G7 sounds post-quantum alarm, calls for urgent migration to quantum-resistant cryptography
Quick Look
- The G7 published a report on September 3, 2026 calling for immediate preparation for post-quantum cryptography, due to the “harvest now, decrypt later” threat.
- Bitcoin, Ethereum and Solana are directly affected, their infrastructures being in the crosshairs despite the absence of frontal targeting of cryptocurrencies.
- Developers are working on solutions like BIP-360 for Bitcoin, while Ethereum and Solana are testing post-quantum fixes, although the computing power required remains speculative at this time.
AI-generated summary
Why It Matters
On September 3, 2026, the G7 published a report entitled “Preparing for the Post-Quantum Era: A Call to Action”, written by its cybersecurity working group led by ANSSI, in collaboration with the European Commission and ENISA. The report aims to anticipate the threat of quantum computers to current cryptography, particularly through the "harvest now, decrypt later" strategy, where encrypted data is stored today to be decrypted later when quantum technology is powerful enough.
A countdown with no date displayed. The G7 signaled the end of recess on September 3, 2026. Its cybersecurity experts are calling on governments and companies to prepare without delay for the switch to post-quantum cryptography. Message received five out of five on the Bitcoin side, where the theoretical threshold for breaking a cryptographic key has never seemed so close. Governments are not directly targeting cryptocurrencies. Their wallets, exchanges and custody infrastructures are nonetheless directly in the crosshairs. We take stock.
The G7 sounds the post-quantum alarm
The report is simply titled Preparing for the Post-Quantum Era: A Call to Action, published on September 3, 2026 by the G7 cybersecurity working group, led by the French agency ANSSI, with the European Commission and ENISA as guests.
The text never mentions Bitcoin or Ethereum. It aims at an unstoppable principle. Post-quantum cryptography must be anticipated even before the arrival of a quantum computer capable of bringing it down.
The threat has a name, “harvest now, decrypt later”. In other words, an attacker can siphon encrypted data today to breach it in ten years, once the necessary computing power is available, without waiting for the technology to already exist to act.
The European Union has set the end of 2026 as the starting point for migration and 2030 for the most sensitive systems. The American NIST, in its draft IR 8547, provides for a scheduled depreciation after 2030 and an outright ban after 2035, over a wider scope than just the ECDSA. None of this will panic the markets immediately.
“Our message is clear: the transition to post-quantum cryptography is a critical security issue that requires a collective and coordinated effort. Organizations — public or private — must act now (…)”
ANSSI working group
Bitcoin, number one target of a post-quantum transformation which is not anecdotal
The calculation remained theoretical for a long time. It has been much less so since this summer. Many of the dormant addresses from 2009, including those of Satoshi Nakamoto, are in P2PK (pay-to-public-key) format: their public key has been hanging out in the open on the blockchain since their very first receipt of funds, without any outgoing transaction being necessary to expose it.
Conversely, more recent addresses, in P2PKH format, remain protected from hashing as long as they have never been used to pay. The developers are working on BIP-360, an address proposal called Pay-to-Merkle-Root (P2MR), which removes the direct spending path by key inherited from Taproot to force passage through a script.
The choice of the post-quantum signature scheme itself still remains to be decided in a future proposal, with signatures significantly heavier than the 64 bytes of a classic ECDSA signature. Multiply that by millions of daily transactions, and the decade-old debate over block size is likely to come back with a vengeance. Its adoption, however, requires a soft fork, therefore the agreement of a large part of the ecosystem. A fundamental project, not a sprint.
Ethereum and Solana, the race to post-quantum is already on
Ethereum did not wait for the G7 to get to work. Its roadmap touches four bricks of the protocol, BLS signatures of validators, KZG commitments, ECDSA signatures of user accounts and zero-knowledge proofs.
The post-quantum core network infrastructure is due to be completed in 2029, the same year Google promises to have completed its own migration. Solana is not left out. Its developers are also testing post-quantum patches to protect wallets and custody systems, work carried out in parallel on the three largest blockchains on the market.
Should we panic though? No. The computing power needed to crack a Bitcoin or Ethereum key remains, to date, speculative. But a government report that urges action ten years before the deadline is never a coincidence of timing.
What to Watch
AI outlook — possibilities, not facts
Bitcoin will adopt a new form of address resistant to quantum computers, such as P2MR proposed in BIP-360, by 2029.
Likely · Within years
Ethereum will complete the migration of its core infrastructure to post-quantum algorithms by 2029.
Likely · Within years
Solana will deploy post-quantum patches to protect wallets and custody systems by 2028.
Possible · Within years
Open Questions
- What post-quantum signature scheme will ultimately be adopted for Bitcoin?
- How will the increased size of post-quantum signatures affect the scalability of blockchains?
- Will NIST standards after 2030 be binding on non-US private actors?
- How much will post-quantum migration cost for cryptocurrency exchanges and custody systems?







