Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIIntegrationsNewsEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto Gaming24h ReportPress KitAPI Docs
CoinStats

Ethereum and Quantum Computers: Are Your ETH Affected?

bullish:

0

bearish:

0

No, your ETH are not in danger today, and you do not need to move anything. On September 7, 2026, the Ethereum Foundation announced that Ethereum L1 should become quantum-resistant by December 2029. That is a deadline for developers rather than a warning to holders. What counts for you is a different fact, one that appears in none of the reports on this decision: every Ethereum account that has ever sent a transaction disclosed its public key in doing so. That is exactly what the risk hangs on, and exactly where Ethereum differs from Bitcoin.

This piece sets out what the decision actually says, which keys are at risk, what holders, stakers and rollup users can check today, and why one widely repeated piece of advice from the Bitcoin world simply misses the mark on Ethereum.

What the Ethereum Foundation decided on September 7, 2026

The Ethereum Foundation's protocol cluster, meaning the group inside the foundation that works on the network's base layer, has committed to a goal under the title "EF Protocol: Current and Emerging Priorities". It states that the aim is for Ethereum L1 to become quantum-resistant across all three layers: execution, consensus and data availability. The date set for that is December 2029.

Three qualifications belong with it immediately, and they have been lost in much of the coverage. First, this is a self-imposed deadline set by a foundation. The foundation writes in its own text that it is "non-negotiable at least until January 2027", after which the state of quantum research will be reassessed with outside experts. Second, the foundation does not determine the direction of the protocol; upgrades are decided by the client teams and the open All Core Devs calls. Third, the foundation itself calls the assumed arrival of a cryptographically relevant quantum computer in 2030 a "deliberately aggressive assumption" and adds that most credible estimates fall later, some very much later, and that this point may never arrive at all.

The decision says nothing about the ETH price. It is a plan for developing an encryption scheme, and it is no market event.

Can quantum computers steal your ETH today?

No. The foundation's post-quantum team describes the state of the hardware soberly: to break elliptic curve cryptography, a machine would need thousands of stable logical qubits and permanently error-corrected operation. A logical qubit is not a single component: it consists of many error-prone physical qubits that together form a computing element stable enough for long enough to carry a calculation. Today's machines are far below that. Most technical roadmaps place cryptographic relevance in the early to mid-2030s.

The attack in question is called Shor's algorithm: a quantum method that derives the matching private key from a known public key. The foundation names the consequence plainly: stolen balances and identity abuse. The chain's past is out of scope. Transactions already confirmed and blocks already finalised remain valid, and nobody rewrites chain history with this.

Why the public key on Ethereum is almost always exposed

Here is the point at which most coverage passes your actual question by. The quantum risk does not attach to the coin; it attaches to whether the public key of an address is known. As long as only the address exists, Shor's algorithm has nothing to work on.

An Ethereum address is derived from the public key and does not reveal it by itself. But as soon as the account signs a transaction, the signature sits on the chain, and the public key can be reconstructed from it. The foundation puts it in its FAQ without hedging: every account that has ever executed a transaction has an exposed public key. That applies to ordinary accounts, known as EOAs, whose keys rest on the ECDSA scheme over the secp256k1 curve.

The decisive difference from the balance of a Bitcoin address: on Ethereum the balance stays on the same account after sending. Key exposed and money still sitting there is the normal case on Ethereum, and hardly the exception.

Two steel safe deposit boxes in a dark vault wall: on the left the door stands open with a brass key still in the lock, on the right it is closed, with a silver coin bearing a diamond-shaped stamp in front of each
An account that has already sent once resembles the box on the left: the key is lying visibly in the light, while the balance is still behind it.

What that means compared with Bitcoin: 0.1 percent instead of 5 percent

For Bitcoin, on September 5 we took apart which addresses disclose their public key: essentially old P2PK holdings and reused addresses. For Ethereum, the foundation turns the comparison around itself in its FAQ. On Bitcoin, it says, around 5 percent of the supply is tied to early address formats that are widely considered abandoned, including roughly a million BTC attributed to Satoshi Nakamoto. The comparable share of permanently dormant holdings on Ethereum, meaning holdings presumably lost for good, is closer to 0.1 percent. That is the foundation's own estimate rather than a measured figure.

An inversion follows from this that only becomes visible on a second look. On Ethereum the share of lost holdings is small, which is why the foundation regards the option of ultimately doing nothing at all as more workable than on Bitcoin. At the same time the share of accounts with an exposed key is far larger on Ethereum. The risk is therefore spread more evenly, and the migration correspondingly broader: it concerns a great many active accounts instead of a bounded legacy stock. What should happen to balances that are never migrated is explicitly a question of network governance rather than a technical one, and opinions in the community diverge widely.

Which keys are really at risk: the post-quantum group's ranking

The post-quantum team ranks the attack surfaces by priority in its FAQ, and that order is more useful to you than any general threat assessment.

  1. Ordinary user accounts (EOAs). The largest store of value, public keys exposed after the first transaction.
  2. High-value operational keys. Exchanges, bridges between blockchain networks and custodial hot wallets concentrate a great deal of value behind a handful of keys.
  3. Governance and upgrade keys. Multisig accounts that steer entire protocols.
  4. Validator keys. These concern participation in consensus, but hold no balances themselves.

The foundation names the shared pattern as a concentration of value or control behind exposed, long-lived keys. Important for context: this does not put every ETH equally in the line of fire. How heavily a scenario weighs depends on how far the migration has progressed by the time the hardware is ready.

For you as a holder that means: if your ETH sits on an exchange, your risk hangs on point two and therefore on somebody else's operational keys rather than your own. That is one more argument for self-custody, independently of the quantum question.

What stakers can check on their withdrawal credentials now

Validators sign with BLS keys, a different scheme from the one used by ordinary accounts. That scheme also rests on elliptic curves and is therefore vulnerable as well. It becomes concrete with the withdrawal credentials, meaning the entry that says where a validator is allowed to pay out its balance. Old deposits still carry the 0x00 format there, which is bound directly to a BLS key. Newer formats point to an ordinary execution address instead.

In the Hegotá fork, EIP-8365 is up for a decision, a proposal meant to retire exactly these legacy credentials. The foundation writes that this work can begin without waiting for the full post-quantum design of consensus. Anyone staking should therefore look today at which format their validator carries. How to do that we described step by step in our guide to checking validator credentials. If you delegate your ETH through a provider, the operator takes on this check for you; the details still belong among the things you should ask about when choosing a service.

The roadmap to December 2029: Glamsterdam, Hegotá and five hard forks

A hard fork is a network upgrade in which all client teams switch to new rules at the same time. The foundation does its own arithmetic in its text: if Glamsterdam arrives in December 2026 and full quantum resistance is meant to stand five hard forks later in December 2029, that works out to an average cadence of 7.2 months per fork. It writes itself that this timetable is "quite aggressive" and leaves little room if a fork takes longer than assumed a year in advance.

For the case where things get tight, there is a fallback marker called MV-PQ, a minimum viable level of quantum resistance meant to carry the network through the crunch with reduced guarantees. The intermediate stages sit on the post-quantum group's roadmap: a registry for quantum-safe public keys in fork I*, building blocks for quantum-safe signatures on the execution layer in fork J*, quantum-safe attestations only after that. About Hegotá, the next fork after Glamsterdam, the foundation writes one sentence that sums up the whole situation: Hegotá is not itself the quantum fork; it is the fork that decides whether the quantum forks arrive on time.

The deadline, incidentally, is not plucked from the air: December 2029 sits on the same line as the 2029 migration targets that Google, Cloudflare and Microsoft have set independently of one another for their own systems. Anyone accusing Ethereum of trailing the rest of the technology industry here is measuring against the wrong yardstick.

Why the consensus layer is harder to convert than the execution layer

The two layers get deliberately different treatment, and that explains why on one side you will soon be able to act yourself and on the other you will not.

On the execution layer, where your accounts and transactions live, the foundation is banking on cryptographic agility: the ability to swap signature schemes without needing a separate hard fork for every new one. What makes that possible is native account abstraction, in which an account brings its own rules for verifying a signature. EIP-8141, the proposal earmarked for this, is meant to give accounts a protocol-native route away from the vulnerable secp256k1 keys. That is the reason the switch is intended to run gradually and voluntarily for users, instead of as a cut-off date on which everything tips over at once.

On the consensus layer that does not work. Its cryptography can only be changed by hard fork, and the aggregation of many signatures into a single one, which BLS delivers today, has no finished counterpart in the quantum-safe world. The foundation is working there on hash-based signatures under the name leanXMSS, on a Rust implementation, and on aggregation over a minimal zero-knowledge machine. An executable specification called leanSpec is, according to the foundation, already being used by around ten client teams for their quantum-safe consensus clients. The price of these schemes is larger signatures and more expensive verification, which loads bandwidth, storage and ultimately the efficiency of the whole network. That is why the consensus layer will first be hardened and then rolled out, instead of appearing building block by building block.

Close-up of a cylindrical cooling unit made of gold-coloured ring plates and frosted copper coils, with a silver coin bearing a diamond-shaped stamp in the foreground
The machine all the deadlines are aimed at: to attack today's signatures it would need thousands of stable logical qubits.

What "harvest now, decrypt later" means for your coins

The term describes the strategy of collecting encrypted data today in order to decrypt it later with better hardware. In connection with crypto it is constantly misused, and the foundation clears up precisely that: blockchains are primarily integrity systems resting on signatures, not on secrecy. Recording transactions today lets nobody later undo past payments or clear out old balances.

Where collecting very much does count is everything encrypted around the ecosystem: private communication, systems for confidential transactions, custody infrastructure and sensitive data off the chain. For your ETH the rule is this: the risk lies in the future, and none of it lies in the past. It only arises at the moment a sufficiently powerful machine exists, and it then hits accounts whose keys have not been migrated by then.

What happens to tokens, NFTs, DeFi positions and rollups

Tokens, NFTs and positions in applications exist as entries in contracts that point to your account, and not as keys of their own. Those entries therefore hang on exactly the same key as your ETH. Migrate your account and the rest travels with it; fail to do so and everything stands in the same risk together. No separate treatment is needed for it.

With rollups, meaning chains that bundle their transactions and hand them to Ethereum for security, vulnerabilities of their own are added. The foundation names four: the operational keys of the sequencer and of administration, the bridges and cross-chain messaging, the user accounts themselves, and, in zero-knowledge rollups, the proof system. The pattern is the same as above. It gets dangerous wherever few keys control a lot of value. If you hold larger balances on a rollup, that is the point at which you should watch for announcements from the operator in the years ahead.

What you can do today, and what you should leave alone

First things first: there is currently no technical reason to move balances around, sell coins or switch to another network. The foundation warns explicitly in its FAQ against rushing into an immature scheme, because that can create more risk than it removes.

What genuinely helps is unspectacular. The decisive thing is that you are able to act at the moment an official migration path exists. That presupposes that you have control over your keys and do not lose it. A balance whose seed phrase nobody can find any more cannot be migrated either, and holdings of exactly that kind end up in the debate about frozen coins. If your keys sit today on a computer that is also used for browsing, moving to a device that does nothing but sign is the one step worth taking regardless of the quantum question. Which devices manage that, and how they differ, is set out in our hardware wallet comparison.

One piece of advice from the Bitcoin world does not carry over to Ethereum, though: there the recommendation is to use every address only once, so that the public key stays hidden. On Ethereum that achieves nothing once an account has sent, because the key is exposed by then and the balance stays on the same account. Pushing your ETH into a fresh address reveals the old key when you send anyway and merely produces costs.

How to spot scams that use the quantum argument

Every big headline on this subject brings a wave of messages urging an immediate "quantum-safe migration". Three features give them away reliably. First, they manufacture time pressure, while the real roadmap runs over years and will be reassessed in January 2027 in any case. Second, they demand that you enter or upload a seed phrase, which no legitimate upgrade will ever need. Third, they arrive through channels nobody uses for protocol upgrades, such as a direct message or a promoted search result.

The reliable counter-check takes two minutes: the foundation's post-quantum work runs openly and publicly, with specifications, code and minutes. What is not documented there is no upgrade.

Checking Ethereum's quantum risk: what to take away

  1. Stay calm and sell nothing. The decision is a development goal for December 2029, not an alarm. Use the time instead to put your custody on a clean footing; the differences between software and device-based solutions are set out in the software wallet comparison.
  2. Make sure you can act. Check whether you store your seed phrase securely and can find it again, and whether you sign a transaction on a device that is not online at the same time. Suitable devices are compared in the hardware wallet comparison.
  3. As a staker, establish the format of your withdrawal credentials. Old 0x00 credentials are the part of the quantum question where you can already change something concrete today. Anyone staking through a service provider checks that provider's details and will find the providers in the comparison of staking platforms.

Sources for further reading: the announcement by the EF protocol cluster of September 7, 2026 and the overview from the Ethereum Foundation's post-quantum group.

(As of September 11, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.