A Group of Seven (G7) cybersecurity working group urged governments and companies to immediately begin shifting to post-quantum cryptography. While the arrival of practically usable quantum computers is uncertain, it judged that technology capable of threatening existing public-key cryptography is advancing faster than expected. Cryptocurrency networks are also facing quantum computing as a new security challenge because they use public-key cryptography for transaction signatures and fund management.
On Sept. 5 local time, blockchain outlet Cryptopolitan reported that the G7 cybersecurity working group released a report on Sept. 3 titled "Preparing for the Post-Quantum Era: A Call to Action". The report stressed that governments and companies should begin the transition to post-quantum cryptography before quantum computers can actually neutralise existing cryptographic systems.
The G7 did not present a specific timeline for when quantum computers will be commercialised. It said recent technical advances point to the likely development of quantum computers capable of breaking widely used public-key cryptography.
In particular, the G7 identified "harvest now, decrypt later" attacks as a key risk. In such attacks, an attacker secures encrypted data now and decrypts it later when quantum computers become sufficiently advanced.
The blockchain industry is also paying attention to such risks. Because blockchains are structured so transaction records and some public-key information remain for long periods, there are concerns that even currently secure cryptography could become a target of future attacks using quantum computers. The G7 recommended that countries pursue not only new cryptographic algorithms but also national-level policy, research, public-private cooperation and procurement standards that take post-quantum technology into account.
The European Union has already presented a specific transition schedule. In June last year, the EU introduced a joint implementation roadmap for the shift to post-quantum cryptography and told member states to begin the transition by the end of 2026. It aims for high-risk systems to start the transition immediately and complete migration before 2030. Post-quantum responses are extending beyond a technical choice into cybersecurity regulations and procurement policy. For companies, delayed responses could increase burdens in regulatory compliance and competitiveness.
Major blockchain networks have also begun preparing for quantum computers. In bitcoin, BIP-360, a soft-fork proposal to reduce long-term quantum attack risks, is under review. The proposal includes removing Taproot key-path spending, which is considered relatively vulnerable to quantum-computer attacks.
BIP-360 cannot address all quantum attacks on its own. In particular, preventing attacks targeting transactions in the mempool may require the actual adoption of post-quantum digital signatures. A specific activation date for BIP-360 has not been set.
Ethereum is preparing a broader upgrade. Vitalik Buterin (비탈릭 부테린), Ethereum co-founder, said in a roadmap in February that key areas needing a shift to post-quantum systems include validators' BLS signatures and KZG commitments, ECDSA account signatures, and zero-knowledge proofs at the application layer. Ethereum has set a plan to build core post-quantum infrastructure by 2029, but there are forecasts that an actual network transition could take longer than that.
One of the biggest obstacles is cost. Widely used secp256k1-based ECDSA signatures are about 64 bytes, but post-quantum signature methods can require much larger data. The signature size of ML-DSA-87, standardised by the U.S. National Institute of Standards and Technology (NIST), is about 4,627 bytes. The earlier Dilithium-5 parameter set also used signatures of about 4,595 bytes.
Larger signature data would increase the burden on blockchain storage and network bandwidth, and could raise transaction processing costs as a result. In decentralised networks, higher node operating costs could also affect the network structure itself.
Therefore, an analysis says the most realistic risk facing the cryptocurrency industry now is the transition process itself rather than quantum computers immediately hacking bitcoin or ethereum.
Cited as practical challenges are community consensus and protocol development around new signature systems, infrastructure burdens from larger signature data, and how to handle older wallets whose public keys have already been exposed.
The pace of quantum computing development is also a variable. In March, Google Quantum AI presented research findings that the resources required to break 256-bit elliptic-curve cryptography could be far less than previously estimated. Google also said it plans to complete its own post-quantum transition by 2029.
The United States is also detailing standards for cryptographic transitions. In draft IR 8547, NIST proposed phasing out ECDSA at the 112-bit security level after 2030 and banning the use of ECDSA after 2035.
This trend suggests that whether cryptocurrency networks respond to quantum threats could become a standard for judging business competitiveness and regulatory compliance, not just a security issue.
In the end, what matters is not exactly when quantum computers can break existing cryptography, but how quickly a transition can be made before that happens. Attention is focused on how concretely major blockchains, including bitcoin and ethereum, will flesh out post-quantum cryptography transition plans following the G7 recommendation.