# Securing Cryptography and Hardware for the Quantum Era | Charles Guillemet - Ledger

- Speakers: Charles Guillemet
- Channel: [Ethereum Denver](https://streameth.org/ethereum-denver)
- Date: 2026-03-09
- Duration: 18:28
- Topics: ETHDenver, Crypto, Web3, Blockchain, Event, Conference, ETHDenver 2025, ETHDenver 2024, Bitcoin, Ethereum
- Watch: https://streameth.org/watch/yt-rWop5ddF9lA
- YouTube: https://www.youtube.com/watch?v=rWop5ddF9lA

## Description

With no doubt, the Quantum Era will challenge us. We will therefore discuss how to secure cryptography and hardware to ensure we can address this.

## Transcript

Hello and welcome back. How's everyone doing? Good. When I say let's welcome the next speaker, am I going to get lots of energy in the room? All right. So, our next topic is about our next talk is about securing cryptography and hardware for the quantum era. And we're joined here by Charles, CTO at Ledger. Welcome to the stage. Hi everyone. Um, when I decided to to join the the conference, uh, I didn't expect that was an AI conference. So, I decided to do a talk about cryptography and quantum computer. My name is Charles Y. I'm a CTO at Ledger. My background is cryptography and security. There are topics I'm interested in since I'm 12. Uh, when I got a computer, the first thing I did was to hack everything that could be hacked. So I did it I did this for fun and it it became my job a long time after. Um I discovered Bitcoin in 2011. Uh at the time a friend of mine was mining with his own computer. Um and he was talking about Bitcoin like every day. So I decided to uh study the cryptography, the blockchain technology, the decentralized consensus, all of this. I thought that was amazing but I I didn't really get the the use case. And this is and and so I didn't I didn't get interested more uh in in Bitcoin at the time and uh I started to uh interest to to be interested in Bitcoin uh in 2017 when I joined uh Ledger. Um so I guess like most of you are already aware of what Ledger is. So Ledger is the world leader when it comes to digital asset security. Uh we estimate that around like 20% of the global market cap of crypto is secured within ledger technology. Uh a big part of it is secured in the 8 million devices that we have sold for retail. We are um shipping in over 165 countries over the world. uh but we also have um a B2B offering for enterprise finance institution that wants to uh manage crypto uh in security but also uh with uh governance. I think the the the thing that I didn't really get when I started to uh to to study Bitcoin in 2011 is the fact that with Bitcoin with crypto uh you can really own your uh value and today when you have a look at the statistics we estimate we estimate that around 600 million uh users of crypto but most of them are not in self custody. So only 30 millions crypto users who who self custody. So it's really relatively small compared to the number of people that are exposed to the crypto value and out of this 30 million uh we estimate that it's around like 10 millions user that are using secure self custody such as ledger devices. So let's h get into uh the the topic of of the day. Um I'm going to talk about like quantum computers. So a quantum computer is something very different from a classical computer. First of all, it's leverage quantum phenomenon like superposition, entanglement and interference. It use cubits and not bits. Uh so this part is really different and cubits can exist in multiple states simultaneously. Also when you think about it uh for a classical computer to uh search for a solution, imagine like finding a path in a maze. A classical computer will try every single path one after the other until it finds the right solution while a quantum computer can try every single path at the same time. So it's fundamentally different. What but one of the problem is uh it's very powerful at least in theory but very fra fragile. It's highly sensitive to noise that that's why it needs to run close to uh absolute zero. And what you can see on the image um this is what we think is a computer but at the end it's a big fridge like all this uh golden stuff are uh just in charge of maintaining a very very low temperature and at the bottom of the image you can see the actual quantum computer. Quantum computer are um exceptional for different things but they are not like generic general purpose computer. you cannot compute any kind of things but they are really good at uh physics chemistry and breaking cryptography and this is what we're going to talk about right now. So we don't have a quantum computer today capable of breaking cryptography but for more than 20 years we know algorithm that given a quantum computer could break classic uh could break classical modern cryptography and we know that with like two main algorithm on one side you have a shor algorithm which allows to break asymmetric cryptography RSA uh elliptic elliptic curve cryptography and you have Grover which basically is able to leverage the highly parallel way of computing and could weaken symmetric encryption. Um and why it matters because today we we don't have a quantum computer. Um it matters because like most of digital sec security relies on there's uh two main algorithm and for uh the the encryption part there is there is a big issue because what we what we can imagine is that some thread actors start harvesting plenty of encrypted encrypted data so that they can decrypt it later. So this is one of the problem we have in terms of timeline. um it's very difficult to assess how far we are from having a a quantum computer. However, um I think like cryptography is a mathematical way to create trust, create security and as as soon as we are in a situation where we have doubt uh then uh we need to find solution and and we need to find solution just in case tomorrow we would have a quantum computer. So as I mentioned in cryptography you have like three main class of algorithm. On one side you have encryption. Uh as I mentioned it's at risk and it's vulnerable to to the attack that consists in harvesting all the all the encrypted data now to decrypt it later. The good news is it's quite easy to mitigate. uh if you use like classical um encryption that we have today and you use like longer keys uh it's uh it's uh um practically secure. Hashes are not for fundamentally at risk and signatures are at risk and this is the main brick that we are using for blockchain technology. It's widely used everywhere especially in blockchain but not only and there's there's algorithm are not safe against a a large quantum computer again uh what's the current state of quantum computing. So first of all it's a very long reserve cycle. Uh we started uh studying this this uh topic back in 1980s and the progress has been steady uh and nothing was sudden. Today there is more momentum but still limited capabilities. There was a lot of investment but uh the machine that we are able to build today remain very experimental and errorprone. This is really one of the challenge in terms of um like scientific and technical challenges to build this quantum computer and to today we are like very far away uh from um from having a quantum computer uh capable of breaking cryptography. uh we always say like it could be in the next five to 25 years and to be honest uh I studied cryptography maybe 20 years ago and at the time we said the same thing. I feel the situation is quite different um but uh but we are saying that we will have a quantum crypto very soon for quite quite some time now. uh what's changes uh changed recently is that we have like uh big companies IBM, Microsoft, Google, AWS like investing a lot uh on this particular topic and when you have a look at the investment like the funding has been multiplied by 10 uh in the last seven years. So there is something that is changing. Contou is now like a strategic technology waste again. Uh how far are we from uh breaking modern cryptography? So we are still very far uh because in order to break uh modern cryptography you would need a fault tolerant quantum computer with like several million of cubits. And today what we are able to do is like quantum computer with around 1,000 cubits and scaling is nonlinear. There was this issue that consists in when when you add like more cubits it's exponentially more difficult uh to maintain the state and this is the main challenge that the quantum computing industry has is facing. Recently um Google has made like a good progress in this area. So this might change in the future. But the reality uh today is is that uh the biggest quantum computer that we have cannot do like anything anything complicated like you cannot factor large numbers at all. I think the record is is around like factoring 1,00 which you can do like by hand. So we are we are still far from breaking modern cryptography. However, as I mentioned like cryptography is a mathematical way to build trust and the more we are uh stating or overstating the threat and the more the distrust is eroded. So we might be in a situation where the trust uh is um very eroded while we are still far from having quantum computers. But there are good news. Um the good news is that we already have tools uh to be quantum safe uh in case tomorrow there would be a quantum computer. This is what we called PQC that stands for postquantum cryptography and this class of cryptography is specifically designed to be secure against a large um fault tolerant quantum computer. This is not a new topic. uh this like the the first idea of postquantum crypto started back in back in the 1970s and uh it started to be like really um extensively studied from the '9s and now it's becoming a standard uh back in 2016 the NIST which is the national institute of standard and technology start started to standardize the uh the the postquantum crypto and now we have um a list of algorithm that are standardized by the NIST and the NIST mandate recommend to migrate every single system in the world uh by 20 2035. 2035 is is in 9 years. So it could uh seem um a long time but changing every single system in the world in less than 10 years is very challenging. When you think about it, nine years is a very short period of time. Um however like the migration efforts uh recently accelerated especially from 2024 2024 and the different progress that have been made uh in the industry. But as I mentioned the NIST mandates um full PQC migration by 2035. And now the question is like what kind of algorithm we will choose for encryption. This is not really um a big issue. Uh most of people are uh agrees on which algorithm which algorithm to use. It's Kyber and I think for this one it's a really a no-brainer. We should move towards Kyber as soon as possible because of the harvest now decrypt later uh problem. So this one is is not really a problem. this migration must happen but not that a big problem and encryption is not that used uh in in the blockchain technology for signatures it's it's a little bit more challenging because you have like different standard that have like pros and cons um the you you have like on one side you have like hashbased signature the pros is that is very very conservative wellstied uh strong security confidence this is really this is the the type of signature that the Bitcoin community is looking at. Uh however, you have like cons uh the signature is very very large. Uh it's mostly stateful and you have like limited hardware support. Today this is the preferred option by the Bitcoin community and on the other side you have like latisbased cryptography with MLGSA DHM falcon and de algorithm. Um in terms of pros like you have a smaller keys and signatures which will be like still far bigger that that we have on ECC. You have a fast performance uh hardware acceleration is coming. Uh on the cons side uh it's newer like uh and it's more complex math. So in terms of guarantee um it's um you have a little less guarantee because uh it's less studied than the hash that are very uh simple to understand and the latisbased cryptography is the one that is preferred in the EVM ecosystem but on both ecos we are still in the discussion uh stage and u and we we don't have a clear plan for the years to come. So as I mentioned we might be very far from having quantum computer capable of breaking cryptography. However like this transition is inevitable and uh the more uh we the faster we start doing this transition and the better it is because we have to uh transition every single system in the world from banking, internet, defense and crypto. Obviously everything uh will need to be uh upgraded and uh this requires a lot of coordination, standardization and a lot of work at the end. So uh this will take uh years um and uh and we shouldn't uh lose uh any time and blockchain um face a special uh specific challenge challenge because you need to reach a consensus and uh we built blockchain so that they are like as decentralized as possible u and it makes things a little bit more difficult to uh to agree on a plan and to activate the plan. Um at le we we have built operating system that are running on the device and also on the HSM. Uh the operating system is basically a big cryptographic toolbox that provide uh cryptographic services to the application. Uh, Bitcoin is an application that requires uh to the operating system cryptographic services for signature and what we are going to do is to add new uh primitives uh in order to uh support postquantum crypto. Um we can we can do like hashbased and latis based cryptography on device and this is probably what we are going to do. Um however in terms of like hardware support so today we can implement everything in software within uh our devices it's not ideal but it's possible so we can already support this new algorithm and in the next generation of uh secure element smart cards and HSM uh we will have hardware support uh directly which which will make uh the implementation more secure and faster. uh however on our side we are still um we are still dependent from the migration of the EVM and bitcoin and so on we can implement uh every single postquantum crypto algorithm on device if bitcoin and etherum that do not migrate uh we don't solve any problem I implementing new cryptography comes with new challenges uh so uh it open a new class of attacks and we have um a dedicated team at the at ledger which is called the dungeon that is doing like security research in order to uh clearly understand the new attack vector that can that can come with the implementation of this uh new postconquum crypto algorithm. So as I mentioned um we are leveraging like smart car technology secure element and today uh there's smart car do not provide like hardware acceleration primitive to build this post quantum crypto but in the next generation devices uh that will be the case. So to finish with as I mentioned we the the research in a quantum computer is progressing well. We are still very far from having a quantum computer capable of breaking modern cryptography. However, um as I mentioned, cryptography uh is a mathematical way to create trust and as soon as this this trust is eroded, uh we need to move towards uh like postquantum cryptography. And the good news is that we have the tool now. It's just a matter of coordination and um reaching a consensus on uh building the plan to move towards postcon crypto. Thank you for your attention.
