# ECC Has an Expiry Date, Post-Quantum Cryptography Fixes It | Danno Ferrin - Tectonic Labs

- Speakers: [Danno Ferrin](https://streameth.org/speakers/danno-ferrin)
- Channel: [Ethereum Denver](https://streameth.org/ethereum-denver)
- Date: 2026-03-09
- Duration: 18:19
- Topics: ETHDenver, Crypto, Web3, Blockchain, Event, Conference, ETHDenver 2025, ETHDenver 2024, Bitcoin, Ethereum
- Watch: https://streameth.org/watch/yt-hVJ0uTW0w30
- YouTube: https://www.youtube.com/watch?v=hVJ0uTW0w30

## Description

🚀 Get Ready for ETHDenver 2026! 🚀

We're already hard at work preparing for next year's biggest Web3 event!

Keep your eyes peeled for more info on ETHDenver 2026—it’s going to be epic! 🌟

## Transcript

Great. Glad to be here. Uh like I was mentioned, my name is Dan O Farren and I'm a core engineer at Tectonic Labs. And what we're doing at Tectonic Labs is we're really focused on the issues of how quantum computers are going to impact more things in life than you're going to realize. And the first thing they're going to impact before they start folding proteins and predicting the weather and doing all sorts of amazing calculations is they're going to solve hard math problems. The kinds of hard math problems that ECC elliptic curve cryptography depend on. And anybody who's deep in the industry knows ECC is everywhere in blockchain. It is everywhere in there. And recently the way things have been developing, elliptic curve cryptography has an expiration date. It's going to start aging like milk. So, so why is it developing this this expiration date? Why is it a problem? The problem has to do with something called a cryptographically relevant quantum computer. And this is they've got quantum computers. They've got them doing the cubits. They've got them doing they're using them already in a few places to improve their algorithms. But this is one that has gotten to the level that it can actually crack things like RSA and ECDSA cryptography, the kinds of cryptography that's happening. And uh it's it's kind of a mouthp to say CRQC. So, I like to use the phrase I learned from one of the other people in the industry. Just call it a croc. And being a crocodile is kind of what's going on. It's underneath the surface. It's just kind of lurking and you don't know when it's going to get up and snap at you and bite you. But it is a risk that you really need to plan your visit in the swamp around. So, some of the more aggressive credible claims say it's going to happen within about two to three years. Some of the more realistic claims say it's going to happen sometime in the mid-30s. And the pessimistic claims say it's going to happen in 2050. But nobody's saying that these things are impossible and are never going to happen. Um, and today it's really been accelerating this past year. There's been a lot of breakthroughs with, if you're into it, noisy bits, physical cubit numbers going up, error correction rates going down. Um, if you know a lot about quantum computers, you know why it's a risk. But just if you don't have a PhD in quantum mechanics, know that it is a risk that's going to affect cryptography. So, what's the threat of having a machine that can crack these keys? It's a more generalized threat to all of our secrets in a process called harvest now decrypt later. So nation states listen to the internet. They grab everything. People who infiltrate and break into companies, sure they find your encrypted text. They just take your encrypted text and they hide it. Yes, it's hidden behind elliptic curve cryptography and it cannot be cracked by conventional means. So they sit on it until they get a quantum computer that is fast enough and then they harvest the stuff that they need out of there and they go through it. It's a bit different with blockchain. The reality is the harvest has been done. It's been done by websites by the names of blockchain.com, Etherscan. It's it's kind of a problem because publicly sharing our public keys so we can verify our transactions is a foundational feature of blockchains. So knowing these public keys and these signatures that are out there um this is the basis that they need for for a quantum computer to extract the private key. So, how is this a problem to blockchains that they can extract your private key? Well, it's pretty simple. Not your keys, not your crypto. It doesn't matter if you gave your keys away or if some computer looks like a chandelier figured out what the private key is. If they can get your private key, they can impersonate you online. They can take your funds. They can move it elsewhere. They can vote on your Dows the way they don't want to. They don't that you don't want them to. They can do all sorts of goofy things that you didn't expect would happen. And this is because they can reverse your keys. and what's and you're doing absolutely nothing wrong. You're using the blockchain the way it was intended. Um this is kind of an acceleration of what they were expecting um with the quantum computers and now we're kind of in a hard spot because everything is locked in pretty hard to elliptic curves. Um so we need to step back a bit and figure out why people have been worrying about quantum computers for so long and why in some ways we're actually prepared for this eventuality of things accelerating. Uh this is something called Moscow's equation. Moscow is one of the one of the pre-minent people in quantum mechanics and he did a little bit of the back of the envelope math. So X represents the shelf life of your data. How long do you need this to be secret? Y figures is a is a the amount of time it takes for you to to create and standardize and distribute new cryptography to reenrypt this data. And Z is how long it's going to take for these quantum computers to show up that are going to go through and are going to reverse um this this key. Now you add up the equation X plus Y. If it's greater than Z, you're in trouble. It's a bit different for blockchain though. Um because the distribution is pretty easy on the nodes. It's going to distribute on the nodes, especially if it's integrated at consensus. The availability of this is going to be instant. The forks you get it out. But X is the real problem. X is more of a diffusion crisis. It's not the core computers we're worried about. It's the people who have their smart wallets and who have their cold storage that are locked into old addresses that are locked into old ECDSA values. If they don't move their coins, then your coins are still at risk. The risk isn't over when they deploy quantum cryptography on the blockchains. No, the risk is over when your money is out of elliptic curve signatures and into postquantum signatures. So people out there who are keeping their their their little metal tablets in their firebox, they lock it away in a storage facility in in some place in Montana, if they're not going to go to that and retrieve it for eight years, then that is eight years that the blockchain is at risk. And what is the risk of of keeping an insecure key on the chain? It's secure now, but it might not be secure um in in 8 to 10 years. What is the risk of keeping that key out there that other people could take? The problem is something I call the zombiecoin apocalypse. And this is something that like blockchain that um that Bitcoin in particular is facing a crisis of because of how long it takes Bitcoin to make changes. If it takes more time to change the coins and for people to go retrieve and move their coins than it does for quantum computer to get around and resolving this data, um then you have the risk of people taking that money and doing what they will with it. Bitcoin famously has about 25% of its entire mint available in these pay to public key addresses. So the public key and the signed transaction information, everything you need is onchain already if you have these magical computers. They don't exist, but they will. But another problem is that Ethereum nearly every key gets used because Ethereum has a strong culture of account reuse. Once you do one transaction and you verify one transaction with transaction with that address, your public key is out there. Now, if quantum computers didn't exist and we just had classical computing, that is a perfectly fine security assumption. But the rules of the road are trading or the rules of the road are changing and and we are trading one one one world of security with another world of security, the pre-quantum and postquantum. Um, but who should we really be afraid of? Do you think the US government and their defense departments can use their quantum computers? They're most likely going to decode um messages from other nations. Similarly, China is probably going to go for uh you know public uh national security information. But what about Lazarus? What if people like that get a hold of this? What about other nation state actors who want to attack some of the economic powers of America? Um are these the nation state actors we should be afraid of? Um is this what we should be concerned about? While I do think we should be afraid of nation state actors, I think we need to think of a different kind of a nation state actor that is really the biggest threat to um to the current state of elliptic curve cryptography in blockchains. These nation state actors are banks and their regulators. If you're not concerned about quantum computing and the impact it's going to have on cryp encryption, don't worry. These banks have thought about it for you and they've made the decision for you that if you're going to use a banking system in five years you're going to be using systems that involve quant postquantum cryptography and in 10 years you will not be able to use elliptic curve cryptography in your banking systems. Now this is going for the regulated level. This is um you know talking about your your Wells Fargos and your city corpse. But if we're trying to get Bitcoin and Ethereum into these systems and become a full practicing member of this society, if we're trying to replace the rails of how trades are done, then these rails are going to be subject to these regulations. And this is going to have a bigger impact on Ethereum's transition to postquantum cryptography, I feel, than the threat of some nation state actor stealing your keys and selling your monkey JPEGs. Um, while those are really important to us, it's going to be a a much more impactful impact when we're talking about the entire world economy that's trying to use our chain that says, "Well, we can't use you anymore. Go back to your little circle. We want to be louder. We want to be broader." So the the impact is that by 2030 and 2032 um the G7 and this is like basically the biggest banks. You got the European Central Bank, you got the Department of Treasury, you got the SEC, you got Baffin out of Germany, you've got every major regulator saying that by 2030 all of the banks and financial institutions and financial people's systems need to be migrated into um a system that uses postquantum cryptography by 2030 to 2032. And then by 2035, it's a straightup ban. and if you're not migrated by then, you can't use the system. So, they're putting a really aggressive schedule and for banks, a 5-year transition p plan to new technology is super aggressive. But the G7 cyber expert group has made that decision. Now, how serious is this? And I give this next slide to give just how serious the context is behind this. Um, US Department of War and Department of Defense contractors um have been given a much stricter time frame. um at the end of the year if you're if your piece of hardware wow that gong is really loud um that is not very zen but what's um going on with the national security system is that by the end of the year if you are selling hardware and it cannot support postquantum cryptography um then then national security systems in the US cannot buy it you your systems must support it you don't have to have it turned on but you must be able to support these postquantum cryptography systems that I'll talk about in a bit and by 2030 30, you have to shut off elliptic curves. Not only do you have to support it, you have to use it. And so this makes sense because financial regulators tend to follow two years after um a national security mandate. And that's exactly what we're seeing going on. So now that we know that X ECC has an expiration date, um how does postquantum cryptography fee fix this? And I'm going to be honest with you, it's not all sunshine and daisies. It's not all rainbows and butterflies. There are some hard problems that need to be solved with this because if this was easy, it would have been done. It would have been just another change to an elliptic curve and it would have been very easy to to to to um to uh make it progress through all the systems. So the NST saw this problem a decade ago. They did Moscow's math and they said we're in trouble. We need postquantum cryptography now. So in 2016, almost a decade ago, they started a process that they called um uh I forgot what the exact name for it was, but it the the outcome of this is that they they started a new uh postquantum security signature process. The first round they got nearly 70 candidates. Um people have their own secret little cryptography thing that's academic. Um a lot of these things look great until you put it under serious scrutiny. So you put a lot of these systems under serious scrutiny and it was just carnage. um within two years over half of them had been demonstrabably broken in classical systems or had severe issues with it that caused them to be withdrawn. The second round was a focus between three older forms of cryptography. Latisbased cryptography, isogyny based cryptography and codebased cryptography. Well, isogyny is kind of newer, but these three candidates were kind of in in a little battle to say which which which family is going to win. Um in round three is when the truth really started coming out because you you winnowed it down to 15 candidates and then one by one there were major classical breaks that were found um in some of these some of these candidates. a particular famous one rainbow which was codebased. They found a classical break in the particular construction of it and that lost. And the isogyny one had a similar break in the chem variety and that one lost. And lattisbased cryptography was the one left standing without major breaks that brought the security below acceptable security thresholds. And in 2024 they standardized these. Um FIPS 2004 is MLDDSA. FIPS 2005 is a backup. It's a hashbased protocol. SLHDSA and coming out this year hopefully is going to be FIPS 206, FNDSA or Falcon. Falcon signatures are the ones that all the blockchains are excited about because we look at the the what what resulted in some of the changes that are coming on. Yes, these algorithms are a little bit faster, but the pain comes in the size of the public keys and in the signatures. ECDSA was magical in that you needed 33 bytes or 64 bytes to store your keys and share them publicly. Um but but so these are the lowest grade uh the lowest level of security that that is acceptable for finance and we're talking about kilobytes for public keys and for and for signature sizes. Um and sure sure the a hashbase one has a small 32 byt public key but the signature size is is huge uh nearly 8k and it's also 22 times slower. So these are not you know magical replacements for ECDSA. You can be fast, you can be small, you can be quantum resistant. Pick two. You can't be all three anymore because we know that ECDSA. So the ones that won, a lot of the systems that are working today are going to have to deal with larger memory requirements and larger public key size. And that's where a lot of the struggle is coming on with blockchains today. Now the NAS team was not terribly satisfied with what they came out as a final solution. Um everything was based on lattice cryptography and the backup wasn't that great. So they opened up another process that has colloally been called PQC on-ramp. Um additional signature schemes. It was opened up in uh 2022. Um and the focus here was to get things that weren't lattice that could serve as another backup and provide more alternatives for systems to use uh postquantum cryptography. Um we're in round two. There's 14 candidates. They're undergoing deep evaluation. Any day now. We expect the system to progress uh and tell us which candidates are actually going to be candidates for standardization. Um there's some exciting ones going in there and it covers all of the major remaining categories. Um the most exciting one is key sign. Even though the verification speed is 32 times slower to verify, it has the magical small signatures and small public keys that might be valuable for for um blockchains that have very expensive block space and the verification is not a problem. Um but there's a multivariate solution um with mayo and unbalanced oil and vinegar. The problem there large to gigantic keys. There is one that is very friendly to ZK processing called feast based on symmetric uh multi- encryption. Um the problem is is very large signatures 10 kilobyte signatures but it's just amazing when you look at ZK provability. So people who are serious about ZK systems if this gets standardized should look at that. And finally we got a a codebase system that was kind of like rainbow again large signatures and small public key sizes but it's it's got a lot of support. I mean the signatures are gigantic. Um not nearly as big as the public key as unbalanced oil and vinegar 43 kilobyte public key that is just but you know 96 sign byte signature if you can store your public keys it can it can get pretty amazing. But that's not where the problems end. Hardware wallets also are facing a problem with postquantum cryptography. Um I forgot to bring my old uh useless wallet that I bought at ETH Denver um six years ago. A keep key. It can only handle EC cryptography. Um, I just don't remember where I put it because it's not going to be useful um when they transition to these. Um, the newer wallets, I know that um the the Ledger the new the new e- in ones um have enough to support that and the new treasure wallet that they're that they're selling has enough um RAM usage to handle the lattice math for at least some of the keys. But you get into things like um you have your um your credit cards that have like that little me chip on there. um that little electronic chip that you tap with those can't handle the computational requirements of some of these larger ones and don't have the memory requirements. So this is going to be a problem not just in our industry but all the problems in all industries and a lot of these problems deal either with extremely high RAM usage higher than they want to use or absurdly large processor usage and sometimes it's both. But I think one of the more more critical issues is that these are all subject to side channel attacks that they haven't gone through and analyzed in quite the same way and optimized with lipic curve cryptography. So your your wallet when it creates a signature if someone has it they can divine information out of it or if you're running it on a computer in a cloud system other programs that are on the same system might be able to slowly figure out pieces from it just by being there. These side channel attacks are quite quite the big problem. So with all of this in mind, when you're looking at at systems that are migrating to postquantum cryptography, the one thing you need to look for is something called cryptographic agility. If a chain picks one true signature and sticks with that, that's a warning sign because they might be in the same situation in the future that they are in today because they picked the one true signature of ECDSA. You want to make sure that that they can swap in and out uh cryptography systems easier um than then happens today. So that's the real sign. they don't have to ship multiple signatures immediately, but if they they are in a situation where they need to change a signature, add a signature or they find a better signature, um then then that's where you want to um look look for. So, in summary, um you want something that's going to age like fine wine, not like milk. You're going to want to use cryptography that has a long proven thing. And the real threat is the is the G7 um is the nation state regulators and administrators that are saying it's time to get off elliptic curves. that's going to be the real more pertinent issue to to your company and your projects going forward with postquantum cryptography. And uh if any of you have questions, um I don't have time for Q&amp;A right here, but I'll be here in the uh I'll be wearing this shirt the whole day um at the conference. So, thank you for your time and postquantum cryptography, it's uh it's time to wake up. It's been time.
