Post-quantum migration gained urgency after the G7 Cybersecurity Working Group urged governments and businesses to prepare immediately.
The warning affects crypto networks, exchanges, wallets, and custodians using public-key cryptography.
The group published Preparing for the Post-Quantum Era: A Call to Action on September 3, 2026. It described quantum computing as a cybersecurity and business risk requiring preparation before capable machines emerge.
G7 warning directly affects crypto
The report does not mention cryptocurrency, but its recommendations apply to blockchain infrastructure. Decrypt noted that crypto transactions and fund management depend on public-key cryptography.
The G7 said, “Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms.”
The group highlighted the “Harvest now, decrypt later” threat. This involves collecting encrypted information today for decryption once quantum systems become capable.
Blockchains face a challenge because transaction histories and exposed public keys remain permanently visible, leaving keys vulnerable to future attacks.
The G7 recommended awareness, national strategies, research, public-private cooperation, and post-quantum procurement requirements.
Europe sets post-quantum deadlines
The European Union introduced its Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography in June 2025.
European Commission policy requires member states to begin migration by the end of 2026. High-risk systems must transition immediately and finish before 2030.
Quantum readiness is now a compliance, procurement, and technical issue. Companies without migration plans could face compliance and competition problems.
Bitcoin developers are exploring BIP-360, known as Pay-to-Merkle-Root, as a possible soft fork. The proposal would remove the Taproot key-path spend vulnerable to long-term quantum attacks.
Its authors acknowledge that faster mempool attacks would still require post-quantum digital signatures. BIP-360 has no activation date.
Crypto networks face costly migration
Ethereum is developing a broader framework. Vitalik Buterin’s February 2026 roadmap identified validator BLS signatures, KZG commitments, ECDSA account signatures, and application-layer zero-knowledge proofs for upgrades.
Ethereum aims to establish core post-quantum infrastructure by 2029, though migration may take longer.
A secp256k1 ECDSA signature is about 64 bytes, while Dilithium-5 uses roughly 4,595 bytes. NIST’s ML-DSA-87 standard uses about 4,627 bytes, potentially increasing storage, bandwidth, and transaction costs.

The immediate risk is migration itself, including governance disputes, protocol development, larger signatures, infrastructure changes, and older wallets with exposed public keys.
Google Quantum AI reported in March 2026 that breaking 256-bit elliptic-curve cryptography may require fewer resources than previously estimated. Google plans to complete its migration by 2029.
NIST draft IR 8547 recommends phasing out 112-bit ECDSA after 2030 and prohibiting ECDSA after 2035.
Quantum preparedness could enter institutional custody standards and investor due diligence, potentially making migration planning a competitive advantage.

