The G7 is urging states and companies to switch immediately to quantum-resistant cryptography. Its report of September 3, 2026 does not cite bitcoin, nor exchanges, nor the blockchain, but targets the brick on which each wallet depends: the public key signature, which a sufficiently powerful quantum computer can break.

In brief
- The G7 publishes “Preparing for the Post-Quantum Era” on September 3, 2026.
- The EU wants national transitions initiated at the end of 2026, with high-risk systems migrated at the end of 2030.
- Bitcoin and Ethereum are following distinct trajectories, with no activation date on the Bitcoin side.
An eight-page report that never talks about crypto
The document is eight pages long and contains no mention of “cryptocurrency”, “bitcoin” or “blockchain”. This silence does not mean that the sector is on the sidelines. Nine players, including BlackRock, Coinbase and Strategy, have already joined the Bitcoin Security Consortium to work on the subject.
“ Although the exact timeline is uncertain, several recent advances point to the development of quantum computers capable of breaking widely used public key cryptography mechanisms and threatening the security of digital infrastructure. », write the authors, managed by ANSSI for the French presidency of the G7.
The G7 is especially interested in a threat well known to specialists: “collect now, decipher later”. Encrypted data can be stored today and then decrypted when computing capabilities allow.
In the case of cryptos, the problem is a little different. Public keys and transaction history are exposed on the blockchain. A vulnerable signature cannot therefore simply be replaced after the fact. The question is how long a key will remain secure.
Brussels and Washington have already set dates
The G7 does not impose anything, the existing calendars do. The European roadmap of June 2025, adopted by the NIS cooperation group, requires member states to have taken their “first steps” before December 31, 2026 and migrated high-risk cases “by the end of 2030 at the latest”.
On the American side, the NIST IR 8547 project proposes to ban algorithms of at least 128 bits after 2035, and those of 112 bits from 2030. CISA, co-editor of the call, is pushing the same logic. However, Bitcoin’s secp256k1 curve offers approximately 128 bits and falls under the second deadline, not the first.
The constraint will come from calls for tenders and compliance: the G7 recommends integrating post-quantum cryptography into cybersecurity requirements and public procurement.
Bitcoin and Ethereum do not have the same timetable
On the Bitcoin side, BIP-360, known as Pay-to-Merkle-Root, creates a type of output that removes spending per Taproot key, the path exposed to quantum. First step assumed: rapid attacks on pending transactions would require post-quantum signatures, with no fixed activation date.
Ethereum aims broader. Published in February 2026, Vitalik Buterin’s roadmap identifies four building blocks to replace, from validator signatures to KZG commitments, for an infrastructure targeted for 2029, as detailed in our monitoring of Ethereum’s cryptographic choices.
The cost explains these cautions. An ECDSA signature occupies approximately 64 bytes, compared to nearly 4,627 for ML-DSA-87, a profile standardized by NIST: a factor of 72 per transaction. Google Quantum AI in March reduced its estimates for breaking ECDLP-256, under 500,000 physical qubits and a few minutes of calculation.
The challenge of the coming months is not Q-Day but governance: adoption of BIP-360, national roadmaps expected before the end of 2026, first post-quantum clauses in public markets. To judge these signals, understanding bitcoin and the protection of its keys remains useful.
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
