Is Hyperliquid Quantum Safe? Where HYPE and the Chain StandRead more
Oct 7, 2026

Is Ethereum Quantum Resistant? The Threat, and Ethereum's Plan

Ethereum isn't quantum-resistant today. Its standard externally owned accounts sign transactions with elliptic-curve cryptography, and its validators sign with a related scheme. Both can be broken by a capable enough quantum computer. That said, Ethereum has one of the most active post-quantum migration efforts of any major chain. This guide covers why Ethereum is exposed and what its roadmap proposes, as of September 2026.

Two signature schemes, both exposed

Standard Ethereum accounts, called externally owned accounts (EOAs), authorize transactions with ECDSA on the secp256k1 curve. As a reminder, that's the same ECDSA and secp256k1 that legacy Bitcoin transactions use. 


Shor's algorithm can recover a private key from an exposed public key and forge a transaction. Ethereum's validators sign with BLS signatures, which rest on the same kind of discrete-log problem that Shor's algorithm can break.

So, Ethereum's signature layer is quantum-vulnerable on two fronts, accounts and consensus. The difference from most chains is what comes next.

Why Ethereum's accounts are already exposed

An EOA address is derived from the last 20 bytes of the Keccak-256 hash of its public key, so the key itself isn't written on the chain when the account is created.


Bitcoin can use that protection to its advantage with hash-key output types such as P2PKH or P2WPKH, where a fresh address keeps the public key hidden until the output is spent. Unfortunately, it doesn't apply to legacy P2PK or Taproot outputs, which expose a public key from the start.


Ethereum works differently. It's account-based, so you reuse one account, and the moment that EOA sends an ECDSA-signed transaction, its public key can be recovered from the signature. 

From there on, the key is public, and the account keeps being used. In practice, any EOA that has sent a transaction has an exposed public key that a future quantum computer could work against. A 2026 arXiv preprint, which covers the quantum threat to Bitcoin and Ethereum, treats account reuse as a core part of Ethereum's exposure.

Indeed, once an EOA's public key is on-chain, it stays there. A future cryptographically relevant quantum computer could use it to derive the private key and authorize new transactions. Past transactions stay valid; the danger is forged future ones. It resembles a 'collect now, exploit later' problem, though it isn't strictly 'harvest now, decrypt later,' since no encrypted data is being collected.


Contract accounts are a different case, as they hold no protocol-level private key of their own. Their owner or admin keys, and any custom validation logic, may still use quantum-vulnerable cryptography, but the exposure most users face sits with EOAs, the standard user wallets.

eth-account-exposure.png

An Ethereum account's key stays hidden only until its first transaction. After that it's exposed for good.

Consensus and the rest of the stack

The risk isn't only user funds. Far from it.

Ethereum's proof-of-stake consensus runs on validator signatures, BLS on the BLS12-381 curve. A quantum attacker who recovered a validator's private key could impersonate that validator and sign messages that trigger slashing or a voluntary exit. However, breaking consensus itself is a taller order, as that would take control of enough validator weight, which a single key doesn't give.

Therefore, whole-chain quantum resistance requires replacing every quantum-vulnerable building block the protocol uses, well beyond the signatures. Ethereum's roadmap also covers the KZG commitments in its data layer and the pairing-based cryptography the ecosystem relies on.

What Ethereum is building

In February 2026, Ethereum's roadmap set out several areas of the protocol that need post-quantum upgrades, and work is underway on each. 


The Ethereum Foundation's post-quantum team runs weekly interop devnets with more than 10 client teams. The roadmap sets a direction, and its milestones are targets that depend on further research and Ethereum's open governance, which the Foundation can't settle on its own.


Where accounts are concerned, the roadmap leans on account abstraction, which lets an account define its own validation rules. Ethereum's roadmap proposes using account abstraction to give accounts signature agility, so a user could switch to a post-quantum signature scheme without waiting for a chain-wide replacement. 


Legacy accounts wouldn't gain this automatically, because account abstraction demands protocol changes and wallet support. Nonetheless, willing users could adopt protection early, which makes Ethereum's path easier than that of a chain that would need every holder to move in one coordinated fork.


In terms of consensus, the roadmap proposes replacing BLS validator signatures with leanXMSS, a hash-based scheme that rests only on the security of hash functions. Grover's algorithm, the main quantum threat to hashing, offers only a square-root speedup, which a large enough hash absorbs. Given that hash-based signatures are larger than BLS, an aggregation layer is being built to keep them scalable.


Ethereum has also thought about the worst case scenario, a quantum computer arriving before the migration is done. Vitalik Buterin has sketched out a quantum-recovery hard fork that would let legitimate owners prove ownership from secret data they already hold and migrate to safe accounts. This way, a cracked ECDSA key alone wouldn't be able to authorize the recovery. 

The sketch wouldn't cover every historical key-generation method, and it would need the chain to be rolled back to an earlier state, a step the community would argue over, plus a coordinated hard fork. None of this is live at the base layer as of the time of writing, and the full migration is a multi-year effort.

Meanwhile, qLABS' L1 Quantum Vulnerability Index has given Ethereum the score of 6.80 and ranks it as the seventh-most vulnerable among the 10 chains assessed. It earns the index's best preparedness score, based on the strength of its roadmap and active work, though the methodology rewards visible preparedness and doesn't confirm a completed migration.

eth-account-exposure-1.png

Ethereum's four quantum-vulnerable areas and their proposed fixes. None is live yet; core work targets around 2029.

What ETH holders can do now

Address hygiene is less relevant for Ethereum than for Bitcoin, since account reuse is the norm and the key is exposed after the first outgoing transaction. The more useful move is to follow the post-quantum account options as they ship, and to adopt them once wallets support them. The larger the position, the more that early adoption is worth doing.

On smart-contract chains like Ethereum, a vault can require post-quantum authorization before it releases assets, which adds protection against a compromise of the user's ordinary wallet key. 

qLABS says its qVAULT is a non-custodial smart-contract vault of this kind, using a Falcon-based authorization on withdrawals, with qONE described as the token used to pay for quantum-safe transactions. 


Its current public materials focus on Hyperliquid and list qONE and HYPE as supported assets. This protects the vault's withdrawal path, and leaves the underlying chain and its consensus untouched. The support for Ethereum is on the roadmap.


Do note that qLABS stands to benefit from qVAULT and qONE, so weigh that accordingly. None of this is financial advice.

Exposed today, building for tomorrow

Ethereum isn't quantum-resistant today and, because accounts get reused, an EOA that has sent a transaction already has a recoverable public key on-chain. Against such a backdrop, Ethereum is among the better-prepared large chains. 

Account abstraction gives it a migration path that doesn't need every user to move at once, and the Foundation's work is active and public. The threat is Q-Day, still years out on wide estimates. Regardless, the plan is well underway.

FAQ

Is Ethereum quantum resistant?

Not yet. Ethereum EOAs sign with ECDSA and validators with BLS, both breakable by a large enough quantum computer. Its roadmap has an active post-quantum plan, but nothing is live at the base layer as of September 2026.

Can a quantum computer steal my ETH?

Not with today's hardware. That risk will arise when a capable quantum computer is built and your account's public key is exposed, which happens once the EOA sends its first transaction. An account that has already transacted is the one at risk. A brand-new EOA that has never sent a transaction keeps its public key hidden on-chain behind the address hash.

When will Ethereum be quantum-safe?

There's no live base-layer protection as of September 2026. EIP-8141, which would give accounts a native route toward signature agility, is scheduled for inclusion in the Hegota upgrade, but remains a draft, and Hegota's mainnet date hasn't been set. The wider roadmap targets core post-quantum infrastructure around 2029, and full migration extends beyond that.

When is Q-Day, and how does it affect this?

Forecasts remain extensive. Expert estimates stretch across the 2030s and 2040s, and no authoritative source pins Q-Day to a specific year. This uncertainty is one reason Ethereum's migration work has started before the hardware exists.

Is Ethereum more exposed than Bitcoin?

It's exposed differently. Bitcoin's exposure depends on the output type. P2PKH and P2WPKH hide the public key until the output is spent when used with a fresh key, and legacy P2PK or Taproot outputs expose one from the start. Ethereum normally reuses an EOA, whose public key becomes recoverable after its first outgoing transaction. Having said that, Ethereum is further along on a migration plan.

What can I do to protect my ETH?

Follow the post-quantum account options as wallets add them, and adopt them when they arrive. On smart-contract chains, application-layer vaults can add a post-quantum check before the base layer migrates. Treat it as one part of ordinary security, and remember that none of this is financial advice.

qLABS Editorial. Sources are linked inline. See the L1 Quantum Vulnerability Index for our full methodology and conflict-of-interest disclosure.