G7 report presses crypto to start post-quantum migration now

- The G7 Cybersecurity Working Group urged governments and businesses to begin moving to post-quantum cryptography now, warning that current public-key systems face future quantum risk.
- The warning matters for crypto because wallets, exchanges, custodians and blockchain networks depend on cryptography that may eventually need costly upgrades.
- The near-term risk is not a quantum computer breaking Bitcoin tomorrow, but the governance, infrastructure and compatibility burden of migrating before the threat becomes real.
The cybersecurity working group of G7 is requesting that nations and enterprises begin transitioning to post-quantum cryptography immediately, a caution that has direct relevance to crypto networks, exchanges and custodians that must make costly upgrades to their systems before quantum computers pose a threat to contemporary cryptography.
The working group released “Preparing for the Post-Quantum Era: A Call to Action”, on September 3, 2026, treating quantum computing as a risk to business and cybersecurity that organizations must be ready for prior to the advent of a cryptographically viable machine.
Why a report that never says “crypto” still hits crypto
The G7 paper makes no specific reference to cryptocurrency, though the concept is directly tied in with blockchain technology. Decrypt notes that cryptocurrency transaction and funds management relies on public-key cryptography.
Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms.
— G7 Cybersecurity Working Group
The concern is not limited to future attacks.
Harvest now, decrypt later.
— G7 Cybersecurity Working Group
The strategy entails gathering encrypted data today and decrypting it in the future when quantum technology is capable enough. There is a similar issue with blockchains in which public keys and transaction history can remain visible forever, leaving the keys available to be hacked in the future.
The G7 suggests that efforts should be made in terms of awareness, national policies, research, collaborations with public and private sectors, and post-quantum procurement requirements.
Europe has already put dates on the calendar
Europe has taken a step further by implementing deadlines. The EU implemented the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (PQC) in June 2025.
The PQC policy of the European Commission insists that all its member states start the transition by the end of 2026, while systems with high risk must migrate immediately and before 2030.
This means that quantum readiness has turned into more than just a technical issue. As new requirements concerning post-quantum technology become part of the procurement and cybersecurity laws, companies without appropriate migration policies may encounter issues of compliance and competition.
Bitcoin and Ethereum are taking different roads
BIP-360, Pay-to-Merkle-Root, is being explored by Bitcoin as a proposal for soft-fork aimed at cutting down vulnerability to long-term attacks by quantum computers. BIP-360 requires the abolishment of the Taproot key-path spend susceptible to quantum processing, though its creators admit that the faster attacks on the mempool transactions would still depend on the implementation of post-quantum digital signatures. BIP-360 has no activation date.
Ethereum is working on a wider post-quantum security framework. In his roadmap for February 2026, Vitalik Buterin mentioned four components that need to be upgraded: BLS signatures of validators, KZG commitments, ECDSA account signatures, and zero-knowledge proofs of the application layer. Ethereum plans to achieve core post-quantum infrastructure in 2029 although the process of migrating to this new technology might still take time.
The cost is high. The compact secp256k1 ECDSA signature is about 64 bytes while the older Dilithium-5 parameter set made use of approximately 4,595 bytes. The ML-DSA standard finalized by NIST utilizes the ML-DSA-87 signatures which utilized about 4,627 bytes. The size of the signature can therefore also increase the amount of storage, bandwidth, and transaction costs.

The near-term risk is the migration itself
As a result, the immediate market risk is not when a quantum computer will break Bitcoin. Rather, it is everything associated with preparing for that: governance disputes, development of protocols, larger key signatures, infrastructure changes, and old wallets with their public keys made known.
An article published in March 2026 by Google Quantum AI claimed that breaking 256-bit elliptic-curve cryptography would be much less resource-intensive than previously assumed. Google even announced the completion of the migration of its systems by 2029.
NIST introduced a draft IR 8547, in which it recommends phasing out 112-bit ECDSA after 2030 and forbidding the use of EDSCA after 2035.
Earlier on, Cryptopolitan published a report stating that quantum preparedness might eventually enter institutional custody criteria and the standards for investor due diligence, which will make the network migration plan a competitive advantage.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
What did the G7 actually recommend?
The G7 cybersecurity working group urged governments and organizations to begin their post-quantum cryptography transition as soon as possible, framing the quantum threat as a near-term economic and business risk and laying out five priority areas from awareness campaigns to procurement requirements.
When does the EU want the post-quantum migration done?
The European Commission says all member states should start transitioning by the end of 2026, with high-risk systems moved to quantum-safe cryptography no later than the end of 2030.
How are Bitcoin and Ethereum preparing for quantum computers?
Bitcoin developers are considering BIP-360, a new Pay-to-Merkle-Root output type that resists long-exposure quantum attacks, while Ethereum is following its "Lean Ethereum" roadmap targeting 2029 for full post-quantum protection across four vulnerable parts of its cryptography.
What is “harvest now, decrypt later”?
It is an attack strategy in which an adversary collects encrypted information today and stores it until a future quantum computer can break the public-key cryptography protecting it. The G7 treats that as a present-day reason to migrate because information that must stay confidential for years can already be exposed to future decryption. For blockchains, the related concern is that public keys and cryptographic records can remain visible indefinitely, giving a future attacker persistent material to target.
Why does a report that never mentions crypto affect blockchains?
Because cryptocurrency networks depend on public-key cryptography for signatures, authentication and control of assets. A quantum computer capable of defeating elliptic-curve cryptography could potentially derive private keys from exposed public keys and forge valid signatures. Bitcoin's BIP-360 and Ethereum's post-quantum roadmap are already addressing precisely that class of risk.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Micah Abiodun
Micah Abiodun makes good use of his Environmental Engineering and Management (MSc) at Tallinn University of Technology (TalTech) to polish content and price prediction news at Cryptopolitan. Now on his 7th year in the crypto media space, he covers major cryptos, altcoins, DeFi, stablecoins, macro trends, and emerging tech.
















