The U.S. Department of the Treasury has announced the launch of the Quantum-Readiness Task Force in accordance with President Donald J. Trump's Executive Order 14412.
The Task Force will bring together the public and the private sector to prepare for quantum-related cyber risks.
“Quantum computing holds significant promise, but it also presents a serious long-term challenge to the cryptographic tools that underpin the U.S. financial system,” said Treasury Assistant Secretary for Financial Institutions Luke Pettit.
July Milestone: Successful completion of the TestNet migration to the official Ethereum execution client
Our primary objective this month was clear: migrate the QAN TestNet to the official industry-standard Ethereum execution client while remaining compatible with our previous implementation without compromising our unique quantum-secure features.
The engineering team has not only completed the migration to the official Ethereum client but has also proven that QANplatform can operate seamlessly on a standard Ethereum infrastructure while retaining the full power of the QAN Virtual Machine (QVM) and QAN XLINK.
Read the full technical deep dive on our blog (link in comments) 🔗👇
Validators across most major chains are upgrading their hardware, faster CPUs, more bandwidth, better cooling. Ask any of them why, and you'll get an answer about transaction throughput.
Nobody's upgrading for signature size. ML-DSA signatures run roughly 37x larger than ECDSA. That number doesn't fit in the mempool assumptions, block layout, or fee market any of these upgrades were designed around.
So the industry is buying faster hardware to solve a problem it hasn't diagnosed yet, and calling it optimization.
65%.
That is the estimated share of Ether held in quantum-exposed addresses making them potentially vulnerable to a quantum attack the moment sufficiently powerful hardware arrives.
No warning. No opt-in.
With QANplatform, your address is never the weak link, it's secure by design from genesis.
The architects of the most secure identity system ever built have never modeled for Q-Day.
Governments, banks, and hospitals are building the next generation of digital identity on blockchain.
The promise is compelling. No more centralized password databases as the single point of breach. Your identity credential is yours. Cryptographically signed. Anchored to a distributed ledger. Verifiable anywhere, by anyone, without asking a central authority for permission.
It is a genuinely elegant solution to a genuinely broken system.
Here is the flaw nobody is writing about.
The architecture of Decentralized Identifiers, DIDs, the technical standard that underpins most enterprise blockchain identity systems, is built on the same cryptographic primitives as every wallet you already know is vulnerable.
Your identity credential is issued by a signing authority. That authority uses a private key. The corresponding public key is written to the ledger. Anyone can verify your credential by checking the signature against the public key on-chain.
It is clean. It is trustless. And in public ledger-anchored DID systems, the dominant deployment pattern in enterprise and government identity infrastructure, it exposes the public key. Permanently.
Now add one more layer that most commentary skips entirely.
Your credential itself, your digital passport, your KYC record, your professional license, your healthcare authorization, carries a timestamp. It was signed at a specific moment. That signature, and the public key used to verify it, lives on a public ledger indefinitely.
Adversaries are already collecting this data today. Not to use now. To use later, once quantum capability arrives. Researchers call this Harvest Now, Decrypt Later archiving encrypted data today with the intent to break its confidentiality once quantum hardware matures.
But there is a second quantum threat model that is less discussed and more directly dangerous for identity systems.
It is called Trust Now, Forge Later.
In the TNFL model, the adversary does not target the contents of a credential. They target the signing key itself. A quantum computer running Shor's algorithm can derive a signing authority's private key directly from its public key which is already permanently on-chain. Once they hold the private key, they can issue entirely new credentials that carry a cryptographically valid signature, indistinguishable from legitimate ones.
The attacker does not rewrite the ledger. The ledger is immutable that does not change. What changes is your ability to trust what is on it.
Every credential issued under the compromised signing scheme, every digital passport, every KYC attestation, every healthcare authorization, now exists alongside forgeries that the verification system cannot tell apart. The identity infrastructure designed to eliminate fraud becomes the mechanism that enables it at a scale no centralized breach ever could.
Because a centralized breach steals records from one database. A Trust Now, Forge Later attack on a public identity ledger collapses the trust model for every credential ever issued under that signing authority. Not by altering what was written. By making it impossible to distinguish the real from the fabricated.
The enterprise blockchain identity infrastructure being built right now is the most comprehensive, most permanently exposed, most difficult-to-patch identity system ever designed.
And most of its architects have never modeled for Q-Day.
Y2K had a hard deadline everyone could see on a calendar.
Q-Day has a deadline nobody can fix precisely.
One produced one of the largest coordinated infrastructure efforts in history. The other has mostly produced roadmap slides so far.
Important Update
Our Co-Founder & CTO has released an open letter addressing community feedback and reinforcing our commitment to the MainNet launch this year.
Boards have approved blockchain deployments. Almost none have approved a quantum risk policy to go with them. That gap is becoming a liability.
Quantum risk is also a governance problem, not just a technical one.
On June 22, 2026, President Trump signed two executive orders affecting post-quantum cryptography and quantum innovation.
EO 1 ��� "Securing the Nation Against Advanced Cryptographic Attacks"
EO 2 → "Ushering in the Next Frontier of Quantum Innovation"
This is basically the U.S. government declaring that the quantum era has arrived. 🧵👇
It is a Thursday evening in 2030.
Marko, a backend engineer in Berlin is debugging a wallet recovery issue.
A user claims funds were moved without authorization. No phishing. No malware. No leaked seed phrase.
Just a valid signature.
Marko pulls the transaction.
It checks out.
Correct format. Correct curve. Correct verification path. From the protocol’s perspective, nothing is wrong.
But something is.
He traces the wallet history back.
First transaction: 2022.
The moment the public key was revealed on-chain.
After that, years of inactivity.
No rotations. No changes. Just a key sitting there, exposed, forgotten.
Until now.
He opens an internal thread. Someone mentions it quietly.
“Could be quantum-derived.”
No one replies for a minute.
Because if that sentence is true, even once, this is not an incident.
It is a pattern waiting to be found.
Marko looks at the verification result again.
The system did exactly what it was designed to do.
Accept a mathematically valid signature.
It just no longer knows who is behind it.
The myth
"Quantum-safe cryptography is just a stronger version of what we have."
The reality
It’s a completely different foundation.
Different math. Different key behavior. Different tradeoffs.
You’re not upgrading a component.
You’re replacing the ground it stands on.
And most systems were never designed for that kind of swap.
Two tech giants. One timeline: 2029.
Microsoft just unveiled Majorana 2: topological qubits that last 20 seconds (vs. 1-12 milliseconds in Majorana 1).
That improvement is roughly comparable to inventing a phone battery that instead of dying in a day could last for nearly three years on a single charge.
That's a 1,000x reliability leap, built with agentic AI.
Their practical quantum computer target? 2029, the original timeline cut in half.
Google independently set the same year as its internal deadline to complete PQC migration across all systems, warning that quantum computers could break current encryption before the decade ends.
When Microsoft AND Google converge on 2029, that's not a prediction. That's a countdown.
Every blockchain still running on legacy cryptography needs to ask: are you quantum-safe?
The migration window is closing.
There are two main positions on quantum risk to blockchain infrastructure.
One of them requires believing decentralized networks can coordinate a full cryptographic migration under time pressure with no central authority and no enforcement mechanism.
The other one requires starting earlier than feels necessary.
Both positions might seem defensible. But only one survives the reality of decentralized coordination.
Position A: The threat is already active.
"Harvest-now-decrypt-later" means data collected today is already compromised. Chains not building on post-quantum primitives are accumulating debt, not buying time.
Position B: The timeline is long enough for a retrofit.
"Hard forks happen. Ecosystems upgrade." Migration can wait. It is too expensive to over-engineer for a threat years away.
Here is the friction point:
Position B requires a massive bet on coordination.
It assumes that decentralized networks, which lack central authority, enforcement mechanisms, and contain millions of independent wallets, can execute a full cryptographic migration in a compressed window under pressure.
History suggests this is the hardest thing a decentralized network can do.
The industry has mostly let Position B win by default, simply because it is the path of least resistance.
So, a direct question for the builders:
If a protocol must be secure in 2030:
Is it a viable strategy to bet the project's survival on a forced hard fork that requires 100% of the community to coordinate perfectly at the last minute?
Or is the only safe path to build on infrastructure where quantum resistance is native, not retrofitted?
The blockchain industry has metrics for throughput, latency, and finality. It has no metric for developer onboarding friction.
There are metrics the blockchain industry tracks obsessively.
Transactions per second. Block time. Finality. Speed.
Dashboards everywhere. Real-time graphs. Leaderboards.
You know what nobody tracks?
How long it takes a developer to go from "I want to build on-chain" to "I have something deployed that works."
Not the tutorial. The real path. The one with the broken RPC endpoints, the documentation that describes a version nobody runs anymore, the error messages that assume you already know what the error means.
And when you actually ask developers what that journey looked like, the answers are quietly impressive. Not because it was easy. Because they pushed through something that was genuinely hard, and built something real anyway.
The tooling in Web3 is good now in the places that got attention. Wallets, bridges, DEX interfaces.
It is still a maze in the places that matter most. The parts that touch new builders. The onboarding layer. The moment someone capable decides whether the ecosystem is worth their time.
Most of the people who made it through never complained loudly. They just adapted, documented, helped the next person, and kept building.
The developers who are in Web3 earned it. The ones who could have been in Web3 just decided their time was worth more than the friction.
Both of those things are true at the same time.
Every transaction you have ever signed on-chain left a message in a dead language.
Permanently public. Permanently recorded. Safe, because no one could read it.
Shor's algorithm is the translation key.
The messages did not become vulnerable on Q-Day. They were written vulnerable. The translator just had not been built yet.
Everything signed before the quantum transition is archived and waiting.
He built a legal practice on one promise: that anchoring agreements to a blockchain made them the most cryptographically verifiable contracts ever written.
He was right. Until it turned out the math underneath them had an expiration date.
It is a Friday afternoon in 2028.
Daniel is a law firm partner. Between 2020 and 2023 he built an entire practice around anchoring legal agreements to public blockchains. Immutable. Timestamped. Cryptographically verifiable. He gave talks. He wrote papers. He brought in fourteen enterprise clients.
He is staring at an email from the firm's new cryptographic security consultant.
The summary is this:
Nearly every agreement anchored on-chain during those years was signed with ECDSA. The public keys are permanently recorded on the ledger. And in a post-quantum world, where quantum computers can break elliptic curve math, a sophisticated adversary could forge a signature mathematically indistinguishable from the original. Not altering the document, but destroying the ability to prove beyond doubt who signed it.
Daniel's entire practice was built on one promise.
We can prove who signed what, and when, beyond any reasonable doubt.
He reads the consultant's recommendation.
"Review evidentiary reliance on pre-2024 on-chain signatures before introducing them in any proceedings."
He picks up the phone to call the first client on the list.
He puts it back down.
He picks it up again.
In 2017, Vitalik Buterin named the problem every blockchain builder lives with.
The Trilemma. Security. Scalability. Decentralization. Pick two. You cannot fully have all three at once. Every L1 architecture ever built is essentially a bet on which one to sacrifice. 🧵
April Milestones: Enterprise-Ready Architecture, macOS Launch, and SDK Maturity
April marked a definitive turning point for QANplatform. Following in-depth strategic planning, we aligned our engineering roadmap with the rigorous demands of our upcoming government and enterprise partners. We celebrated full cross-platform availability with the macOS release of QAN XLINK and made significant strides in SDK maturity across Go, Python, Java, and more.
Read the full recap on our blog, link in the comments 🔗👇
Tiffany has priced cyber risk for eleven years. Ransomware. State-sponsored breaches. AI exploits.
She had never declined to quote. Until she tried to count the public keys.
It is a Monday morning in 2029.
Tiffany prices cyber risk for a living. Eleven years in. She is not easily surprised.
The application on her screen is from a crypto exchange. They want quantum-transition liability coverage for the eighteen months it will take them to complete their migration. She has seen six of these this month alone.
She opens their cryptographic asset inventory. Active wallets, signing infrastructure, hot wallet architecture. All migrated or in progress. Clean.
Then she scrolls to the section the exchange marked low priority.
Historical transaction records, 2017 to 2024.
She pulls the number of unique public keys ever broadcast by users during that window. A public key exposed every time someone made a withdrawal. Every time anyone signed anything on-chain. All of it permanently sitting on public ledgers the exchange does not own, cannot modify, and cannot take down.
Keys they were never authorized to rotate. Belonging to users who have since left, lost access, or simply do not know this conversation is happening.
She looks at the number.
Forty-one million.
Not forty-one million dollars of exposure. Forty-one million individual cryptographic attack surfaces. Each one a direct mathematical path to a private key. Each one permanent.
She types one line into the file.
"Decline to quote. Unquantifiable tail risk. Historical on-chain exposure falls outside any actuarial model currently available."
Then she opens the next application. A different exchange. Larger.
She already knows what she is going to find.
Elliptic curves for anyone to understand.
You pick a point on a curve. You multiply it by a secret number to get a new point. That new point is your public key. The secret number is your private key. Multiplying is easy. Reversing the multiplication is hard. A quantum computer makes it not hard.