Quantum computing is increasingly framed as a looming break in the cryptography that underpins major blockchains, but one overlooked risk is operational: an attacker may not need to hack exchanges or wallets in the usual way. Instead, a sufficiently powerful quantum computer could derive private keys directly from public data on-chain, enabling theft without triggering clear evidence of a โcryptographic break,โ according to Christopher Smith, CEO and co-founder of blockchain security startup Quantus Network.
Smithโs comments highlight why so-called โQ-dayโ โ the moment when quantum machines can realistically defeat widely used public-key systems โ could look less like a dramatic breach and more like confusing, untraceable losses. Combined with rapid progress in quantum-related research and algorithmic improvements, the discussion is shifting from whether quantum attacks are possible to how quickly they may become practically actionable.
Key takeaways
- Quantum attacks may be hard to detect because compromising keys via public information could leave little or no forensic trace of โhowโ funds were stolen.
- Early targets might not be the most famous holdings; researchers point to high-value administrative keys and hot-wallet access as more likely first moves.
- Estimates for when quantum systems can break elliptic-curve cryptography vary widely, with uncertainty still high across industry leaders.
- Several teams are already preparing post-quantum signature migrations, reflecting a view that waiting for certainty is not an option.
Why quantum theft could evade traditional incident response
In conventional attacks, a breach often leaves cluesโmalware, compromised systems, exposed credentials, or unusual access patterns. Smith argues that a quantum-enabled key derivation would be different. โWhen someone cracks your key, you donโt get a memo saying how they did it,โ he told Cointelegraph.
In his scenario, an attacker could use the public keys available on-chain to infer the corresponding private keys using quantum computation, then move funds without necessarily breaching the victimโs internal infrastructure. This creates a high-stakes detection problem: even well-run organizations might only discover the problem after funds have already been drained, while forensic teams see no โbreachโ in the traditional sense.
Smith described this as potentially producing a confusing outcome where โthe only forensic evidence would be that there was no breach.โ For investors, exchanges, custody providers, and institutional operators, that distinction matters: if incident response teams are trained to look for signs of intrusion, they may need new playbooks designed around cryptographic compromise rather than system compromise.
What attackers might go after first
The public debate around Q-day often centers on Bitcoin and the fear that dormant holdings could suddenly become vulnerable. Cointelegraph notes that Satoshi Nakamotoโs estimated holdings are often cited in the tens of billions, with one reference in the report placing the figure at $63 billion at the time of writing. Smithโs framing, however, suggests the first targets might be different and could be driven by attacker economics and operational convenience rather than symbolic value.
He argued that state-grade targets could be prioritized, pointing to โmilitary systems and state secrets.โ Within crypto specifically, he suggested that the highest-value keys might be operational or administrative rather than widely celebrated. โIf Iโm focusing on blockchain, whatโs the single most valuable key? Itโs probably Tetherโs minting key,โ Smith said.
His reasoning is that a quantum-capable attacker might mint tokens from an administrative wallet and sell into the market before the issuer can fully react. The report further notes that USDT is multi-chain and that some networks supporting its issuance are already working on post-quantum migration efforts.
Security researcher Sean Cheetham from Blockchain Capital added another angle: rather than aiming at the most famous cold wallets, attackers could focus on hot wallets at exchanges. In his view, those targets are more likely to avoid triggering alarm bells because their access patterns can resemble ordinary operational risk.
Smith also described an alternative tactic: a quantum-enabled theft could be disguised through plausible deniability. He suggested an attacker might present the incident as an ordinary loss of keys, using the uncertainty of how the keys were compromised to reduce the chance of immediate escalation.
How the timeline for Q-day keeps slipping and sharpening
One reason Q-day remains difficult to plan for is that timelines are unsettled. The report highlights recent developments that have compressed estimates for when quantum machines could attack elliptic-curve cryptography.
It points to a March update in which Google accelerated a post-quantum migration timeline to 2029, citing an AI-assisted breakthrough indicating elliptic curve cryptography could be cracked with fewer physical qubits than previously thought. Cointelegraph also attributes an explanation for why forecasts may have missed the mark to the parallel growth of AI-assisted approaches to quantum problem-solving.
Still, consensus is lacking. Smith, whose company is building a blockchain network intended to be quantum-resistant from launch, said there is a โ50-50โ chance the capability arrives by 2028, while Cheetham expects the early 2030s as โalmost a certaintyโ and frames an earlier arrival as a trailing probability.
Michael Coates, chief information security officer at the Solana Foundation, declined to give a precise estimate during an earlier interview, saying โthereโs no way to know,โ while noting that industry discussions have often treated quantum timelines as โfive years awayโ for much longer than a decade. He added that while uncertainty should temper prediction, it should not delay action.
Across these views, the common theme is not a shared date but a shared urgency: improving forecasts may be faster than compliance cycles and security migrations, so teams are trying to reduce dependency on assumptions.
Post-quantum migrations are already becoming the default security posture
Even with timeline disagreement, the report emphasizes that blockchains are not waiting for a clear verdict. It quotes NGRAVE CEO Roy Blackstone arguing that threat models have underestimated how quickly AI could advance alongside quantum technology, but regardless of exact timing, the migration work is underway.
Smith said Quantus is focused on launching a blockchain designed to be quantum-resistant from the outset, reflecting a โbake it inโ approach rather than a last-minute retrofit. Blackstone similarly stressed that damage would be โcatastrophicโ if systems did not migrate, and that blockchains have begun shifting toward post-quantum signatures.
For market participants, this creates a different way to think about quantum risk. Instead of treating Q-day as a single future cliff, readers may need to evaluate how resilient different networks are todayโparticularly whether they rely heavily on legacy public-key schemes, and whether migration strategies are actively implemented across critical components.
What to watch next is less about a single predicted year and more about measurable migration progress: whether major ecosystems complete post-quantum signature adoption in a verifiable way, and whether security teams update incident response procedures to account for cryptographic compromise that may not look like a conventional breach.






