· via dev.to (home feed)
Ethereum Foundation targets 2029 for post-quantum cryptography overhaul
The Lean Ethereum roadmap would replace BLS signatures with hash-based leanXMSS and move data commitments off elliptic curves, with core post-quantum infrastructure due in 2029.

The Ethereum Foundation has laid out a concrete timeline, branded the Lean Ethereum roadmap, for moving the network to post-quantum cryptography by 2029. As dev.to reports in a post republished from Basis Desk, the plan addresses the four places where Ethereum's security currently rests on elliptic curve mathematics: consensus signatures, data availability commitments, user account signatures and application-layer zero-knowledge proofs.
The deadlines shaping the plan
The 2029 target is not arbitrary. According to dev.to, Google Quantum AI published research in March 2026 estimating that roughly 1,200 logical qubits would suffice to break the 256-bit elliptic curve cryptography behind Ethereum account signatures, and that the hardware gap is closing faster than earlier projections assumed. Google has reportedly set its own internal deadline of 2029 for migrating to post-quantum standards, while NIST expects to deprecate ECDSA by 2030 and disallow it entirely by 2035.
On the organisational side, the Ethereum Foundation created a dedicated Post-Quantum Security team in January 2026 under Thomas Coratger. The group runs weekly interoperability tests involving more than ten client teams, including Lighthouse, Grandine, Zeam, Ream Labs and PierTwo, and administers a $1 million Poseidon Prize aimed at refining hash-based cryptographic primitives.
Replacing BLS signatures at the consensus layer
The most visible piece of the migration is the consensus layer. BLS signatures efficiently aggregate votes from hundreds of thousands of validators, but they depend on elliptic curve pairings that a quantum computer running Shor's algorithm could break. The roadmap proposes swapping them for leanXMSS, a hash-based scheme. Hash functions are considered resilient because quantum algorithms can reduce their strength somewhat but cannot break them the way Shor's algorithm breaks elliptic curves.
The trade-off is size. Where a BLS signature takes 96 bytes, a hash-based signature needs roughly 3,000 bytes, which would flood the chain with data if deployed as-is. The proposed answer is leanVM, a minimal zero-knowledge virtual machine acting as an aggregation engine that compresses signature data by a factor of about 250. Open-source reference implementations are already available for testing: leanSpec in Python and leanSig in Rust.
Rethinking KZG commitments
Ethereum's data availability machinery for rollups leans on KZG polynomial commitments, which share the same elliptic curve weakness. The existing trusted setup, secure so long as at least one participant was honest and destroyed their secret, is described as a mitigation rather than a permanent fix. Two quantum-safe replacements are under evaluation: STARK-based commitments built on hash functions, and lattice-based commitments resting on hard lattice problems. Both are being researched for efficiency and viability at mainnet scale.
Accounts and signature agility
At the execution layer, standard externally owned accounts sign transactions with ECDSA over the secp256k1 curve, and exposure varies by history. An account that has only ever received ETH keeps its public key offchain, since only the address, a hash of the key, appears on the ledger. Any account that has sent a transaction has permanently exposed its public key, and a mature quantum computer could in theory derive the private key from that data. Rather than force a simultaneous network-wide migration, developers are pursuing EIP-8141, slated for consideration in the Hegotá upgrade in the second half of 2026. It introduces signature agility, letting users and wallet providers voluntarily move individual accounts to post-quantum schemes ahead of the broader transition.
The application layer
Many SNARK-based proof systems used by Layer-2 rollups also rest on quantum-vulnerable assumptions, but the ecosystem is already drifting toward safety. Several rollups use STARKs, which rely on hash functions and therefore provide post-quantum security natively. According to the report, this organic adoption is hardening the application layer without top-down protocol mandates.
Why it matters
Ethereum is positioned as financial infrastructure meant to endure for centuries, and its current cryptography would not survive that horizon if quantum hardware matures on the timelines now sketched by Google and NIST. The 2029 deadline synchronises Ethereum's work with Google's internal migration plan and NIST's ECDSA deprecation schedule, and gives client teams a shared target rather than a vague aspiration. The effort also has shipped artefacts, including interop testing across a dozen client teams, open-source implementations and a prize programme, alongside standardised algorithms from NIST's FIPS 203, 204 and 205. The hardest problems, notably replacing KZG commitments at scale and coordinating millions of voluntary account upgrades, remain unsolved, and the timeline leaves little slack if capable quantum hardware arrives sooner than expected.
- #ethereum
- #post-quantum-cryptography
- #cryptography
- #blockchain
- #security