
GDC 2026 · Geneva · Meeting report
Post-Quantum Cryptography Migration on DLTs: Deployment, Agility & Governance
3 September 2026 · 17:00–17:50 · Blockchain Governance Initiative Network (BGIN)
IKP · Chatham House Rule
3 September 2026 — BGIN held a 50-minute GDC 2026 breakout in Geneva on post-quantum cryptography migration for public ledgers, wallets, and credentials: deployment, crypto agility, and governance, not a new-algorithm contest. This page is the session record. It is written under the Chatham House Rule: information may be used; other participants are not identified.
Agenda
- Opening: BGIN; PQC as deployment, agility, and governance for digital-asset stacks, not a new-algorithm contest.
- Scene-setting: quantum vulnerabilities in cryptocurrencies; ECDLP; error correction and interconnects; attack classes; migrate now.
- Competition: Japan-hosted, internationally open prize on PQC migration for blockchain networks; NIST schemes, not new primitives.
- Open discussion: slowing quantum; PQ verifiable credentials; signals of a step change; AI in cryptanalysis and resource estimates; industry roadmaps and Q-day as a probability.
- Close: BGIN Block 15 (Washington, D.C., October 2026); hybrid.
Session description
Wallets and credentials rely on long-lived cryptographic trust. NIST-standardized post-quantum primitives exist. What still lacks an agreed playbook for public ledgers is how to stage a hybrid then a cutover when every node must agree on validity rules, how to keep verifying old signatures while funds remain live, how to rotate keys without stranding dormant accounts, and how to tell a genuine PQ-ready stack from a screenshot.
This 50-minute breakout held resource estimates and migration design in one room. It built on BGIN IKP crypto-agility work, a Google Quantum AI scene-setting on quantum vulnerabilities in cryptocurrencies, a Japan-hosted multi-year migration prize (BGIN coordinating evaluation; NIST remaining the primitive authority), and industry remarks on protocol roadmaps. Follow-on drafting continues at BGIN Block 15.
Speakers
The session was conducted under the Chatham House Rule. Floor interventions may be used; neither the identity nor the affiliation of other participants is recorded here.
On the programme: Mitchell Travers (BGIN), moderating; Adam (Google Quantum AI), scene-setting on quantum hardware progress, attack classes, and why ECDLP-based public-key cryptography is the exposed assumption; Shin'ichiro Matsuo (BGIN), announcing a Japan-hosted internationally open prize on PQC migration for blockchain networks; and Conor (Project 11), on protocol-community sentiment, hybrid then cutover, and DLT-specific knock-on costs.
Floor discussion included whether quantum development can be slowed, post-quantum recommendations for verifiable credentials, what signals a step change if qubit count is the wrong metric, AI-assisted factoring and cryptanalysis, public resource-estimate leaderboards, and how long protocol versus hardware roadmaps actually are.
Slides
Session slides were presented from a BGIN Beamer deck combining DLT-versus-TLS cutover frames, resource estimates versus migration/agility, the Japan prize lanes (METI/NEDO, BGIN, NIST), discussion questions, and a Block 15 call with session, event, and registration links.
Download the session slides (PDF). A citeable PDF of this meeting report is also in Publications.
Notes and key points
The assumption at the bottom of the stack is the failure point
Most deployed public-key cryptography, including on-chain and off-chain finance, rests on the elliptic-curve discrete logarithm problem being hard. A cryptographically relevant quantum computer makes that problem easy. Contagion paths already exist—stablecoins backed by short-term government debt; a planned NYSE-linked on-chain trading system; an EU pilot for cross-border educational credentials using on-chain identities.
Qubit count is the wrong progress metric
Google's Sycamore (53 qubits, 2019) to Willow (105 qubits, 2024 error-correction demonstration) looks like a slow doubling if one only counts qubits. The years were spent on capabilities that make larger devices functional. Quantum error correction was presented as a performance discontinuity; a next discontinuity discussed was coherent interconnects. Progress was described as escaping one scalability barrier then hitting the next, not Moore's-law linear.
Attack classes are not one race
In-flight attacks on a public mempool need a fast cryptographically relevant machine. At-rest attacks can use slower machines against keys already on-chain. A third class, attributed to the recent PRX Quantum paper, separates exploit manufacture from exploit use. Harm paths named included theft of on-chain assets, rewriting history on proof-of-work consensus, breaking confidentiality, inflation attacks, collapsing stablecoin pegs, and forging cryptographic votes. Devices of that class do not exist yet; the way off the bleak path is post-quantum cryptography.
Do not wait for a grokable Q-day signal
Late entrants may not announce themselves; known labs may go quieter. The recommended stance was to assume it will happen and start PQC work now, rather than wait for a visible “this is the moment.”
Japan-hosted prize: migrate networks, do not invent a primitive
A multi-year, internationally open competition (Japanese government as host and funder; BGIN coordinating; path into a BGIN standard and then ISO, including TC 307) will score efficient methods to migrate blockchain networks to quantum-resistant signatures and advanced key management, using NIST-class schemes. Comparative targets named were Bitcoin and Ethereum. Evaluation axes: theoretical security and implementation efficiency. This year defines a “PQC-ready” chain, including a one-day workshop alongside SSR in December. Applications next year; winner targeted by March 2029. Block 15 stands up evaluation.
AI is a forcing function for crypto agility
There is no known campaign to slow quantum hardware; AI is being used to speed it. AI cryptanalysis is already in the wild. A one-shot jump from elliptic curves to ML-DSA was rejected. Crypto agility—rotating schemes without a wholesale redesign—was presented as the design goal. ML-DSA was noted as the relevant recommended scheme for verifiable credentials.
Industry is at “it is real; what now”
Protocol roadmaps are appearing. After “yes, migrate,” the hard questions are algorithm choice, throughput, block size, node sync, and social consensus. Minimum protocol-side timeline to a fully post-quantum chain was given as about two to three years on the aggressive end, with an undefined user-migration tail. Hybrid then cutover was the preferred path. Elliptic curves were stated as still fine to use today.
Q-day is a probability, not a date on a slide
The quantum speaker would not bet personal money on a cryptographically relevant machine by 2030, would bet around 2032, and would put 2029 at about 5%. For a cybersecurity owner, that 5% already demands action. A same-day viral RSA-260 factorization was classical AI, not quantum; sentiment risk for institutions was named as a reason to start now.
Session outcomes
- NIST primitives exist; the DLT gap is deployment, consensus-wide validity rules, long-lived verification, dormant funds, and comparable evidence of “PQ-ready.”
- Qubit count and a single Q-day date are the wrong monitors; error correction, interconnects, compiler progress, and a 5% near-term tail already justify starting now.
- Crypto agility as the design objective: hybrid then cutover; do not freeze a one-time elliptic-curve-to-ML-DSA rewrite.
- A Japan-hosted, internationally open migration prize (NIST schemes; Bitcoin/Ethereum as evaluation anchors; BGIN standard then ISO), with Block 15 to stand up evaluation.
- A named continuation: BGIN Block 15 (15–16 October 2026, Washington, D.C.; hybrid), including Keynote: PQC (15 October, 09:20–09:50) and IKP: PQC Migration (15 October, 09:50–11:20 and 11:30–13:00).
- Event: BGIN Block 15
- Registration: Eventbrite
- Keynote: Keynote: PQC
- Session: IKP: PQC Migration
For media inquiries: bgin_admin@bg2x.org