Invest2 distinct publishers3 min readPublished
The G7's report carries no binding force and never says the word crypto, arriving four months before the EU wants member states moving, and it pushes quantum readiness into government procurement, which is how the cost eventually reaches private custodians.
The Investor · Invest desk
Compiled by The InvestorSomething wrong?How this is made
The bill is denominated in bytes. A compact secp256k1 ECDSA signature is about 64 bytes and the ML-DSA-87 parameter set NIST finalised is about 4,627 [9][10], so the same authorisation arrives roughly 72 times heavier [17], and standardisation added rather than shaved, landing about 32 bytes above the older Dilithium-5 figure of 4,595 [18]. Cryptopolitan notes that signature size feeds directly into storage, bandwidth and transaction cost [11].
That ratio is why the custodian's version of this problem is the manageable one. The G7 tells organisations to identify critical systems and buy quantum-safe products during upgrades they had already scheduled [12], which is a procurement preference rather than a capital project, or rather a cost that hides inside a refresh cycle nobody itemises until a vendor cannot meet the clause.
The chains' timetables, by contrast, read like engineering. BIP-360 would remove Taproot's quantum-vulnerable key-path spend and has no activation date [7], and Decrypt points out that a change of that size needs broad support from developers, miners, businesses and users, plus a way for holders to move funds off vulnerable addresses without disrupting the network [13]. Vitalik Buterin's February 2026 roadmap names four components to replace, validator BLS signatures, KZG commitments, ECDSA account signatures and application-layer zero-knowledge proofs, with core post-quantum infrastructure targeted for 2029 [8], which sits one year inside the EU's requirement that high-risk systems migrate before 2030 [19]. Solana researchers say its EdDSA signatures give it a simpler path, and the Solana Foundation has tested post-quantum signatures on a test network and added an optional hash-based vault [14].
The dates on the calendar bind member states, not exchanges. The European Commission wants transition begun by the end of 2026 and high-risk systems migrated before 2030 [5], and that first mark falls about four months after the September 3 report [20]. The belt that reaches a private custodian is purchasing: the G7 asks governments to write quantum security into procurement requirements alongside research and national strategies [6], and Cryptopolitan's reading is that firms without a migration plan meet compliance and competitive friction as those clauses spread [21].
The reading the evidence supports is that a custodian's near-term expense is inventory and compatibility testing rather than cryptography, and that the number likely to surprise people is the fee arithmetic on 72x signatures once some chain actually activates one, rather than the migration budget. The counter-thesis is that the exposure is already dated. The G7's own phrase is "harvest now, decrypt later" [3], and on a public ledger the harvesting step is free, because keys and transaction history stay visible indefinitely [15]; if that is the binding constraint, anything with a long secrecy life has already been taken, and every schedule above is about limiting new exposure rather than protecting what is on chain now.
Ranked by verification strength, evidence, and original report placement.
The G7 Cybersecurity Working Group released a report titled "Preparing for the Post-Quantum Era: A Call to Action" on September 3, 2026, treating quantum computing as a business and cybersecurity risk organisations must be ready for before a cryptographically capable machine exists.
The G7 Cybersecurity Working Group urged governments and businesses to begin moving to post-quantum cryptography now, warning that current public-key systems face future quantum risk.
The G7 group used the phrase "harvest now, decrypt later" to describe collecting encrypted data today and decrypting it in future when quantum technology is capable enough.
The G7 report does not mention cryptocurrency, although the same class of public-key cryptography protects blockchain wallets and authorises transactions.
The G7 Cybersecurity Working Group urged governments to support research, public-private partnerships and national PQC strategies while adding quantum security to procurement requirements.
BIP-360, Pay-to-Merkle-Root, is being explored by Bitcoin as a soft-fork proposal that would remove the quantum-vulnerable Taproot key-path spend, and it has no activation date.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Bitcoin's first post-quantum signature BIP arrives with its tradeoffs already conceded1 distinct publisher
invest
Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good1 distinct publisher
invest
Crypto's signature swap now has a date, a price tag, and no owner1 distinct publisher
build
JDK 24 relocates the post-quantum blocker to your key custody plumbing1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One document, two trade reports, no primary link
Every number that gives this story its point traces to Cryptopolitan: the report's title and date, both EU deadlines, Buterin's four components, and the byte counts. Decrypt is the only source quoting the G7 text, and Cryptopolitan credits Decrypt rather than the report for the crypto connection. The 4,627-byte ML-DSA-87 figure is checkable against NIST's published parameters and nobody in our coverage checked it, and the report's five priority areas are referred to but never listed out.
Deadlines on paper, signatures on testnets
What is actually in force is policy: an EU roadmap from June 2025, member-state starts due at the end of 2026, high-risk systems before 2030. On the network side the inventory is thinner, a Bitcoin soft-fork proposal with no activation date, an Ethereum target four years out, and Solana Foundation tests on a test network plus an optional vault. No production chain in this reporting has changed a signature scheme, and the G7 asks for procurement language rather than migration.
A recommendation reported as a clock
The G7 urges and advises; Cryptopolitan's headline puts crypto on the clock and predicts compliance and competitive trouble that no regulator or named analyst in this reporting asserts. Both outlets do hold the line where it counts, neither suggesting a machine can break Bitcoin now, and Decrypt says the opposite plainly. The overstatement lives in the framing rather than in any specific figure.
Crypto trade press supplying the angle the report withheld
The G7 wrote about public-key cryptography in general and both publishers make their living on the part it left out, so each has reason to convert a general warning into a crypto story. Cryptopolitan then cites its own earlier piece for the claim that quantum readiness will reach custody criteria, which lends a house view the look of corroboration. Neither outlet has a visible stake in migration vendors or timing, which holds this in the middle of the range.
Firm on what was said, thin on what it costs
The G7's recommendations and the two chains' broad direction are reported consistently by both outlets, so that layer holds. The parts a reader would act on, the byte counts, the EU dates and the compliance forecast, come from one publisher, and the only physical claim in the story, that a signature scheme roughly 72 times heavier is the price of quantum safety, has no primary citation behind it.