Skip to content

Invest1 publisher3 min readPublished

Google and Ethereum set 2029 dates one year ahead of NIST's ECDSA deprecation

LayerZero shipped a lattice-based proof component on Wednesday; Coinbase gathered Bitcoin developers and custodians at Stanford and left without a chosen signature scheme, which is the piece no date can order.

The Investor · Invest desk

Illustration accompanying Google and Ethereum set 2029 dates one year ahead of NIST's ECDSA deprecation

What happened

  • LayerZero released Akita on Wednesday, a lattice-based post-quantum commitment scheme for the part of a zero-knowledge system that commits to a computation and proves it ran correctly.
  • Coinbase held a closed Post-Quantum Bitcoin Workshop at Stanford with cryptographer Dan Boneh and Localhost Research, drawing Bitcoin developers, institutional custodians and hardware-wallet specialists.
  • The workshop compared several candidate signature schemes and agreed on none, with each option trading off security, transaction size, hardware performance and key management.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Because the candidate schemes differ in transaction size and hardware performance, choosing one is a negotiation among custodians and wallet makers rather than an engineering release, and a target year cannot force that negotiation to close.
  • decision Anyone signing multi-year custody or key-management arrangements now has to decide whether to commit to a curve that NIST expects to deprecate by 2030, before the replacement has been picked.
  • exposure Coinbase's 99.9% coverage claim leaves a tenth of a percent of held customer assets outside the system it names, and the material does not say whether that system is the post-quantum PQ-CoreKMS or its predecessor.

Sixty percent is the floor on Akita's claimed compression and 67.5% the ceiling, because 200 kilobytes down to 80 is the first and down to 65 is the second [1][4], and kilobytes matter here because a proof is the object a verifier has to receive and check. The baseline in that comparison is the hash-based post-quantum alternatives [7], not the elliptic-curve signatures Bitcoin and Ethereum actually run [16], so the material prices quantum resistance against other quantum-resistant designs and leaves the comparison an operator would want unmade. The speed figure has the same shape: LayerZero says proving runs two to three times faster and memory use is roughly halved against its Jolt system [5], which is the system Akita will ship inside [6].

Akita has a version number and a deployment target because LayerZero owns the stack it goes into, Jolt being the zero-knowledge virtual machine it built with a16z crypto and the engine under its Zero chain [6]. Bitcoin's signature scheme has neither, and the Stanford session shows why: the candidates differ in security, transaction size, hardware performance and key management, and the room, which included institutional custodians and hardware-wallet specialists, did not converge on one [2][3]. One of those is a release; the other is a vote.

The calendar is carrying the load the hardware cannot yet carry. Google has set 2029 to finish its own post-quantum migration and named Coinbase, the Stanford Institute for Blockchain Research and the Ethereum Foundation as collaborators [10]; Ethereum's Lean Ethereum roadmap targets the same year [11]; NIST anticipates deprecating ECDSA by 2030 and disallowing it by 2035 [13], which leaves one year between those migration targets and deprecation and six between them and the ban [4][3]. The machine side is thinner. Google Quantum AI's Ryan Babbush and Hartmut Neven put breaking 256-bit elliptic curve cryptography at fewer than 1,200 logical qubits and roughly 90 million Toffoli gates in a March 2026 paper [8], while Google's Willow chip has 105 physical qubits [9], a raw ratio near 11 [2] that is not a timetable, since the material gives no physical-per-logical conversion.

Vitalik Buterin's February 2026 roadmap lists what has to move on one chain: consensus-layer BLS signatures, KZG data-availability commitments, account-level ECDSA, and the ZK proof systems [12]. Four distinct dependencies inside a single protocol is also the outer limit of what this evidence establishes, because there is no figure anywhere in it for what a migration costs, and nothing at all about what custodians or corporate treasuries have inventoried.

On what is here, the binding constraint is scheme selection rather than qubit count, and the counter-case is Coinbase's own posture: it says a solid, well-tested plan matters more than the exact year of an attack and that migration will proceed in steps [14], and it shipped PQ-CoreKMS in July while stating that its current system already protects about 99.9% of the assets it holds for customers [15]. If the migration is absorbed inside custodians rather than settled in public consensus, then the 0.1% outside that figure [5] is the number worth tracking and the Stanford deadlock is a footnote. What would break the read is a 2029 that arrives with Google's and Ethereum's targets met and no Bitcoin signature scheme chosen, which would mean the coordination problem was never binding, or rather, was routed around.

What to watch

  • Whether the next Bitcoin post-quantum session publishes a shortlist or a single recommended signature scheme rather than a summary of trade-offs.
  • Whether Coinbase discloses how much of the 99.9% of customer assets sits under PQ-CoreKMS rather than its earlier key-management system.
  • Whether the logical-qubit estimate for breaking 256-bit elliptic curve cryptography is revised down again, which would make the 2029 targets late rather than early.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories