Summary
- The G7 recommends that organizations begin transitioning to post-quantum cryptography immediately.
- Cybercriminals could collect encrypted information now and decrypt it in the future with advanced quantum computers.
- Developers of Bitcoin, Ethereum, and Solana are already exploring defensive measures against this impending threat.
The G7 has issued a call for governments and businesses to proactively prepare for potential cyberattacks facilitated by quantum technology, emphasizing that the migration to enhanced security protocols could take years and that sensitive data remains vulnerable.
A recent report from the G7's cybersecurity working group, which includes Canada, France, Germany, Italy, Japan, the United Kingdom, and the United States, labels quantum computing as a significant threat to both public and private sectors, extending beyond just critical infrastructure operators.
“While the timeline remains unclear, recent developments indicate a potential arrival of quantum computers capable of compromising prevalent public-key cryptography systems, posing risks to digital infrastructures,” the report states.
The G7 has urged institutions to adopt post-quantum cryptography (PQC) to safeguard against both traditional and quantum attacks. Without this transition, data that is captured and stored today could be decrypted by future quantum computers, which could also invalidate digital signatures, facilitate impersonations, and threaten businesses and their supply chains.
“We recognize that the shift to PQC is not an issue that individual organizations can resolve alone, but rather a collective endeavor requiring early engagement, coordinated planning, and informed decision-making across both public and private sectors,” the report emphasizes.
Although the report does not specifically mention cryptocurrencies, the same public-key cryptography that secures blockchain wallets and transactions is at risk.
Currently, quantum computers are not capable of breaking Bitcoin's cryptography. However, developers are considering post-quantum proposals such as BIP-360 to prepare the network for new signature schemes.
The governance structure of Bitcoin complicates this transition. Any significant security modifications would require widespread consensus among developers, miners, businesses, and users. Additionally, Bitcoin holders will need a method to transfer funds from vulnerable addresses without disrupting the network.
Ethereum researchers are working on updates for several cryptographic elements used by accounts, validators, and applications. One recent proposal aims to revamp Ethereum’s deposit contract to accommodate the larger keys necessary for post-quantum systems.
According to researchers, Solana may have an easier transition due to its use of EdDSA signatures. The Solana Foundation has experimented with post-quantum signatures on a test network and created an optional hash-based vault to secure funds.
The G7 Cybersecurity Working Group has urged governments to back research, foster public-private collaborations, and develop national PQC strategies, while integrating quantum security requirements into procurement processes. It also recommended that organizations identify critical systems and adopt quantum-safe products during regular upgrades to manage costs effectively.
“To enhance collective resilience and protect confidential data, supply chains, and essential systems, both public and private entities must take immediate action,” the report concludes. “The transition to PQC is fundamental to establishing a secure and resilient digital future.”
