New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Ian Smith - Migrating Web3 to Quantum Safety

ETHCluj MeetupTue, Oct 7, 2025, 12:00 AM

Quantum computing poses many challenges to web3 with the erosion of all key based security. Since quantum computers will turn the public key into the private key, a quantum attacker can impersonate any user in the ecosystem. ZK technology faces additional challenges at the circuit, prover, validator and user. Navigating to quantum safety is a widely misunderstood problem. The presentation will occur on three levels simultaneously, with the speech based on high level understanding while slides cover both the web3 protocols and the quantum attacks. The bulk of the material is based on migration to safety.

Transcript

So the QR code uh will take you to our community and all of these slides are also available inside the community as a PDF file. So if you want to check some of the technical information or details you can you know refer to the slides later on. And then some of my other presentations as well as uh you know podcasts and other things are also in the same uh community as resources. Here are the companies grouped by the technology that they're working on that are making quantum hardware. And some of these are very advanced and some of them are a long ways away.

Um my pick for the leaders would be uh Saquantum and Riverlane uh because they have very good manufacturing at Saquantum and they have very good uh gates at Riverlane. A lot of people are just paying attention to, you know, IBM. They're paying attention to D-Wave. They're paying attention to Regetti. But like Alice and Bob has a much more advanced system that isn't getting much attention.

With this many companies working on it and there's more joining and growing, there's more likely going to be a predictable hardware increase. Now as the algorithms improve the hardware requirements go down and then as you know the manufacturing improves the hardware performance goes up. Uh this was a report by McKini and they're they're saying that basically 2027 is a start of being able to possibly break RSA 2048. uh elliptical curves used by blockchain are about five times weaker than RSA based off of the scaling for handling the additional bits. what the algorithms mean for quantum comput uh for quantum computing breaking elliptical curves and blockchain is that they switched from a single computer that we can't build to a large number of small computers that we can build and that network mode runs 45 times faster.

So it's there's more of a threat from the algorithms than there is from the hardware. And this is much more attainable. This is just people who can you know do math at their house. This doesn't require access to liquid helium and you know advanced physicists. This is just programming and mathematics in a different way.

The scaling for quantum's active volume architecture if you triple the cubits you 7x the speed. So they were talking about how to break uh Bitcoin in 10 minutes using uh 6,000 nodes. Well, if you cut the number of cubits down to 1 nth, then you're cutting the speed by 149th. And so you're talking basically eight hours on a million cubits. So, a lot of people say that uh blockchain and bitcoin they're they're going to be fine because the hacks are going to get the banks are going to get hacked first.

all these other the whole world is going to have problems and just Bitcoin and and web 3 are going to survive is the new the new dawn to a new revolution and for some reason everybody else is upgrading but web 3 is not I was at the Bitcoin conference in Vegas there was six presentations on migration to quantum safety uh there was multiple panels and I'm part of that community as well so the issue is that Bitcoin is now talking about this, but web 3 is not. So, we should at least catch up to Bitcoin and plan our migration strategy. Bitcoin has a viable migration strategy. Uh, one of the questions is what do you do with Satoshi's coins? The problem here is that the the information on the ledger is all that is required to wreak havoc throughout the entire ecosystem.

Quantum computers can turn the public key into the private key when they get big enough for the algorithms get, you know, small enough. The disadvantage here is that uh it's very easy for Bitcoin to add a new address type. It is extremely hard for web 3 to add new address types when you're dealing with smart contracts and web 3. So just the extended use case means massive extra complexity in terms of migration. Ethereum Foundation looked at converting from 160 bit addresses to 256-bit addresses and they basically gave up and said it is not possible and that was after they worked on it for about two years.

So the quantum attacker can become anybody now in terms of like what happens when uh Qday occurs. Qday is probably going to be accepted as the day that Satoshi's coins move and then people will start to sell their assets and if they are convert they're converting from ETH to USDT and then trying to withdraw it to their bank how much money will actually exit the system and so you're going to end run into a problem where people will sell at basically any price um if we don't prepare it says This is basically the damage that will be caused if we don't prepare. The more that we prepare, the less people will try to sell, right? The less damage will be done to the the underlying security. So, one of the reasons I say that, you know, people will agree on Qday is that we don't actually know when it will occur.

We may not know when it occurred until several years after the fact. There's a large number of Bitcoin wallets that have over a thousand Bitcoin. There's over 2,000 of them. Every month, one of them sells like $30 million worth of Bitcoin or hund00 million worth of Bitcoin every month like clockwork. It's really weird.

Are those is that a quantum attacker? We can't tell. So now migration these are the various like topics that have to be covered in order to actually handle migration. You have to migrate the consensus model the wallets and then the data on the ledger. And the first the first one consensus is actually the easiest to do.

You tell whoever's validating your transactions, you have to use this new cryptography, sign a transaction, move your your your proof of stake to the new system. It's not that hard to do and you know they're going to do it because they have so much money at stake. Users are a much different problem. They generally don't follow instructions very well. And in the case of um EIP 7702 and 4337, it's no longer having the public key on the blockchain itself, but now it's this third party authentication system.

uh it can be mpc, it can be multisig, it can be local devices, it can be some code that's running on some uh some server and that authenticates the transaction and that makes it harder to force upgrades because now you have infrastructure that's also has to do a different upgrade in parallel to the main upgrade. But it's also safer because there's they don't have the public key sitting on the ledger. They can't just, you know, get the public key, get the private key, and then drain the funds. The ledger itself, I'm going to have to cover in more depth. So, the methodology of migrating the consensus.

There's different pieces that have to be uh changed. The first one is the block signatures. Whoever's signing that block, they have to now do it with a postquantum signature. If they sign a block and they don't have a postquantum signature, well then the attacker has that key and now they can sign blocks as if they were that validator. Second thing, the validator contract.

This is very specific to like Ethereum where there's a lot of like delegation that occurs. Uh so the delegation methods are also part of the surface area of attack. The way in which the contracts manage between the uh the validators and the actual staking the cues that occur. All of that is now part of the surface area of the uh that can be attacked and all of that has to do a more complicated migration because now there's a lot of technology and infrastructure in place around that contract system. the proof of stake and you know knowing that basically there's assets that are being uh staked.

It's possible for the attacker to simply drain the staked assets and say oh you're not validating anymore as part of the consensus. It's also possible for the attacker to slash honest validators in concert because they will have multiple keys. they would be able to uh perform actual slash attacks against uh something that maybe has a contract or in you know isn't using the same architecture or they could you know slash someone that uh they dislike for some reason they can cause unlimited havoc within the web 3 ecosystem and then the transaction the network protocols this is more specific to like polka dot and xx network the network protocols for Cosmos also have the elliptic curves inside the network messages. That's a bad thing. That makes that makes it very very hard to migrate.

Um the transactions they need to be postquantum cryptography and they need to be checked by whoever's validating the block and validating the transactions and that is a scaling problem. Um and I'll cover that later on. So when the wallets are signing the transaction, they are using their private key to do an elliptical curve signature and then they're submitting their public key along with the signature to prove that they are the correct and responsible party for managing those assets. It's fairly simple to change the cryptography, but every user will have to sign a transaction that goes from the old cryptography to the new cryptography and the new uh wallet address. And the new cryptography will have a different method of signing it.

So, EC recover, Q, ethers.js, all that stuff has to also be replaced. Web3.js, hard hat all has to be replaced. So this this very simple thing in terms of doing the transaction verification for Bitcoin is actually really really hard for web 3 no matter which protocol you're referring to.

The EIP7702 was my big hope to actually go to quantum safety. Uh because I was I was really really hoping that they would force a quantum safe method and then the validator of that transaction, whoever's hosting that account would then accept that postquantum methodology and they would not have to publish a public key. Instead, what happened is that you now have this basically unmanageable system where any validation validation provider or signing provider can use whatever architecture they choose and you've now pushed a centralized problem to a decentralized distributed problem where phones are using fingerprints or you know the sixdigit recovery phrase as a method of val of proving and validating transactions. It's a it's a problem because now we can't necessarily upgrade it in the same way and it's the surface area is again increasing. So even if we do everything right in one way, we might fail the other two steps and still lose hundreds of millions of dollars in in TVL.

This is where it gets hard. So every time you have a smart contract that has an admin, that admin has some level of permission over that contract. Anything that the admin can do, the attacker can do. All of the admins need to migrate from the old cryptography to the new cryptography, but it may not be able to hold the new cryptography and it may not they may not have added the management where they're able to transfer owner from signature one to signature 2. The smart contract may not have the correct logic in validating the new signature or the error checking may error when it should have succeeded for a postquantum system.

And that's just the admin migration function. So each one of these smart contracts has a large amount of surface area uh based off of the ecosystem usage. If they're able to upgrade that smart contract, well the attacker would be able to upgrade that smart contract and replace a known good library with an attack library. then post quantum signature users that migrated properly could call the now corrupted smart contract and lose all of their funds anyway. The contagion in a mixed environment is extremely bad and extremely dangerous.

So there's a lot to do here. um bridges are going to be uh of course hacked like usual because they have large balances but now it's not just let's say that Ethereum you know upgraded everything but then they're bridged over to Binance Smart Chain and whoever manages Binance Smart Chain end of that bridge didn't upgrade everything well now the Binance Smart Chain can be attacked and drain funds that were shared between Binance Smart Chain and Ethereum. So, every single peer also needs to upgrade because otherwise the manager of that bridge or the funds on either side could also be drained. The attack surface is very very high in web 3. Um, Algarand is like, "Yay, we're doing postquantum because we have a backup of the chain history having a Falcon signature once every 5 to 10 minutes.

And I do not know of any attack that that prevents." So, some people have actually done this last item and none of the others and they're advertising themselves as being postquantum. No, they haven't done any of the other work. Algurand also has an additional problem because they have data owned by a wallet managed by a manager and most of the time there is no ability to actually edit who owns manages or uh does bookkeeping on the data and there's also staking involved in having data on chain and the sometimes these wallets cannot be replaced. So I expect that they will have to make their immutable ledger simply editable uh in order to change all of the addresses.

I don't expect them to actually complete this task. Any questions so far on this? Like because now it gets hard. Oh, Mike,

just a quick question because I arrived a bit late. Uh, this seems really serious. How close do you think this is?

The attackers say that they'll be ready to attack in 2027.

Which are the attackers? Who are they?

Uh, that was the first slide. Uh, I think that Cyclquantum and Riverlane are the closest and they both said they're going to be ready by 2027. Uh there are multiple attack avenues. Uh there is a large number of algorithms. There's shores, optimistic shores, red jevs and a fourth one I don't discuss.

The resource requirements go down year after year. Uh the typical rate is a 10 to 100x performance improvement every 1 to two years. It is even with no improvements in the algorithms that we're still talking 2027 2028 based off of the active volume architecture network mode and the ability to simply scale up through mass production which has been going on for the last 13 months.

Okay, thank you.

Soon. Another question sort of a followup to that. How expensive would that attack be uh to perform?

Uh a couple hundred dollars on equipment that costs a few hundred million. Uh there's also the possibility of doing emulators instead of quantum hardware. But the emulators there would have to be algorithm and emulator improvement performance that would be significant before that would be possible. And then you would be able to rent mainframe time for a few thousand dollars to do it. Unfortunately, it's really cheap.

I've heard people saying, "Oh, it'll be too expensive to run the machine. Those quantum, you know, we have to buy helium 3 and helium 4. The radioactive isotopes only come from nuclear reactors or volcanoes." Not all of them. You can just cycle quantum runs on liquid hydrogen or liquid helium.

It scale at giant massive steel fridges. So it's cheap for them. Okay. So now the harder stuff, the scaling, the rollups, and the schnore signatures. Now, one of the things that uh the lightning network, the Ethereum network, and Salana have all done is they've all used the same equation for aggregating signatures.

And most of the rollups use the same the same equation. The shnore signature is ED25519. This is an elliptic curve. And you can take an unlimited number of transactions or signatures and compress and and put merge them into one single signature that is the same size. Check that one signature and you know that every single signature is valid.

If it fails, you can do them in batches. Uh there's no quantum safe replacement for that. There's nothing in quantum post plus quantum cryptography that does anything similar to that inside quantum cryptography that uses quantum computers. Yes, there is something similar to that. But there's nothing that would work on silicon uh that is also protected against quantum computers.

So layer 2 lost their cryptography. Um they lost their scaling. Uh ZK snarks are directly attackable because there's an elliptic curve inside the circuit that proves the circuit and proves the validity. And then um multi-IG MPC and like Schnore secret sharing. These all are attackable by a different algorithm known as the ability hidden subgroup problem.

It also has a polomial time speed up. It is also just as vulnerable. So use of multi-ig has to become ephemereral and it should be done on blockchain. There's in via smart contracts. There isn't a way for banks to continue to do multi-party computation and secret sharing amongst themselves without having some kind of like smart contract that does the logic.

The mathematics are expiring uh for security fully encryption um which is available on Ethereum today uh is the possibility of having a privacy layer. Uh it's basically like you have a spreadsheet that you can do math on without seeing the numbers that you're doing the math on. Um and there are variations of polyomorphic encryption that are postquantum. ZK starks are also postquantum but nobody uses them exclusively not even starket. This is a problem that every blockchain will experience to some degree.

Um, for Bitcoin, not every address has a known public key. The question of what to do with the assets that don't migrate to Postquantum. Right now, there's 6.2 million BTC sitting exposed with known public keys. Web 3 has uh 100% of its addresses basically known with known public keys and then the the new EIPs are changing that and they're making it you know basically a delegated problem.

What do you do to people who don't migrate and if you don't burn the addresses you're leaving all kinds of problems in the chain but that would destroy a large amount of value. uh however if you don't burn it you simply give that large amount of value to the attacker. One of the reasons why we cannot migrate easily is that we have to migrate before the attacks begin. If we if we allow the the risk to come to fruition and there is now the possibility of a quantum attacker, the quantum attacker can migrate the funds to their quantum safe wallet and out of the original owner. So you've simply facilitated theft by delaying migration.

If they don't migrate, you probably have to burn them. And that means most of web 3 even if we migrate to starting today which the technology doesn't exist uh for the most part that's still what we would need to do. Now the Bitcoin protocol will still function until the machines get under 1 hour solve time. Web 3 won't even have the the protocol. So the basic opportunity here is replace all the math and replace the leaders.

If you wanted to become the new unis swap now you can u by changing the to a blank slate there will be a new number one for each category. Uh maybe unis swap will migrate early and still be keep their number one throne position but the real opportunity is that there's a bit of a shakeup. Uh, Bitcoin will have forks. You might benefit on, you know, six forks and sell some of those Bitcoin and keep the rest. But it's it's all going to uh change.

It's um one of the things that I'm looking at doing is providing uh quantum safe uh technologies to do quantum computing because that makes sense. uh and one of the the partner businesses is going to basically run a compute network uh for running AI on quantum computing which is really good. Cryptography requirements are harsh. You have to replace all the public private stuff. Uh you have to replace well some of the symmetric keys are also broken.

Um you have to use lattises and codes. I highly recommend NIST post pulse quantum cryptography not the thing that they made last week in their garage. And also Falcon has not been standardized. So if you use Falcon today, you have to throw it away for whatever the next version of Falcon is. Quantum resistant chains.

Quantum EVM is I'm the CEO unfortunately. Cellframe uh technology that has scaling and builtin. Uh Kelvpn is built on Cellframe, but this is a postquantum VPN which is rare. Uh QRL is the oldest and they're using u a hashbased signatures. They're going to migrate to a smart contract architecture either late this year or middle of next year.

They don't have a roadmap timeline. Mochimo is a small proof of work system. They're micro cap, but they're actually postquantum. So, I give them applause and QR code to join the community and get the presentation.

Thank you so much, Ian. Everybody give a hand to Ian.

Automatic transcript — names and jargon may be misspelled.