Quantum Readiness: Major Chains (Qrisk)
Q-Risk Pack: Every Major Chain's Path to Quantum Resistance
As of Thu 2026-10-08, 16:43 ET. Market caps come from CoinGecko (/simple/price, include_market_cap) and were pulled at 16:38 ET. Chains are sorted by those caps. On-chain stats were pulled 16:30–16:43 ET.
Labels used: Fact means verified against a primary source today. Reported means it comes from press, a vendor, or a secondary source. Speculative means it is my inference. Unknown means I could not source it.
Summary
- Ethereum is the only chain with a dated, L1-wide PQ deadline. The EF Protocol cluster (Sep 7 2026) set a target of a quantum-resistant L1 across execution, consensus and data by Dec 2029, with a reassessment in Jan 2027 (Fact). Four lean-consensus PQ devnets have already run (Fact). No PQ signature is live on mainnet.
- Zcash is the only chain that has shipped a consensus-level quantum measure on mainnet. NU6.3 "Ironwood" activated 2026-07-28 at height 3,428,143 (Fact). It makes new notes quantum-recoverable, which is not the same as quantum-secure. The Recovery Protocol itself is still unspecified (Fact, ZIP 2005).
- Bitcoin has specs but no activation path. BIP-360 (P2MR) and BIP-361 (legacy-signature sunset) are merged Drafts (Fact). There is no PQ-signature BIP and no activation client. Exposed supply is 31.2% per Glassnode (Oct 8 2026) and 34.45% per Project Eleven (block 950,000) (Reported).
- Mid-caps are split. TRON (TIP-899, live on Nile testnet, "year-end" mainnet target, Reported) and Sui (ML-DSA-65 mainnet targeted Q1 2027) have dated plans. Solana has app-level Winternitz vaults and Falcon client prototypes, but its Falcon syscall SIMD was closed (Fact). Monero's FCMP++ adds forward secrecy, not PQ spend authority. Hyperliquid has no public plan.
- The threat baseline moved left in 2026. Google Quantum AI estimates ECDLP-256 can be broken with ≤1,200 logical qubits on <500k physical qubits (Mar 31 2026, Fact). ECDSA.fail (Sep 2026) cuts point-addition circuits to 793 logical qubits (Fact). Justin Drake's "bunker mode" warning (Oct 7–8 2026) adds an AI-cryptanalysis tail risk (Reported).
- L2s mostly inherit Ethereum's timeline. Starknet (59) leads, using STARK proofs, native AA, a mainnet Falcon-512 account and BLAKE2s OS hashes. Optimism has a 10-year ECDSA-EOA sunset plan to Jan 2036. Arbitrum has no official plan.
Scoreboard
Ranked by CoinGecko mcap (16:38 ET). Score bands: 🟢 ≥60, 🟡 35–59, 🔴 <35.
| # | Chain | Mcap (USD) | Score | Badge | Stage | Next milestone |
|---|---|---|---|---|---|---|
| 1 | Bitcoin (BTC) | $1,641.3B | 42 | 🟡 | 2: Spec drafts (BIP-360/361), no activation | Move a PQ-signature BIP and an activation proposal past Draft. Date unknown |
| 2 | Ethereum (ETH) | $301.2B | 65 | 🟢 | 3: Dated roadmap + PQ devnets | Glamsterdam mainnet (tentative Dec 2026, Reported), then the Jan 2027 reassessment, then Hegotá with EIP-8141 Frames (expected 2027) |
| 3 | Solana (SOL) | $64.4B | 37 | 🟡 | 1–2: Research + app-level vaults | SIMD-0579 Keccak-p1600 syscall (open PR). No dated PQ protocol milestone |
| 4 | TRON (TRX), extra L1 | $31.6B | 48 | 🟡 | 3: Testnet (Nile) | TIP-899 mainnet SR votes, prioritizing ML-DSA-44. "Year-end 2026" target (Reported) |
| 5 | Zcash (ZEC) | $19.9B | 68 | 🟢 | 4: Partial mainnet (quantum-recoverable notes) | Recovery Protocol spec (undated). Shielded Labs Epoch production PQ crypto by end-2027 (target) |
| 6 | Hyperliquid (HYPE) | $18.8B | 5 | 🔴 | 0: No public plan | None announced |
| 7 | Monero (XMR) | $9.9B | 31 | 🔴 | 1–2: Research; FCMP++ (forward secrecy) on stressnet | FCMP++/Carrot mainnet hard fork. No date |
| 8 | Sui (SUI) | $4.3B | 54 | 🟡 | 2–3: Dated plan, audits underway | PQ vaults on mainnet in 2026, ML-DSA accounts on testnet by end-2026, mainnet in Q1 2027 (targets) |
| 9 | Ethereum L2s (group) | $1.98B combined ARB+STRK+OP+ZK | 15–59 | 🟡/🔴 | Varies (see section) | Starknet Phase 2 tooling; OP scheme selection; most others follow L1 |
L2 group placement basis: the group is ranked by the combined mcap of ARB ($1.171B), STRK ($0.412B), OP ($0.274B) and ZK ($0.124B), which totals ≈$1.98B. Base has no token, so it contributes $0. Using the largest single token (ARB, $1.17B) gives the same rank: below SUI ($4.32B). Within the group, scores are Starknet 59, Optimism 35, zkSync 26, Base 21 and Arbitrum 15.
Extra L1 = TRON. It is #2 by stablecoin supply at $94.22B (DefiLlama, behind Ethereum's $150.77B), had 4,449,621 active accounts and 11.62M transactions on 2026-10-07 (Tronscan), and has an active PQ TIP with a live testnet.
Rubric (0–100). Applied identically to every chain.
Sub-score Max What earns points R: Research depth 15 Published threat models, papers, scheme comparisons, and core-team engagement S: Spec / proposal 15 Formal BIP/EIP/SIMD/TIP/ZIP text. More points for merged, accepted, or scheduled I: Implementation / testnet 15 Client code, devnets/testnets running PQ paths, audits M: Mainnet PQ capability today 20 What a user can do today on mainnet. Native PQ signatures score highest; app-level vaults and recoverability earn partial credit G: Migration plan for existing funds 20 Concrete path for already-exposed keys and legacy funds, such as sunset rules, recovery proofs, or key rotation C: Governance momentum / dated commitment 15 Official dated targets, scheduled forks, funding, and absence of blocking disputes Stages: 0 none · 1 research · 2 spec drafts · 3 testnet/devnet · 4 partial mainnet · 5 full PQ mainnet. Badges in tables: 🟢 done or High likelihood · 🟡 in progress or Med · 🔴 blocked, absent, or Low. Scores are my judgment applied to the sourced facts below (Speculative by nature). The sub-scores are shown so they can be re-weighted.
Bitcoin (BTC)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $1,641.27B (price $81,674) | Fact (CoinGecko 16:38 ET) | |
| Signature schemes | ECDSA secp256k1 (legacy/SegWit v0) and BIP-340 Schnorr (Taproot) | 🔴 | Fact |
| Quantum-exposed | P2PK outputs, reused addresses, and Taproot key-path outputs (the tweaked key is visible on-chain). Exposed supply: 6.26M BTC / 31.2% (Glassnode, Oct 8 2026); 6,900,573 BTC / 34.45% (Project Eleven, block 950,000); 4–10M BTC (Chaincode range) | 🔴 | Reported |
| Exchange exposure | Exchanges hold 1.79M exposed BTC. Binance is 83% exposed and Coinbase 10% | 🔴 | Reported (CoinDesk/Glassnode) |
| PoW | SHA-256. Grover gives at most a quadratic speedup, so this is not a direct break | 🟢 | Fact |
| Ops | Height 970,526; hashrate ≈979 EH/s (3-day, mempool.space) | Fact |
Readiness score: 42 / 100 🟡
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 13 | 10 | 5 | 3 | 7 | 4 |
The deep research and two merged BIP drafts drive the score. It is held down by having no PQ signature spec, no activation path, and only a nonstandard workaround on mainnet.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2024-12-18 | BIP-360 number assigned (then P2QRH; authors Hunter Beast, Ethan Heilman, Isabel Foxen Duke) | 🟢 | Fact |
| 2025-07-07 | BIP-360 v0.8.0 drops the key path and moves PQ signatures to future opcodes | 🟢 | Fact |
| 2025-09-17 | BIP-360 v0.10.0 is renamed P2TSH | 🟢 | Fact |
| 2026-02-11 | BIP-360 merged into bitcoin/bips as Draft (#1670), renamed P2MR (v0.11.0) | 🟢 | Fact |
| 2026-02-11 / 2026-04-14 | BIP-361 "Post Quantum Migration and Legacy Signature Sunset" (Lopp et al.) is assigned, then merged as Draft | 🟢 | Fact |
| 2026-03-31 | Google Quantum AI publishes ECDLP resource estimates for secp256k1 | 🟢 | Fact |
| 2026-06-18 / 2026-07-24 | BIP-360 v0.12.0 (depth-zero trees made anyone-can-spend) and v0.12.1 | 🟢 | Fact |
| 2026-07-21 | Galaxy Bitcoin Quantum Readiness Initiative offers up to $5M in milestone grants | 🟢 | Fact |
| 2026-07-23 | Bitcoin Security Consortium: nine institutions (BlackRock, Fidelity Digital Assets, Coinbase, Strategy, Block, Blockstream, etc.) pledge $15M over 3 years. It takes no protocol positions and is coordinated by Mike Schmidt (Brink) | 🟢 | Fact |
| 2026-07-28 | Independent BIP-360 regtest implementation in Bitcoin Core posted on Delving Bitcoin | 🟢 | Reported |
| 2026-08-03 | Latest BIP-360 edits merged (#2223) | 🟢 | Fact |
| 2026-08-26 | StarkWare QSB (Avihu Levy): first quantum-safe tx mined on mainnet with no soft fork. It is nonstandard, was submitted via MARA Slipstream, and took hours of GPU grinding | 🟢 | Fact (StarkWare); cost is Reported |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| BIP-360 P2MR (Pay-to-Merkle-Root) | Draft, consensus soft fork, merged | Med to eventual activation | 🟡 | It is the most mature output-type proposal, has a Core regtest implementation, and has support from investors such as Ben-Sasson ("should happen, and I believe it will", Reported). But it adds no PQ signature itself and has no activation mechanism or date |
| BIP-361 Legacy Signature Sunset | Draft. Phase A bans sends to vulnerable outputs 160,000 blocks (about 3 yrs) after activation. Phase B restricts ECDSA/Schnorr spends 2 yrs later | Low within 24 mo | 🔴 | It requires a not-yet-written PQ signature BIP, and freezing coins is the most contentious idea in Bitcoin governance (Speculative) |
| SHRINCS / OP_CHECKSHRINCS (Blockstream) | Research. The draft repo is not a numbered BIP. It has a 324-byte stateful signature path and a larger stateless fallback, and was demonstrated on Liquid via Simplicity | Low–Med | 🟡 | It is the leading hash-based candidate for the missing signature opcode, but has no BIP number |
| ML-DSA/SLH-DSA opcodes | No BIP. A third-party BTQ Technologies testnet v0.3.0 (Mar 2026) has ML-DSA opcodes | Low | 🔴 | It is a fork-chain experiment, not Core (Reported) |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | 2024–25: P2QRH evolves into P2TSH. 2026: P2MR merged, BIP-361 merged, consensus funding consortia formed | Fact |
| Now | P2MR is in Draft with regtest code. QSB is a costly opt-in hack for new coins only. Glassnode and Project Eleven are tracking exposure | Fact |
| Next 12–24 mo | Expect a PQ-signature BIP (SHRINCS-style or SLH-DSA) to be numbered, and activation-mechanism debate. Soft-fork activation within 24 months is unlikely | Speculative |
| Longer term | P2MR plus a PQ opcode soft fork, followed by BIP-361-style sunset debates over Satoshi-era P2PK coins | Speculative |
Risks and open questions
- About 1.9M BTC is structurally exposed (P2PK, early coins; Glassnode May 2026 put it at 1.92M) and cannot be protected by its owners if the keys are lost. Whether those coins get frozen is unresolved (Reported).
- Binance's 83% exposure rate means a single exchange's hygiene drives a large share of the operational exposure (Reported).
- Activation politics: there is no activation client or signaling plan, and the 2017-style dispute risk is untested for a freeze proposal (Speculative).
- Signature size and block weight: PQ signatures are 10–100x the size of Schnorr. The fee-market impact is unquantified on-chain (Unknown).
Ethereum (ETH)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $301.23B (price $2,466.78) | Fact | |
| Execution signatures | ECDSA secp256k1 (EOAs). Precompiles: ecrecover, BN254 pairings (used by ZK rollups), and BLS12-381 | 🔴 | Fact |
| Consensus | BLS12-381 aggregate signatures | 🔴 | Fact |
| Data | KZG commitments (blobs) | 🔴 | Fact |
| Quantum-exposed | Every EOA that has ever sent a transaction. Estimated 50–65% of supply, most defensibly 55–60% (arXiv 2606.14484, Jun 2026). Deloitte's 2021 figure of >65% is the root of most press numbers. EF estimates long-dormant ETH at ≈0.1% | 🔴 | Reported |
| Ops | 854,739 active validators; 43.7M ETH staked (35.78%) per validatorqueue.com | Reported (aggregator) |
Readiness score: 65 / 100 🟢
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 15 | 12 | 11 | 4 | 10 | 13 |
The score comes from an official dated target, a named fork sequence, multi-client PQ devnets and the AA rails (EIP-8141). It is held down because no PQ signature is native on mainnet. Smart-contract wallets can verify PQ signatures only at high gas cost.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2025-10-06 | pq-devnet-0 (lean consensus, hash-based leanSig/XMSS) | 🟢 | Fact (leanEthereum/pm) |
| 2026-01-20 | pq-devnet-1 | 🟢 | Fact |
| 2026-02 | Vitalik's PQ roadmap post (Feb 2026), referenced on pq.ethereum.org | 🟢 | Reported |
| 2026-02-27 | pq-devnet-2 | 🟢 | Fact |
| 2026-03-26 | pq-devnet-3 | 🟢 | Fact |
| 2026-06-27 | pq.ethereum.org updated. It lists a $20M zkEVM formal-verification effort and the ≈0.1% dormant-ETH estimate | 🟢 | Fact |
| 2026-08-19 | Strawmap update. I*: PQ key registry. J*: minimum-viable PQ (PQ heartbeat, leanDA, leanSPHINCS txs). L* (or K*): PQ attestations. M*: PQ aggregation and PQ blobs | 🟢 | Reported |
| 2026-09-07 | EF Protocol "Current and Emerging Priorities": L1 to be quantum-resistant by Dec 2029, planning for Q-day as early as 2030. The target is non-negotiable until the Jan 2027 reassessment | 🟢 | Fact |
| 2026-10-06 | Glamsterdam activates on Sepolia (13:53 UTC / 09:53 ET) | 🟢 | Fact (EF blog) |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| EIP-8141 Frame Transactions (native AA) | SFI'd as a Hegotá headliner. Expected in 2027 | High | 🟢 | EF designates it must-ship. It lets accounts swap ECDSA for PQ verification |
| EIP-7805 FOCIL | Hegotá headliner | High | 🟢 | Not PQ itself. It is protected because PQ milestones are sequenced behind it |
| EIP-8365 Disallow new 0x00 validators | CFI'd for Hegotá (ACDC #188), scope narrowed | Med | 🟡 | Hygiene step toward withdrawal-credential migration. CFI is not SFI |
| EIP-8151, EIP-8298 (account-related, Hegotá candidates) | Under discussion | Med | 🟡 | Their scope and final inclusion are not settled (Reported) |
| EIP-8051 ML-DSA precompile / EIP-8052 Falcon precompile | Draft | Med | 🟡 | Would make PQ verification gas-practical. Not yet scheduled for a fork |
| Strawmap I*/J*/L*/M* PQ forks | Planning artifacts, not EIPs | Med to hit Dec 2029 | 🟡 | The fork cadence it needs (about 7.2 months) has never been achieved historically (Speculative) |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | 2018-era research into hash-based signatures and STARKs. 2025–26 lean consensus and four PQ devnets | Fact |
| Now | Glamsterdam on testnets (mainnet tentatively Dec 2026; officially TBD). Hegotá scoping. pq-devnet-4 (proposer keys, recursive aggregation) was being specced, current status unverified | Fact / Unknown |
| Next 12–24 mo | Jan 2027 target reassessment; Hegotá (Frames + FOCIL) in 2027; PQ key registry (I*) spec work | Reported |
| Longer term | J* minimum-viable PQ fallback, then L* PQ attestations, then M* PQ aggregation and blobs. Goal: PQ across execution, consensus and data by Dec 2029 | Fact (target) |
Risks and open questions
- Fork-cadence risk: the Dec 2029 target needs roughly five forks in three years (Speculative).
- Vitalik warned that botched migrations cause losses. Rushing EOA migration could create phishing and loss events (Reported).
- PQ signature sizes vs. consensus bandwidth: leanMultisig/leanVM aggregation is unproven at mainnet scale (Speculative).
- Justin Drake's "bunker mode" (Oct 2026) argues AI could break ECDSA before quantum computers do and advises moving to never-exposed addresses. No practical attack has been shown (Reported).
- ZK rollups and bridges that rely on BN254/KZG precompiles inherit the L1 schedule (Fact).
Solana (SOL)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $64.36B (price $109.23) | Fact | |
| Signature schemes | Ed25519 for accounts and transactions. Validators sign votes with Ed25519 today. Alpenglow adds BLS vote signatures, a new quantum-vulnerable surface | 🔴 | Fact |
| Quantum-exposed | Every non-PDA address is an Ed25519 public key, so effectively all funded wallets are exposed from creation. PDAs have no private key | 🔴 | Fact |
| Ops | 671 current + 10 delinquent vote accounts (getVoteAccounts). getAgGenesisCert = null at 16:43 ET, meaning mainnet still runs TowerBFT and Alpenglow is not active | Fact |
Readiness score: 37 / 100 🟡
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 11 | 5 | 7 | 7 | 4 | 3 |
App-level vaults are live, and two clients have Falcon prototypes. There is no active PQ SIMD beyond a hash syscall, the migration plan is conditional ("if the threat becomes credible"), and there are no dates.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2024 (live for >2 yrs) | Blueshift Solana Winternitz Vault (hash-based one-time signatures, user-level), later cited by Google | 🟢 | Reported |
| 2025-12 | Project Eleven PQ testnet for Solana | 🟢 | Reported |
| 2026-02-01 | SIMD-0461 (Falcon verification syscall) PR opened | 🟢 | Fact |
| 2026-04-27 | solana.com "Quantum readiness": Anza and Firedancer independently chose Falcon and have initial implementations | 🟢 | Fact (post) / Reported (implementations) |
| 2026-07-08 | SIMD-0387 BLS pubkey registration live on mainnet (Alpenglow prerequisite). VAT (SIMD-0357) followed on 2026-07-22 | 🟢 | Reported (solana.com/upgrades) |
| 2026-07-27 | SIMD-0563 Keccak-p1600 syscall closed in favor of SIMD-0579 | 🟢 | Fact |
| 2026-09-01 | SIMD-0461 Falcon syscall closed without merge | 🔴 | Fact |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| SIMD-0579 Keccak-p1600 syscall | Open PR since 2026-07-09 | Med | 🟡 | A cheaper permutation helps hash-based and Falcon (SHAKE) verifiers in programs. It is generic infrastructure with no PQ mandate |
| Falcon verification syscall (SIMD-0461) | Closed 2026-09-01 | Low in the near term | 🔴 | Closed. Blueshift's solana-falcon512 and solana-hawk512 already run as programs without protocol changes |
| Jump Crypto migration design (PQ key + ZK proof of Ed25519 seed possession) | Research post | Med long term | 🟡 | A credible path for exposed wallets, but it is not a SIMD. Note: Jump cites "SIMD-0416" for the Falcon syscall, but GitHub PR #416 is a SIMD-0387 change. The Falcon syscall was PR #461 (discrepancy) |
| Alpenglow Votor (SIMD-0326) | Live on testnet/devnet. Mainnet date unknown | High to ship, but it adds BLS | 🔴 | It increases the classical-crypto surface in consensus |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | Winternitz vaults (user-level), Falcon prototypes | Reported |
| Now | Research. Hash-syscall SIMD in review. Alpenglow rollout | Fact |
| Next 12–24 mo | Per solana.com: PQ for new wallets "if the threat becomes credible," then migration. No dates | Fact (stated plan) |
| Longer term | Falcon-based accounts and some PQ consensus aggregation (aggregate lattice signatures are still research per Jump) | Reported |
Risks and open questions
- Address = public key means no "hash shield." Exposure is close to 100% of non-PDA balances (Fact by construction).
- BLS in Alpenglow will need its own PQ replacement later (Speculative).
- The roadmap is conditional on a threat trigger, so lead time depends on how quickly the trigger can be recognized (Speculative).
TRON (TRX), extra L1
Why TRON: #2 chain by stablecoin supply ($94.22B, DefiLlama, pulled today); 4,449,621 active accounts and 11.62M transactions on 2026-10-07 (Tronscan); has an active consensus-level PQ TIP.
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $31.61B (price $0.3327) | Fact | |
| Signature schemes | ECDSA secp256k1 for accounts and for the 27 Super Representatives' block signing | 🔴 | Fact |
| Quantum-exposed | Any address that has sent a transaction (pubkey recoverable from signature). This includes major USDT hot wallets | 🔴 | Fact (mechanism) / exposure % Unknown |
| Ops | 5,121 nodes; height 86,938,662; 2.26M USDT transfers on 2026-10-07; TVL $5.58B | Fact (Tronscan, DefiLlama) | |
| Usage (reported) | $2.08T Q2 2026 stablecoin volume | Reported (CoinLaw citing TRON Q2 report) |
Readiness score: 48 / 100 🟡
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 9 | 12 | 11 | 0 | 7 | 9 |
A detailed TIP and a live testnet drive the score. It is held down because nothing is on mainnet, the mainnet date has already slipped, and the audit plan is undetermined.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2026-04 | Justin Sun states a Q3 2026 mainnet target | 🟡 | Reported |
| 2026-06-30 | TIP-899 created (author Federico2014). FN-DSA-512 + ML-DSA-44 for transactions, SR block signing, and the network handshake; TVM precompiles 0x02000016–0x0200001a | 🟢 | Fact |
| 2026-07-02 | PQ enabled on Nile testnet (GreatVoyage-v4.8.2-PQ1, committee proposal 20628) | 🟢 | Reported |
| 2026-07-20 | Devs: prioritize ML-DSA for mainnet, Falcon waits for FIPS 206; third-party audit plan "not determined" | 🟢 | Fact (TIP thread) |
| 2026-08-11 | Phase 2 key-registry V2 design posted | 🟢 | Fact (TIP thread) |
| 2026-08-27 | Sun at Bitcoin Asia: target slips to year-end 2026 | 🟡 | Reported |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| TIP-899 Phase 1: ALLOW_ML_DSA_44 (#1001) | Draft. Needs a 27-SR committee vote; disabled by default | Med for mainnet by end-2026 | 🟡 | Strong founder push and a working Nile build. Undetermined audit, plus Nile gaps (no gas-free transfers, no BIP-39 recovery, no Ledger) |
| TIP-899: ALLOW_FN_DSA_512 (#1000) | Draft | Low by end-2026 | 🔴 | Devs said it waits for FIPS 206, which is not final |
| Phase 2: key registry (rotate ECDSA → PQ) | Design V2 (Aug 11) | Med within 24 mo | 🟡 | Required for existing funds. Design-only |
| Later phases: emergency SR channel, FORBID_ECDSA_SIGN, ZK recovery | Concepts in TIP discussion | Low within 24 mo | 🔴 | Unspecified |
| ML-DSA-65 instead of -44 (shemnon suggestion) | Comment | Low–Med | 🟡 | Security-margin debate is open |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | No PQ work before 2026 found | Unknown |
| Now | Nile testnet with both schemes; TIP-899 Draft | Fact |
| Next 12–24 mo | ML-DSA-44 mainnet vote (target year-end 2026), then the key registry | Reported |
| Longer term | ECDSA prohibition plus ZK recovery for exposed accounts | Reported (TIP discussion) |
Risks and open questions
- Throughput: reports say PQ signatures could cut TPS by up to 95% in testing (Reported, Coindoo). This has not been verified independently.
- Concentrated governance (27 SRs) makes activation fast but also concentrates the decision (Fact on structure).
- Some wallets may be able to pay but not replace keys under the current design (Reported).
- No audit commitment yet (Fact as of Jul 20).
Zcash (ZEC)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $19.89B (price $1,171.96) | Fact | |
| Signature / proof systems | Transparent: ECDSA secp256k1. Sapling: RedJubjub + Groth16 (BLS12-381). Orchard: RedPallas + Halo 2 (Pasta). Ironwood: quantum-recoverable notes (lead byte 0x03) | 🟡 | Fact |
| Quantum-exposed | Transparent pubkeys. Shielded privacy (ECDH note encryption, harvest-now-decrypt-later). Soundness (proof forgery means counterfeiting in shielded pools). Sapling and Orchard funds that are never migrated to Ironwood are unrecoverable under the recovery model | 🔴 | Fact (ZIP 2005) |
| Ops | Height 3,511,013. Zebra is the only full validator supporting NU6.3 (zcashd does not) | Fact |
Readiness score: 68 / 100 🟢
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 14 | 13 | 10 | 8 | 12 | 11 |
This is the only chain here with a consensus change on mainnet aimed at the quantum transition, plus a written migration model. It is held down because recoverability is not PQ security, the Recovery Protocol is unspecified, and Tachyon's Ragu stack is unaudited.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2026-02 | Polls back quantum recoverability: 90.5% ZCAP, 94.6% coinholders | 🟢 | Reported |
| 2026-05-22 | Tachyon testnet release candidate | 🟢 | Reported |
| 2026-05-29 / 06-02 / 06-03 | Orchard soundness bug (halo2_gadgets missing copy constraint, CVE-2026-54496) found by Taylor Hornby. Emergency soft fork disabled Orchard on Jun 2. NU6.2 re-enabled it with the fix on Jun 3 | 🟢 | Fact (ZF, GHSA) |
| 2026-07-28 14:07 UTC (10:07 ET) | NU6.3 "Ironwood" activates at height 3,428,143. New shielded value goes to the Ironwood pool with quantum-recoverable notes (ZIP 2005); Orchard becomes spend-only | 🟢 | Fact |
| 2026-09-15 | ZIP 259 (NU7 deployment) published: 25s blocks, v4 txs disallowed (Sprout becomes unspendable). No quantum content | 🟢 | Fact |
| 2026-10-01 | Shielded Labs announces Epoch (Haböck, Edwards, Bagad): formally verified PQ crypto, production-ready by end-2027 (target) | 🟢 | Fact (forum) |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| ZIP 2005 Ironwood Quantum Recoverability | Status: Proposed. Deployed via NU6.3 | High (already live) | 🟢 | Activated on mainnet |
| Recovery Protocol (spend Ironwood notes after ECC is disabled) | Not specified or deployed | Med within 24 mo | 🟡 | Explicitly future work in ZIP 2005 |
| Three-step plan: recoverability → ML-KEM with Tachyon → fully PQ pool | Step 1 done; Step 2 on testnet | Med | 🟡 | Development is spread across ZODL, Tachyon, Valar, ZF and Shielded Labs. Ragu is unaudited |
| Shielded Labs Epoch | Phase 1 research | Med for the end-2027 target | 🟡 | Strong team. Scope "may be narrower than Tachyon" |
| NU7 (ZIP 259) | Mainnet height "TBD (to be set on Oct 20)" | High to ship; not PQ | 🟢 | Relevant only because it ends Sprout |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | Sprout bug (2018), Orchard bug (2026), quantum-recoverability polls | Fact |
| Now | Ironwood live. Users need to migrate Sapling/Orchard funds into Ironwood to be recoverable | Fact |
| Next 12–24 mo | NU7 (non-PQ); Recovery Protocol spec; Tachyon with ML-KEM note encryption; Epoch design proposal | Reported |
| Longer term | Fully PQ shielded pool and formally verified PQ proving system | Reported (plan) |
Risks and open questions
- Two critical soundness bugs in shielded pools (2018, 2026) show implementation risk is at least as large as quantum risk (Fact).
- There is now a single full-validator implementation (Zebra) for NU6.3+ (Fact).
- Migration burden: unmigrated Sapling/Orchard value is unrecoverable in the recovery model, and the share already migrated is Unknown.
- Harvest-now-decrypt-later: historical shielded transactions remain exposed to future decryption until ML-KEM ships (Fact by design).
Hyperliquid (HYPE)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $18.77B (price $84.37) | Fact | |
| Signature schemes | HyperCore actions: EIP-712 secp256k1 ECDSA. HyperEVM: ECDSA. HyperBFT validator signatures: undocumented (reverse-engineered docs suggest secp256k1) | 🔴 | Fact / Unknown |
| Quantum-exposed | Every account that has signed an action; bridge validator keys | 🔴 | Speculative (mechanism) |
| Ops | 35 validators, 27 active, 29 not jailed (Hyperliquid info API) | Fact |
Readiness score: 5 / 100 🔴
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 2 | 0 | 0 | 3 | 0 | 0 |
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2026-06 | qLABS qVAULT: third-party Falcon (FN-DSA) vault on HyperEVM (early access, then commercial availability). qLABS is a vendor, so treat its claims as marketing | 🟡 | Reported |
| No official Hyperliquid or Hyper Foundation PQ statement found (X search of @HyperliquidX, @chameleon_jeff, @hyperfnd returned 0 results) | 🔴 | Fact (search result) |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| None public | 🔴 | No HIP or roadmap item found |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past / Now | ECDSA everywhere; one third-party vault | Fact / Reported |
| Next 12–24 mo | Unknown | Unknown |
| Longer term | Could follow the EVM AA patterns via HyperEVM | Speculative |
Risks and open questions
- Closed-source core plus an undocumented consensus signature scheme makes external assessment impossible (Fact).
- The small validator set (27 active) controls the bridge. Quantum or AI key recovery against those keys would be systemic (Speculative).
Monero (XMR)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $9.90B (price $525.99) | Fact | |
| Signature / proof systems | Ed25519-family keys; CLSAG ring signatures; Bulletproofs+; ECDH one-time addresses; key images | 🔴 | Fact |
| Quantum-exposed | Privacy (retroactive de-anonymization through ECDH), soundness (inflation via forged proofs), spend authority | 🔴 | Fact (MRL issues #151/#159) |
| PoW | RandomX (not ECC-based) | 🟢 | Fact |
| Ops | Height 3,779,811; hashrate ≈6.34 GH/s; hard-fork version 16 (xmrchain.net) | Fact |
Readiness score: 31 / 100 🔴
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 11 | 6 | 6 | 0 | 5 | 3 |
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2025-11-27 | jeffro256 PQ "turnstile" gist: a migration path for Carrot-derived enotes only, not legacy RingCT | 🟢 | Reported |
| 2026-04 to 2026-06 | Jamtis-PQ draft (tevador, CSIDH-1024 encryption, about 400-character addresses) and MRL discussion updates | 🟢 | Reported |
| 2026-09-25 | FCMP++ & Carrot beta stressnet v3.0 (v0.19.0.0-beta.3.0) released | 🟢 | Fact |
| 2026-10-05 | Stressnet fork at block 3,102,800 | 🟢 | Reported |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| FCMP++ + Carrot hard fork | Stressnet. Integration audit CCS !663. No mainnet date | High to ship eventually (date unknown) | 🟡 | Gives forward secrecy for privacy. Spend authorization stays Ed25519, so it is not PQ |
| Jamtis-PQ addressing | Draft | Low–Med within 24 mo | 🟡 | Large addresses; MRL still debating |
| PQ turnstile (Carrot enotes) | Gist | Low within 24 mo | 🔴 | Excludes legacy RingCT outputs |
| PQ signatures (MRL #159) / PQ encryption (MRL #151) | Open research issues | Low | 🔴 | No candidate construction chosen |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | MRL research issues opened | Fact |
| Now | FCMP++/Carrot stressnet | Fact |
| Next 12–24 mo | FCMP++ mainnet (no date); Jamtis-PQ decision | Speculative |
| Longer term | PQ turnstile and PQ spend authority | Reported (research) |
Risks and open questions
- Privacy coins face harvest-now-decrypt-later on all historical transactions. Forward secrecy only protects new Carrot outputs (Fact by design).
- Inflation detection under a quantum adversary is unsolved for legacy outputs (Reported, MRL).
- The FCMP++ timeline has repeatedly been "when ready" with no date (Fact).
Sui (SUI)
Snapshot
| Item | Detail | Badge | Label |
|---|---|---|---|
| Mcap | $4.32B (price $1.05) | Fact | |
| Signature schemes | Users: Ed25519, secp256k1, secp256r1/passkey, multisig, zkLogin. Validators: BLS12-381 (not re-verified this session) | 🔴 | Fact (users) / Unknown (validators) |
| Quantum-exposed | Addresses are hashes, but the public key is exposed on first use. zkLogin relies on a pairing-based SNARK | 🔴 | Fact (Sui blog) |
| Ops | 127 active validators, epoch 1274 (Sui GraphQL) | Fact |
Readiness score: 54 / 100 🟡
| R | S | I | M | G | C |
|---|---|---|---|---|---|
| 12 | 10 | 7 | 3 | 11 | 11 |
The score is driven by the chosen NIST schemes, dated targets and an in-place key-rotation path. It is held down because nothing PQ is on mainnet yet.
Completed milestones
| Date | Milestone | Badge | Label |
|---|---|---|---|
| 2025 | Mysten-affiliated paper "Post-Quantum Readiness in EdDSA Chains" (eprint 2025/1368): a zk proof of seed possession for EdDSA. Deployment deferred | 🟢 | Fact (paper) / Reported (deferral) |
| 2026-07 | Sui blog: an AI model halved HAWK key strength in about 60h, which informed the scheme choice | 🟡 | Reported |
| about 2026-08-06 | "Making Sui Quantum Ready" and "From the cryptographer's desk": ML-DSA-65 native accounts and SLH-DSA-SHA2-128s Move vaults. Address aliases let accounts rotate keys without moving funds. ML-DSA-65 is also supported in multisig. Audits underway | 🟢 | Fact (blog) |
Active proposals
| Proposal | Status | Likelihood | Badge | Reason |
|---|---|---|---|---|
| SLH-DSA vaults (Move) | Targeted for mainnet in 2026 | Med for 2026 | 🟡 | Contract-level, so lower protocol risk, but less than 3 months remain |
| ML-DSA-65 native accounts | Testnet by end-2026, mainnet Q1 2027 | Med–High | 🟡 | Single foundation-led governance; audits underway |
| Address-alias rotation for existing accounts | Described in the blog | Med | 🟡 | Mainnet status of aliases not independently verified (Unknown) |
| PQ validator signatures / zkLogin PQ | Not announced | Low | 🔴 | No public plan |
Roadmap
| Horizon | What | Label |
|---|---|---|
| Past | EdDSA seed-proof research | Fact |
| Now | Audits; vault and account implementations | Reported |
| Next 12–24 mo | Vaults on mainnet (2026), ML-DSA on testnet (end-2026), on mainnet (Q1 2027) | Fact (targets) |
| Longer term | Consensus and zkLogin migration | Unknown |
Risks and open questions
- Validator BLS and zkLogin are not covered by the announced plan (Fact by omission).
- ML-DSA-65 signatures (3,309 bytes per FIPS 204) increase transaction size and storage (Fact on size; throughput impact Unknown).
Ethereum L2s (grouped)
Group mcap: combined ARB+STRK+OP+ZK ≈ $1.98B. The largest token is ARB at $1.171B. Base has no token. Either basis ranks the group below SUI. Shared dependency: all five settle to Ethereum L1. Their bridges, blob data (KZG) and any L1 ECDSA/BLS signer inherit Ethereum's Dec 2029 timeline (Fact).
Arbitrum (ARB, $1.171B): score 15 🔴
| Item | Detail | Badge | Label |
|---|---|---|---|
| Signatures | ECDSA EOAs; ECDSA sequencer and batch poster | 🔴 | Fact |
| Sub-scores | R 5 · S 1 · I 3 · M 4 · G 2 · C 0 | ||
| Done | 2026-06-30 community forum technical overview of PQ risk in Arbitrum contracts. Stylus ML-DSA-65 verifier PoC at about 374,000 gas (unaudited) | 🟡 | Reported |
| Research | Offchain Labs researchers' eprint 2026/1660 "Transient Quantum Resistance" (on Ethereum BLS) | 🟢 | Fact (paper) |
| Proposals | No AIP or official roadmap found. Likelihood of an official plan within 12 mo: Low–Med | 🔴 | Fact (absence) / Speculative |
| Roadmap | Now: PoCs only. Next 12–24 mo: Unknown. Longer term: follow the L1 AA path (Speculative) | ||
| Risks | No dated commitment; Stylus contracts need reactivation after 365 days or ArbOS upgrades (Reported) |
Base (no token): score 21 🔴
| Item | Detail | Badge | Label |
|---|---|---|---|
| Signatures | ECDSA EOAs; ECDSA sequencer (OP Stack lineage) | 🔴 | Fact |
| Sub-scores | R 5 · S 3 · I 4 · M 3 · G 3 · C 3 | ||
| Done | 2026-07-23 Coinbase blog: Base inherits Ethereum's PQ roadmap and a Base-specific plan is to come. PQ-CoreKMS (custody, not Base) is targeted within a year | 🟢 | Fact |
| Done | 2026-09-30 Cobalt mainnet: validity transactions, B20, dynamic upgrades, TEE registration. No PQ feature in the official overview | 🟢 | Fact |
| Proposals | EIP-8130 native AA (pluggable verifiers) is documented for Base's "vibenet" dev network. Inclusion in Cobalt mainnet is unverified. Likelihood within 24 mo: Med | 🟡 | Reported |
| Third party | PQ1 hardware wallet (FreedomFactory) USDC transfer on Base on 2026-09-21 | 🟡 | Reported |
| Roadmap | Next 12–24 mo: concrete Base plan (undated). Longer term: inherit L1 | Reported | |
| Risks | Centralized sequencer key, plus TEE attestation chains that are themselves ECDSA-based (Speculative) |
Optimism / OP Stack (OP, $0.274B): score 35 🟡
| Item | Detail | Badge | Label |
|---|---|---|---|
| Signatures | ECDSA EOAs; ECDSA sequencer and batcher | 🔴 | Fact |
| Sub-scores | R 7 · S 5 · I 3 · M 3 · G 9 · C 8 | ||
| Done | 2026-01-14 Karl Floersch, "A Post-Quantum Roadmap for the Superchain": deprecate ECDSA EOA transactions by Jan 2036 (subject to governance) through EIP-7702 delegation to PQ smart accounts; dual ECDSA/PQ period; sequencer and batcher to migrate; scheme undecided | 🟢 | Fact |
| Done | 2026-02-27 OP 2026 roadmap aligned with Ethereum's strawmap | 🟢 | Reported |
| Proposals | Scheme selection and the PQ smart-account standard: not yet specified. Likelihood within 24 mo: Med | 🟡 | Speculative |
| Risks | The 10-year horizon is long relative to Google/EF Q-day planning (2030) (Speculative) |
zkSync (ZK, $0.124B): score 26 🔴
| Item | Detail | Badge | Label |
|---|---|---|---|
| Signatures | Native AA (accounts can define custom verification); default ECDSA | 🟡 | Fact |
| Sub-scores | R 6 · S 3 · I 6 · M 6 · G 3 · C 2 | ||
| Done | Airbender STARK/FRI prover (hash-based, PQ-friendly). The final on-chain proof is an FFLONK SNARK over BN254/KZG, which is not PQ | 🟡 | Fact (zkSync docs, L2BEAT) |
| Claim | X post 2026-01-24 says the prover is "100% PQ-proof". True for the inner STARK, not the L1 wrapper | 🟡 | Reported |
| Proposals | None found for replacing the wrapper. Likelihood within 24 mo: Low–Med | 🔴 | Unknown |
| Risks | Proof forgery against the BN254 wrapper means invalid state could be finalized on L1 (Fact by construction) |
Starknet (STRK, $0.412B): score 59 🟡
| Item | Detail | Badge | Label |
|---|---|---|---|
| Signatures | Native AA. Default Stark-curve ECDSA (vulnerable). STARK proofs verified on L1 with hash-based verifiers | 🟡 | Fact |
| Sub-scores | R 13 · S 9 · I 10 · M 10 · G 8 · C 9 | ||
| Done | 2026-06-30 StarkWare 3-phase PQ roadmap. Phase 1: BLAKE2s replaces Pedersen. Phase 2: legacy-storage migration tooling. Phase 3: depends on Ethereum (bridge secp syscalls, KZG blobs) | 🟢 | Fact |
| Done | 2026-07-22 OpenZeppelin Falcon-512 account executes a live mainnet transfer. An S2morrow Falcon account also exists | 🟢 | Reported |
| Done | v0.14.3: BLAKE2s for OS program/config hashes on mainnet (migration register updated 2026-08-19). Trie and address-derivation changes not yet live | 🟢 | Fact |
| Proposals | Phase 2 tooling (research). Likelihood within 24 mo: Med. Ben-Sasson has floated Starknet becoming an L1 with a 2027 PQ target | 🟡 | Fact / Reported (L1 idea, Speculative outcome) |
| Risks | Phase 3 is gated on Ethereum. Default accounts remain ECDSA until users opt in (Fact) |
Cross-chain takeaways
- Hash-based is winning at the base layer, lattice at the account layer. ETH lean consensus uses XMSS/leanSig, BTC's leading candidate is SHRINCS/SLH-DSA, and Sui vaults use SLH-DSA. Accounts on Sui, TRON, Solana prototypes and Starknet use ML-DSA or Falcon (Fact). The pending FIPS 206 (Falcon) is a gating item for TRON's FN-DSA and some Solana designs (Fact).
- Account abstraction is the migration rail. Chains with native AA or key rotation (Starknet, zkSync, Sui aliases, ETH via EIP-8141/7702, TRON's key registry) can move users without moving funds. Bitcoin and Monero cannot, so they need new output types and turnstiles (Fact by design).
- Exposure measurement is diverging. BTC estimates range from 31.2% (Glassnode) to 34.45% (Project Eleven) and 20–50% (Chaincode). ETH estimates of 50–65% trace back to a 2021 Deloitte figure. Treat any single "% exposed" number as methodology-dependent (Reported).
- Dated commitments now exist in four places: ETH (Dec 2029), Sui (Q1 2027), TRON (year-end 2026, already slipped once), and OP (Jan 2036). Zcash has a dated end-2027 crypto target from one org. Bitcoin, Solana, Monero, Hyperliquid, Arbitrum and zkSync have none (Fact).
- New classical surfaces keep being added. Solana's Alpenglow BLS, zkSync's BN254 wrapper, Ethereum KZG blobs and Sui's zkLogin SNARK all add pairing-based dependencies that will need their own migration (Fact).
- Implementation bugs and AI cryptanalysis compete with quantum as the near-term risk. Examples: the Zcash Orchard bug, AI weakening HAWK, and Drake's "bunker mode" warning (Reported).
Timeline of expected milestones
| When | Chain | Milestone | Badge | Label |
|---|---|---|---|---|
| 2026-10-20 | ZEC | NU7 mainnet activation height to be set (non-PQ; ends Sprout) | 🟡 | Fact (ZIP 259 text) |
| Late Oct 2026 | ETH | Glamsterdam on Hoodi | 🟡 | Reported (tentative) |
| Dec 2026 | ETH | Glamsterdam mainnet (official schedule says TBD) | 🟡 | Reported (tentative) |
| By end-2026 | SUI | SLH-DSA vaults on mainnet; ML-DSA-65 accounts on testnet | 🟡 | Fact (target) |
| By end-2026 | TRX | TIP-899 PQ mainnet (ML-DSA-44 first) | 🟡 | Reported (target; slipped from Q3) |
| Jan 2027 | ETH | EF reassessment of the Dec 2029 PQ target | 🟡 | Fact |
| Q1 2027 | SUI | ML-DSA-65 accounts on mainnet | 🟡 | Fact (target) |
| 2027 | ETH | Hegotá: EIP-8141 Frame Transactions + FOCIL | 🟡 | Reported (expected) |
| 2027 | STRK | Floated PQ L1 target | 🔴 | Speculative |
| End-2027 | ZEC | Shielded Labs Epoch production-ready PQ crypto | 🟡 | Fact (target) |
| Undated | BTC | PQ-signature BIP; BIP-360 activation; BIP-361 Phase A (+160,000 blocks after activation) | 🔴 | Unknown |
| Undated | XMR | FCMP++/Carrot mainnet | 🟡 | Unknown |
| Undated | SOL | PQ for new wallets "if the threat becomes credible" | 🔴 | Unknown |
| Dec 2029 | ETH | L1 quantum-resistant across execution, consensus and data | 🟡 | Fact (target) |
| End-2030 / end-2031 | US federal (context) | EO 14412: PQ key establishment / signatures across federal systems | 🟡 | Reported (via Sui blog) |
| Jan 2036 | OP | ECDSA EOA transactions deprecated (subject to governance) | 🟡 | Fact (target) |
WHAT COULD I BE WRONG ABOUT?
- Scores are judgment calls. Zcash outranks Ethereum only because shipped mainnet changes are weighted at 20+20 points. Weighting dated commitments more heavily would flip them. The sub-scores are shown so they can be re-weighted.
- Timelines from founders slip. TRON already moved from Q3 to year-end, and Sui's "2026" vault target has under 3 months left. Glamsterdam's December date is tentative, and the official schedule says TBD.
- Exposure figures are methodology-driven. The Glassnode 31.2%, Project Eleven 34.45% and ETH 55–60% figures all count visible pubkeys, not economically attackable coins. Project Eleven's filtered "attractive" set is only 351,654 BTC (Reported).
- Threat timing could move either way. Google's <500k-physical-qubit estimate and ECDSA.fail's 793-logical-qubit point-addition circuit are resource estimates, not demonstrations. ECDSA.fail's figure is per point-addition, not a full attack. AI-cryptanalysis warnings (Drake) are unproven.
- I may have missed non-public or non-English work, especially for Hyperliquid (closed source), Arbitrum (no official plan found) and Solana client repositories.
- Some items are unverified. These include the Base EIP-8130 mainnet status, the Sui validator signature scheme, the Sui address-alias mainnet status, the pq-devnet-4 status, the HyperBFT signature scheme, and the Nile build and proposal numbers (from press).
- The extra-L1 choice is debatable. BNB ($97.5B) and XRP ($86.8B) are larger by mcap. TRON was picked on usage (stablecoin settlement) plus active PQ work. Using pure mcap would favor BNB.
Sources / technical notes
Market and on-chain data (pulled 2026-10-08, 16:30–16:43 ET)
- CoinGecko simple price API: https://api.coingecko.com/api/v3/simple/price
- mempool.space (BTC height, hashrate): https://mempool.space/
- validatorqueue.com (ETH validators and staked ETH): https://www.validatorqueue.com/
- Solana JSON-RPC (getVoteAccounts, getAgGenesisCert): https://api.mainnet-beta.solana.com
- Hyperliquid info API (validatorSummaries): https://api.hyperliquid.xyz/info
- xmrchain.net (XMR height, hashrate): https://xmrchain.net/
- Tronscan (TRON accounts, txs, nodes): https://tronscan.org/
- DefiLlama stablecoins by chain: https://defillama.com/stablecoins/chains
Threat baseline and standards
- Google Quantum AI blog: https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/
- Google whitepaper (arXiv 2603.28846): https://arxiv.org/abs/2603.28846
- IACR eprint 2026/625: https://eprint.iacr.org/2026/625
- ECDSA.fail (arXiv 2609.09582): https://arxiv.org/abs/2609.09582
- NIST FIPS 203: https://csrc.nist.gov/pubs/fips/203/final
- NIST FIPS 204: https://csrc.nist.gov/pubs/fips/204/final
- NIST FIPS 205: https://csrc.nist.gov/pubs/fips/205/final
- Drake "bunker mode" (CoinDesk): https://www.coindesk.com/tech/2026/10/08/bitcoin-and-ether-holders-urged-to-prepare-bunker-mode-against-possible-ai-attacks
- Drake "bunker mode" (The Block): https://www.theblock.co/news/ecosystems/2026-10-07-ethereum-researcher-justin-drake-bunker-mode-planning-private-key-recovery-risk-417954
Bitcoin
- BIP-360: https://github.com/bitcoin/bips/blob/master/bip-0360.mediawiki
- BIP-360 merge PR: https://github.com/bitcoin/bips/pull/1670
- Latest BIP-360 edits PR: https://github.com/bitcoin/bips/pull/2223
- BIP-361: https://github.com/bitcoin/bips/blob/master/bip-0361.mediawiki
- SHRINCS (Blockstream): https://blog.blockstream.com/shrincs-324-byte-stateful-post-quantum-signatures-with-static-backups/
- OP_CHECKSHRINCS (Blockstream): https://blog.blockstream.com/op_checkshrincs-a-hash-based-signature-opcode-for-post-quantum-bitcoin/
- SHRINCS draft spec: https://github.com/SHRINCS/shrincs-bip/blob/main/SHRINCS.md
- StarkWare QSB: https://starkware.co/blog/the-first-quantum-safe-bitcoin-transaction-has-been-mined/
- Glassnode exposure (CoinDesk, Oct 8 2026): https://www.coindesk.com/markets/2026/10/08/over-6-million-bitcoin-sit-behind-exposed-public-keys-as-ai-warnings-mount
- Project Eleven at block 950,000 (Bitcoin Magazine): https://bitcoinmagazine.com/print/the-quantum-issue-bitcoin-quantum-exposure-at-block-950000
- Galaxy initiative: https://www.galaxy.com/newsroom/galaxy-launches-bitcoin-quantum-readiness-initiative
- Bitcoin Security Consortium (Strategy press release): https://www.strategy.com/press/leading-financial-institutions-bitcoin-companies-launch-the-bitcoin-security-consortium_07-23-2026
- Bitcoin Security Consortium (CoinDesk): https://www.coindesk.com/business/2026/07/23/blackrock-coinbase-strategy-in-group-pledging-usd15-million-to-prepare-bitcoin-for-quantum-threats
Ethereum
- EF Protocol priorities (Sep 7 2026): https://blog.ethereum.org/2026/09/07/protocol-priorities
- Glamsterdam testnet announcement: https://blog.ethereum.org/2026/09/17/glamsterdam-testnet-announcement
- pq.ethereum.org: https://pq.ethereum.org/
- Strawmap: https://strawmap.org/
- leanEthereum pm (devnets): https://github.com/leanEthereum/pm
- leanSpec: https://github.com/leanEthereum/leanSpec
- EIP-8141: https://eips.ethereum.org/EIPS/eip-8141
- EIP-7805: https://eips.ethereum.org/EIPS/eip-7805
- EIP-8365: https://eips.ethereum.org/EIPS/eip-8365
- EIP-8051: https://eips.ethereum.org/EIPS/eip-8051
- EIP-8052: https://eips.ethereum.org/EIPS/eip-8052
- ETH exposure (arXiv 2606.14484): https://arxiv.org/abs/2606.14484
- The Block on the 2029 target: https://www.theblock.co/news/ecosystems/2026-09-08-ethereum-foundation-quantum-resistance-2029-413716
Solana
- Solana quantum readiness (Apr 27 2026): https://solana.com/news/quantum-readiness
- Jump Crypto migration paths: https://jumpcrypto.com/resources/quantum-migration-paths-for-solana
- Blueshift Winternitz vault: https://github.com/blueshift-gg/solana-winternitz-vault/
- SIMD-0461 PR: https://github.com/solana-foundation/solana-improvement-documents/pull/461
- SIMD-0563 PR: https://github.com/solana-foundation/solana-improvement-documents/pull/563
- SIMD-0579 PR: https://github.com/solana-foundation/solana-improvement-documents/pull/579
- BLS pubkey and VAT: https://solana.com/upgrades/bls-pubkey-vat
- Alpenglow: https://solana.com/upgrades/alpenglow
TRON
- TIP-899: https://github.com/tronprotocol/tips/issues/899
- Sun year-end target: https://www.livebitcoinnews.com/tron-targets-quantum-resistant-network-upgrade-by-year-end/
- Key-replacement limitation: https://cryptonews.net/news/altcoins/33441512/
- TPS impact report: https://coindoo.com/tron-quantum-signatures-cut-tps/
Zcash
- ZIP 2005: https://zips.z.cash/zip-2005
- ZIP 258: https://zips.z.cash/zip-0258
- ZIP 259: https://zips.z.cash/zip-0259
- Ironwood Book on quantum recoverability: https://zcash.github.io/ironwood/concepts/quantum-recoverability.html
- Epoch announcement: https://forum.zcashcommunity.com/t/epoch-future-proof-cryptography-for-zcash/57955
- Orchard bug (ZF): https://zfnd.org/zebra-4-5-3-and-5-0-0-emergency-soft-fork-and-nu6-2-activation/
- Orchard bug advisory: https://github.com/advisories/GHSA-ww9q-8r59-xv46
Hyperliquid
- qVAULT commercial availability: https://www.newsfilecorp.com/release/301993/01-Quantum-and-qLABS-Announce-qVAULT-Commercial-Availability
Monero
- Stressnet v3.0: https://monero.observer/fcmp++-carrot-beta-stressnet-v3.0-released/
- MRL #151: https://github.com/monero-project/research-lab/issues/151
- MRL #159: https://github.com/monero-project/research-lab/issues/159
- Jamtis (tevador): https://gist.github.com/tevador/639d083c994c1ef9401832c08e2b7832
- CCS !663: https://repo.getmonero.org/monero-project/ccs-proposals/-/merge_requests/663
Sui
- Making Sui Quantum Ready: https://www.sui.io/blog/making-sui-quantum-ready
- Sui's post-quantum signature schemes: https://www.sui.io/blog/suis-post-quantum-signature-schemes
- eprint 2025/1368: https://eprint.iacr.org/2025/1368
L2s
- Arbitrum forum PQ overview: https://forum.arbitrum.foundation/t/post-quantum-cryptography-risk-in-arbitrum-smart-contracts-a-technical-overview/31027
- Stylus ML-DSA-65 verifier: https://doc.quantum.systems/smart-account/stylus-verifier
- eprint 2026/1660: https://eprint.iacr.org/2026/1660
- Coinbase PQ blog: https://www.coinbase.com/blog/what-coinbase-is-doing-to-prepare-for-post-quantum-cryptography
- Base Cobalt overview: https://docs.base.org/upgrades/cobalt/overview
- EIP-8130: https://eips.ethereum.org/EIPS/eip-8130
- Optimism PQ roadmap: https://optimism.io/blog/a-post-quantum-roadmap-for-the-superchain
- zkSync Airbender: https://docs.zksync.io/zk-stack/components/zksync-airbender
- L2BEAT Airbender: https://l2beat.com/zk-catalog/airbender
- StarkWare Starknet PQ roadmap: https://starkware.co/blog/the-architecture-advantage-starknets-quantum-readiness-roadmap/
- Starknet migration register: https://quantum.starkware.co/migration-register
- OpenZeppelin Cairo PQ verifiers: https://github.com/OpenZeppelin/cairo-pq-verifiers
- Starknet blog on quantum resistance: https://www.starknet.io/blog/quantum-resistance/
Technical notes
- CoinGecko
last_updated_at= 1791491818. Box clock at pull: 16:38:39 EDT. - Solana
getAgGenesisCertreturnednullat 16:43 ET, meaning mainnet is on TowerBFT. - Sui stats came from GraphQL (JSON-RPC is deprecated).
- The ETH validator count came from an aggregator because beaconcha.in requires an API key.
- Blockchair confirms Zcash block 3,428,143 at 14:07 UTC (10:07 ET) on 2026-07-28.