In brief
- The G7 says organizations should begin migrating to post-quantum cryptography now.
- Attackers can collect encrypted data today and decrypt it if sufficiently powerful quantum computers emerge.
- Bitcoin, Ethereum, and Solana developers are already testing defenses against the threat.
The G7 is urging governments and businesses to prepare for quantum-enabled cyberattacks now, warning that migration could take years and that sensitive data is already at risk.
In a new report, the cybersecurity working group of the Group of Seven, better known as the G7—a forum comprising Canada, France, Germany, Italy, Japan, the United Kingdom and the United States—called quantum computing a security and economic threat to public and private organizations, not just critical infrastructure operators.
“Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures,” the group wrote.
The group urged organizations to adopt post-quantum cryptography, or PQC, to protect against classical and quantum attacks. Without it, data stolen and stored today could later be decrypted by a sufficiently powerful quantum computer, which could also break digital signatures, enable impersonation, and expose companies and their supply chains.
“We acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning, and informed decision-making across the public and private sectors,” wrote.
While the report does not mention cryptocurrency, the same class of public-key cryptography protects blockchain wallets and authorizes transactions.
Current quantum computers cannot break Bitcoin’s cryptography. Developers are nevertheless considering post-quantum proposals including BIP-360, which would prepare the network to support new signature schemes.
Bitcoin’s governance makes the transition more complicated. Any major security change would require broad support from developers, miners, businesses, and users. Bitcoin holders would also need a way to move funds from vulnerable addresses without disrupting the network.
Ethereum researchers are planning replacements for several cryptographic components used by accounts, validators, and applications. One recent proposal would rebuild Ethereum’s deposit contract to support the larger keys required by post-quantum systems.
Solana may have a simpler migration path because it uses EdDSA signatures, researchers have said. The Solana Foundation has tested post-quantum signatures on a test network and introduced an optional hash-based vault for protecting funds.
The G7 Cybersecurity Working Group urged governments to support research, public-private partnerships and national PQC strategies while adding quantum security to procurement requirements. It also advised organizations to identify critical systems and adopt quantum-safe products during scheduled upgrades to contain costs.
“To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now,” the group wrote. “The transition to PQC is the key foundation to help build a secure and resilient digital future.”
Facts Only
* The G7 cybersecurity working group identified quantum computing as a security and economic threat to public and private organizations.
* Organizations should begin migrating to post-quantum cryptography (PQC) now.
* Attackers could collect encrypted data today and decrypt it if sufficiently powerful quantum computers emerge.
* Bitcoin, Ethereum, and Solana developers are testing defenses against the threat.
* The group urged organizations to adopt PQC to protect against classical and quantum attacks.
* Transitioning to PQC requires collective transition through early engagement and coordinated planning.
* Public and private organizations must jointly act now to strengthen resilience.
* Governments should support research, public-private partnerships, and national PQC strategies.
* Organizations should identify critical systems and adopt quantum-safe products during upgrades.
Executive Summary
Full Take
The narrative frames a technical inevitability—the threat posed by future quantum capabilities—as an immediate governance and organizational mandate. The core tension lies between the uncertainty of the exact timeline ("Although the exact timeline is uncertain") and the urgency of the risk (data exposure today). This structure is designed to bypass lengthy deliberation by invoking existential security concerns. The pattern observed is a shift from a theoretical, long-term research problem (quantum computing) to an immediate operational necessity (PQC migration), leveraging collective action across disparate sectors (G7 nations, developers).
The implication is that the inertia of traditional security planning must be overcome by embedding quantum risk into foundational business and procurement processes. The pattern of urging coordinated action across public and private spheres reflects a recognized failure in siloed response, suggesting that singular organizational responsibility is insufficient for systemic threats. The focus on the specific actions taken by blockchain developers—testing protocols rather than definitive solutions—highlights a complex friction point: where cryptographic theory meets decentralized governance and practical implementation. The demand for public-private partnerships suggests an understanding that technical solutions cannot be achieved solely through private sector innovation, pointing toward a necessary structural reconfiguration of security accountability to ensure equitable resilience against this shared, latent threat.
Bridge Questions: If the transition timeline remains highly uncertain, what risk is embedded in forcing immediate organizational migration before the underlying cryptographic standards are fully solidified? How can governance mechanisms be established to ensure that national strategies and private sector adaptations align effectively without creating new points of dependency or inequity during the transition? What specific metrics should governments use to quantify "collective resilience" across diverse public and private systems?
Sentinel — Human
The text appears to be a well-structured summary of a policy recommendation, effectively bridging high-level geopolitical concerns with specific technological implementation details across major blockchain projects.
