Blockchain vs Quantum Computing: What Is Actually at Risk
Three places a blockchain uses cryptography
To judge the risk, split a blockchain into its parts. Each part uses different math and faces a different quantum threat.
| Part | Used for | Quantum algorithm | Effect |
|---|---|---|---|
| Digital signatures | Proving you may spend your coins | Shor | Could derive a private key from a public key. The main risk. |
| Hash functions | Block links, addresses, mining | Grover | Quadratic speedup only. Longer hashes offset it. |
| Encryption of data in transit | Wallet apps, websites, exchanges | Shor | Fixed by upgrading to post-quantum key exchange, not a blockchain rule. |
Signatures: the real exposure
Bitcoin and Ethereum use elliptic curve signatures and Solana uses Ed25519. Shor's algorithm (arXiv:quant-ph/9508027) would let a large quantum computer recover a private key from the matching public key. When you spend coins your public key appears on chain. Coins sitting at addresses whose public keys are already visible, for example after address reuse or in older output types, are the easiest targets because an attacker does not have to race a pending transaction. See exposed public keys and elliptic curves explained.
Mining and hashing: a smaller risk
Grover's algorithm (arXiv:quant-ph/9605043) searches an unstructured space in roughly the square root of the usual steps. For a hash like SHA-256 that turns 256 bit security into about 128 bits against a quantum attacker, which is still very large. The speedup is also hard to use in practice, because quantum operations are slow and the search must run serially. Proof of work mining is therefore much less exposed than signatures. See Grover's algorithm and hashes and quantum computers.
How far away is an attack?
Nobody knows, and honest sources say so. Today's best chips have on the order of a hundred physical qubits, such as Google's 105 qubit Willow. A 2025 paper by Craig Gidney estimates that breaking 2048 bit RSA would take under one million noisy qubits running about a week, a 20 fold drop from an earlier estimate (Google Security Blog). IBM has published a target of a fault tolerant machine with 200 logical qubits by 2029. These figures do not directly give the cost of breaking elliptic curves, which have their own estimates tracked in this guide. The fair summary is: not now, estimates are falling, and the timing is uncertain.
Why plan early if it is far away?
Migration is slow. A chain must choose new signature schemes, build them into clients and wallets, get consensus on the change and move users' funds. Post-quantum signatures are larger, which raises costs. Coins whose owners have lost keys cannot be migrated by their owners, so a deadline forces hard choices about them. NIST finalised its first post-quantum standards in August 2024 and its draft transition plan, NIST IR 8547, proposes retiring today's vulnerable public key algorithms by 2035. Blockchains are not bound by that plan but face the same clock. Read how Bitcoin, Ethereum and Solana compare.
What does this mean for QNT holders?
QUANTUM (QNT) is a token on Solana, so its exposure is Solana's. Nothing about the token changes the risk, and the token does not perform quantum computation. The risk is a long term, ecosystem wide one, not a reason for panic today. Memecoins carry far larger near term risks such as thin liquidity and scams, see risk factors. Nothing here is financial advice.
Sources and further reading
- Shor: Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer (arXiv)
- Grover: A fast quantum mechanical algorithm for database search (arXiv)
- Gidney: How to factor 2048 bit RSA integers with less than a million noisy qubits (arXiv)
- Google Security Blog: tracking the cost of quantum factoring
- Google: Meet Willow
- IBM Quantum blog: large scale fault tolerant quantum computing (June 2025)
- NIST: first three finalized post-quantum encryption standards (August 2024)
- NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards
Checked 2026-10-11. Roadmaps and estimates change, so check the primary sources. This is education, not investment or security advice. QUANTUM (QNT) is an independent community token on Solana and is not affiliated with Quantinuum Ltd or Quant Network.
Frequently asked questions
Can a quantum computer break a blockchain?
Not today. A large, error corrected quantum computer could in theory forge the signatures many blockchains use, but no machine close to that exists.
Is Bitcoin mining at risk from quantum computers?
Much less than signatures. Grover's algorithm gives only a quadratic speedup on hashing, which longer hashes can offset.
When could quantum computers threaten crypto?
Nobody knows. Estimates of the needed machine keep falling, but today's chips are far short. Planning starts early because migration takes years.
Which coins are most exposed?
Coins at addresses whose public keys are already visible on chain, because an attacker would not have to race a pending transaction.
Keep reading
- Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care. - Q-Day Explained: What It Means, Why Nobody Knows the Date, and the Early Warning Signs
Q-Day is the day a quantum computer can break today's public key cryptography. Here is what it really means, why dates are ranges, and what signs to watch. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary