Back to News
quantum-computing

How Blockchains are Preparing for Quantum Computing - Circle Internet

Google News – Quantum Computing
Loading...
8 min read
0 likes
⚡ Quantum Brief
Experts warn quantum computers could break blockchain security by 2030, threatening elliptic curve and RSA-based cryptography via Shor’s algorithm, though SHA256 and AES remain secure. US and EU regulators mandate post-quantum cryptography for critical infrastructure by 2030, pushing blockchains to upgrade all stack layers, with TLS 1.3 already supporting hybrid algorithms like X25519MLKEM768. Ethereum plans XMSS multi-signatures with Poseidon2 for validator consensus, but transaction signatures face challenges due to state maintenance requirements in HSMs and cold storage. Post-quantum migration requires larger signatures (e.g., 2,420-byte ML-DSA), with Ethereum eyeing 666-byte Falcon and Aptos proposing 7,856-byte SLH-DSA, complicating HSM and wallet compatibility. Zero-knowledge proofs must shift from Groth16/Halo2 to quantum-resistant STARKs or SNARGs, while Circle prioritizes privacy-first transitions to mitigate "harvest-now-decrypt-later" risks.
AI Audio Summary
0:00 / 0:00
Click to play
ChatGPT Image Nov 30, 2025, 05_45_25 PM.png
Quantum News · Media Library

Connect with financial institutions globally for real-time settlement Power liquid financial markets with regulated stablecoins Infrastructure, liquidity, and connectivity to lead in the stablecoin era We explain how blockchains are preparing for the shift to quantum computing. Read our research to see which blockchain layers are vulnerable and more. Some experts estimate that quantum computers may be powerful enough to threaten blockchain security by 2030. Any cryptographic protocol that relies on elliptic curves or RSA is vulnerable to Shor’s algorithm. Hash functions (SHA256, SHA3) and symmetric encryption (AES) are expected to remain secure. US and EU regulators require critical infrastructure and national security systems to switch to post-quantum algorithms by 2030. Blockchain designers and Web3 developers must upgrade every layer of their technology stack. TLS 1.3 already supports post-quantum algorithms and major providers like Google and AWS are quietly migrating their services. The hybrid classic/post-quantum algorithm X25519MLKEM768 appears to be the industry winner (the ML-KEM portion of the protocol is approved by NIST). Developers can secure their connections by upgrading their TLS certificates and storing larger 1,216 byte public keys. Proof-of-Stake blockchains will need to upgrade how validators sign proposals and votes during consensus.

The Ethereum Foundation roadmap plans to use XMSS multi-signatures with the Poseidon2 hash function; there is now a reference implementation in Rust. Blockchains that rely on multi-party computation or zero-knowledge proofs will need to switch to post-quantum alternatives. Note: It is unlikely blockchains will choose XMSS for transaction signatures because XMSS requires signers to maintain state. While validator nodes can maintain state and use complex algorithms to achieve shorter signatures, this is not true for externally owned accounts, especially in Hardware Security Modules (HSM) and cold storage. Blockchains will need to migrate from short transaction signatures like 65-byte ECDSA (Bitcoin, Ethereum) or 64-byte Ed25519 (Solana, Stellar) to larger post-quantum signatures. There is no industry consensus yet and many post-quantum options. Developers who want HSM support right away may consider the 2,420-byte NIST ML-DSA. Ethereum is looking at 666-byte Falcon, while Aptos recently proposed 7,856-byte SLH-DSA-SHA2-128s for transaction signatures.  Cryptographers are experimenting with optimizations like using NIST ML-DSA with the BLAKE3 hash function. Blockchain designers will need to take into account HSM wallets and multi-signatures. Post-quantum HSMs are beginning to appear on the market. Cloud providers like AWS and Google have created post-quantum software KMS services, and cloud HSMs will eventually follow. Blockchain specific HSMs won’t appear until there is sufficient demand. Blockchain designers should publish their specs soon, and consider the trade-off between choosing a less optimal algorithm vs leaving crypto-holders without an HSM option on Q-Day. Most institutional grade crypto-holders prefer to secure their keys using threshold signatures and general MPC protocols. All these currently rely on elliptic curves and will need to be replaced. Transaction signature algorithms should be chosen with threshold signatures in mind. XMSS is technically a multi-signature but would require significant on-chain support for flexible-policies. Smart contract wallets may provide a mechanism for token holders to choose their own post-quantum signature by programming verification into custom smart contracts. They face the same trust issues as on-chain multi-signature smart contracts. Crypto-holders will need to migrate to post-quantum addresses. Active addresses that have previously signed transactions must migrate before Q-Day because their public key has been exposed. Passive Ed25519 addresses can be recovered after Q-Day by proving knowledge of the seed used to generate the public key. ECDSA addresses derived from BIP-32 or BIP-39 may be able to use a similar technique. Blockchain developers and token providers will need to publish migration roadmaps and develop recovery plans for orphaned tokens whose owners miss the deadline. Recent estimates show it would take 76 days of non-stop processing to migrate all Bitcoin UTXOs to post-quantum wallets. Quantum computers can break popular zero-knowledge systems like Groth16, Halo2, and PlonK because they use elliptic curves. Blockchains will need to use the newer STARK and SNARG zero-knowledge systems which are quantum resistant at the price of larger proofs and longer verification times.  Starknet is transitioning to FRI.  Ethereum is looking at FRI, STIR, and WHIR. Blockchain designers have the tools they need to transition to post-quantum. It is now a question of will. Regulators are pushing financial institutions to be quantum-ready as soon as possible. On the other hand, it is reasonable to delay to see which algorithms the industry will support, and which will become final NIST and IETF standards. Everybody in the crypto industry needs a quantum transition roadmap. Circle is already considering how to mitigate the cost of address migration, and how to prepare Arc for the transition. The Circle post-quantum roadmap focuses on privacy first to protect our users from harvest-now-decrypt-later attacks. Arc Privacy will be post-quantum secure on day 1. By submitting this form, you agree to receive marketing and other communications from Circle about Circle Products and other company updates. You can unsubscribe from these communications at any time. For more information on our privacy practices, please review our Privacy Policy. By submitting this form, you agree to receive marketing and other developer communications from Circle. You can unsubscribe from these communications at any time. For more information on our privacy practices, please review our Privacy Policy. By submitting this form, you agree to receive marketing and other communications from Circle about Circle Products and other company updates. You can unsubscribe from these communications at any time. For more information on our privacy practices, please review our Privacy Policy. Digital assets are subject to a number of risks, including price volatility. Transacting in digital assets could result in significant losses and may not be suitable for some consumers. Digital asset markets and exchanges are not regulated with the same controls or customer protections available with other forms of financial products and are subject to an evolving regulatory environment. Digital assets do not typically have legal tender status and are not covered by deposit protection insurance. The past performance of a digital asset is not a guide to future performance, nor is it a reliable indicator of future results or performance. Additional disclosures can be found on the Legal and Privacy page.

Circle Internet Financial, LLC (NMLS ID# 1201441).

Circle Internet Financial, LLC is licensed as a Money Transmitter by the New York State Department of Financial Institutions and to engage in Virtual Currency Business Activity by the New York State Department of Financial Services. Texas customers click here for information about filing complaints. Maryland customers click here for information about filing complaints.

Circle International Bermuda Limited is licensed to conduct digital asset business by the Bermuda Monetary Authority.

Circle Technology Services, LLC (“CTS”) is a software provider and does not provide regulated financial or advisory services. You are solely responsible for services you provide to users, including obtaining any necessary licenses or approvals and otherwise complying with applicable laws. For additional details, please click here to see the Circle Developer terms of service. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. For example, they help us to know which pages are the most and least popular and see how visitors move around the site. These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly. These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you adverts that are more relevant to you and your interests on other sites. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of advertising campaigns. They are based on uniquely identifying your browser and device. If you do not allow these cookies, you will still receive advertising, but the advertising will be less tailored, or targeted, to you personally.

Read Original

Tags

quantum-algorithms
quantum-computing

Source Information

Source: Google News – Quantum Computing

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.