No top-20 cryptocurrency is fully quantum-safe yet, but Bitcoin and Ethereum both have upgrade paths underway.
Post-quantum signatures are bigger and slower, which raises storage costs for every computer running the network.
The thing to watch is not whether quantum-safe code gets written, but how long it takes anyone to use it.
Think about the lock on your front door. Now imagine a locksmith who can glance at the outside of that lock and work out the exact shape of your key. There's no picking, forcing, or breaking anything. The locksmith just looks at the security tool you show to the whole world every day, then walks right in.
That is roughly what a big enough quantum computer would do to Bitcoin (CRYPTO: BTC) and Ethereum (CRYPTO: ETH). Every time you spend from a crypto address, you publish a public key. Today, using that public key to derive the matching private key would take a normal computer longer than the universe has been around.
Missed AI’s "Act 1"? Act 2 Could Be 15x Bigger. Most investors think they missed the AI boat because they didn't buy Nvidia in 2005. But according to our analysts, we’re only at the end of "Act 1"—the R&D phase. "Act 2" is the global rollout. Continue »
A powerful quantum machine running Shor's algorithm turns that into an afternoon. Google Quantum AI, a division of Alphabet, put numbers on it in March: about 1,200 to 1,450 logical qubits, meaning the reliable kind you get by welding hundreds of today's error-prone physical qubits into one. With superconducting hardware, that works out to fewer than 500,000 physical qubits and a runtime of 18 to 23 minutes. Researchers from the Ethereum Foundation and Stanford co-signed the paper.
Nobody knows when the afternoon arrives. Google's Willow chip carries 105 qubits, and the biggest machines anyone has today run roughly 2,000 to 2,500. A companion paper from Oratomic, co-authored by Caltech's John Preskill, argues that neutral-atom hardware could do the same job with about 26,000 qubits. Some people say the tipping point will come before 2030. Other serious people say 2040. Cryptocurrency developers have to prepare for the early guess, because you cannot patch a decentralized network overnight.
The good news is that researchers have found quantum-resistant encryption algorithms already. They're not even new.
The National Institute of Standards and Technology finished standardizing its first post-quantum algorithms in 2024, including the lattice-based ML-DSA and the hash-based SLH-DSA. The names sound like droid model numbers by George Lucas. Microsoft and IBM will sell you post-quantum security inside their cloud and security products today.
So why has nothing switched? Well, the new stuff is chunky. Post-quantum signatures are bigger and slower than the elegant little elliptic curve signatures crypto currently runs on. On a blockchain, every computing node stores every signature forever. Swapping them in is like replacing every door in a skyscraper with a bank vault door. Safer, definitely. Also heavier, pricier, and slower to open. And asking for more storage is particularly unpopular right now, as artificial intelligence computing has sent storage prices into the stratosphere.
There is also more than one door to guard. The hashing that chains data blocks together holds up reasonably well against known and expected quantum attacks. Transaction signatures do not, and neither does the firmware inside a hardware wallet. Each layer needs its own fix.
No top-20 cryptocurrency is fully quantum-safe in September 2026. Calling it a race is generous; it looks more like a group of people stretching at the starting line while arguing about the course.
Bitcoin's contribution is BIP 360, which adds a new address type called P2MR. Think of it as pre-wiring the house for an appliance that has not been delivered yet. It lets people opt into quantum-resistant signatures later without dragging the whole network through a hard-fork fight. Blockstream researchers also found that Taproot, integrated since November 2021, is quantum-safe in certain uses.
Ethereum is being more aggressive, which makes sense. The Ethereum Foundation staffed an actual Post-Quantum Security team. Co-founder Vitalik Buterin's Lean Ethereum plan maps a multiyear swap of validator signatures for hash-based ones, plus quantum-resistant STARK proofs. In other words, Ethereum's weak points are being upgraded, one by one.
The most interesting progress is happening outside the top two, though. Algorand has already performed real transactions signed with the quantum-resistant Falcon-1024 algorithm, making it the first major smart contract chain where optional keys with next-generation security actually work. The privacy-focused Zcash is funding a project to bring quantum-proof private transactions directly to hardware security chips. Zcash itself should be quantum-proof in 2027, according to founder Josh Swihart.
Wallet makers are also on the move. The Trezor Safe 7 advertises a quantum-ready dual-chip setup so it can run post-quantum firmware the day the big chains ship it, and the Ledger group is retooling its wallets' chips for those fatter keys.
Image source: Getty Images
As Douglas Adams said, don't panic (but you should always carry a towel).
This is a multiyear story with a lot of committee meetings in it. The thing to watch is not whether quantum-safe code gets written; it is how long it takes before people actually use it.
Bitcoin cannot make holders upgrade, and millions of coins sit in old addresses with public keys already sitting in the open, waiting patiently for a quantum-powered locksmith. Meanwhile, the major cryptocurrencies are preparing for a quantum-safe future. Those expensive algorithms won't be optional forever.
Before you buy stock in Bitcoin, consider this:
The Motley Fool Stock Advisor analyst team just identified what they believe are the 10 best stocks for investors to buy now… and Bitcoin wasn’t one of them. The 10 stocks that made the cut could produce monster returns in the coming years.
Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you’d have $406,141!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you’d have $1,347,745!*
Now, it’s worth noting Stock Advisor’s total average return is 940% — a market-crushing outperformance compared to 211% for the S&P 500. Don't miss the latest top 10 list, available with Stock Advisor, and join an investing community built by individual investors for individual investors.
See the 10 stocks »
*Stock Advisor returns as of September 18, 2026.
Anders Bylund has positions in Alphabet, Bitcoin, Ethereum, and International Business Machines. The Motley Fool has positions in and recommends Alphabet, Bitcoin, Ethereum, International Business Machines, and Microsoft. The Motley Fool has a disclosure policy.