Newsroom
5 September, 2026 / News / AI / Tags: quantum, bytes, ecdsa, cryptography, migration

The G7 Cybersecurity Working Group calls on governments and firms to begin post-quantum cryptography migration now, citing risks to public-key systems that underpin digital assets and transactions
The Group of Seven cybersecurity working group has issued a formal call for governments and organizations to start transitioning to post-quantum cryptography without delay. The document, titled “Preparing for the Post-Quantum Era: A Call to Action” and released on September 3, 2026, frames quantum computing advances as a near-term economic and security risk rather than a distant concern.
Although the report does not name cryptocurrencies, its warnings apply directly to blockchain networks, exchanges, custodians and wallets. These systems depend on public-key cryptography for transaction authorization, key management and asset control. A sufficiently powerful quantum computer could eventually break widely used schemes such as elliptic-curve cryptography, potentially allowing private keys to be derived from exposed public keys.
The working group stresses that the threat is already present in one important respect. Adversaries can collect and store encrypted data or public cryptographic material today and wait until quantum capabilities mature to decrypt or forge signatures. This approach, often described as “harvest now, decrypt later,” is especially relevant for blockchains, where transaction histories and public keys remain permanently visible on public ledgers.
The group identifies five priority areas for action: raising awareness that the quantum threat is a business and economic issue; developing national strategies that support an adequate supply of post-quantum products; advancing research and practical solutions; fostering public-private partnerships; and integrating post-quantum requirements into cybersecurity rules and procurement processes.
Organizations are advised to adopt a phased, risk-based approach. This includes inventorying cryptographic assets, mapping dependencies, prioritizing critical systems and incorporating quantum-safe products into routine technology refreshes to control costs.
Europe has moved beyond general guidance. In June 2025 the European Commission adopted the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. Member states are required to begin the transition by the end of 2026. High-risk systems must complete migration no later than the end of 2030.
These deadlines turn quantum readiness into a compliance and competitive matter. Firms without clear migration plans risk falling behind regulatory expectations and market standards as procurement rules increasingly favor post-quantum capable solutions.
Major blockchain networks are already examining technical responses. Bitcoin developers are discussing BIP-360, a soft-fork proposal known as Pay-to-Merkle-Root. The change aims to reduce long-term exposure by eliminating certain Taproot key-path spending options that are more vulnerable to future quantum attacks. Proponents note that full protection against faster mempool-based attacks would still require post-quantum signature schemes. No activation timeline has been set.
Ethereum is pursuing a broader upgrade path. In a February 2026 roadmap update, network co-founder Vitalik Buterin outlined four components that need attention: validator BLS signatures, KZG commitments, ECDSA account signatures and application-layer zero-knowledge proofs. The stated target for core post-quantum infrastructure is 2029, though full migration of existing accounts and applications is expected to take longer.
One practical challenge is the size of post-quantum signatures. A conventional secp256k1 ECDSA signature occupies about 64 bytes. Earlier Dilithium-5 parameters required roughly 4,595 bytes, while the finalized ML-DSA-87 standard uses approximately 4,627 bytes. Larger signatures increase storage, bandwidth and transaction costs across networks.
| Cryptographic Scheme | Approximate Signature Size |
|---|---|
| secp256k1 ECDSA | 64 bytes |
| Dilithium-5 | 4,595 bytes |
| ML-DSA-87 | 4,627 bytes |
Industry assessments indicate that the more immediate pressures involve governance, protocol development, infrastructure upgrades and the handling of older wallets whose public keys are already exposed. Research published by Google Quantum AI in March 2026 suggested that breaking 256-bit elliptic-curve cryptography may require fewer resources than earlier estimates implied. Google itself has targeted completion of its internal post-quantum migration by 2029.
The U.S. National Institute of Standards and Technology has issued draft guidance recommending the phase-out of 112-bit ECDSA after 2030 and a complete ban on ECDSA use after 2035. These timelines reinforce the view that organizations should treat the transition as a multi-year engineering and operational project rather than a sudden emergency response.
The G7 call to action therefore places the focus on preparation. Networks, service providers and institutional holders that develop clear migration roadmaps may gain an advantage as custody standards and due-diligence requirements begin to incorporate quantum-readiness criteria.









