A sweeping new technical report warns that the cryptographic foundations securing trillions of dollars in digital assets could be broken by quantum computers within the next four to seven years—and that the blockchain industry is dangerously unprepared for the transition needed to survive.
The window for action, the authors argue, is rapidly closing.
"Migration to quantum-resistant cryptography is no longer optional but imperative for any blockchain system expected to be trusted and secure into the future," the report states.
The threat centers on Shor's algorithm, a quantum computing technique first described in 1994 that can solve the mathematical problem underpinning most modern public-key cryptography in a fraction of the time it would take classical computers. Recent breakthroughs have dramatically lowered the hardware bar required to run such an attack.
The report estimates that approximately 6.9 million Bitcoin—about one-third of the total possible supply—sits in addresses whose public keys have already been exposed on-chain, making them potentially vulnerable to quantum attack. On Ethereum, the exposure is even broader: analysts have found that over 65% of all ETH is held in quantum-exposed addresses.
What makes blockchains particularly vulnerable, the report explains, is that their public ledgers and bearer-instrument design offer no safety net. Unlike a bank, a blockchain has no fraud department, no chargeback mechanism, and no way to reverse a forged transaction. Once a quantum attacker recovers a private key and drains a wallet, the loss is permanent.
Even under the most optimistic assumptions, the report estimates that migrating all Bitcoin UTXOs (or unspent transaction outputs) to quantum-resistant addresses—if 100% of block space were dedicated to that effort—would take approximately 76 days. As migration competes with ordinary economic activity, timelines extend significantly.
The rest of the technology world has already begun moving. Over half of all human web traffic is now post-quantum encrypted, according to Cloudflare data from December 2025. OpenSSH defaults to post-quantum key exchange, while Apple enabled hybrid post-quantum support across its devices in iOS 26. The National Security Agency has set a 2030–2033 target for complete migration across government systems.
"The internet has already moved," the report concludes. "The digital asset industry—which arguably has more at stake because blockchains directly protect bearer value with the exact cryptographic primitives that quantum computers threaten—has barely started."
The authors recommend that blockchain networks begin immediate cryptographic inventories, deploy post-quantum key exchange in off-chain infrastructure without delay, and start the complex governance and design work needed for on-chain signature upgrades—warning that by the time the threat feels urgent, there will no longer be enough time to respond.


















