications](https://www.nature.com/articles/s41467-025-65937-z)
- [Phys.org](https://phys.org/news/2025-12-tiny-optical-modulator-enable-giant.html)

### Shor's Algorithm Hits 99.999% Reliability

December 11, 2025

Researchers achieved 99.999% success rates for Shor's quantum factoring algorithm across over one million test cases, up from unreliable single-digit percentages in traditional implementations. The paper explicitly notes this is designed for "quantum cryptanalysis." One execution now suffices where thousands were previously needed.

- [arXiv:2512.11004](https://arxiv.org/abs/2512.11004)

### QuantWare Announces 10,000-Qubit Processor

December 10, 2025

Dutch company QuantWare unveiled the VIO-40K: 10,000 physical qubits via 3D chiplet architecture with NVIDIA integration. Shipments begin 2028 at ~€50 million per chip. They're also building Kilofab, one of the largest quantum fabrication facilities planned.

10,000 physical qubits represents significant scaling progress, though fault-tolerant logical qubit yields depend on achieved error rates and code distance. At current error rates, this might yield tens of logical qubits; with improved fidelity, potentially more.

- [QuantWare](https://quantware.com/news/quantware-announces-scaling-breakthrough-with-vio-40k)
- [IO+](https://ioplus.nl/en/posts/quantware-unveils-10000-qubit-quantum-chip-breakthrough)

### Photonic Calculates Distributed Shor's Algorithm Requirements

December 10, 2025

Photonic Inc. released the first resource estimates for running Shor's algorithm on networked quantum computers, accounting for distributed computation costs. Previous estimates assumed monolithic systems. Attackers can network smaller systems together rather than building one massive machine.

- [GlobeNewswire](https://www.globenewswire.com/news-release/2025/12/10/3203455/0/en/Photonic-Sets-New-Standard-with-Distributed-Quantum-Resource-Estimation.html)
- [The Quantum Insider](https://thequantuminsider.com/2025/12/11/photonic-introduces-distributed-quantum-resource-estimation-for-large-scale-systems/)

### Tsinghua Demonstrates 78,400 Optical Tweezers

December 9, 2025

Tsinghua University achieved 78,400 optical tweezer spots using a single metasurface (nearly 10x current limits). Optical tweezers trap atoms in neutral-atom quantum computers (the platform holding the 6,100-qubit record). This shows the path to 100,000+ qubit systems.

- [arXiv:2512.08222](https://arxiv.org/abs/2512.08222)

### Google's Self-Improving Quantum Error Correction

November 2025

Google Quantum AI demonstrated quantum computers that learn from their own errors and continuously self-calibrate. The reinforcement learning system achieved 3.5x improvement in error rate stability and 20% beyond human-expert tuning, managing over 1,000 control parameters. This enables sustained computation over the extended periods required for Shor's algorithm.

- [arXiv:2511.08493](https://arxiv.org/abs/2511.08493)

### Caltech Sets 6,100-Qubit World Record

September 2025

Published in Nature, Caltech created the largest qubit array ever: 6,100 neutral cesium atoms with 13-second coherence times (10x previous records) and 99.98% manipulation accuracy. The researchers stated they're "close to a truly scalable platform." Scaling is now an engineering problem, not physics.

- [Nature](https://www.nature.com/articles/s41586-025-09641-4)
- [Caltech News](https://www.caltech.edu/about/news/caltech-team-sets-record-with-6100-qubit-array)

### Japan Building 600km Quantum-Encrypted Network

November 2025

Japan announced a 600km quantum-encrypted fiber network linking Tokyo, Nagoya, Osaka, and Kobe. Operational 2027, full deployment 2030. Purpose: defend financial and diplomatic communications against harvest-now-decrypt-later attacks. Investment: tens of billions of yen. Nation-states are preparing; Bitcoin has no quantum protection.

- [The Quantum Insider](https://thequantuminsider.com/2025/11/26/japan-to-link-major-cities-with-600-km-quantum-encryption-network/)
- [Nikkei Asia](https://asia.nikkei.com)

### Tsinghua Demonstrates Quantum Factoring on Hardware

November 2025

Tsinghua University factored N=35 on a superconducting quantum computer using optimized Regev's algorithm, reducing space complexity to O(n log n) (the theoretical minimum). This is a direct demonstration of quantum cryptographic attacks on real hardware.

- [arXiv:2511.18198](https://arxiv.org/abs/2511.18198)

### IBM-Cisco Partner on Quantum Networking

November 2025

IBM and Cisco announced plans to network fault-tolerant quantum computers. Proof-of-concept by early 2030s, "quantum internet" by late 2030s. Networked systems can combine computational power, reducing the single-machine requirements for cryptographic attacks.

- [IBM Newsroom](https://newsroom.ibm.com/2025-11-20-ibm-and-cisco-announce-plans-to-build-a-network-of-large-scale,-fault-tolerant-quantum-computers)

### QEC Report Shows 3.3x Acceleration

November 2025

Riverlane's 2025 report (25 experts including Nobel laureate John Martinis): 120 QEC papers in 2025 vs 36 in 2024. All major qubit types crossed 99% two-qubit fidelity. Seven error correction codes now have working hardware. Critical bottleneck identified: 1μs real-time decoders. IonQ's January 2026 decoder addresses this.

- [Riverlane QEC Report](https://www.riverlane.com/qec-report-2025)

### Stuttgart Achieves Quantum Teleportation

November 2025

Published in Nature Communications: first quantum teleportation between photons from distinct semiconductor sources with >70% fidelity. Previously maintained entanglement across 36km of urban fiber. Enables distributed quantum computing across geographic distances.

- [Nature Communications](https://www.nature.com/articles/s41467-025-65912-8)
- [University of Stuttgart](https://www.uni-stuttgart.de/en/university/news/all/Milestone-on-the-road-to-the-quantum-internet)

### IonQ Acquires Space-Based Network Company

November 2025

IonQ acquired Skyloom Global (90 Space Development Agency-qualified optical terminals deployed). IonQ is simultaneously building cryptographically-relevant quantum computers (1,600 logical qubits by 2028, 40,000-80,000 by 2030) and global infrastructure to connect them.

- [IonQ Press Release](https://ionq.com/news/ionq-acquires-skyloom)

### NVIDIA Integrates Quantum with Supercomputers

November 2025

Japan's RIKEN and other centers adopted NVIDIA's NVQLink: microsecond latency between classical and quantum processors (1000x faster). Shor's algorithm requires hybrid classical-quantum computation; this integration signals quantum entering mainstream computing infrastructure.

- [NVIDIA](https://www.nvidia.com)

### Harvard/MIT/QuEra Achieve Scalable Fault-Tolerance

November 2025

Published in Nature: first complete, scalable fault-tolerant architecture using 448 neutral atoms with 2.14x below-threshold error correction, meaning errors decrease as more qubits are added. Senior author Mikhail Lukin (Harvard): "This big dream...is really in direct sight."

- [Harvard Gazette](https://news.harvard.edu/gazette/story/2025/11/a-potential-quantum-leap/)
- [Nature](https://www.nature.com/articles/s41586-025-09848-5)

### Stanford Discovers Superior Cryogenic Crystal

November 2025

Published in Science: strontium titanate demonstrates 40x stronger electro-optic effects than lithium niobate at cryogenic temperatures. Compatible with semiconductor fabrication for wafer-scale production. Better materials mean better qubit control and lower error rates.

- [Cold Facts](https://cold-facts.org/2025/11/09/stanford-finds-crystal-that-could-revolutionize-quantum-tech/)

### UChicago Extends Quantum Networking to 4,000km

November 2025

Published in Nature Communications: quantum entanglement sustained over 2,000-4,000 km (200-400x improvement). Distributed quantum systems can combine power across continental distances, reducing single-machine requirements.

- [UChicago PME](https://pme.uchicago.edu/news/breakthrough-could-connect-quantum-computers-200x-distance)

### Princeton Achieves 1ms Coherence

November 2025

Published in Nature: quantum coherence exceeding 1 millisecond (15x industry standard). Compatible with existing Google/IBM processors. Researchers: "By end of decade we will see scientifically relevant quantum computer."

- [Princeton Engineering](https://engineering.princeton.edu/news/2025/11/05/princetons-new-quantum-chip-built-scale)

### Quantinuum Helios Achieves Record Gate Fidelity

November 2025

Quantinuum announced Helios: 98 physical qubits with 99.921% two-qubit gate fidelity (the highest in the industry). They demonstrated 48 "logical qubits" using the Iceberg code at a 2:1 encoding ratio, achieving "better than break-even" performance where encoded qubits outperform unencoded ones.

Important context: The Iceberg code is distance-2, meaning it can detect errors but not correct them. Fault-tolerant logical qubits for Shor's algorithm require higher-distance codes with hundreds to thousands of physical qubits each. Helios represents significant progress in fidelity, but the path to cryptographically-relevant quantum computing still requires major scaling.

- [Quantinuum](https://www.quantinuum.com/blog/introducing-helios-the-most-accurate-quantum-computer-in-the-world)

### IBM Roadmap: 2,000 Logical Qubits by 2033

November 2025

IBM released Nighthawk (120 qubits) and Loon (112 qubits) processors with all hardware elements for fault-tolerant computing. Roadmap: Starling (2029, 200 logical qubits), Blue Jay (2033, 2,000 logical qubits). The ~2,330 threshold falls between these milestones.

- [Live Science](https://www.livescience.com/technology/computing/ibm-unveils-two-new-quantum-processors-including-one-that-offers-a-blueprint-for-fault-tolerant-quantum-computing-by-2029)
- [IBM Quantum](https://www.ibm.com/quantum/blog/qdc-2025)

### Oxford Sets World Record for Qubit Accuracy

June 2025

University of Oxford physicists achieved a single-qubit error rate of 0.000015% (99.999985% fidelity), using electronic microwave signals to control trapped calcium ions at room temperature. This is nearly an order of magnitude better than previous records.

- [University of Oxford](https://www.ox.ac.uk/news/2025-06-10-oxford-physicists-set-new-world-record-qubit-operation-accuracy)

### Microsoft's 4D Codes Achieve 1,000x Error Reduction

June 2025

Microsoft unveiled a family of four-dimensional geometric codes that achieved a 1,000-fold reduction in error rates while requiring 5x fewer physical qubits per logical unit. This directly compresses the timeline to cryptographically relevant quantum computers by reducing physical qubit overhead.

- [Microsoft Azure Blog](https://azure.microsoft.com/en-us/blog/quantum/2025/06/19/microsoft-advances-quantum-error-correction-with-a-family-of-novel-four-dimensional-codes/)

## Key Technical Advances Accelerating the Threat

Seven independent areas of progress are converging faster than anticipated, with each breakthrough compounding the others to accelerate the timeline toward cryptographically-relevant quantum computers.

### Stability: How Long Qubits Stay Usable

Qubits need to stay "alive" long enough to perform calculations. Recent advances extended this from microseconds to milliseconds, a thousand-fold improvement.
Recent advances:
- Caltech 6,100-Qubit Array (September 2025): 13-second coherence times, nearly 10x longer than previous similar arrays
- SQC 11-Qubit Processor (December 2025): 660ms nuclear spin coherence with Hahn echo refocusing
- Princeton 1ms Coherence (November 2025): 15x industry standard, 1,000x potential system improvement
- Stanford Strontium Titanate (November 2025): 40x stronger electro-optic effects at cryogenic temperatures, enabling better qubit control

- [Nature](https://www.nature.com/articles/s41586-025-09827-w)
- [Nature](https://www.nature.com/articles/s41586-025-09641-4)
- [Nature](https://engineering.princeton.edu/news/2025/11/05/princetons-new-quantum-chip-built-scale)
- [Stanford/Science](https://cold-facts.org/2025/11/09/stanford-finds-crystal-that-could-revolutionize-quantum-tech/)

### Conversion Efficiency: Physical to Logical Qubits

Physical qubits need error correction to create reliable "logical qubits." Current estimates for fault-tolerant logical qubits: hundreds to thousands of physical qubits each, depending on error rates and code distance. However, QLDPC codes are dramatically changing this equation.
Recent advances:
- Iceberg Quantum Pinnacle Architecture (February 2026): QLDPC (generalized bicycle) codes encode 14 logical qubits in ~860 physical qubits at distance 16, compared to 1 logical qubit in ~511 physical qubits for surface codes at the same distance - a 14× improvement in encoding rate. RSA-2048 attack requires <100,000 physical qubits
- Reed-Muller Codes (February 2026): Full Clifford group without ancilla qubits, further reducing overhead
- Quantinuum Helios (November 2025): 99.921% gate fidelity, demonstrated error detection (not correction) with 2:1 Iceberg code
- Harvard/MIT/QuEra (November 2025): 2.14x below-threshold error correction with surface codes, proving scalability
- Microsoft/Quantinuum (2024): 12 logical qubits from 56 physical qubits using distance-4 codes

- [Quantinuum](https://www.quantinuum.com/blog/introducing-helios-the-most-accurate-quantum-computer-in-the-world)
- [Nature](https://www.nature.com/articles/s41586-025-09848-5)

### Scale: Physical Qubit Counts

Current records: neutral atoms (6,100 Caltech research; 1,600 Infleqtion commercial; 1,180 Atom Computing), superconducting (156 IBM Heron, 105 Google Willow), trapped ions (98 Quantinuum Helios). With hundreds to thousands of physical qubits needed per fault-tolerant logical qubit (surface codes), or under 100,000 via QLDPC codes, significant scaling is advancing rapidly.
Recent advances:
- QuTech QARPET (February 2026): 1,058 spin qubits at 2 million qubits/mm² density in crossbar architecture
- QuantWare VIO-40K (December 2025): 10,000-qubit processor shipping 2028
- Tsinghua Metasurface (December 2025): 78,400 optical tweezers demonstrated
- Caltech 6,100-Qubit Array (September 2025): Current neutral atom record
- Harvard/MIT/QuEra 448-Atom System (November 2025): Complete fault-tolerant architecture
- IBM Nighthawk/Loon (November 2025): 120/112 qubits with fault-tolerant features

- [QuantWare](https://quantware.com/news/quantware-announces-scaling-breakthrough-with-vio-40k)
- [arXiv:2512.08222](https://arxiv.org/abs/2512.08222)
- [Caltech](https://www.caltech.edu/about/news/caltech-team-sets-record-with-6100-qubit-array)
- [Harvard Gazette](https://news.harvard.edu/gazette/story/2025/11/a-potential-quantum-leap/)
- [IBM Quantum Blog](https://www.ibm.com/quantum/blog/qdc-2025)

### Reliability: Making Systems More Stable as They Grow

Old problem: Adding more qubits made systems less reliable. New breakthrough: Systems now become more reliable as they scale up. This reverses a 30-year problem and makes large quantum computers actually buildable.
Recent advances:
- IonQ EQC (October 2025): 99.99% two-qubit gate fidelity (world record "four nines"), error rate 8.4×10⁻⁵ per gate, maintained without ground-state cooling. Basis for planned 256-qubit systems in 2026
- Infleqtion Sqale (September 2025): 12 logical qubits with error detection, first execution of Shor's algorithm with logical qubits, 1,600 physical qubits demonstrated
- Google RL-QEC (November 2025): 3.5x improvement in logical error rate stability using reinforcement learning; 20% beyond human-expert tuning
- SQC 11-Qubit Processor (December 2025): 99.90% two-qubit gate fidelity, 99.99% single-qubit fidelity in silicon
- QEC Report 2025 (November 2025): 120 peer-reviewed QEC papers in 2025 (vs. 36 in 2024); all major qubit types crossed 99% two-qubit gate fidelity
- Harvard/MIT/QuEra (November 2025): First complete fault-tolerant architecture with below-threshold performance
- Quantinuum Helios (November 2025): 99.921% gate fidelity (highest in industry)

- [arXiv:2511.08493](https://arxiv.org/abs/2511.08493)
- [Nature](https://www.nature.com/articles/s41586-025-09827-w)
- [Riverlane QEC Report](https://www.riverlane.com/qec-report-2025)
- [Nature](https://www.nature.com/articles/s41586-025-09848-5)
- [Quantinuum](https://www.quantinuum.com/blog/introducing-helios-the-most-accurate-quantum-computer-in-the-world)

### Speed: Operations Per Second

Recent advances:
- Shor's Algorithm Enhancement (December 2025): 99.999% success rate, reducing retries dramatically
- Tsinghua Regev Optimization (November 2025): Space complexity O(n log n), demonstrated factoring N=35
- Gate speeds: Superconducting 20-100ns (Google, IBM); Trapped ions 1-100μs (Quantinuum, IonQ)

- [arXiv:2512.11004](https://arxiv.org/abs/2512.11004)
- [arXiv:2511.18198](https://arxiv.org/abs/2511.18198)

### Networking: Distributed Quantum Computing

Multiple smaller systems can be networked to combine computational power.
Recent advances:
- Photonic Distributed QRE (December 2025): First resource estimates for distributed Shor's algorithm
- IBM-Cisco Partnership (November 2025): Networked quantum by early 2030s
- Japan 600km Network (November 2025): Tokyo-Osaka backbone by 2027
- UChicago (November 2025): 2,000-4,000 km entanglement (200-400x improvement)
- IonQ Skyloom (November 2025): Space-based quantum networking
- China: 2,000+ km operational network (since 2017)

- [Photonic/GlobeNewswire](https://www.globenewswire.com/news-release/2025/12/10/3203455/0/en/Photonic-Sets-New-Standard-with-Distributed-Quantum-Resource-Estimation.html)
- [IBM Newsroom](https://newsroom.ibm.com/2025-11-20-ibm-and-cisco-announce-plans-to-build-a-network-of-large-scale,-fault-tolerant-quantum-computers)
- [The Quantum Insider](https://thequantuminsider.com/2025/11/26/japan-to-link-major-cities-with-600-km-quantum-encryption-network/)
- [Nature Communications](https://pme.uchicago.edu/news/breakthrough-could-connect-quantum-computers-200x-distance)

### Rational Design: Engineering Qubits to Specification

Moving from trial-and-error to computational design of quantum systems with predictable properties.
Recent advances:
- Wisconsin-Madison Asymmetric Rydberg Gate (December 2025): Modified π-2π-π protocol enables high-fidelity entangling gates without requiring strong Rydberg blockade, reaching within a factor of 1.68 of the fundamental lifetime limit. Enables long-range entanglement between neutral atoms, relaxing distance constraints for QLDPC code implementations.
- CU Boulder/Sandia Optical Modulator (December 2025): CMOS-fabricated acousto-optic phase modulator enabling scalable laser control for atom-based quantum computers
- Stanford Strontium Titanate (November 2025): Discovery of material optimized for cryogenic quantum operations

- [arXiv:2512.22767](https://arxiv.org/abs/2512.22767)
- [Nature Communications](https://www.nature.com/articles/s41467-025-65937-z)
- [Cold Facts](https://cold-facts.org/2025/11/09/stanford-finds-crystal-that-could-revolutionize-quantum-tech/)

## Enterprise Migration to Post-Quantum Cryptography

While Bitcoin and Ethereum scramble for solutions, centralized systems are already migrating. Banks, enterprises, and cloud providers are actively deploying post-quantum cryptography to meet regulatory deadlines. The technology is ready and the migration is underway.

### NIST Finalized Standards (August 2024)

- Standard
- Algorithm
- Basis
- Use Case

FIPS 204 (ML-DSA)

CRYSTALS-Dilithium

Module-Lattice

Primary choice for general use

FIPS 205 (SLH-DSA)

SPHINCS+

Stateless Hash

Backup if lattices fail

FN-DSA

FALCON

NTRU-Lattice

Constrained environments

### NSA CNSA 2.0 Requirements

- New national security systems quantum-safe by January 1, 2027
- Full phase-out of non-compliant systems by 2030

Performance trade-off: SLH-DSA (SPHINCS+) signing is 2,200x slower than ECDSA P256 on ARM architectures. This overhead drives Ethereum's planned gas limit increases.

### Major Infrastructure Already Migrated

Cloudflare (October 2025): Over 50% of Internet traffic now protected with post-quantum encryption (the largest PQC deployment globally). Cloudflare's infrastructure serves millions of websites, demonstrating PQC works at scale without performance issues.

AWS and Accenture: Launched comprehensive enterprise migration framework serving financial institutions, governments, and Fortune 500 companies. Their multi-year phased approach addresses the reality that complete migration takes 3-5 years, which is why they started now for the 2030 deadline.

### The Contrast

Centralized systems: Migrating now through coordinated infrastructure updates. AWS, Cloudflare, Microsoft, Google managing the complexity for their customers.

Bitcoin/Ethereum: Must coordinate millions of independent users, update billions in hardware wallets, achieve network consensus, and hope for 100% participation. A process requiring 5-10 years that hasn't even started.

The infrastructure exists. The migration is happening. Traditional finance is preparing. Cryptocurrency is not.

- [NIST Post-Quantum Cryptography](https://www.nist.gov/pqc)
- [Cloudflare: State of Post-Quantum Internet 2025](https://blog.cloudflare.com/pq-2025/)
- [AWS/Accenture PQC Framework](https://aws.amazon.com/blogs/apn/accenture-and-aws-accelerate-customers-post-quantum-cryptography-journey/)

## Understanding Bitcoin's Quantum Vulnerability

### What Actually Gets Broken?

Bitcoin uses two different cryptographic systems with vastly different quantum vulnerabilities:

- SHA-256 (Mining) - Quantum-Resistant: Grover's Algorithm provides only quadratic speedup. Would require hundreds of millions of qubits to meaningfully impact mining. Effectively quantum-proof.
- ECDSA secp256k1 (Transaction Signatures) - Vulnerable: Shor's Algorithm provides exponential speedup. Requires ~2,330 logical qubits minimum (Roetteler 2017) or ~6,500 for practical runtime (~2 hours, Kim et al. 2026). Highly vulnerable to quantum computers.
- Result: The blockchain ledger remains safe, but individual wallet balances can be stolen because the cryptographic signatures proving ownership are vulnerable.
- Bottom Line: Approximately 34% of all Bitcoin (6.5 to 6.9 million BTC) has permanently exposed cryptographic keys that attackers are already harvesting today for future decryption.

### The Two-Stage Quantum Threat

The quantum threat arrives in two waves, with different capabilities and target dates:

- Stage 1: CRQC-Dormant (2029-2032) - Break keys over hours to days using "Harvest Now, Decrypt Later". Target: ~6.9 million BTC in dormant/exposed wallets (~1.7M Satoshi-era P2PK coins, reused addresses, all Taproot addresses). Requirements: ~6,500 logical qubits with extended computation time (~2 hours per key, per Kim et al. 2026).
- Stage 2: CRQC-Active (2033-2038) - Break keys within Bitcoin's 10-minute block time. Target: ALL 19+ million BTC during any transaction. Requirements: ~23,700 logical qubits with depth-optimized circuits (~48 minutes per key), completing 126 billion operations in <10 minutes.
- Company Targets: IonQ aims for 1,600 logical qubits by 2028. IBM targets 200 logical qubits by 2029 (Starling) and 2,000 by 2033 (Blue Jay). Google aims for error-corrected system by 2029. Quantinuum targets "hundreds" of logical qubits by 2030.

Traditional estimates assumed 1,000-10,000 physical qubits per logical qubit. Quantinuum has achieved 2:1 ratio. With networking capabilities, multiple smaller systems can now work together to achieve the same result.

### Bitcoin Wallet Vulnerability Breakdown

#### Permanently Exposed (Harvest Now, Decrypt Later)

- Pay-to-Public-Key (P2PK): 1.9 million BTC - Public key directly recorded in UTXO. No protection possible. Includes Satoshi Nakamoto's ~1 million BTC.
- Reused Addresses (All Types): 4 million BTC - Public key revealed after first spend. Any remaining balance permanently at risk.
- Pay-to-Taproot (P2TR): Growing amount - Address directly encodes public key upon receiving funds. Immediate exposure upon first receipt.
- Total Permanently Exposed: ~6.9 million BTC (~34% of circulating supply). Pieter Wuille (Bitcoin Core developer) estimated ~37% in 2019.

#### Temporarily Exposed (10-60 Minute Window)

- Fresh P2PKH, P2WPKH, P2SH, P2WSH: Only vulnerable during transaction (10-60 minutes in mempool).
- Current safety: Safe until first use.
- Attack requirement: Full Shor's algorithm execution in <10 minutes.
- Protection: Never reuse addresses (but once exposed, protection is lost forever).

## Government Warnings and Mandates

U.S. Federal Quantum Security Mandates

The U.S. government has issued comprehensive directives requiring transition to post-quantum cryptography across all federal systems and regulated industries.

### NIST Post-Quantum Standards

August 2024

Published three quantum-resistant algorithms: ML-KEM (Kyber), ML-DSA (Dilithium), SLH-DSA (SPHINCS+).

2030

ECDSA deprecated - discouraged for new systems

2035

ECDSA prohibited - banned from all federal systems

Now - 2030

All agencies must begin migration planning

ECDSA, including secp256k1, is the cryptographic foundation of Bitcoin and Ethereum. The U.S. government will officially classify this cryptography as insecure by 2035. These mandates will force governments and regulated institutions worldwide to prohibit holding or transacting these assets unless Bitcoin and Ethereum complete their complex multi-year upgrade process by these deadlines.

- [NIST IR 8547](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf)
- [NSA CNSA 2.0](https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)

### NSA Requirements

CNSA 2.0 mandates immediate planning for National Security Systems with specific algorithm requirements. High-value and long-lifetime assets must be prioritized. Complete transition by 2035.

- [NSA CNSA 2.0](https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)

### Federal Reserve Warning

October 2025

The Federal Reserve explicitly warned that quantum computers pose an existential threat to cryptocurrency security. Nation-states are actively pursuing "Harvest Now, Decrypt Later" attacks. Current blockchain cryptography will be completely broken. Historical transaction data will be exposed. No major cryptocurrency is currently protected.

- [The Quantum Insider](https://thequantuminsider.com/2025/10/06/federal-reserve-warns-quantum-computers-could-expose-bitcoins-hidden-past/)

International Government Mandates

Allied nations are coordinating quantum-safe migration timelines, with some moving even faster than the United States.

### Canada

Following NIST's roadmap - ECDSA deprecated 2030, prohibited 2035

- [Roadmap for migration to post-quantum cryptography](https://www.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001)

### Australia

More aggressive timeline - cryptographic standards update by 2030

- [Guidelines for cryptography](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography)

## The "Harvest Now, Decrypt Later" Attack

### What is HNDL?

Adversaries are already collecting encrypted blockchain data today, planning to decrypt it once quantum computers become available. The Federal Reserve confirmed in October 2025 that these attacks are happening now, not in the future.

### Why This Matters

- Past transactions can never be secured retroactively - blockchain immutability makes this impossible
- Privacy is compromised NOW, not in the future - your transaction history is already harvested
- Every transaction made today is potentially vulnerable tomorrow when quantum computers arrive
- Approximately 34% of all Bitcoin (~6.9 million BTC) has permanently exposed public keys waiting to be broken
- No software update can protect these coins - they are mathematically doomed

### Who's at Risk?

- Satoshi Nakamoto's ~1 million BTC in Pay-to-Public-Key addresses
- Anyone who has ever reused a Bitcoin address (4 million BTC exposed)
- All Taproot (P2TR) address holders - keys exposed immediately upon receiving funds
- High-value dormant wallets with no way to migrate to quantum-safe addresses
- Future: Every Bitcoin and Ethereum user once quantum computers can break keys in 10 minutes

## The Urgency Cannot be Overstated

### Why 2026 is Critical

NIST mandates beginning migration in 2026 to have any hope of completing before quantum computers arrive. The math is brutal:

- Quantum computers: 2029-2032 (converging timeline from IBM, Google, IonQ, Quantinuum)
- Bitcoin upgrade process: 4-7 years minimum (SegWit took 2+ years just for consensus)
- NIST deadline: 2030 deprecation, 2035 prohibition
- Conclusion: Bitcoin needed to start 2-3 years ago

### The Window is Closing

Every day without action makes the situation worse:

- More transactions become vulnerable to HNDL attacks
- The coordination challenge grows across millions of users
- The migration window narrows while quantum computers improve exponentially
- The risk increases that quantum computers arrive before migration completes
- Adversaries continue collecting encrypted data for future decryption

### The Migration Challenge

- A fix existing is not the same as a network being safe. Safe means the entire stack is migrated before Q-Day.
- Bitcoin: BIP-360 (P2MR) protects only new addresses, and only at rest - the moment a coin is spent its public key still appears in the mempool, and it does nothing for existing coins. BIP-361 (legacy signature sunset) proposes freezing or migrating exposed coins, but it is a draft with no activation timeline and freezing lost coins is contested. About 34% of all BTC (6.5 to 6.9 million, including ~1.7 million Satoshi-era) already have exposed public keys that no fix can hide. Moving Bitcoin's ~190 million UTXOs at the network's ceiling of ~7 transactions per second is roughly a year of blocks doing nothing but migration, and multi-year in practice - each migration transaction itself briefly exposes its key.
- Ethereum: the Foundation targets core Layer-1 post-quantum upgrades by 2029, but that is the base protocol only (validator signatures, KZG commitments, ZK proofs). The value sits above it: hundreds of millions of ECDSA accounts, the entire smart-contract and DeFi stack, bridges, and Layer-2s, each with its own cryptographic dependencies. Many contracts are immutable and must be redeployed with liquidity migrated; composability means a single protocol depends on tokens, oracles, bridges, and an L2 that must all migrate compatibly. Per-account signature agility via EIP-8141 is still only proposed for late 2026.
- The common thread: no agreed timeline, coordination across millions of users, post-quantum signatures tens of times larger than ECDSA, and a quantum clock that keeps speeding up. A base-layer upgrade is a milestone, not safety.

## The QRL Difference

While Bitcoin and Ethereum face existential quantum threats and scramble for solutions, QRL has been quantum-secure since day one. Launched June 26, 2018 - mainnet operational for 7+ years. Using NIST-approved XMSS signatures (standardized 2020). Multiple external security audits (Red4Sec, X41 D-Sec). Already meets NIST 2030/2035 deadlines.

While Bitcoin and Ethereum face existential quantum threats and scramble for solutions,

QRL

/story

has been quantum-secure since day one. Launched June 26, 2018 - mainnet operational for 7+ years. Using NIST-approved XMSS signatures (standardized 2020). Multiple external security audits (Red4Sec, X41 D-Sec). Already meets NIST 2030/2035 deadlines. Find out

more

/faq

.

No emergency scrambling. No panic-driven retrofits. No vulnerable past. Planned evolution when ready.

## References

### April - May 2026

- [BIP-361: Post Quantum Migration and Legacy Signature Sunset](https://www.bip361.org/)
- [Bitcoin Developers Propose Freezing Coins Under BIP-361 (news.bitcoin.com)](https://news.bitcoin.com/bitcoin-developers-propose-freezing-coins-that-skip-quantum-safe-migration-under-bip-361/)
- [Justin Sun Says Tron Launching Post-Quantum Upgrade (The Block)](https://www.theblock.co/post/397572/justin-sun-says-tron-launching-post-quantum-upgrade-plan)
- [Ethereum Post-Quantum Roadmap (ethereum.org)](https://ethereum.org/roadmap/future-proofing/quantum-resistance/)
- [Ethereum Foundation Elevates Post-Quantum Security to Top Priority (The Quantum Insider)](https://thequantuminsider.com/2026/01/26/ethereum-foundation-elevates-post-quantum-security-to-top-strategic-priority/)
- [Halborn Audit Validates QRL's Post-Quantum Cryptography Library (April 3, 2026)](https://www.theqrl.org/press/halborn-audit-validates-qrls-postquantum-cryptography-library/)
- [QRL Launches Post-Quantum Smart Contract Testnet V2 (March 31, 2026)](https://www.theqrl.org/press/qrl-launches-testnet-v2-for-its-postquantum-evmfriendly-blockchain/)
- [QuEra 96 Logical Qubits, 448 Physical Atoms (Nature)](https://www.nature.com/articles/s41586-025-09848-5)
- [DOE RFI, IonQ Boulder Lab, Q-CTRL/IBM 3,000x Speedup (Quantum Computing Report)](https://quantumcomputingreport.com/news/)

### Major Milestone Breakthroughs

- [Google Willow Chip (December 2024)](https://blog.google/technology/research/google-willow-quantum-chip/)
- [Oxford Ionics World Record (December 2025)](https://www.nature.com/articles/s41586-025-09862-7)
- [Microsoft 4D Floquet Codes (December 2025)](https://www.microsoft.com/en-us/research/blog/new-microsoft-breakthroughs-general-purpose-quantum-computing-moves-closer-to-reality/)
- [IonQ Beam Search Decoder (December 2025)](https://ionq.com/resources/research/beam-search-decoder)
- [IonQ 99.99% Two-Qubit Gate Fidelity (October 2025)](https://www.ionq.com/news/ionq-achieves-landmark-result-setting-new-world-record-in-quantum-computing)
- [Infleqtion: First Shor's Algorithm Execution on Logical Qubits (September 2025)](https://infleqtion.com/infleqtion-unveils-new-architecture-to-accelerate-its-quantum-computing-roadmap-to-achieve-1000-logical-qubits-by-2030/)
- [Nobel Prize in Physics 2025](https://www.nobelprize.org/prizes/physics/2025/press-release/)
- [IBM Nighthawk and Loon Processors (November 2025)](https://www.livescience.com/technology/computing/ibm-unveils-two-new-quantum-processors-including-one-that-offers-a-blueprint-for-fault-tolerant-quantum-computing-by-2029)
- [Quantinuum Fault Tolerance Milestone (June 2025)](https://arxiv.org/abs/2404.16728)
- [Iceberg Quantum Pinnacle Architecture: RSA-2048 Under 100,000 Qubits (arXiv, February 2026)](https://arxiv.org/abs/2602.11457)
- [QuTech: First Majorana Qubit Readout via Quantum Capacitance (Nature, February 2026)](https://www.nature.com/articles/s41586-025-09927-7)
- [QuTech QARPET: Crossbar Spin Qubit Benchmarking Platform (Nature Electronics, February 2026)](https://doi.org/10.1038/s41928-026-01569-5)
- [Nature: Quantum Computers Will Finally Be Useful (February 2026)](https://www.nature.com/articles/d41586-026-00312-6)
- [Kim et al. 2026: Optimized ECDLP Quantum Circuits (ePrint 2026/106)](https://eprint.iacr.org/2026/106)
- [ETH Zurich/PSI: Lattice Surgery on Superconducting Qubits (Nature Physics, February 2026)](https://www.nature.com/articles/s41567-025-03090-6)
- [Alice & Bob Elevator Codes (January 2026)](https://alice-bob.com/newsroom/reducing-quantum-computing-errors-with-new-code/)
- [USTC Zuchongzhi 3.2 Below-Threshold QEC (PRL, December 2025)](https://link.aps.org/doi/10.1103/rqkg-dw31)

### Recent Breakthroughs

February 2026

- [Iceberg Quantum Pinnacle Architecture: RSA-2048 Under 100,000 Qubits (arXiv, February 2026)](https://arxiv.org/abs/2602.11457)
- [QuTech: First Majorana Qubit Readout - Single-Shot Parity via Quantum Capacitance (Nature, February 2026)](https://www.nature.com/articles/s41586-025-09927-7)
- [QuTech QARPET: Crossbar Spin Qubit Benchmarking at 2M Qubits/mm² (Nature Electronics, February 2026)](https://doi.org/10.1038/s41928-026-01569-5)
- [Reed-Muller Codes: Full Clifford Group Without Ancilla Qubits (February 2026)](https://quantumzeitgeist.com/quantum-computing-error-correction-breakthrough-unlocks-powerful-minimal-extra/)
- [PsiQuantum Appoints AMD/Xilinx Veteran as CEO for Deployment Phase (February 2026)](https://quantumzeitgeist.com/psiquantum-quantum-computing-quantum-deployment/)
- [Nature: "Quantum computers will finally be useful" - Vibe Shift Confirmed (February 2026)](https://www.nature.com/articles/d41586-026-00312-6)
- [ePrint 2026/106: Optimized Quantum Circuits for ECDLP - Kim et al. (February 2026)](https://eprint.iacr.org/2026/106)
- [Strike 2026: PQC Signatures Alone Cannot Support Coherent Bitcoin Migration (Zenodo, February 2026)](https://zenodo.org/records/18526451)
- [ETH Zurich/PSI: First Lattice Surgery on Superconducting Qubits (Nature Physics, February 2026)](https://www.nature.com/articles/s41567-025-03090-6)
- [Stanford Cavity-Array Microscope for Million-Qubit Scaling (Nature, February 2026)](https://www.sciencedaily.com/releases/2026/02/260201223737.htm)
- [Los Alamos National Laboratory Establishes Center for Quantum Computing (February 2026)](https://thequantuminsider.com/2026/02/06/los-alamos-forms-quantum-computing-focused-research-center/)
- [Ubuntu 26.04 LTS Ships with Post-Quantum Cryptography by Default (February 2026)](https://pbxscience.com/ubuntu-26-04-lts-tpm-encryption-rust-core-and-post-quantum-security-arrive/)

January 2026

- [MIT Chip-Based Trapped Ion System (January 2026)](https://news.mit.edu/2026/scientists-trap-atoms-chip-create-first-room-temperature-quantum-computers-0115)
- [MIT Sub-Doppler Cooling Photonic System (January 2026)](https://news.mit.edu/2026/new-chip-based-laser-system-can-generate-cold-atoms-quantum-devices-0114)
- [D-Wave On-Chip Cryogenic Control (January 2026)](https://www.dwavequantum.com/company/newsroom/press-release/d-wave-demonstrates-world-s-most-compact-quantum-computer/)
- [blueqat Silicon Quantum Computer Display (January 2026)](https://eetimes.itmedia.co.jp/ee/articles/2601/16/news022.html)
- [Equal1 $60M Funding for Bell-1 Quantum Server (January 2026)](https://thequantuminsider.com/2026/01/15/equal1-announces-60-million-raise-for-quantum-computer-that-use-existing-semiconductor-manufacturing/)
- [D-Wave Acquires Quantum Circuits Inc. (January 2026)](https://www.dwavequantum.com/company/newsroom/press-release/d-wave-to-acquire-quantum-circuits/)
- [Japanese QEC Near-Theoretical Accuracy (npj Quantum Information, January 2026)](https://phys.org/news/2026-01-error-technology-quantum-real-world.html)
- [Quantum Structured Light Review (Nature Photonics, January 2026)](https://www.sciencedaily.com/releases/2026/01/260106001911.htm)

December 2025

- [Asymmetric Rydberg Gate for Long-Range Entanglement (arXiv, December 2025)](https://arxiv.org/abs/2512.22767)
- [11-Qubit Silicon Atom Processor (Nature, December 2025)](https://www.nature.com/articles/s41586-025-09827-w)
- [Scalable Optical Phase Modulator (Nature Communications, December 2025)](https://www.nature.com/articles/s41467-025-65937-z)
- [Shor's Algorithm Reliability Enhancement (arXiv, December 2025)](https://arxiv.org/abs/2512.11004)
- [QuantWare VIO-40K 10,000-Qubit Processor (December 2025)](https://quantware.com/news/quantware-announces-scaling-breakthrough-with-vio-40k)
- [Photonic Distributed Quantum Resource Estimation (December 2025)](https://www.globenewswire.com/news-release/2025/12/10/3203455/0/en/Photonic-Sets-New-Standard-with-Distributed-Quantum-Resource-Estimation.html)
- [78,400 Optical Tweezer Metasurface (arXiv, December 2025)](https://arxiv.org/abs/2512.08222)

September-November 2025

- [Google RL-Powered QEC Self-Calibration (arXiv, November 2025)](https://arxiv.org/abs/2511.08493)
- [Tsinghua Space-Optimized Quantum Factoring (November 2025)](https://arxiv.org/abs/2511.18198)
- [IBM-Cisco Quantum Networking Partnership (November 2025)](https://newsroom.ibm.com/2025-11-20-ibm-and-cisco-announce-plans-to-build-a-network-of-large-scale,-fault-tolerant-quantum-computers)
- [Japan 600km Quantum Encryption Network (November 2025)](https://thequantuminsider.com/2025/11/26/japan-to-link-major-cities-with-600-km-quantum-encryption-network/)
- [Stuttgart Quantum Teleportation Breakthrough (Nature Communications, November 2025)](https://www.nature.com/articles/s41467-025-65912-8)
- [QEC Report 2025 (Riverlane, November 2025)](https://www.riverlane.com/qec-report-2025)
- [IonQ Skyloom Acquisition (November 2025)](https://ionq.com/news/ionq-acquires-skyloom)
- [Princeton 1ms Coherence Chip (Nature, November 2025)](https://engineering.princeton.edu/news/2025/11/05/princetons-new-quantum-chip-built-scale)
- [University of Chicago Quantum Networking (Nature Communications, November 2025)](https://pme.uchicago.edu/news/breakthrough-could-connect-quantum-computers-200x-distance)
- [Quantinuum Helios Announcement (November 2025)](https://www.quantinuum.com/blog/introducing-helios-the-most-accurate-quantum-computer-in-the-world)
- [Harvard/MIT/QuEra 448-Atom Architecture (Nature, November 2025)](https://www.nature.com/articles/s41586-025-09848-5)
- [Stanford Strontium Titanate Discovery (November 2025)](https://cold-facts.org/2025/11/09/stanford-finds-crystal-that-could-revolutionize-quantum-tech/)
- [AWS and Accenture PQC Migration Framework (November 2025)](https://aws.amazon.com/blogs/apn/accenture-and-aws-accelerate-customers-post-quantum-cryptography-journey/)
- [IBM 120-Qubit Cat State (October 2025)](https://arxiv.org/abs/2510.09520v1)
- [Google Quantum Echoes (October 2025)](https://blog.google/technology/research/quantum-echoes-willow-verifiable-quantum-advantage/)
- [Caltech 6,100-Qubit Array (Nature, September 2025)](https://www.nature.com/articles/s41586-025-09641-4)
- [Tokyo Institute LDPC Codes (September 2025)](https://phys.org/news/2025-09-quantum-error-codes-enable-efficient.html)

### Bitcoin Vulnerability Analysis

- [Quantum Attacks on Bitcoin (Aggarwal et al., 2017)](https://arxiv.org/abs/1710.10377)
- [Breaking ECC with Quantum Computing (Webber et al.)](https://www.schneier.com/blog/archives/2022/02/breaking-245-bit-elliptic-curve-encryption-with-a-quantum-computer.html)
- [Bitcoin Address Vulnerability Analysis (Project Eleven)](https://blog.projecteleven.com/posts/quantum-vulnerability-of-bitcoin-addresses)
- [River Learn: Will Quantum Computing Break Bitcoin?](https://river.com/learn/will-quantum-computing-break-bitcoin/)

### Government Standards & Warnings

- [NIST IR 8547 - Transition Timeline](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf)
- [White House NSM-10](https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/)
- [NSA CNSA 2.0](https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF)
- [NIST Post-Quantum Cryptography Standards](https://csrc.nist.gov/projects/post-quantum-cryptography)
- [Federal Reserve Quantum Warning (October 2025)](https://thequantuminsider.com/2025/10/06/federal-reserve-warns-quantum-computers-could-expose-bitcoins-hidden-past/)

### Company Roadmaps

- [IonQ Accelerated Roadmap](https://ionq.com/blog/ionqs-accelerated-roadmap-turning-quantum-ambition-into-reality)
- [IBM Quantum Roadmap](https://www.ibm.com/roadmaps/quantum/)

### Industry Analysis

- [Physics World - Quantum Timeline](https://physicsworld.com/a/quantum-computing-on-the-verge-correcting-errors-developing-algorithms-and-building-up-the-user-base/)
- [SpinQ Industry Trends 2025](https://www.spinquanta.com/news-detail/quantum-computing-industry-trends-2025-breakthrough-milestones-commercial-transition)
- [UK Science Museum - Neutral Atoms](https://blog.sciencemuseum.org.uk/how-lasers-and-atoms-could-change-the-future-of-computation/)

## The Three Quantum Threats to Cryptocurrency

Quantum computing threatens cryptocurrency through three distinct attack vectors, each with different timelines and targets.

### Shor's Algorithm: Breaking Digital Signatures

ECDSA secp256k1 (Bitcoin, Ethereum transaction signatures)

Provides exponential speedup for integer factorization and discrete logarithm problems

~2,330 logical qubits minimum (Roetteler 2017); ~6,500 for practical ~2-hour attack (Kim et al. 2026)

Wallet private keys can be derived from public keys, enabling theft of funds

Stage 1 (2029-2032): Break keys over hours/days. Stage 2 (2033-2038): Break keys within 10-minute block time.

~6.9 million BTC (~$470B) permanently exposed; ALL crypto during transactions

### Grover's Algorithm: Mining Attack

SHA-256 (Bitcoin mining proof-of-work)

Provides quadratic speedup for search problems, effectively halving hash security

Hundreds of millions of qubits for meaningful impact

Could enable 51% attacks by quantum-equipped miners, but much further away than Shor's

Not expected to be practical threat before 2040+

Mining security, but signature attacks will arrive first

### Harvest Now, Decrypt Later (HNDL)

All encrypted blockchain data transmitted today

Adversaries collect encrypted data now, store it, decrypt when quantum computers arrive

Only storage capacity today; quantum computers in future

Past transactions exposed, privacy compromised, permanently-exposed wallets vulnerable

Happening NOW - Federal Reserve confirmed October 2025

~6.9 million BTC already exposed; all future transaction privacy

- [Quantum Attacks on Bitcoin (Aggarwal et al., 2017)](https://arxiv.org/abs/1710.10377)
- [Federal Reserve Quantum Warning (October 2025)](https://thequantuminsider.com/2025/10/06/federal-reserve-warns-quantum-computers-could-expose-bitcoins-hidden-past/)

## The "Burn or Steal" Dilemma

Bitcoin faces an impossible decision regarding the ~1 million BTC in Satoshi Nakamoto's P2PK wallets and other permanently-exposed addresses.

Approximately 6.9 million BTC (~$470 billion) have permanently exposed public keys that cannot be protected by any software update. These include Satoshi's ~1 million BTC, early miner rewards, and all addresses that have ever been reused.

Option 1: Do Nothing

Attackers steal billions in Bitcoin, devastating market confidence and creating the largest theft in history. Early adopters who secured the network lose everything.

Those who believe property rights are absolute and the market should handle the fallout

Option 2: Freeze/Burn Exposed Coins

Violates Bitcoin's core principle of immutability. Sets precedent for future confiscation. Potentially illegal seizure of property. Could face legal challenges.

Those who prioritize network security over individual property rights

Option 3: Force Migration with Deadline

Coins that don't move to quantum-safe addresses by deadline are frozen. But owners of lost keys, deceased holders, and long-term cold storage cannot comply.

Those seeking a middle ground that preserves what can be saved

There is no good answer. Every option violates fundamental principles Bitcoin was built upon. The debate will likely split the community and could result in chain forks with different approaches. A February 2026 preprint by Strike formalizes this further, demonstrating that even with perfect PQC algorithms, Bitcoin's protocol semantics create migration constraints that cannot be resolved without modifying underlying consensus rules. The problem is structural, not merely cryptographic.

- [Project Eleven Bitcoin Vulnerability Analysis](https://blog.projecteleven.com/posts/quantum-vulnerability-of-bitcoin-addresses)
- [Strike 2026 - Bitcoin PQC Migration Constraints (Zenodo)](https://zenodo.org/records/18526451)
- [Human Rights Foundation: The Quantum Threat to Bitcoin](https://hrf.org/latest/the-quantum-threat-to-bitcoin/)

## Geopolitical and Institutional Risks

Beyond direct theft, quantum computing creates systemic risks that threaten cryptocurrency adoption and legitimacy.

Institutional Perception Risk

Even before quantum computers can break crypto, institutions may divest based on perceived future risk. Insurance companies, pension funds, and regulated entities face fiduciary duties that may prohibit holding assets with known future vulnerabilities.

Price collapse from institutional selling could occur years before actual quantum attacks.

Could begin any time as awareness grows; accelerates as NIST 2030 deadline approaches

Quantum Archaeology

All historical blockchain data is public and immutable. When quantum computers arrive, every transaction ever made can be analyzed. Transaction graph deanonymization becomes trivial.

Complete privacy collapse for all historical Bitcoin/Ethereum activity. Every wallet, every transaction, every flow of funds exposed.

Inevitable once Shor's algorithm is practical; cannot be prevented retroactively

Geopolitical Competition

Nation-states are racing to achieve quantum supremacy. China, US, EU investing billions in quantum computing. First nation to achieve cryptographically-relevant quantum computing gains massive strategic advantage.

Quantum capability could be used for economic warfare, targeting adversary financial systems including cryptocurrency.

Multiple nations expected to achieve CRQC by 2030-2035

- [Federal Reserve Quantum Warning](https://thequantuminsider.com/2025/10/06/federal-reserve-warns-quantum-computers-could-expose-bitcoins-hidden-past/)
- [NIST IR 8547 Transition Timeline](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf)

## The Bitcoin Community Debate

BIP-360 (now specified as Pay-to-Merkle-Root, authored by Hunter Beast) is the leading proposal, but it remains a draft with no agreed algorithm and no activation date, and it protects only new addresses. The community does not even agree on how urgent the problem is, which is itself part of the risk: the range of expert views below spans nearly two decades.

### BIP-360: Pay-to-Merkle-Root (P2MR)

Hunter Beast

Draft - no agreed algorithm, no activation date

Introduces a new address type using NIST-approved post-quantum signatures (ML-DSA, SLH-DSA, FALCON), protecting only new addresses at rest

- P2MR (Pay-to-Merkle-Root): hides the public key on-chain for new addresses
- Protects only at-rest coins; the key still appears in the mempool on every spend
- Backward compatible soft fork approach
- No mainnet activation timeline; SegWit and Taproot each took 7 to 8 years to adopt

- Signature size: PQC signatures are 40-100x larger than ECDSA (gas cost explosion)
- Block space: Migration of all UTXOs requires 76-568 days of block space
- Consensus: No agreement on which algorithm to use (ML-DSA vs FALCON vs SLH-DSA)
- Timeline: Process requires 4-7 years but quantum computers may arrive in 3-6 years
- Exposed coins: No solution for permanently-exposed P2PK and reused addresses

Charles Edwards (Capriole)

Advocates for 2026 deployment; suggests coins that don't migrate to BIP-360 could be "burned" by 2028. Warns of 20-30% of Bitcoin being vulnerable to quantum attackers.

Adam Back (Blockstream)

Argues the quantum threat is "decades away" and pushes back against urgency, noting Bitcoin doesn't use encryption in the way many understand.

Jameson Lopp (Casa)

Agrees quantum isn't an immediate threat but estimates a full transition to quantum-resistant signatures would take 5-10 years to implement.

Willy Woo

Notes Taproot usage has fallen from 42% of transactions in 2024 to 20%, stating he's "NEVER seen the latest format losing adoption before."

- [BIP-360 Official Site](https://bip360.org/)
- [CoinDesk: Bitcoin's Quantum Debate](https://www.coindesk.com/tech/2025/12/20/bitcoin-s-quantum-debate-is-resurfacing-and-markets-are-starting-to-notice)
- [Cointelegraph: BIP-360 Push](https://cointelegraph.com/news/bitcoin-quantum-resistant-bip-360-post-quantum-signatures-taproot)

## Ethereum's 2026 Quantum Preparation

Ethereum is pursuing quantum resistance through planned protocol upgrades, with key milestones in 2026.

### Glamsterdam (H1 2026)

Gas limit increase from 60 million to potentially 200+ million to accommodate larger post-quantum signatures. Parallel transaction processing for improved scalability. ZK proof validation: validators move from re-running transactions to verifying ZK proofs.

Gas limit expansion directly enables post-quantum signature deployment; ZK proof validation is a foundational step toward quantum-resistant execution

Targeting H1 2026

### Hegota (H2 2026)

Enshrined Proposer-Builder Separation (ePBS): decentralizes block production to defend against quantum-equipped actors dominating the proposer market. 128-bit provable security as foundation for institutional-grade financial applications.

ePBS prevents quantum-advantage actors from monopolizing block production; 128-bit security provides quantum-resistant foundation

Planned for H2 2026

### ZK-STARKs for Quantum Resistance

Ethereum is prioritizing ZK-STARKs (based on hash functions) over ZK-SNARKs (based on elliptic curves) because STARKs are quantum-resistant. As Ethereum Foundation researcher George Kadianakis noted: "A soundness issue in ZK-EVMs is catastrophic: if an attacker can forge a proof, they can mint tokens from nothing."

ZK-STARKs provide quantum-resistant zero-knowledge proofs, eliminating elliptic-curve assumptions from the proving system

Active development

- Gas limit increases accommodate larger PQC signatures without breaking the fee market
- ePBS decentralizes block production, neutralizing quantum proposer advantage
- ZK-STARKs replace elliptic-curve-based SNARKs with hash-based quantum-resistant proofs
- 128-bit provable security establishes foundation for institutional-grade quantum resistance

- ~65% of Ether currently exposed to quantum attacks
- PQC signatures increase gas costs 37-100x
- Contract migration requires individual developer action
- DeFi protocols with locked funds face complex migration

- [BeInCrypto: Ethereum 2026 Upgrades](https://beincrypto.com/ethereum-network-upgrades-for-2026/)
- [AMBCrypto: ETH 2026 Upgrades](https://ambcrypto.com/ethereum-how-eths-2026-upgrades-aim-to-reshape-the-network/)

## Strategic Recommendations

Based on the current threat landscape and industry trajectory, here are key considerations for different stakeholders.

Bitcoin/Ethereum Holders

- Never reuse addresses - each use exposes your public key permanently
- Move funds from P2PK addresses to P2PKH or P2WPKH (hashed) addresses
- Avoid Taproot (P2TR) addresses for long-term storage - public key exposed on receipt
- Consider allocation to quantum-resistant alternatives (QRL)
- Follow BIP-360 development and prepare for migration when available
- Understand your exposure: funds in exposed addresses cannot be protected by software updates

Institutions and Fiduciaries

- Assess quantum risk in crypto holdings as part of fiduciary duty
- Monitor NIST timeline: 2030 deprecation, 2035 prohibition of ECDSA
- Evaluate quantum-safe alternatives for long-term holdings
- Document quantum risk assessment for regulatory compliance
- Consider timeline for divesting vulnerable assets before institutional exodus

Developers and Protocols

- Implement crypto-agile architectures that can swap signature schemes
- Use account abstraction (EIP-4337) to enable PQC wallet upgrades
- Avoid hard-coding ECDSA assumptions in smart contracts
- Test with NIST-approved PQC algorithms (ML-DSA, SLH-DSA, FALCON)
- Follow Ethereum Glamsterdam/Hegota upgrade developments

Long-term Perspective

The transition to quantum-resistant cryptography is inevitable. The question is not if but when, and whether migration can complete before attacks begin. Projects built quantum-safe from the start (QRL) avoid this risk entirely. Those facing migration (Bitcoin, Ethereum) are in a race against time with uncertain outcomes.

Nature Feature (Feb 2026)

"Vibe shift" - usable quantum computers within a decade. Four teams now below QEC threshold.

Dorit Aharonov (Hebrew University)

"We've entered a new era...the timeline is much shorter than people thought" (Feb 2026)

Fred Chong (U Chicago, ACM Fellow)

"We're very comfortably in era of escape velocity. Building a big useful quantum computer is no longer a physics problem but an engineering problem."

Scott Aaronson (UT Austin)

2025 "met or exceeded" expectations. Compares PQC migration urgency to Frisch-Peierls memo of 1940.

Charles Edwards (Capriole)

"Quantum Event Horizon" is 2-9 years away

Adam Back (Blockstream)

Meaningful threat 20-40 years away

Michele Mosca (Waterloo)

1-in-7 probability public-key cryptography broken by 2026

Chainalysis

5-15 years before quantum computers could break current standards

Alice & Bob CEO (Nvidia partner)

Quantum computers powerful enough to crack Bitcoin "a few years after 2030"

Chao-Yang Lu (USTC)

Expects fault-tolerant quantum computer by 2035

Infleqtion (September 2025)

First execution of Shor's algorithm on logical qubits; targeting 1,000 logical qubits by 2030. Going public on NYSE as INFQ.

IonQ Roadmap

99.99% two-qubit gate fidelity in lab; 256-qubit system planned 2026; 1,600 logical qubits by 2028; targeting 2 million physical qubits by 2030

IBM Roadmap

2,000 logical qubits by 2033 (Blue Jay) - exceeds ECDSA-breaking requirement

## Ready to Learn More?

Explore the Quantum Resistant Ledger and discover how it's protecting the future of blockchain.

Newer Updates

Older Updates

Page

of

August 23, 2026


---

# About QRL Hub | Independent Quantum-Resistant Blockchain Resource

> Who runs QRL Hub and how it is edited: an independent educational resource on the quantum threat to crypto and QRL, with primary-source citations, a corrections policy, and no financial ties.

- Language: en
- Canonical URL: https://qrlhub.com/en/about
- Source: QRL Hub, an independent educational resource (not the official QRL project, which is at https://theqrl.org).

---

## About QRL Hub

Your resource for quantum-resistant blockchain information

## About QRL Hub

introduction

QRL Hub is an information resource dedicated to the Quantum Resistant Ledger and the critical field of quantum-resistant blockchain technology. As quantum computing advances at an unprecedented pace, the cryptographic foundations securing today's blockchains face existential risks. QRL Hub bridges the gap between complex post-quantum cryptography and practical understanding, providing accessible and accurate information for everyone from blockchain enthusiasts to security researchers.

## Understanding the Quantum Threat

quantum-threat

The blockchain industry, representing over $3 trillion in digital assets, relies on cryptographic algorithms vulnerable to quantum computers. Bitcoin, Ethereum, and virtually every major blockchain use elliptic curve cryptography that quantum computers will eventually break. Recent breakthroughs have accelerated timelines dramatically: in 2026 Google set a 2029 Q-Day deadline, QuEra demonstrated a record 96 error-corrected logical qubits, and the hardware estimated to break Bitcoin fell sharply. Experts now assign roughly a 20-33% probability of a cryptographically relevant quantum computer arriving by 2030. The threat extends beyond future attacks: adversaries are already harvesting encrypted data today to decrypt tomorrow.

## The QRL Solution

qrl-solution

The Quantum Resistant Ledger launched its mainnet in June 2018 as the world's first fully operational quantum-resistant blockchain. While others scramble to retrofit security, QRL was built quantum-secure from its genesis block using NIST-approved post-quantum cryptography. Nearly eight years of proven operation, multiple external security audits, and continuous development have established QRL as the most battle-tested quantum-resistant network in existence.

QRL employs XMSS (eXtended Merkle Signature Scheme), a hash-based signature system that relies on secure hash functions rather than vulnerable mathematical structures. This approach offers forward security and requires only minimal cryptographic assumptions. With QRL 2.0 now live on an independently audited public testnet (an EVM-compatible, post-quantum blockchain supporting smart contracts), QRL is positioned to become the foundation for the next generation of secure decentralized applications.

## Our Mission

mission

QRL Hub serves the global blockchain community by educating about quantum threats, providing clear technical information, and supporting those exploring post-quantum cryptography. We maintain this independent educational resource to help users, developers, and decision-makers understand why quantum resistance matters now and how QRL provides a proven solution.

Whether you're safeguarding digital assets, building decentralized applications, or researching blockchain security, QRL Hub offers the knowledge you need to navigate blockchain's quantum age. The future of secure blockchain infrastructure is already here: it's been operating since 2018.

## How this site is edited

editorial-policy

Every factual claim on QRL Hub is meant to be checkable:

- News items cite their primary sources inline: the original paper, announcement, audit report, or regulatory document, not a retelling of it.
- Figures that change (qubit counts, attack estimates, audit status) carry their as-of date, and each page shows when it was last updated.
- Claims about QRL follow the same rule as claims about any other chain: if it cannot be verified on-chain or in a public document, it does not go on the site.
- Machine-readable copies of every page (Markdown, RSS/Atom/JSON feeds, llms.txt) are published so the content can be checked and reused programmatically.

## Corrections

corrections

If something on this site is wrong or out of date, report it in the QRL Discord (linked in the footer). Reports are reviewed against the primary sources; substantive corrections are applied directly to the affected page, and its last-updated date changes accordingly.

## Independence and funding

independence

QRL Hub is an independent, self-funded educational resource maintained by a member of the QRL community. It is not the official QRL project (that is theqrl.org) and is not operated by the QRL Foundation. The site sells nothing, runs no advertising or paid placements, and never solicits or holds funds. Nothing on this site is financial advice.
