The quantum reckoning

Quantum will break most chains. Starknet has been waiting for it.

Governments, Big Tech, and researchers are increasingly converging on the same timeline for when quantum breaks today's cryptography. When it arrives, nearly every onchain wallet is exposed. For most of crypto, this is a threat. For Starknet, it highlights the strength of its architecture.

The industry's converging deadline 2029

  • 847Days
  • 00Hrs
  • 00Min
  • 00Sec

Starknet will be ready before Q-day

01

Money and mandates converged on quantum.

The catalyst

States started taking equity.

For decades, government support for quantum computing meant research grants and patient science. In the span of a few weeks in spring 2026, that posture changed in nature: equity stakes, national programs, and the first hard regulatory deadlines.

March 17, 2026

UK ProQure

GBP 2B

The UK's national quantum program, part of a broader wave of sovereign quantum funding.

May 21, 2026

US takes equity

$2B

Letters of intent across 9 quantum firms, in exchange for minority equity. The federal government became, structurally, a venture investor in quantum.

May 22, 2026

France responds

EUR 1B

An immediate top-up of the national quantum strategy, announced by Macron at the CEA, in a speech naming the US and China as the only other countries with comparable technological breadth.

June 16, 2026

France targets a qualification deadline

2027

ANSSI, France's cybersecurity agency, says it aims to require post-quantum cryptography for security products entering its qualification scheme from 2027, and that buying products without it "will not be reasonable" after 2030. Its approvals are a de facto requirement for French government agencies and critical infrastructure operators.

July 9, 2026

Switzerland's regulator sets a date

8%

FINMA Guidance 05/2026 expects supervised institutions to have a post-quantum cryptography roadmap in place by mid-2027 at the latest. Its survey of 60 Swiss financial institutions found that only 8 percent have one today.

July 20, 2026

Israel opens a national quantum call

NIS 100M

The Israel Innovation Authority opens a call for proposals, worth 100 million shekels (roughly $33 million), to establish a national quantum computing R&D infrastructure integrating at least three different quantum processing technologies. Applications close October 8, 2026.

Private money made the same bet.

The state was not alone. Starting in September 2025, the industry's biggest names and funds committed capital at a scale quantum had never seen: record rounds, a vertical-integration acquisition, and the first real exit wave.

Then the state armed itself.

On June 22, 2026, the White House signed two quantum executive orders the same day. One launches a national effort to build a government-scale machine. The other orders an accelerated, government-wide migration to post-quantum cryptography.

Executive Order 14413 · June 22, 2026

Ushering in the Next Frontier of Quantum Innovation

“This national effort shall pursue development of a quantum computer at a scale intended to initiate the era of quantum-enabled scientific discovery, with the intent to deliver at least one such computer to a Department of Energy facility and, to the extent possible, make it available to the scientific community.”
Executive Order 14413 as published at whitehouse.gov: the presidential seal, the order number, and the authority formula, through “it is hereby ordered:”.Sections 1 to 3 omittedSec. 4(a): “This national effort shall pursue development of a quantum computer at a scale intended to initiate the era of quantum-enabled scientific discovery, with the intent to deliver at least one such computer to a Department of Energy facility and, to the extent possible, make it available to the scientific community.” Opens the full order in the Federal Register, 91 FR 38487. Sec. 4(a), the QC-ADDS Effort · 91 FR 38487
Executive Order 14412 · June 22, 2026

Securing the Nation Against Advanced Cryptographic Attacks

“It is the policy of the United States to safeguard national security and maintain technological leadership by responsibly and effectively executing the transition of Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography (PQC), and to assist critical infrastructure owners and operators with their transitions.”
Executive Order 14412 as published at whitehouse.gov: the presidential seal, the order number, the authority formula, and Section 1 in full, ending “It is the policy of the United States to safeguard national security and maintain technological leadership by responsibly and effectively executing the transition of Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography (PQC), and to assist critical infrastructure owners and operators with their transitions.” Opens the full order in the Federal Register, 91 FR 38483. Sec. 1, Policy · 91 FR 38483

Finally, three of the biggest names in quantum converged on a single year.

The three companies actually building the machines have independently pointed to the same date.

When states set compliance dates for quantum-resistant cryptography, presidents order the machine built and the defenses raised, and private capital commits billions in the same months, the risk profile has changed. And the biggest names in quantum have independently converged on the same year: 2029. That year is now a deadline.

02

Q-day, and the fault line it draws.

The threat

One key. Two machines.

Nearly every account in mainstream crypto is protected by the same lock: elliptic-curve signatures, the math that links your private key to your public address. Bitcoin and Ethereum both sign this way. Breaking that math with today's computers would take longer than any human timescale, and a quantum computer collapses it to hours.

So what happens the day a quantum computer finally reaches the exit? It holds your private key, and your funds are already gone. That is the exact risk sitting under most blockchains today.

Classical

Walks the corridors one by one, and keeps walking.

time 0.0scorridors walked 0

Quantum

Does not walk. It reads the maze and computes the exit.

time 0.00sidle
  • Elliptic-curve cryptography
  • Shor's algorithm
  • Your private key
  • Two machines

Safe every day, until one day in 2029.

A turkey grows more confident every day, fed and cared for, right up to Thanksgiving, the day it gets eaten. Every safe day made the turkey more certain the next one would be safe too. Most blockchains sit on the same curve: a lengthening track record of safety that proves nothing about the day the machine arrives.

Unlike the turkey, we can see the knife. And it is moving faster every year: the cost and the hardware needed to break these keys have been collapsing for over a decade, and every new paper brings the drop closer.

status secure confidence 0%
  • The turkey
  • Track record of safety
  • One day in 2029
  • We can see the knife

The cost of the attack is collapsing.

<500k

Fewer than half a million physical qubits: the March 2026 estimate for breaking secp256k1's elliptic curve, the one behind most crypto wallets.

Babbush et al., 30 Mar 2026

The pressure is not only from labs. September 2026: an open leaderboard where humans and AI agents compete to make one step of Shor's algorithm cheaper cut its score by 86% in months. Note that this is one step in the stack a quantum attack needs, the full stack is still far from cheap.

ECDSA.Fail, arXiv:2609.09582, 9 Sep 2026 · project site · code · read

Seven of the 36 authors work at StarkWare and the Starknet Foundation.

  • Conditional estimates
  • Physical qubits
  • RSA-2048
  • ECDLP-256

What breaks. What holds.

The Google and Ethereum Foundation paper (March 30, 2026) maps exactly what breaks: a whole ECDLP-256 circuit of ~1,200 logical qubits and 90M Toffoli gates, executable on fewer than 500,000 physical qubits.

The exposure is concrete. On Bitcoin, 6.9M BTC is vulnerable. On Ethereum, 20.5M ETH sits in exposed top accounts, with $200B in stablecoins behind admin keys.

The paper draws a sharp line between what a quantum computer breaks and what it cannot touch:

Quantum-vulnerable

  • ECDSA signatures (Bitcoin, Ethereum)
  • BLS consensus signatures
  • KZG commitments
  • Pairing-based SNARKs (Groth16, Plonk)
  • Optimistic rollups, sidechains

Quantum-safe

  • zk-STARK proofs
  • Hash-based commitments (BLAKE2)
  • Post-quantum signatures (Falcon, ML-DSA)

In the paper's March 2026 risk chart, zk-STARK is the only proving category not flagged as quantum-vulnerable by Google, and Starknet's proving system is named explicitly as resistant. The authors call the chart a point-in-time assessment.

The Bitcoin case

Bitcoin can be saved, at a price.

Bitcoin's signatures are ECDSA and Schnorr, and neither survives Shor. One published scheme gets around that without a soft fork: QSB, by StarkWare's Avihu Levy, replaces the quantum-vulnerable step of earlier designs with a hash-to-sig puzzle whose security rests only on the pre-image resistance of RIPEMD-160, roughly 118 bits even against Shor, inside Bitcoin's legacy limits of 201 non-push opcodes and 10,000 bytes. The first quantum-safe Bitcoin transaction ran on Bitcoin mainnet on 26 August 2026.

What it costs

StarkWare is explicit about what this is not: QSB does not make Bitcoin itself quantum-safe, and it would not help an address whose public key was already published. The paper estimates $75 to $150 of cloud GPU compute for the off-chain search behind a single transaction, and the transactions it produces are non-standard, so they never travel the ordinary mempool and need a direct path to a miner. It works, and it shows what quantum safety costs on a chain that was not built for it.

  • 1,200 logical qubits, whole ECDLP-256 circuit
  • 6.9M BTC
  • 20.5M ETH
  • $200B in stablecoins
  • zk-STARK proofs

03

Starknet will be ready before Q-day.

The head start

Chains are not starting this from the same place, and several are not starting from nothing: Ethereum publishes a post-quantum roadmap covering accounts, consensus signatures and its KZG commitments. The difference is what each has to replace. A chain whose proof system rests on elliptic curves has to change that proof system; Starknet's rests on hash functions, so its proving layer needs no migration, and Ethereum's own roadmap says as much about STARKs. What Starknet still owes is everything above that layer, which the rest of this section sets out.

The proofs were born post-quantum.

STARKs

STARKs rely on hash functions, not elliptic curves, which is why Shor's algorithm has nothing to attack. It comes from the original STARK paper co-authored by StarkWare's founders in 2018. Starknet's entire proving layer, the foundation every other layer on the network rests on and the most expensive part to change, never needs to migrate.

“The computational assumptions on which the security of these constructions is founded—the existence of collision-resistant hash functions [74] for interactive solutions, and common access to a random function (“the random oracle model” [50]) for non-interactive ones [85]—are not known to be susceptible to attacks by large-scale quantum computers; we call such solutions post-quantum secure.”Eli Ben-Sasson, Iddo Bentov, Yinon Horesh, Michael Riabzev · IACR ePrint 2018/046 · Sec. 1

One transaction, not a hard fork.

Native account abstraction

On Starknet, signature logic lives in the account contract, not in the protocol. Upgrading a wallet to post-quantum signatures is a single transaction by the user: no protocol change, no new address format, no network-wide coordination.

Most chains
  • Protocol-level hard fork
  • New address formats
  • Forced user migration
Starknet
  • Deploy a new account contract
  • Same network, same wallet interface, self-custody intact
  • One-transaction migration per user

WALLET / ACCOUNT CONTRACT

STARKNET STARK PROOFS: HASH-BASED, POST-QUANTUM BY CONSTRUCTION INTEGRITY AT Q-DAY SIGNATURE VERIFIERECDSASHOR-BREAKABLE SIGNATURE VERIFIERFALCON-512LATTICE
1 transaction migrationquantum-vulnerable

Post-quantum accounts are deployable on Mainnet today.

In April 2026 StarkWare announced S2morrow live on Starknet Mainnet, using Falcon-512. Three months later, on 22 July 2026, an OpenZeppelin Falcon-512 account executed a real transfer on Starknet mainnet, for a fee of 1.93 STRK, a few cents. Two teams wrote Falcon-512 accounts in Cairo independently, and neither needed the protocol to change: signature logic lives in the account, so shipping a post-quantum one takes nobody's permission. Simply put, quantum-safe accounts can be deployed on Starknet Mainnet today, and adopting one is a single transaction for the user rather than a migration for the network. Both accounts are proofs of concept for now: experimental, unaudited, and built for research and benchmarking rather than for holding funds. Wallet-level support is the next step: adopting a post-quantum account becomes one tap in a wallet you already use, with the same experience as the account you have today.

What remains is mapped, owned, and scheduled.

The head start does not cover everything. Here is every remaining cryptographic surface on Starknet: what it runs on today, what it moves to, who owns the change, and whether it is live, planned, research or somebody else's to migrate. Filter by status, and click any row for the details and its source.

All8 Live2 Planned3 Research1 External dependency2
SurfaceCurrentDesiredRoadmap statusOwner
STARK proverHash-based (no ECC)n/aLiveStarknet

The core proof system relies on collision-resistant hash functions, not elliptic curves, so it carries no quantum exposure. This is the layer that is normally the most expensive to change, and on Starknet it was never the problem.

State trie hashingPedersenBLAKE2PlannedStarknet

The contracts and storage tries commit state with Pedersen today. The published direction is BLAKE2, which would remove the ability to forge balance proofs and is also cheaper to prove than Pedersen.

Address derivationPedersenBLAKE2PlannedStarknet

Account and contract addresses are derived with Pedersen. Moving derivation to BLAKE2 would close a narrow window where an attacker could find a collision and slip a malicious contract into an address before it is funded.

OS program & config hashBLAKE2s-256BLAKE2s-256Live in v0.14.3Starknet

The OS program hash and the chain's environment anchor (chain ID, version, fee token) were hashed with Pedersen. Both moved to a BLAKE2s-256 construction in Starknet v0.14.3 and are live on Mainnet.

Consensus signingECDSAPost-quantum (e.g. Falcon-512)PlannedStarknet

Sequencer signatures use ECDSA. The published direction is a post-quantum scheme, named in the roadmap as one such as Falcon-512, in two steps: the signing layer becomes scheme-agnostic first, then sequencers rotate their keys.

Legacy storagePedersen (slot keys)BLAKE2ResearchStarknet

Contracts already deployed under Pedersen-derived storage keys keep working, but their internal key derivation would no longer align once the trie moves. Bringing them forward is research: StarkWare has described wanting a migration path for legacy deployments, and there is no public specification, no implementation, no released toolkit and no developer workflow.

secp syscallssecp256k1/r1 (ECDSA)TBDExternalEthereum

The Cairo VM's secp256k1/r1 syscalls support L1 to L2 messaging and the Ethereum bridge. They are quantum-vulnerable, and removing them depends on Ethereum migrating first, otherwise the bridge breaks.

Blob data availabilityKZG commitmentTBDExternalEthereum

State-diff data posted to Ethereum as blobs is anchored by a KZG commitment, which is quantum-vulnerable. A KZG compromise would affect data availability transparency, not state-transition soundness, which the STARK proof still protects.

Fallback Starknet's sequencer can already post state diffs as calldata instead of blobs, a switch that exists today for blob-price spikes and does not depend on KZG.Source Starknet docs, data availability, read
No surfaces in this category.

In February 2026, Prof. Scott Aaronson joined StarkWare's Scientific Advisory Board with a clear mandate: pressure-test this roadmap. Every assumption about what quantum computers can and cannot do, every cryptographic choice on the path to end-to-end resistance, now gets challenged by one of the foremost authorities in the field.

Scott Aaronson · Schlumberger Chair of Computer Science, UT Austin · Founding Director, Quantum Information Center

Prof. Scott Aaronson
The core of Starknet's quantum case.
THE THREAT01 · 1:13

Starknet's strength against the quantum threat, and what are the missing pieces

Watch
THE MIGRATION02 · 0:55

Starknet's seamless migration to post-quantum security

Watch
THE WHITE PAPER03 · 0:58

Post-quantum by design: the ZK-STARK white paper called it eight years ago

Watch
HOW LITTLE CHANGES04 · 1:12

How little Starknet needs to change to go post-quantum

Watch

Q-day

On the day the line is drawn for everyone, most chains will discover which side they were born on. Starknet already knows.