G7 Urges Immediate Action on Quantum Risk as Crypto Ecosystem Considers Long-Term Fixes
Table of Contents
You might want to know
Could encrypted data captured today become readable if powerful quantum computers arrive in the future?
How are major blockchain projects preparing to defend wallets, signatures, and transactions against quantum threats?
Main Topic
The Group of Seven (G7) cybersecurity working group has issued a clear call to action: organizations across both public and private sectors should begin migrating to post-quantum cryptography (PQC) without delay. The warning stems from growing confidence that quantum computing advances could eventually enable adversaries to break many widely used public-key cryptographic algorithms. Because attackers can collect and archive encrypted data now, that data could later be decrypted if sufficiently powerful quantum machines are built. The G7 framed this as both a security and an economic risk that demands early, coordinated responses.
The report emphasizes that the timing of quantum capability breakthroughs remains uncertain, but recent technical progress makes the threat plausible enough to justify planning and mitigation. Public-key schemes that underpin secure internet communications, authentication, and digital signatures are particularly vulnerable. If quantum computers reach the scale needed to run algorithms such as Shor’s algorithm effectively against widely used keys, they could decrypt previously captured traffic, forge digital signatures, and enable impersonation—exposing sensitive information across supply chains and critical systems.
Recognizing these risks, the G7 recommends rapid adoption of PQC standards and practices that can resist both classical and quantum attacks. Migration to PQC is not simply a technical upgrade for isolated organizations; it is a collective, system-wide transition that requires early engagement between governments, industry stakeholders, standards bodies, and vendors. Coordinated planning can reduce fragmentation, avoid incompatible deployments, and ensure interoperability across networks and services.
One practical reason for urgency is the long lead time involved in large-scale cryptographic transitions. Systems that require interoperability across many actors—financial networks, supply chains, cloud services, and communications infrastructure—often take years to update securely. The G7 report urges organizations to identify critical systems, catalogue assets that rely on vulnerable cryptography, and prioritize migration during planned upgrade cycles to manage costs and reduce operational disruption.
Cryptocurrencies and blockchains are explicitly affected by the same class of public-key cryptography that the G7 highlights. Although existing, commercially available quantum computers cannot yet break the cryptography used by major blockchains, the potential for future quantum attacks has motivated developers to explore post-quantum defenses. Because blockchain addresses, wallets, and transaction authorizations rely on cryptographic signatures and key pairs, archived transaction data and recorded public keys could be at risk if a quantum adversary were later able to recover private keys.
Different blockchain projects face distinct migration challenges. Bitcoin, for example, uses a governance model that emphasizes decentralized consensus for protocol changes. Implementing PQC-compatible signature schemes on Bitcoin would likely require broad agreement among developers, miners, exchanges, wallet providers, and users. Proposals such as BIP-360 aim to add support for new signature types, but any transition must also enable holders to move funds from vulnerable addresses safely. This complexity, coupled with the need to preserve backward compatibility, makes the Bitcoin transition path potentially long and delicate.
Ethereum developers and researchers are actively designing replacements for cryptographic components that underpin accounts, validators, and smart contract interactions. Some suggestions include redesigning contract deposit logic and other protocol elements to accept the larger keys and different formats typical of post-quantum schemes. These redesigns require careful evaluation of performance, gas costs, and ecosystem upgrade mechanisms.
Solana may offer a comparatively smoother migration route in some respects because it uses EdDSA-style signatures; researchers have experimented with post-quantum signature alternatives and tested options on test networks. The Solana Foundation has also trialed an optional hash-based vault to protect funds, demonstrating how layered defenses can reduce near-term exposure while migration pathways are developed and standardized.
The G7’s recommendations extend beyond technical guidance. Governments should support PQC research, foster public–private partnerships, and integrate quantum security considerations into procurement policies. National strategies can help coordinate investments, provide clarity to vendors, and incentivize adoption. The report also encourages adding quantum-security criteria to procurement and upgrading cycles so organizations can align security investments with regular refresh schedules rather than incur excessive one-off costs.
Operationally, the report advises organizations to perform inventories of cryptographic dependencies, classify data according to sensitivity and retention requirements, and apply mitigation strategies for high-risk holdings. These strategies include accelerating migration for data that is most valuable or sensitive, employing hybrid cryptographic approaches during transition periods, and increasing monitoring for signs of quantum-enabled reconnaissance or targeted data harvesting.
Finally, the G7 highlights the need for international collaboration. Because digital ecosystems and supply chains cross national borders, a piecemeal approach risks leaving weak links that can be exploited. Coordinated standards, shared threat intelligence, and joint exercises will help build resilience and reduce the time needed for a global shift to quantum-resistant cryptography. The group concluded that the transition to PQC is foundational to securing a resilient digital future and that collective action is required now to avoid costly consequences later.
Key Insights Table
| Aspect | Description |
|---|---|
| Immediate Recommendation | Start migrating to post-quantum cryptography and plan coordinated transitions. |
| Risk Rationale | Encrypted data collected today could be decrypted in the future by quantum computers. |
| Impact on Blockchains | Wallet keys and digital signatures are vulnerable; projects are testing PQC upgrades. |
| Suggested Actions | Inventory cryptography, adopt PQC in upgrades, support research and public–private efforts. |
| Coordination Need | International and cross-sector collaboration required to ensure interoperability and resilience. |
Afterwards...
Looking ahead, organizations should treat PQC migration as a long-term program rather than a single technology swap. Early planning, pilot deployments, and participation in standards efforts will reduce disruption and cost. For the cryptocurrency ecosystem, staged approaches that combine hybrid cryptographic techniques, user migration tools, and backward-compatible protocol hooks can help manage the transition. Governments can accelerate progress by funding research, mandating quantum-aware procurement, and enabling information sharing between public and private sectors. Collective foresight and coordinated action today will determine how effectively digital systems withstand the arrival of practical quantum computing.