Quantum Computing and Crypto

Updated | QUANTUM (QNT) community | Not financial advice

How could quantum computers threaten crypto?

Blockchains rely on two kinds of cryptography. Hash functions secure blocks and addresses. Digital signatures prove that you own the funds you spend. Shor's algorithm (arXiv:quant-ph/9508027) would let a large quantum computer recover a private key from a public key for the elliptic curve signatures Bitcoin, Ethereum and Solana use (ECDSA and Ed25519). That is the main risk. Grover's algorithm gives only a quadratic speedup against hashing, which doubling the hash length can offset. See elliptic curves explained, Grover's algorithm and hashes and quantum computers.

Is crypto at risk today?

No. The machines needed do not exist. A 2025 estimate from Google researchers puts the cost of breaking 2048 bit RSA at under 1 million noisy qubits running for about a week (Google Security Blog, arXiv:2505.15917). Today's best chips have on the order of a hundred qubits, such as the 105 qubit Willow. IBM's published target is 200 logical qubits by 2029 (IBM). Those are plans, not delivered machines, and the gap to the cryptographic estimates is still large. Elliptic curve estimates are tracked in this guide.

Which coins are most exposed?

A signature reveals the public key. Coins whose public keys are already visible on chain, for example from address reuse or older address types, would be easiest to attack first, because the attacker would not have to race a transaction. Read exposed public keys and address reuse. Data stored now could also be decrypted later: harvest now, decrypt later matters for encrypted messages more than for public blockchains.

What is quantum resistant crypto?

Quantum resistant, or post-quantum, cryptography uses mathematical problems that are not known to be easy for quantum computers. NIST finalised the first standards in August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) (NIST). Its draft transition plan, NIST IR 8547, proposes retiring today's vulnerable public key algorithms by 2035. Post-quantum signatures are larger, which is a real cost for blockchains. See quantum resistant signatures explained and crypto agility.

What are Bitcoin, Ethereum and Solana doing?

Plans differ and change, so read the current state in our comparison guides: roadmaps compared, Bitcoin proposals BIP 360 and 361 and Ethereum and Solana plans. Treat any claim that one chain is already "quantum proof" with caution and look for the primary source.

Does this affect QNT?

QNT is a token on Solana, so its security against quantum attack is whatever Solana's is. The token does nothing quantum itself and is not a quantum resistant coin. Read what QNT is and the quantum computing explainer.

Keep reading

Sources

Educational content, not investment or security advice.

Frequently asked questions

Can quantum computers break Bitcoin?

Not with any machine that exists today. A large, error corrected quantum computer could in theory forge the elliptic curve signatures Bitcoin uses, which is why post-quantum upgrades are being discussed. See the full answer.

What is quantum resistant crypto?

Cryptography built on mathematical problems that are not known to be easy for quantum computers. NIST finalised its first standards, FIPS 203, 204 and 205, in August 2024.

Is Solana quantum resistant?

Solana signs transactions with Ed25519, an elliptic curve scheme, so it is not quantum resistant by itself. Upgrade options are discussed in Ethereum and Solana post-quantum plans.

Is QNT a quantum resistant coin?

No. QNT is an ordinary token on Solana and inherits Solana's cryptography. The quantum theme is branding.

Keep reading