Post-Quantum Cryptography and Crypto: What It Means

Updated | 3 min read | QUANTUM (QNT) community

What is at risk

Most blockchains protect your wallet with public key cryptography. Solana signs transactions with Ed25519, and Bitcoin and Ethereum use elliptic curve signatures. These are safe against today's computers.

The quantum threat

In 1994 Peter Shor described an algorithm that, on a large enough quantum computer, could break the math behind elliptic curve and RSA cryptography. No machine can do this today. The worry is about the future, and about data collected now and decrypted later.

The new standards

In 2024 NIST published its first post-quantum standards: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. Governments and companies are planning migrations.

What it means for crypto projects

Blockchain communities are discussing how to move to quantum-resistant signatures over time. It is long-term engineering, not an overnight switch. For a direct look at the main chains, read will quantum computers break Bitcoin and Solana?

Background: what quantum computing is and why error correction decides the timeline.

The three standards in plain English

StandardAlgorithmJobBased on
FIPS 203ML-KEM (from Kyber)Agree a shared secret keyLattices
FIPS 204ML-DSA (from Dilithium)Digital signaturesLattices
FIPS 205SLH-DSA (from SPHINCS+)Backup signaturesHash functions

NIST released all three on 13 August 2024. In March 2025 it picked a fifth algorithm, HQC (code-based), as a backup for key exchange in case lattices are ever weakened. NIST said it planned a draft standard for HQC about a year later and a final one in 2027. See the standards status page, ML-KEM, ML-DSA and SLH-DSA.

Why signature size matters on a blockchain

Ed25519 signatures are 64 bytes. Post-quantum signatures are many times larger, which strains block space and fees. That is one reason chains cannot just flip a switch. Read signature sizes and block space and the signature options compared.

What is changing in 2026

Common mistakes

Also read harvest now, decrypt later and what individuals can do today.

Sources

Frequently asked questions

What is post-quantum cryptography?

Cryptography designed to resist attacks from both normal and quantum computers, while running on ordinary hardware.

Is my crypto at risk from quantum computers today?

No. No existing quantum computer can break the signatures used by major blockchains. The risk is a future one that the industry is preparing for.

What are the NIST post-quantum standards?

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), published in 2024.

Is post-quantum cryptography the same as quantum cryptography?

No. Post-quantum cryptography is ordinary math that runs on normal computers. Quantum cryptography, like QKD, uses quantum physics itself.

Why was a hash-based signature standard included?

SLH-DSA rests on different math from the lattice schemes, so it is a safety net if lattices are weakened.

Are my browser connections already post-quantum?

Many are, for key exchange. See the 2026 rollout and hybrid key exchange.

What is crypto agility?

Designing systems so algorithms can be swapped without a rebuild. See crypto agility explained.

Share on X

Keep reading

All Quantum computing guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.