ch en false false Default
Marketing Communication

Q-Day Watch: What's Moved Since May

24 September 2026

In May we argued that 2026 could be the inflection point at which quantum computing crossed from theoretical threat to engineering reality, and that the crypto industry’s response, not the hardware itself, would be the story to watch. Four months on, both halves of that argument have advanced. The resource estimates for an attack have kept falling, governments have started treating error-corrected machines as procurement targets rather than research curiosities, and the two largest networks have moved from discussion toward concrete migration plans, with Ethereum now putting a key enabling upgrade on its formal schedule. Here is what has changed.

Hardware And Algorithms: The Target Keeps Moving Closer

In May the reference point was a set of early-2026 papers that cut the estimated cost of breaking the elliptic-curve cryptography behind Bitcoin and Ethereum by an order of magnitude, to well under 500,000 physical qubits. Since then the direction has not reversed:

  • Algorithmic cost continues to fall. Fresh academic work has published more efficient quantum circuits for attacking secp256k1 (the exact curve securing Bitcoin and Ethereum), trimming the qubit and gate cost further still. The engineering bar and the algorithmic bar are dropping at the same time.
  • Governments are now buyers, not just funders. A US Department of Energy request for information in May sought a fault-tolerant system in the range of 150–250 logical qubits by 2028. In June the DOE followed up with its “Quantum Genesis” initiative, including a competition with a $100 million incentive pool for a first-generation fault-tolerant system by autumn 2028. An error-corrected machine is now treated as something to acquire on a defined timeline.
  • Vendor roadmaps have pulled forward. Hardware makers continue to expand capacity and, in at least one case, project a cryptographically relevant machine as early as 2028, earlier than the central estimates we cited in May, though still well inside the range of serious disagreement.

None of this means a capable machine exists today. It does mean the “harvest now, decrypt later” logic (collect encrypted data now, decrypt it once hardware arrives) continues to strengthen the case for migrating early.

Bitcoin: From A Defence Proposal To A Migration Plan

In May the centrepiece was BIP-360 (Pay-to-Merkle-Root), which keeps public keys off-chain and protects new coins. The gap it left (the roughly one-third of all BTC sitting in addresses with already-exposed public keys) is now the subject of a companion proposal, BIP-361 (“Post Quantum Migration and Legacy Signature Sunset”), published to Bitcoin’s proposal repository in April by Jameson Lopp and co-authors.

BIP-361 is deliberately coercive, because voluntary migration alone cannot protect coins whose owners never move them. Its three phases would, in sequence: stop payments to quantum-vulnerable address types (on the order of three years after a quantum-resistant output type such as BIP-360 activates); invalidate legacy ECDSA/Schnorr signatures entirely (around five years); and (still at the research stage) let owners reclaim frozen coins using a zero-knowledge proof of their seed phrase. This crystallises the “freeze-or-steal” dilemma we flagged in May: with an estimated 6.5–6.9 million BTC exposed (including roughly 1.1 million coins attributed to Satoshi Nakamoto that will never voluntarily move), the network faces a genuine choice between freezing lost coins and leaving them to a future quantum attacker. It is as much a governance and property-rights question as a cryptographic one. As of September, both BIP-360 and BIP-361 remain drafts and no network-wide migration has been activated; Bitcoin’s slow governance remains the binding constraint.

Ethereum: The Coordinated Path Continues

Ethereum’s more centralised roadmap has kept progressing along the lines set out in Vitalik Buterin’s early-2026 plan, and has now taken a concrete step. The key enabling piece remains native account abstraction (EIP-8141, “Frame Transactions”), which would let wallets adopt quantum-safe signature types without forcing every user to migrate at once, the mechanism that makes an orderly transition plausible. At the end of August, core developers moved EIP-8141 to “Scheduled for Inclusion” in the Hegótá upgrade, planned for 2027 after the Glamsterdam upgrade expected in the fourth quarter of 2026. The specification is still a draft and can change before deployment. The working assumption is still a Layer 1 quantum-resistance window toward the end of the decade, with the steep gas cost of post-quantum signatures addressed through recursive proof aggregation.

Layer 2s And Other Networks: Migration Becomes A Scheduled Program

A notable shift since May is that post-quantum migration is starting to look like a dated engineering project rather than a research topic:

  • At the end of June, StarkWare published a three-phase post-quantum roadmap for Starknet. Its first phase replaces Pedersen hashing with BLAKE2 and introduces post-quantum signatures such as Falcon-512 to protect new on-chain activity, leaning on the native quantum resistance of its STARK proof system; later phases cover migration tooling for existing contracts and dependencies on Ethereum. It is a useful reminder that a Layer 2’s protection ultimately depends on the Layer 1 beneath it migrating too.
  • Solana’s core client teams, Anza and Firedancer, have independently converged on Falcon signatures and built early implementations, under a phased plan that would start with new wallets. No immediate protocol change is planned, however: opt-in “Winternitz Vaults” remain available, but default accounts still rely on non-quantum-safe signatures. For now it is a prepared plan and an optional tool, not chain-wide resistance.
  • Purpose-built and older chains (for example, hash-based signature networks that have run for years) remain the proof that the engineering is achievable; the challenge for the majors is coordination at scale.

Conclusion

Our May conclusion still stands: the quantum threat is real, but it is also a catalyst forcing the industry to modernise its cryptographic foundations far earlier than it otherwise would. What has sharpened since May is the sense that the clock is now shared: governments buying hardware, academics cutting attack costs, and developers publishing roadmaps, sunset schedules and, in Ethereum’s case, a scheduled protocol upgrade. The window for an orderly migration remains open. The open question is the same one we ended on in May: whether decentralised governance can move at the pace the hardware is setting.

Disclaimer

This is not financial research but the opinion of the author of the article. We publish this information to inform and educate about recent market developments and technological updates, not to give any recommendation for certain products or projects. The selection of articles should therefore not be understood as financial advice or recommendation for any specific product and/or digital asset. We may occasionally include analysis of past market, network performance expectations and/or on-chain performance. Historical performance is not indicative for future returns.

Important Disclosure

This is a marketing communication. Please refer to the prospectus of the UCITS and to the KID before making any final investment decisions.

This information originates from VanEck Switzerland AG which has been appointed as distributor of VanEck products in Switzerland by the Management Company VanEck Asset Management B.V., incorporated under Dutch law and registered with the Dutch Authority for the Financial Markets (AFM). VanEck Switzerland AG’s registered address is at Genferstrasse 21, 8002 Zürich, Switzerland.

The information is intended only to provide general and preliminary information to investors and shall not be construed as investment, legal or tax advice. VanEck Switzerland AG and its associated and affiliated companies (together “VanEck”) assume no liability with regards to any investment, divestment or retention decision taken by the investor on the basis of this information. The views and opinions expressed are those of the author(s) but not necessarily those of VanEck. Opinions are current as of the publication date and are subject to change with market conditions. Certain statements contained herein may constitute projections, forecasts and other forward-looking statements, which do not reflect actual results. Information provided by third party sources is believed to be reliable and have not been independently verified for accuracy or completeness and cannot be guaranteed. Brokerage or transaction fees may apply. A copy of the latest prospectus, the Articles, the Key Information Document, the annual report and semi-annual report can be found on our website www.vaneck.com or can be obtained free of charge from the representative in Switzerland: First Independent Fund Services Ltd, Feldeggstrasse 12, 8008 Zurich, Switzerland. Swiss paying agent: Helvetische Bank AG, Seefeldstrasse 215, CH-8008 Zürich.

All performance information is based on historical data and does not predict future returns. Investing is subject to risk, including the possible loss of principal.

No part of this material may be reproduced in any form, or referred to in any other publication, without express written permission of VanEck.

© VanEck Switzerland AG