Quantum computing is becoming a more immediate cybersecurity concern, but the greatest challenge facing Bitcoin, Ethereum and other blockchain networks may be coordinating a transition to post-quantum cryptography before a cryptographically relevant quantum computer becomes a reality, according to BlackRock analysts.
A new white paper from BlackRock reports that while a future quantum computer capable of breaking today’s public-key cryptography could threaten digital assets, upgrading blockchain networks to quantum-resistant cryptography is a significantly easier engineering challenge than building such a machine.
The report examines how advances in quantum hardware, error correction and algorithms have shortened estimates for when a cryptographically relevant quantum computer (CRQC), sometimes referred to as “Q-Day,” could emerge.
According to the paper, no such machine exists today, and substantial scientific and engineering obstacles remain. However, recent advances by companies including Google and IBM have compressed expected timelines enough that governments, technology companies and blockchain developers should accelerate migration plans.
The paper points to Google’s decision to move its own post-quantum migration deadline to 2029 and IBM’s roadmap targeting large-scale fault-tolerant quantum computing between 2029 and 2033 as examples of how expectations have shifted.
The BlackRock team writes that quantum computing is likely to present a manageable risk for blockchains, provided the industry upgrades to post-quantum cryptography before quantum computers become capable of breaking current encryption.

Why Quantum Computers Matter
Nearly every modern digital system depends on public-key cryptography, according to the BlackRock analysts.
Protocols such as RSA and Elliptic Curve Cryptography (ECC) secure online banking, encrypted internet traffic, financial messaging systems, government communications and blockchain transactions.
Those systems rely on mathematical problems that are easy to verify but effectively impossible for classical computers to reverse. In Bitcoin and Ethereum, for example, users prove ownership of digital assets through digital signatures generated from private cryptographic keys.
Quantum computers threaten that assumption because, unlike classical computers, which process information using bits representing either zero or one, quantum computers use qubits that exploit quantum mechanical properties such as superposition and entanglement. Combined with Shor’s algorithm, first proposed in 1994, a sufficiently capable quantum computer could solve the mathematical problems underlying ECC dramatically faster than conventional computers.
The paper says quantum computers are not simply faster versions of today’s machines. Instead, they excel at solving certain classes of mathematical problems that underpin modern encryption.
A successful attack could allow an adversary to derive a private key from publicly available information, potentially allowing unauthorized transfers of cryptocurrency or compromising secure communications across many industries.

Progress Is Coming From More Than Hardware
The BlackRock team writes that discussions about quantum progress often focus too heavily on raw qubit counts.
Instead, the paper says the more meaningful advances are occurring in error correction and algorithm development.
Quantum information remains extremely fragile, requiring many physical qubits to produce a single reliable logical qubit capable of executing long computations.
Recent research has improved that picture and the paper highlights Google’s demonstration of below-threshold quantum error correction with its Willow processor, along with improvements in IBM’s Heron and Nighthawk processors that emphasized lower error rates over larger physical qubit counts.
The report also cites Google’s March 2026 work on optimizing quantum circuits for elliptic curve cryptography, which significantly reduced estimated hardware requirements for breaking ECC-256 encryption.
It further references research from Caltech and Oratomic that suggested substantially lower resource requirements for neutral-atom quantum computers than earlier estimates, although it notes those architectures remain less mature than superconducting systems.
Ultimately, these advances have shortened many projections for when cryptographically relevant quantum computers could become practical, according to the paper.
Even so, the analysts write that building such a machine still represents a much larger technical challenge than replacing vulnerable cryptographic algorithms.
Post-Quantum Standards Already Exist
Unlike previous cybersecurity transitions, the paper says much of the replacement technology has already been developed.
The National Institute of Standards and Technology began its post-quantum cryptography standardization effort in 2016, leading to the publication of new federal standards in 2024.
Those standards include ML-KEM for key encapsulation and ML-DSA and SLH-DSA for digital signatures, with additional algorithms still under evaluation.
Governments worldwide have largely aligned around completing post-quantum migrations by approximately 2035, according to the paper, although critical infrastructure often carries earlier milestones.
Technology companies have begun accelerating their own schedules with the paper indicated that Google and Cloudflare have both advanced migration targets to 2029 following recent quantum research, while Microsoft has also published long-term migration plans.
Governments and large enterprises face particular urgency because of so-called “harvest now, decrypt later” attacks, in which adversaries collect encrypted information today with the expectation that future quantum computers could eventually decrypt it, according to the paper.
While blockchains share many of the same cryptographic vulnerabilities as other digital systems, the paper says they also possess unique advantages.
Because blockchain software is open source, potential attack surfaces are well understood and proposed fixes undergo extensive public review.
For Bitcoin, the paper says the core blockchain itself remains relatively resistant because its proof-of-work mechanism depends on SHA-256 hashing rather than elliptic curve cryptography. Grover’s algorithm offers only a quadratic improvement against hashing, which the paper says would largely be offset by Bitcoin’s automatic mining difficulty adjustments.
Instead, the principal quantum risk lies with wallet ownership and transaction signatures.
The report distinguishes between two categories of attacks:
- Long-range attacks target wallets whose public keys have already been exposed on the blockchain through address reuse or older address formats.
- Short-range attacks would require quantum computers fast enough to derive a private key after a legitimate transaction enters the mempool but before it is confirmed in a block.
According to the paper, roughly 35% of Bitcoin’s circulating supply could potentially be vulnerable to long-range attacks because associated public keys have already been exposed.
Most of the remaining supply benefits from address formats that hash public keys, reducing that particular exposure.
The paper also notes that many inactive wallets, including those believed to belong to Bitcoin creator Satoshi Nakamoto, may never be migrated if their private keys have been lost.
That raises difficult governance questions about whether permanently inaccessible coins should remain spendable under future post-quantum rules.
Bitcoin and Ethereum Are Taking Different Paths
The paper says Bitcoin’s technical migration is relatively straightforward but organizationally difficult.
Developers will need to agree on quantum-resistant signature algorithms, implement protocol upgrades and establish policies for migrating existing addresses, according to the paper.
Several Bitcoin Improvement Proposals addressing post-quantum migration already exist in draft form, although no final consensus has emerged.
The paper also discusses proposals that would leverage Taproot’s scripting capabilities to accelerate migration while minimizing disruption.
Ethereum presents a different challenge because Ethereum incorporates multiple cryptographic systems across its consensus, execution, data availability and application layers. To tackle that, the paper says migration requires a series of coordinated protocol upgrades rather than replacing a single signature algorithm.
The report points to the Ethereum Foundation’s long-term roadmap extending through 2029, which includes planned updates affecting validator signatures, externally owned accounts, data availability proofs and other quantum-vulnerable components.
Other blockchain ecosystems have also begun exploring post-quantum protections.
The paper notes that Solana has introduced a Winternitz Vault allowing migration to quantum-resistant addresses, while Algorand has demonstrated a post-quantum signed transaction on its main network.
A Coordination Problem More Than a Technology Problem
The paper concludes that quantum computing represents both a risk and an opportunity for digital assets.
While recent quantum advances have increased the urgency of migration planning, the paper says current momentum still favors defenders.
Governments have standardized new cryptographic algorithms, technology companies have begun deployment, and blockchain communities are actively debating implementation strategies.
The report concludes that the difficult task is not inventing new cryptography but achieving consensus across decentralized ecosystems before quantum computers mature.
If that transition succeeds, BlackRock writes that blockchains could ultimately emerge more secure than they are today.
Rather than presenting quantum computing solely as an existential threat to digital assets, the paper concludes it could serve as a catalyst for modernizing blockchain security and strengthening confidence in cryptocurrency infrastructure over the long term.
Read the BlackRock white paper here.



