Post-Quantum Cryptography and Crypto: What It Means
What is at risk
Most blockchains protect your wallet with public key cryptography. Solana signs transactions with Ed25519, and Bitcoin and Ethereum use elliptic curve signatures. These are safe against today's computers.
The quantum threat
In 1994 Peter Shor described an algorithm that, on a large enough quantum computer, could break the math behind elliptic curve and RSA cryptography. No machine can do this today. The worry is about the future, and about data collected now and decrypted later.
The new standards
In 2024 NIST published its first post-quantum standards: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. Governments and companies are planning migrations.
What it means for crypto projects
Blockchain communities are discussing how to move to quantum-resistant signatures over time. It is long-term engineering, not an overnight switch. For a direct look at the main chains, read will quantum computers break Bitcoin and Solana?
Background: what quantum computing is and why error correction decides the timeline.
The three standards in plain English
| Standard | Algorithm | Job | Based on |
|---|---|---|---|
| FIPS 203 | ML-KEM (from Kyber) | Agree a shared secret key | Lattices |
| FIPS 204 | ML-DSA (from Dilithium) | Digital signatures | Lattices |
| FIPS 205 | SLH-DSA (from SPHINCS+) | Backup signatures | Hash functions |
NIST released all three on 13 August 2024. In March 2025 it picked a fifth algorithm, HQC (code-based), as a backup for key exchange in case lattices are ever weakened. NIST said it planned a draft standard for HQC about a year later and a final one in 2027. See the standards status page, ML-KEM, ML-DSA and SLH-DSA.
Why signature size matters on a blockchain
Ed25519 signatures are 64 bytes. Post-quantum signatures are many times larger, which strains block space and fees. That is one reason chains cannot just flip a switch. Read signature sizes and block space and the signature options compared.
What is changing in 2026
- Deadlines: NIST's draft transition plan, IR 8547 (November 2024), proposes deprecating RSA and elliptic curve signatures after 2030 and disallowing them after 2035. It is a draft, so check the current text. See government deadlines.
- Estimates keep falling: Craig Gidney's May 2025 paper put RSA-2048 under a million noisy qubits and about a week of run time, down from 20 million qubits in 2019. Still a paper estimate. Later preprints propose even lower counts for unbuilt designs.
- Bitcoin: BIP-360, a proposed quantum-resistant output type, was merged into the BIP repository as a draft in February 2026. A draft is not an activated upgrade. See BIP-360 and BIP-361.
- Solana: an opt-in Winternitz Vault, built by developer Dean Little in January 2025, lets individual users protect funds with hash-based one-time signatures. It is not a network-wide change. See Ethereum and Solana plans.
Common mistakes
- Thinking post-quantum means "uses a quantum computer". It runs on ordinary hardware.
- Confusing it with QKD. See QKD versus PQC.
- Buying a "quantum-proof coin" because of marketing. Check the actual signature scheme and audit. Nothing here is financial advice.
Also read harvest now, decrypt later and what individuals can do today.
Sources
- NIST: first three finalized post-quantum standards, 13 Aug 2024
- NIST: HQC selected, March 2025
- Gidney: RSA-2048 with under a million noisy qubits
- Encryption Consulting: summary of NIST IR 8547 (vendor summary of a draft, verify with NIST)
- BIP 360 text
- The Quantum Insider: Solana Winternitz Vault
Frequently asked questions
What is post-quantum cryptography?
Cryptography designed to resist attacks from both normal and quantum computers, while running on ordinary hardware.
Is my crypto at risk from quantum computers today?
No. No existing quantum computer can break the signatures used by major blockchains. The risk is a future one that the industry is preparing for.
What are the NIST post-quantum standards?
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), published in 2024.
Is post-quantum cryptography the same as quantum cryptography?
No. Post-quantum cryptography is ordinary math that runs on normal computers. Quantum cryptography, like QKD, uses quantum physics itself.
Why was a hash-based signature standard included?
SLH-DSA rests on different math from the lattice schemes, so it is a safety net if lattices are weakened.
Are my browser connections already post-quantum?
Many are, for key exchange. See the 2026 rollout and hybrid key exchange.
What is crypto agility?
Designing systems so algorithms can be swapped without a rebuild. See crypto agility explained.
Keep reading
- Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - What Is Quantum Computing? A Plain English Guide
Quantum computers use qubits instead of bits. Learn what quantum computing is, what it is good at, and why the crypto world pays attention. - Quantum Error Correction Explained
Qubits are fragile, so quantum computers need error correction. Learn how logical qubits are built and why this is the key challenge. - Bitcoin BIP-360 and BIP-361 Explained: The Quantum Upgrade Proposals
What the draft Bitcoin proposals P2MR (BIP-360) and the migration and sunset plan (BIP-361) actually say, and what they leave open. - Ethereum and Solana Post-Quantum Plans: What Is Real in 2026
Ethereum's four-part quantum roadmap and Solana's Winternitz Vault and testnet work, with dates and honest caveats. - NIST Post-Quantum Standards Status: FIPS 203, 204, 205, FN-DSA and HQC
Which post-quantum standards are final, which are still drafts, and what that means for companies deciding what to deploy in late 2026.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary