Two documents landed on institutional desks this year. One was a vendor deck warning that the keys behind a digital-asset portfolio will break by a stated year, with a product attached. The other was a rebuttal noting that no quantum computer has yet factored a number larger than 21. Both mislead in a precise way, and the gap between them is where the work sits. No date appears below by which holdings become unsafe, because nobody credible publishes one.

Which cryptography is at risk, and which is not

Two quantum algorithms matter, and they do very different amounts of damage. Shor's algorithm solves factorisation and the discrete logarithm efficiently, which breaks the public-key cryptography that authorises spending: ECDSA over secp256k1 on Bitcoin and Ethereum, EdDSA on Solana, Sui and Near, BLS over BLS12-381 in Ethereum's consensus layer, and RSA and elliptic-curve key exchange elsewhere in the stack. Grover's algorithm offers only a quadratic speed-up on unstructured search, a far weaker result.

That asymmetry bounds the problem. NIST's draft transition guidance states that its symmetric standards, hash functions and block ciphers among them, are "significantly less vulnerable to known quantum attacks than the public-key cryptography standards", and that every approved symmetric primitive at 128 bits of classical security or above is believed to meet at least Category 1 security. SHA-256 is not the exposure. AES-256 is not the exposure. Signatures are.

Mining is not the exposure either, though much of the coverage assumes so. Quantum Horizon, a Monte Carlo study published on 12 June 2026 by Iosif Gershteyn and Jacob Alber, finds that Grover's algorithm "does not meaningfully threaten proof-of-work mining", protected as it is by the quadratic speed-up, the per-operation cost of fault tolerance, a square-root parallelisation wall and difficulty adjustment.

What harvest now, decrypt later does and does not mean

Harvest now, decrypt later describes one attack with one shape: capture ciphertext today, store it, decrypt it once a machine exists. It is an attack on confidentiality, and NIST's draft treats it as grounds for moving key establishment earlier than authentication, which "remains secure as long as the cryptographic algorithms and keys used to perform the authentication are secure when the authentication is performed". Applied to a signature the phrase does not transfer, and the sloppiness sells product. Nobody harvests a signature to forge an earlier one. What is harvested is a public key, and a public key was never secret. The only variable is when it becomes visible.

Where addresses are hashed, the key appears at spend time rather than on receipt, so a never-spent output behind a fresh address is not exposed today; coins behind pay-to-public-key scripts, or behind an address reused after a spend, have been exposed for years. Google Quantum AI's paper of 30 March 2026, written with the Ethereum Foundation, Stanford and Berkeley, separates at-rest attacks on dormant keys from on-spend attacks on a transaction in the mempool, and which comes first depends on hardware, not holdings. Exposure counts are contested: that paper counts "a little over 1.7 million bitcoin (nearly 9% of all bitcoin)" behind P2PK scripts and roughly 6.9 million vulnerable across all script types once key reuse is included; a May 2025 Chaincode Labs report gives 20–50%, or 4–10 million BTC; Quantum Horizon puts roughly six million exposed, of which about 2.3 million are irreducibly at risk, the coins that cannot be migrated at all. No figure travels without its definition.

Where the attack genuinely bites a ledger is privacy rather than theft. A Federal Reserve staff working paper (FEDS 2025-093, Jillian Mascelli and Megan Rodden, September 2025) concludes that maintainers can deploy post-quantum mitigations protecting a network's security and integrity, while the "data privacy of the network's previously recorded transactions remains vulnerable against a future-state quantum computer due to HNDL". A fork can rescue future security. It cannot re-encrypt what is already written down. That puts a shelf life on the confidentiality architecture described in our earlier piece on privacy in regulated finance.

The resource estimates, read in context

Published attack costs have fallen sharply. Webber and colleagues put a one-hour break of Bitcoin's elliptic-curve keys at 317 million physical qubits in January 2022, and Google's 2026 estimate is roughly a twentyfold reduction on prior work. The newer numbers are not one falling sequence, though, and reading them as one is the commonest error here.

  • Google, the Ethereum Foundation, Stanford and Berkeley (30 March 2026) give two circuits for the elliptic-curve attack, one at 1,200 logical qubits and 90 million Toffoli gates, one at 1,450 logical qubits and 70 million Toffoli gates. On superconducting hardware, those circuits "can execute in minutes using fewer than half a million physical qubits".
  • A second team (4 September 2026) optimised the same problem for its proposed Walking Cat trapped-ion architecture and concluded that such a machine "can solve the ECDLP on secp256k1 in approximately 25.7 days using 19,397 physical qubits with an estimated success probability of 63%".

Both are estimates, not experiments, and neither describes a machine that exists. They also agree more than the headlines suggest: both land near 1,450 logical qubits. What differs is the physical realisation, and it moves in the direction people do not expect. The superconducting estimate needs about twenty-five times more physical qubits and finishes in minutes; the trapped-ion one needs far fewer and takes nearly a month, with better than one chance in three of failing. Google supplies the framing worth planning around: clock speed, not qubit count. Fast-clock architectures, superconducting and photonic, would make on-spend attacks on mempool transactions conceivable first; slow-clock ones, ion trap and neutral atom, would reach dormant keys first. Two caveats belong in any board summary: Google withheld its circuits in favour of a zero-knowledge proof, so no third party can reproduce the estimate, and it had announced its own 2029 migration deadline five days earlier.

The standards, with their real status

On 13 August 2024 NIST published its first three finalised post-quantum standards: FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, lattice signatures) and FIPS 205 (SLH-DSA, hash-based signatures). Dustin Moody of NIST urged administrators to "start integrating them into their systems immediately, because full integration will take time". Everything since has run late. FIPS 206, the FALCON-derived signature standard planned for late 2024, still has no public draft; Ray Perlner of NIST told the sixth post-quantum standardisation conference on 25 September 2025 that it was "basically written, awaiting approval", the special challenges being FALCON's floating-point arithmetic. HQC, selected in March 2025 as a backup to ML-KEM, has no draft either.

The dates institutions quote at each other come from a document never finalised. NIST IR 8547 appeared as an initial public draft on 12 November 2024, its comment period closed on 10 January 2025, and no final version exists. It is the source of "deprecated after 2030, disallowed after 2035", and that pairing applies only to the 112-bit rows of its table: secp256k1, P-256 and Ed25519 sit at 128 bits or above, where the table gives no deprecation step at all, only a hard disallow after 2035. The 2035 anchor is not NIST's either: the draft quotes National Security Memorandum 10 on "mitigating as much of the quantum risk as is feasible by 2035". Ledger's June 2026 post, written by its own chief technology officer, says NIST "has mandated that all critical systems must migrate to post-quantum cryptography by 2030", which turns an unfinalised draft into a mandate; ethereum.org says more carefully that NIST "anticipates deprecating ECDSA by 2030". The draft's own vocabulary is worth borrowing: deprecated means usable with a risk the data owner must assess, disallowed means not permitted, legacy use means processing already-protected information only.

Where expert opinion genuinely differs

The Global Risk Institute's Quantum Threat Timeline Report 2025, by Michele Mosca and Marco Piani and published on 9 March 2026, surveyed 26 experts and found a cryptographically relevant quantum computer "quite possible (28–49%)" within ten years and "likely (51–70%)" within fifteen, and describes the timeline as having accelerated. Quantum Horizon gives about one chance in six by 2035, near 30% by 2040 and about 60% by 2050. These are distributions, not schedules.

Two named practitioners land in opposite places. Filippo Valsorda, who maintains the Go standard library's cryptography, wrote on 6 April 2026 of a position changed "compared to just a few months ago", and reframed the decision: "The bet is not 'are you 100% sure a CRQC will exist in 2030?', the bet is 'are you 100% sure a CRQC will NOT exist in 2030?'" Peter Gutmann of the University of Auckland argues the reverse on a checkable empirical core: the first quantum factorisation, of 15, came in 2001; the next record, 21, in 2012; a 2019 attempt at 35 failed; and no new record has been set with Shor's algorithm since. Gutmann's deck labels these "stunt factorisations", a term it credits to François Grieu, and rejects the Pascal's-wager case for migrating anyway because that wager "assumes the cost of compliance is zero". That is the argument a risk committee will hear, and it deserves a costed answer.

What the Paris programme put on the record

The archived Paris 2026 programme, staged at the Louvre Palace on 2–3 June 2026, held the substantive version of this conversation in a session not named after it. "DeFi Under Attack: Securing Onchain Finance and the Machine Economy" ran on the Hecto Main Stage on Wednesday 3 June, 16:30–17:10. The programme listed Kostas Chalkias (chief cryptographer and co-founder, Mysten Labs), Charles Guillemet (chief technology officer, Ledger), Rodrigo Coelho (chief executive, Edge & Node) and Jason Jiang (chief business officer, CertiK), moderated by Nikola Stojanow (partner, new ventures, Bank Frick). Chalkias and Guillemet each appeared once on the programme, and only there.

The pairing matters because the two have since backed different algorithms. Chalkias and Mahdi Sedaghat published Sui's selection on 18 August 2026: ML-DSA-65 at NIST Level 3 for account authentication, and SLH-DSA-SHA2-128s, implemented as a Move contract, for high-value vaults. They set FALCON aside because it ships at Levels 1 and 5 only, lacks a canonical seed-to-key derivation, and because "FIPS 206 is still not final". Guillemet has been reported, in an August 2026 write-up rather than in his own words, as observing that ML-DSA is the default outside blockchain while Bitcoin and Ethereum lean towards SLH-DSA. His own signed account is older: a Ledger explainer written with Victor Servant on 13 February 2023 put the requirement at "2124 qubits at a minimum" against secp256k1 and concluded that "the crypto industry has yet to see the urgency in investing in these measures".

Two absences are as informative as the panel. Adam Back of Blockstream appeared once, in an asset-management fireside with Jenny Johnson of Franklin Templeton on Tuesday 2 June, moderated by Eleanor Terrett, not in a cryptography session; the quantum position is on the record elsewhere, in an April 2026 Bloomberg interview: "The prudent thing to do is to prepare Bitcoin and give people the option to migrate their keys to a quantum-ready format." And the one item with "Quantum-Proof" in its title, a sponsor workshop on the X Ventures Masterclass Stage on Tuesday 2 June, 10:00–11:00, listed no speaker at all. The record sits on the agenda and in the session index.

What migration requires of a chain, and of a custodian

Bitcoin has two live proposals and no consensus. BIP-360 (Pay-to-Merkle-Root, assigned in December 2024 to Hunter Beast, Ethan Heilman and Isabel Foxen Duke) proposes an output type with the quantum-vulnerable key-path spend removed, protects only against long-exposure attacks, and names no signature algorithm. BIP-361, assigned in February 2026 to Jameson Lopp and five co-authors, goes further: Phase A would prohibit sends to quantum-vulnerable addresses roughly three years after activation, and Phase B would encumber legacy ECDSA and Schnorr spends two years after that. Ethereum has published more detail, replacing BLS with the hash-based leanXMSS for validators and using account abstraction rather than a protocol-wide migration, so each account can switch on its own schedule, targeting "completion of core post-quantum infrastructure by approximately 2029". That date and Google's are private commitments citing one another, not regulation.

Others have shipped, in the narrow sense the word deserves. Quantum Horizon's survey records Algorand running FALCON-based state proofs since 2022 and a FALCON-signed mainnet transaction in 2025, though its consensus layer still uses classical signatures; Solana with an opt-in hash-based Winternitz vault live; and the XRP Ledger with ML-DSA on a devnet and a roadmap to full resistance by 2028. The practical obstacle is size: a Bitcoin Schnorr signature runs about 64–72 bytes, ML-DSA-44 is 2,420 bytes and SLH-DSA reaches roughly 49,856 bytes at its largest, which is why designs that commit only to a hash of the post-quantum key are favoured. Google's paper puts Bitcoin's own migration at several months of blocks even if the network processed nothing else, which is the case for starting years early.

The exposure closest to an allocator

For an institution holding tokenised instruments rather than coins, the risk is not its own wallet but the admin key on someone else's contract. Upgrade privileges usually sit with a multi-signature whose public keys were exposed by past upgrades, creating, in Google's words, "the existential risk of a quantum attacker taking complete control over the smart contract". Among the top 500 Ethereum contracts by balance, that paper counts at least 70 admin-vulnerable accounts holding about 2.5 million ETH, alongside some 200 billion dollars in stablecoins and tokenised real-world assets. That is a different question from the one asked in who actually holds it: not who controls your key, but who controls the contract your asset lives in.

A defensible position to hold now

Post-quantum is not automatically safe, a point vendors rarely volunteer. Google's paper warns that the relative novelty of these schemes "raises justifiable concerns about the possibility of undiscovered weaknesses"; supersingular isogeny Diffie-Hellman fell to a classical attack. In July 2026 an AI-assisted key-recovery attack roughly halved the security bits of HAWK, a proposed lattice-isomorphism scheme that is not a NIST standard; Matthew Green notes that the attack "is still exponential time" and does not transfer to schemes resting on a different hard problem. Chalkias draws the sharper lesson from the same event, and it is why Sui bought the more expensive security level: "AI-assisted cryptanalysis is now finding things in schemes that have been reviewed by people for years, and that changes how much margin a lattice assumption deserves."

Five things are actionable without a forecast. Inventory the holdings whose public keys are already visible, separately from those exposed only at spend. Ask each custodian three questions in writing: whether the chains they hold for you support protocol-level key rotation, when their signing hardware and firmware will support ML-DSA and SLH-DSA, and what becomes of your assets under a BIP-361 style legacy sunset. Extend diligence on any tokenised instrument to contract upgrade authority and whether those keys are exposed. Write policy in the draft's vocabulary, so that finalisation of a standard updates a date rather than a doctrine. And treat this as the one threat that invalidates a control you already hold rather than adding one you lack, which is why it sits alongside, not inside, the institutional threat model published here earlier.

The direction is clear, the timing is a distribution rather than a date, and the binding constraint is governance rather than physics: Quantum Horizon surveyed the twenty largest cryptocurrencies and found none fully post-quantum. Failures of that kind get resolved in rooms rather than in papers. The inaugural Gulf edition runs at the Louvre Abu Dhabi on 3–4 December 2026, by application and review, and the Abu Dhabi programme is where this argument goes next.