G7 quantum warning puts crypto security migration on the clock

Wait 5 sec.

The cybersecurity working group of G7 is requesting that nations and enterprises begin transitioning to post-quantum cryptography immediately, a caution that has direct relevance to crypto networks, exchanges and custodians that must make costly upgrades to their systems before quantum computers pose a threat to contemporary cryptography.The working group released “Preparing for the Post-Quantum Era: A Call to Action”, on September 3, 2026, treating quantum computing as a risk to business and cybersecurity that organizations must be ready for prior to the advent of a cryptographically viable machine.Why a report that never says “crypto” still hits cryptoThe G7 paper makes no specific reference cryptocurrency, though the concept is directly tied in with blockchain technology. Decrypt notes that cryptocurrency transaction and funds management relies on public-key cryptography.Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms.— G7 Cybersecurity Working GroupThe concern is not limited to future attacks.Harvest now, decrypt later.— G7 Cybersecurity Working GroupThe strategy entails gathering encrypted data today and decrypting it in the future when quantum technology is capable enough. There is a similar issue with blockchains in which public keys and transaction history can remain visible forever, leaving the keys available to be hacked in the future.The G7 suggests that efforts should be made in terms of awareness, national policies, research, collaborations with public and private sectors, and post-quantum procurement requirements.Europe has already put dates on the calendarEurope has taken a step further by implementing deadlines. The EU implemented the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (PQC) in June 2025.The PQC policy of the European Commission insists that all its member states start the transition by the end of 2026, while systems with high risk must migrate immediately and before 2030.This means that quantum readiness has turned into more than just a technical issue. As new requirements concerning post-quantum technology become part of the procurement and cybersecurity laws, companies without appropriate migration policies may encounter issues of compliance and competition.Bitcoin and Ethereum are taking different roadsBIP-360, Pay-to-Merkle-Root, is being explored by Bitcoin as a proposal for soft-fork aimed at cutting down vulnerability to long-term attacks by quantum computers. BIP-360 requires the abolishment of the Taproot key-path spend susceptible to quantum processing, though its creators admit that the faster attacks on the mempool transactions would still depend on the implementation of post-quantum digital signatures. BIP-360 has no activation date.Ethereum is working on a wider post-quantum security framework. In his roadmap for February 2026, Vitalik Buterin mentioned four components that need to be upgraded: BLS signatures of validators, KZG commitments, ECDSA account signatures, and zero-knowledge proofs of the application layer. Ethereum plans to achieve core post-quantum infrastructure in 2029 although the process of migrating to this new technology might still take time.The cost is high. The compact secp256k1 ECDSA signature is about 64 bytes while the older Dilithium-5 parameter set made use of approximately 4,595 bytes. The ML-DSA standard finalized by NIST utilizes the ML-DSA-87 signatures which utilized about 4,627 bytes. The size of the signature can therefore also increase the amount of storage, bandwidth, and transaction costs.The near-term risk is the migration itselfAs a result, the immediate market risk is not when a quantum computer will break Bitcoin. Rather, it is everything associated with preparing for that: governance disputes, development of protocols, larger key signatures, infrastructure changes, and old wallets with their public keys made known.An article published in March 2026 by Google Quantum AI claimed that breaking 256-bit elliptic-curve cryptography would be much less resource-intensive than previously assumed. Google even announced the completion of the migration of its systems by 2029.NIST introduced a draft IR 8547, in which it recommends phasing out 112-bit ECDSA after 2030 and forbidding the use of EDSCA after 2035.Earlier on, Cryptopolitan published a report stating that quantum preparedness might eventually enter institutional custody criteria and the standards for investor due diligence, which will make the network migration plan a competitive advantage.  The smartest crypto minds already read our newsletter. Want in? Join them.