The Hardy Index Quantum readiness benchmark

Guide · Understand the threat

Is my crypto safe from quantum computers?

If you have seen the scary headlines about quantum computers and crypto, here is the calm version. What is true, what it means for the coins you hold, and what is worth doing about it.

The short answer

Here is the reassuring part first: no quantum computer that could break the cryptography behind Bitcoin or Ethereum exists today, and the best public estimates put that machine years away. Most cryptocurrencies are not quantum-safe yet, though, and readiness varies widely between chains. The Hardy Index scores 23 major chains on exactly that.

What is the quantum threat to crypto, in plain terms?

The quantum threat to crypto is that a large quantum computer could work out your private key from your public key, and then move your coins. Every crypto wallet is a pair of keys. The public key works like an account number that anyone can see. The private key is the only thing that can authorise a payment, which is why losing it means losing the coins.

Those two keys are linked by maths that only runs one way. Going from a private key to a public key is quick. Going back the other way would take an ordinary computer longer than the universe has existed. That one-way street is what makes crypto work at all.

A large quantum computer would run that maths backwards. Shor's algorithm, published in 1994, breaks the elliptic-curve signatures that secure Bitcoin, Ethereum and most other chains. NIST is the United States standards body, and its transition plan for post-quantum cryptography says so plainly. ECDSA, EdDSA and RSA are all vulnerable to Shor's algorithm on a large enough quantum computer.

A longer password will not help you here, and neither will a bigger key. The weakness sits in the signature scheme itself, meaning the method a chain uses to prove a payment is genuine. The only real fix is to swap that scheme for one built on maths quantum computers are bad at. NIST published the first standards for those replacements in August 2024, including ML-DSA for digital signatures.

So there are two things to hold at once, and most headlines carry only one of them. Nothing that exists today can do this to your coins. The signatures protecting most chains will still have to be replaced. That is a serious piece of engineering, and some chains have started it while many have not.

Which cryptocurrencies are at risk?

Almost all of them, to different degrees. As of 12 August 2026, the Hardy Index rates 23 major chains and finds only two, Quantum Resistant Ledger and Abelian, running post-quantum signatures for every account on mainnet today. Bitcoin, Ethereum, Solana and most other well-known chains still sign transactions with quantum-vulnerable cryptography.

Being at risk is not the same as being in danger, and the difference is readiness. The Hardy Index places every rated chain on a five-rung spine, from Native at the top to Exposed at the bottom. It also scores each chain from 0 to 100 across six published dimensions.

  1. 1 Native 2 of 23

    Post-quantum secure at mainnet today, with quantum-resistant signatures built in from genesis.

  2. 2 Shipping 3 of 23

    Post-quantum signature features are live on mainnet and a migration for existing holders is underway.

  3. 3 Committed 9 of 23

    A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.

  4. 4 Debating 4 of 23

    The threat is acknowledged and proposals exist, but there is no consensus and no published timeline.

  5. 5 Exposed 5 of 23

    The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme could be found.

Quantum Resistant Ledger leads the ranking with a Hardy Score of 92.0 out of 100, ahead of Abelian on 84.5. Bitcoin scores 17.0 and sits in Tier 4: Debating, with two draft proposals and no agreed post-quantum signature. Ethereum scores 40.0 in Tier 3: Committed, on the strength of a funded research programme rather than anything live on mainnet.

The top 5 of 23 rated chains, as of 12 August 2026.
RankChainTierHardy Score
1Quantum Resistant LedgerQRL Native
92.0
2AbelianABEL Native
84.5
3Nervos CKBCKB Shipping
75.5
4AlgorandALGO Shipping
74.5
5SolanaSOL Shipping
54.5

You can see the full quantum-readiness ranking or go straight to the profile for the chain you hold. Every score there carries a note and a primary source. If you want to check the arithmetic first, the rubric is published in full.

Is the danger immediate?

No. As of 12 August 2026, no quantum computer capable of breaking the cryptography behind any major blockchain has been built. The machines that do exist are nowhere near the size that job would need.

The clearest public estimate of that size came from Google Quantum AI in March 2026. Its researchers put the attack at fewer than 1,200 logical qubits and fewer than 500,000 physical qubits, running for a few minutes. For a sense of scale, IBM's Nighthawk processor carries 120 qubits. IBM announced it in November 2025 and says it aims to deliver its first large-scale fault-tolerant machine in 2029.

The estimates have been moving in one direction, and that is the part worth taking seriously. Google's March 2026 figure was roughly a twentyfold reduction in the physical qubits thought to be needed, compared with earlier work. A cheaper estimate is not a machine, but it is why standards bodies stopped treating this as a distant problem.

The dates that do exist come from those standards bodies. NIST's draft transition plan would deprecate the weaker classical signature parameters after 2030, and disallow ECDSA and EdDSA after 2035. United States federal systems are expected to finish the migration by 2035, under National Security Memorandum 10. Those are deadlines for replacing cryptography, not predictions of an attack.

Nobody knows the exact date, and anyone who gives you one with confidence is selling something. What the expert estimates actually say about Q-Day walks through the ranges and why they keep changing.

Why does it matter now if Q-Day is years away?

Because of a problem called harvest now, decrypt later. An attacker can record data today and decrypt it years later, once a capable machine exists. NIST names this as one of the main reasons the migration is urgent, even though a cryptographically relevant quantum computer has not been built yet.

For crypto, that problem is simpler and harder to undo. A blockchain is public and permanent. Once your public key has appeared on it, it is there for good. Coins left at that address are exposed to whatever machine arrives later, and moving to a safer chain in 2032 will not un-expose a key published in 2013.

Bitcoin shows the scale of it. Independent estimates of the supply sitting at addresses with visible public keys run from about 4 million BTC (Deloitte) to about 7 million BTC (Galaxy Digital). Glassnode puts it at 6.04 million, or 30.2% of supply. Those coins cannot be un-exposed, which is why exposure is one of the six dimensions in every Hardy Score.

This is the honest case for paying attention now, and it is the only urgency this page will offer you. Harvest now, decrypt later, explained in full covers what it does and does not mean for a wallet.

What should I do about it?

Nothing dramatic, and nothing that involves selling anything in a hurry. The useful steps are small, cheap and mostly permanent, and you can do all of them this week.

  1. Check the chain you hold. The Hardy Index scores 23 chains from 0 to 100 and shows the working behind each number. Find your chain and its readiness score.
  2. Stop reusing addresses. Google's Quantum AI team gave exactly this advice alongside its 2026 estimate: refrain from exposing or reusing vulnerable wallet addresses. A fresh address for each payment keeps your public key out of sight for longer.
  3. Keep long-term holdings in a wallet whose keys you control, with the recovery phrase written down and stored offline. That does not make you quantum-safe on its own, and no wallet can change a chain's signature scheme. What it does is put you in a position to act quickly when your chain ships an upgrade.
  4. Take the migration when your chain offers it. Migration is the moment your risk actually falls. On most chains it will look like a wallet update and a move to a new address, not anything exotic.
  5. Ignore anyone selling you urgency. No coin needs buying today because of quantum computing. If a product promises to quantum-proof your holdings on a chain that has not shipped post-quantum signatures, it is promising something the chain cannot deliver.

If you want the longer version, how to protect your crypto from quantum computers sets out the same steps in detail. It also covers the wallet options worth looking at, and where each one falls short.

What this page will never doThe Hardy Index rates chains and does not recommend assets. Nothing here is a suggestion to buy, sell or hold anything. A low readiness score is a statement about cryptography, not a forecast about price. Read how we make money if you want to know what pays for this work.

Check your chain's readiness

The Hardy Index scores 23 major blockchains from 0 to 100 on quantum readiness, with the working shown for every number and a primary source behind every claim.

Check your chain's readiness

Questions people also ask

Can quantum computers steal Bitcoin?

Not today. Stealing Bitcoin this way needs a quantum computer that can derive a private key from a public key. Google Quantum AI estimated in March 2026 that the job would take fewer than 1,200 logical qubits and fewer than 500,000 physical qubits. No machine at that scale has been built. If one is built, the coins at greatest risk are those at addresses whose public keys are already visible on the blockchain, estimated at between 4 million and 7 million BTC.

Which cryptocurrencies are quantum-safe?

Very few. As of 12 August 2026, the Hardy Index rates 2 of 23 major chains as Tier 1: Native. That means post-quantum signatures protect every account on mainnet today, and those chains are Quantum Resistant Ledger and Abelian. Most large chains still use quantum-vulnerable signatures, including Bitcoin, Ethereum and Solana. Several of them have funded roadmaps to change that.

Should I sell my crypto because of quantum computing?

The Hardy Index does not give investment advice, and it takes no view on what anyone should buy, sell or hold. What it can tell you is how ready a chain is. That readiness is scored on six published dimensions, with a primary source behind every figure. A low Hardy Score is a statement about cryptography, not a prediction about price.

When will quantum computers be able to break crypto?

Nobody knows, and the honest answer is a range rather than a date. Two dated anchors are worth knowing. NIST would disallow ECDSA and EdDSA after 2035, and IBM aims to deliver its first large-scale fault-tolerant quantum computer in 2029. A fault-tolerant machine is not automatically a crypto-breaking machine. Even so, 2029 to 2035 is the window the people building and standardising this technology are working to.

Does a hardware wallet protect me from quantum computers?

Not by itself. A hardware wallet keeps your private key off an internet-connected device. That protects you from the attacks that actually drain wallets today, meaning malware and phishing. It does not change the signature scheme your chain uses, so it cannot make a quantum-vulnerable chain quantum-safe. What it does give you is control of your own keys, and that is what lets you move quickly when your chain ships a post-quantum upgrade.

Where to go next

Sources

  1. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly Google Research · primary · checked 12 August 2026
  2. NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards National Institute of Standards and Technology · primary · checked 12 August 2026
  3. FIPS 204: Module-Lattice-Based Digital Signature Standard National Institute of Standards and Technology · primary · checked 12 August 2026
  4. IBM delivers new quantum processors, software and algorithm breakthroughs on path to advantage and fault tolerance IBM · primary · checked 12 August 2026
  5. 'That is the end of Bitcoin': the quantum race for $470 billion Forbes · secondary · checked 12 August 2026
  6. The Hardy Score methodology The Hardy Index · primary · checked 12 August 2026

This is a security-readiness assessment, not investment advice.