

QRL Weekly, 2026-August-07
Status / overview
- August 4th: Audit results published for go-qrllib
- April 3rd: Audit complete of 2 cryptographic libraries
- March 31st: QRL 2.0 Testnet V2 Released
- Audits: 50% completion
QRL 2.0 (Project Zond)
qrl-web3-wallet
- further security-audit remediation and code-review fixes
- corrected address display and updated documentation
web3.js
- updated CI actions and patched vulnerabilities affecting fast-uri, PostCSS, SVGO and brace-expansion
js-qrl-cryptography
- updated pinned GitHub Actions and the fast-uri dependency
go-qrllib
- updated pinned GitHub Actions and opened further test-related work
qrypto.js
- updated development dependencies, lockfiles and CI actions for mldsa87
qrvmc
- Harden hex parsing, example VMs, and loader
- Tighten gas validation, loader TLS and ABI docs
go-qrl
- –bootnodes flag now override config value
- Go toolchain updated to 1.26.5
- external function values updated to 64-byte address plus a 4-byte selector
- Removed legacy local testnet script (now being moved to new repo qrl-tests)
- Several other bug fixes
qrysm
- Updated tests
- Go toolchain updated to 1.26.5
- Updated QRL dependencies
- Update the staking deposit CLI default to the valid deposit contract address
- Default address aligned with the Qrysm network config
- Fix Zond consensus version descriptor
web3.js
- ICAP and IBAN support removed as those are deprecated
- Added 64 byte topics and 512-bit integers data type
qrl-package
- Changes merged related to 64-byte address
QRL 1.0
dice
- 2018 Python script rewritten as JavaScript application
- session isolation, CI and browser end-to-end tests
- a verifiable single-file offline release
qrllib
- added RNG-regression protection
- modernised Emscripten support
- migrated release processes to GitHub Actions
- added trusted publishing and npm/PyPI deployment
- v1.2.6 released
offline-wallet-generator
- merge of v3 wallet format with stronger encryption and password security
- added reproducible offline builds, CSP tests and a security-focused CI/release pipeline
qrl-wallet
- 7 issues closed
- continued UI refinements
- gated multisig signing on validation and tighter OTS-reuse checks
- applied security hardening and documentation updates
- v1.9.1-beta in pre-release
qrllib-browserify
- updated support to Node.js 22+
- rebuilt the bundle for qrllib 1.2.6 and corrected module export and Browserify interoperability
qrl-cli
- replaced the aes256 dependency with scrypt-derived AES-256-GCM encryption while retaining compatibility with legacy wallet files
The Official QRL Show is Live covering the COLDCARD Exploit, QRL's Trail of Bits Audit Results, and more!
youtube.comQRL Announces Trail of Bits Publication of Security Assessment of its Cryptographic Heart, With All Findings Resolved
QRL Announces Trail of Bits Publication of Security Assessment of its Cryptographic Heart, With All Findings Resolved
An independent review examined the cryptographic heart of QRL, including implementations, public API, and wallet state management.
4th August 2026
ZUG, Switzerland — August 4, 2026 — The Quantum Resistant Ledger (QRL) today announced that Trail of Bits has published its independent security assessment of its cryptographic heart, go-qrllib, a cryptographic library being developed for QRL 2.0. The assessment identified 15 findings, one High, four Low, and ten Informational, all resolved following remediation by QRL and review by Trail of Bits.
The publication marks a security milestone for QRL 2.0, a post-quantum, EVM-friendly Layer-1 blockchain addressing the risk a cryptographically relevant quantum computer (CRQC) poses to public-key signatures used by blockchains.
Digital assets depend on these signatures to establish control and authorize transactions. A capable fault-tolerant quantum computer could use Shor’s algorithm to recover private keys from public keys and forge signatures. A March 2026 study estimated that attacking secp256k1 could require about 1,200-1,450 logical qubits, while IBM, Quantinuum, and Microsoft target fault-tolerant or scalable systems by 2029. These roadmaps do not establish a CRQC date, but reinforce NIST’s guidance to begin post-quantum migration now.
A three-consultant Trail of Bits team conducted an extensive review focused on go-qrllib’s XMSS and ML-DSA implementations, exported API boundary, and wallet state-management paths. The work combined manual source review with fuzzing, external test vectors, reference-implementation comparisons, mutation testing, and other static and dynamic techniques.
Trail of Bits described the codebase as well-organized and modular, noted that its cryptographic primitives strongly followed their specifications, and reported strong testing coverage and defensive wallet implementation. The findings primarily concerned the robustness of the library’s exported API and supporting controls rather than the correctness of its underlying cryptographic primitives.
“go-qrllib is a well-organized, modular codebase with cryptographic primitives that closely follow their specifications. The QRL team was responsive throughout the engagement and resolved every finding we reported,” said Filipe Casal, Principal Security Engineer at Trail of Bits.
QRL’s remediation included stronger API validation; improvements to error handling, documentation, secret-memory handling, and wallet behavior; expanded regression testing; hedged ML-DSA signing by default; and additional CI/CD controls. Trail of Bits reviewed the fixes and mitigations on June 22, 2026.
Trail of Bits published the full assessment through its official publications channel.
The source code is available in the go-qrllib repository.
Why deploy on QRL 2.0?
When it hits mainnet soon, most projects will be able to recompile their existing Ethereum contracts and go fully post-quantum secure—literally overnight. Low barrier. High security. That's $QRL.
Multi-chain isn’t optional anymore.
https://x.com/Strike_Attack/status/2084237824585322566/video/1
New Paper from Caltech/Harvard team introduces "mitten codes": High-rate qLDPC processors with real-time decoding and massive error suppression
A really impressive pre-print just dropped by Aditya Bhardwaj, John Preskill, and a joint team from Caltech, Harvard, and AWS. They are addressing one of the biggest bottlenecks in fault-tolerant quantum computing (FTQC): making qLDPC codes practically usable on real hardware.
Here is a quick TL;DR on why this paper is generating a lot of buzz:
🚀 What are Mitten Codes?
qLDPC (Quantum Low-Density Parity-Check) codes are famous for being far more qubit-efficient than standard Surface Codes, but they usually come with huge hardware routing overheads and complex decoding pipelines.
"Mitten codes" are a new family of qLDPC processor codes based on non-abelian groups that solve a lot of these physical implementation problems.
💡 Key Highlights:
- Insane Encoding Rate (~20%): Instead of needing thousands of physical qubits per single logical qubit (like standard Surface Codes), mitten codes yield 1 logical qubit for every 5 physical qubits.
- Massive Parallelism: Supports high-rate lattice surgery (executing many logical measurements in parallel) and parallel magic-state injection across all logical qubits simultaneously.
- Real-Time Decoding (Sub-millisecond latency): A huge problem with qLDPC has been decoding speed. Their decoder achieves average sub-millisecond latency per cycle—fast enough to run in real-time on hardware like neutral atoms.
- Extremely Low Error Rates:
- Under circuit-level noise at a 0.1% physical error rate (PER), the
[[300, 60, 14]]code hits a block logical error rate of $\sim 10^{-11}$ per round. - In a stress test of 15 billion surgery experiments on the
[[540, 108, 18]]code, they observed only 2 logical failures. That’s baseline proof for running $\sim 10^{10}$ logical operations cleanly.
- Under circuit-level noise at a 0.1% physical error rate (PER), the
🛠 How did they find them?
They built an end-to-end design pipeline powered by sQetch, a new distance estimator that is orders of magnitude faster than existing code-search tools.
Importantly, the authors highlight that mitten codes map cleanly onto near-term neutral atom arrays (with shuttling/reconfigurable connectivity) and superconducting architectures.
Definitely feels like a solid step toward bridging the gap between theoretical FTQC overheads and realistic hardware implementation!
What are your thoughts on non-abelian qLDPC implementations vs. 2D color/surface codes for the next 3–5 years?
QuantaPool Is Preparing for QRL 2.0 Mainnet: DigitalGuards Seeks a US Operating Partner
QuantaPool is heading for QRL 2.0 mainnet under a dedicated US operating entity. DigitalGuards is in advanced discussions with a prospective US partner and remains open to further qualified candidates. Here is the role.
>
DigitalGuards has spent the past two years building the product stack for QRL 2.0: wallets for web, mobile, desktop, and browser, the ZondScan explorer, a post-quantum dApp connect SDK, the QuantaSwap atomic-swap protocol, and QuantaPool, our liquid staking protocol. Today we are announcing the next step for QuantaPool, and putting our search for its operating partner on the public record.
What QuantaPool is
Running a validator on QRL 2.0 requires 40,000 QRL and the operational skill to keep a node healthy. QuantaPool lowers that barrier: users deposit any amount of QRL, the pool funds validators, and depositors receive stQRL, a token whose QRL value grows with validator rewards. The protocol is live on the QRL 2.0 testnet at quantapool.com, fully open source under GPL-3.0, with a 200-test contract suite. Everything runs with valueless test assets today.
Why a US operating structure
Operating a staking protocol with real value is a serious undertaking: real deposits, validator uptime, user trust, and clear accountability. After reviewing the options, we consider a dedicated US operating entity under genuine, active US management the right home for QuantaPool’s mainnet operations. DigitalGuards remains the owner and builder: the copyright, the brand, and all development stay in-house, and the operating entity runs the service under license from us.
The partner we are looking for
We are in advanced discussions with a prospective US partner, and we remain open to hearing from further qualified candidates. The role, in brief:
- Genuine, active management of the operating entity from the United States: the decisions, the operations, and the accountability
- Validator infrastructure operations with continuous monitoring and incident response
- Custody of operational keys and participation in the protocol’s multisig
- Ownership of the entity’s compliance obligations, together with US counsel
- Solid business standing: entity formation, banking, clean records
This is a working operator role, suited to someone with infrastructure experience and compliance seriousness, ideally from the staking or hosting world. Capital participation is open for discussion, and commercial terms are discussed directly with qualified candidates.
Why we are publishing this
Partly for candidates, and partly for the record. QuantaPool’s development has been public from the first commit, and the search for its operating home belongs to that same public history. When the partnership is signed, this post will get its sequel.
Get in touch
Write to info@digitalguards.nl with the subject “QuantaPool operating partner”. Tell us who you are, where you operate, and what you have run.
Any partnership is subject to definitive agreements prepared with counsel, and nothing in this post is binding.
Please, feel free to visit>
https://quantapool.com/
https://quantaswap.io/
https://qrlwallet.com/
QRL Weekly, 2026-July-24 Status / overview
QRL Weekly, 2026-July-24 Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
- Network Performance Optimization: 60% completion
web3.js
- Audit remediation; keystore cryptography hardening; removal of import cycles; coverage gates; reproducible supply-chain checks; dependency overrides; CI timeout and build-order fixes
- 20 constituent packages released
rust-qrllib
- Refactored the demo build, aligned documentation with go-qrllib, and updated demo dependencies and TypeScript configuration
QRL Weekly, 2026-July-17
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
Qrvmc
- Several bug fixes like VM bounds checks for PUSH and memory expansion, loader config boundary and precompile sweep coverage etc.
- Updated and added new test cases
- Reviewing qrvmc to ensure changes made in Hyperion also align with qrvmc
go-qrl
- Unused ECDSA signatures are removed
- Added Local testnet setup script using kurtosis
- Move typed-data encoding to the QRL 64-byte model
- go-qrl still being reviewed for 64 bytes related changes
web3.js
- Migration to 64-byte QRL addresses and 64-byte VM words; supply-chain and dependency hardening; CI fixes; Turbo and GitHub Actions updates; Node 20 compatibility
- Further audit work underway
js-qrl-cryptography
- Added and exported SHAKE256 with selectable output length, test vectors, packaging tests and documentation
qrypto.js
- Dependency and GitHub Actions updates, including Turbo and Zizmor
qrl-web3-wallet
- Bound dApp signing and transaction requests to the authorised chain, with chain-context revalidation and tests
- Added llms.txt along content-negotiation to serve content as markdown files for better LLM support
qrl-wallet (QRL 1.0)
- Prevented custom-node connections unless enabled; synchronised mainnet and testnet branches
Post-Quantum Blockchains in 2026: Where do QRL and Mochimo stand today? (Zond and beyond)
With the post-quantum cryptography (PQC) narrative gaining steady traction, I wanted to take a look at two of the OG Layer 1 projects built from scratch to resist quantum attacks: The Quantum Resistant Ledger (QRL) and Mochimo (MCM).
While both share the core mission of securing ledger states against future quantum computers, their development paths and architectural goals have diverged significantly. Here is a breakdown of where they stand right now and what is on the horizon.
1. The Quantum Resistant Ledger (QRL) & Project Zond
QRL’s focus has transitioned from a pure transactional ledger into a fully programmable ecosystem. All eyes are currently on the rollout of Project Zond (QRL 2.0).
- The Status: The development is highly mature. Following the release of the updated Public Testnet earlier this year, QRL is moving closer to its final mainnet deployment.
- What to expect (Zond):
- QRVM (Quantum Resistant Virtual Machine): An EVM-compatible environment, allowing developers to deploy decentralized applications (dApps) using Hyperion (a Solidity-derived language designed for a post-quantum world).
- Proof-of-Stake (PoS): Transitioning away from Proof-of-Work to a secure PoS consensus mechanism, introducing native staking.
- Mainnet Inbound: With cryptographic audits for the new architecture progressing through their final stages, the official Mainnet 2.0 launch is the definitive next step.
2. Mochimo (MCM) & Its Current Outlook
Mochimo took a completely different, highly academic engineering route. Instead of using XMSS, it utilizes a modified WOTS+ scheme and a unique "state-sequence" architecture designed to prevent blockchain bloat, keeping node storage requirements remarkably low.
- The Status: Mochimo operates at a much lower profile. It remains a technical, niche project with a quieter community and lower market liquidity compared to QRL. It hasn't positioned itself to compete in the DeFi or smart contract space.
- Does MCM have a "Zond" equivalent? Short answer: No. There is no active roadmap or initiative to build a Turing-complete virtual machine or native dApp ecosystem inside Mochimo.
- What to expect in MCM:
- Core Efficiency Upgrades: Development continues to focus purely on ledger optimization, node synchronization efficiency, and maintaining a lightweight, secure network that can run on consumer-grade hardware.
- Pure Store of Value / Ledger: The expectations for MCM are focused on proof-of-concept longevity—proving that its custom anti-bloat network can remain resilient and secure over time, potentially serving as a secure transactional layer or interoperability bridge rather than an all-in-one dApp platform.
TL;DR / Summary
If you are looking for smart contracts, staking, dApp migration, and an imminent network evolution, QRL’s Project Zond is where the tangible action is. Mochimo remains a fascinating, pure cryptographic experiment for lightweight quantum-resistant transactions, but its development and adoption pace are significantly more conservative.
Would love to hear thoughts from anyone running nodes on either network or testing out the Zond testnet!
The $4B Investor: Bitcoin Isn't Ready for Quantum
youtube.comFor those who are just starting to take an interest in QRL. Read the Google article.
reddit.comCZ Floats Freezing Satoshi’s Bitcoin Over Quantum Risk
Binance founder Changpeng Zhao (CZ) floated freezing Satoshi's Bitcoin and other dormant, quantum-vulnerable coins if they stay unmoved after a future network upgrade. He raised it as a question for the community, not a personal plan.
The Binance executive shared the idea on the Galaxy Brains podcast with Galaxy Research head Alex Thorn. He has since pushed back on reports that he would personally freeze Satoshi Nakamoto's address for a year.
Is Freezing Satoshi's Bitcoin a Good Idea?
The debate grew louder in March, when Google Quantum AI published research on breaking the cryptography that secures digital signatures.
Its team estimated an attack could need fewer than 500,000 qubits and run in minutes, well below earlier projections.
The risk sits in exposed keys. A quantum computer could derive private keys from public keys, then drain the wallets they protect.
The fix is to adopt quantum-resistant cryptography, yet coordinating that across the network takes years.
More than a third of all Bitcoin had revealed a public key on-chain by March. That leaves them in addresses vulnerable to quantum theft.
Satoshi Nakamoto mined an estimated 1.1 million BTC in 2009 and 2010. That estimate rests on the Patoshi pattern traced by researcher Sergio Demian Lerner.
What CZ Actually Said
Zhao did not call for a seizure, nor did he say Binance would act. He put the decision to the community, asking why it should not set a roughly 1-year timeline.
Coins left in vulnerable addresses after that point would be locked in by a fork.
CZ said the popular take that he would personally freeze Satoshi's address was not quite right. He also flagged a snag, that telling Satoshi's wallets apart from other early miners is hard.
His thinking aligns with BIP-361, a draft by Jameson Lopp and five other researchers. It would block sends to vulnerable addresses about three years after activation, then void legacy signatures two years later.
The authors frame a blunt choice. A quantum thief could grab the exposed coins, or miners could slowly recover them. The network could instead lock them so no one wins.
That proposal even cites Bitcoin's creator on the issue of lost coins.
>
The dormant coins are contested on another front. An anonymous plaintiff and two Wyoming LLCs are fighting a New York abandoned-property lawsuit.
They want 39,069 idle addresses, including the Satoshi coins, declared theirs. A Galaxy report by Thorn doubts it will prevail.
Any forced lock still violates a core Bitcoin rule: no one can take another person's coins. Many would read it as confiscation.
CZ said there is no perfect answer. He warned that doing nothing could prove the worst outcome of all.
France Says It Will Won’t Certify Security Products That Aren’t Quantum-Resistent Starting in 2027
France’s national cybersecurity agency, ANSSI, will stop certifying security products that do not include quantum-resistant encryption beginning in 2027, a policy that will effectively require government agencies and operators of critical infrastructure to move away from traditional cryptographic systems, according to comments made at the France Quantum conference and reported by Reuters.
The move places France among the most aggressive governments in Europe on quantum security and reflects growing concern that sensitive information encrypted today could be vulnerable in the future as quantum computing advances.
Under the timeline outlined by ANSSI Chief of Staff Samih Souissi, products seeking ANSSI certification after 2027 will need to incorporate quantum-safe cryptography. Souissi also said businesses should be purchasing only quantum-resistant products by 2030, Reuters reported.
Because ANSSI certification is required for deployment in French government organizations and critical infrastructure sectors, the policy amounts to a gradual phase-out of security products that rely solely on conventional encryption methods.
“It’s not only a technical issue,” Souissi said, according to Reuters. “It’s a matter of governance, industrial planning, regulation, and sovereignty.”
Industry participants at the conference also offered differing views on when the threat from cryptographically relevant quantum computers could emerge, Reuters reported.
However, the decision is also driven in part by concerns over so-called “harvest now, decrypt later” attacks. In that scenario, adversaries collect and store encrypted data today with the expectation that future quantum computers may eventually be capable of breaking the cryptographic algorithms protecting it.
Quantum computers capable of defeating widely used public-key encryption systems do not yet exist. However, governments and cybersecurity agencies increasingly argue that organizations with long-lived sensitive data must begin migrating now because cryptographic transitions can take years to complete.
The policy is expected to create new demand for post-quantum security technologies across Europe.
Pascal Brier, chief innovation officer at consulting and technology services firm Capgemini, told Reuters that interest is increasing as banks, public-sector organizations and other institutions evaluate their exposure to future quantum threats.
“That market is becoming big. It’s going to be very substantial,” Brier said, according to Reuters.
The announcement comes as France continues to invest heavily in quantum technologies through a national plan valued at approximately 3 billion euros (about $3.5 billion USD). The country is seeking to strengthen its position in a global quantum race that includes significant investments from China, the United States and other nations.
If BTC decides to go Quantum-Proof: A breakdown of phases, timelines, and the "Lost Coins" problem - Aka "they need 6 or 8 years to resolve the problem"
If Bitcoin ever decides to make the definitive move toward quantum resistance, it will face the most complex, delicate, and massive upgrade in its history. This isn't just about changing lines of code; it’s a socio-economic and technical puzzle.
While proposals like BIP-360 (mitigating public key exposure via P2MR) and BIP-361 hint at early framework discussions, a full migration would require a highly structured, multi-phase approach. Here is a breakdown of how the steps, timelines, consensus, and audits would likely play out.
1. Technical Phases & Migration Strategy
Because PQC signatures (whether lattice-based like Dilithium/Falcon or hash-based like SPHINCS+) have significantly larger byte sizes and higher computational overhead than ECDSA/Schnorr, a sudden switch is impossible. The transition would require a phased rollout:
- Phase 1: Public Key Obscurity (Mitigation): A quantum attacker using Shor’s algorithm requires an exposed public key. Legacy addresses (reused addresses, p2pkh, etc.) are highly vulnerable. The first line of defense is introducing output types like P2MR (Pay-to-Merkle-Root) via BIP-360 to hide the public key until the exact moment of spending.
- Phase 2: Introducing the PQC Algorithm (Soft Fork): A new quantum-resistant address type (e.g., P2QRH) would be introduced. Users would then need to voluntarily move their funds from legacy addresses to these new "shielded" addresses.
- Phase 3: The Sunset Period: After a strict grace period, legacy ECDSA transactions would face severe restrictions, penalization, or ultimately, be frozen to protect the network's integrity.
2. The Consensus Bottleneck (The Political & Economic Debate)
The real bottleneck for Bitcoin isn’t the mathematics—it’s the social consensus. Achieving agreement on this change introduces massive economic dilemmas:
- Soft Fork vs. Hard Fork: Developers will fight to implement this as a Soft Fork to maintain backward compatibility. However, given the drastic structural changes to spending rules and the massive signature sizes, some analysts argue a Hard Fork might be unavoidable, risking a permanent chain split.
- The "Lost Coins" and Satoshi’s Millions Dilemma: Millions of BTC sit in legacy addresses with exposed public keys (including Satoshi’s estimated 1M coins). If a sunset clause is enforced:
- The Pragmatic View: Freeze or burn unmigrated coins to prevent a quantum attacker from stealing them and crashing the market.
- The Purist View: Altering or freezing coins violates Bitcoin’s immutability ("not your keys, not your coins"). The framework in BIP-361 has already sparked intense debate because it would permanently freeze older funds that lack modern recovery methods.
3. Estimated Timelines (The Runway)
If we assume a Cryptographically Relevant Quantum Computer (CRQC) might emerge in the 2030–2035 window, Bitcoin's timeline would have to look something like this:
- Research, Optimization & Auditing (2–3 Years): Selecting the right NIST-approved algorithm is only half the battle. Bitcoin devs would need to heavily optimize the code to minimize block space saturation and fee spikes.
- Network Activation (1–2 Years): From merging the code into Bitcoin Core to waiting for miners and nodes to signal readiness (via BIP9 or Speedy Trial).
- Active User Migration Window (3–5 Years): Because of Bitcoin's limited throughput (~7 TPS), millions of users cannot migrate all at once without sending transaction fees to astronomical levels and clogging the mempool. The migration must be gradual.
4. Audits & Validation
Given that Bitcoin is a trillion-dollar financial infrastructure, the auditing process would be unprecedented:
- Cryptographic & Math Audits: Top-tier firms (like Trail of Bits or OpenZeppelin) alongside academic cypherpunks would intensely audit the chosen primitive against both quantum and advanced classical attacks.
- Consensus & Scalability Simulations: Using testnets and sidechain frameworks (like Anduro) to simulate how Bitcoin Core handles the heavy throughput and validation stress of massive PQC signatures.
- Hardware & Client Audits: Hardware wallet manufacturers (Ledger, Trezor, Coldcard) and third-party node implementations would undergo independent reviews to ensure the new quantum key generation is flawlessly random and secure.
What are your thoughts? Given the sheer size of PQC signatures and the governance gridlock in Bitcoin, do you think BTC can successfully pull this off in time, or does the architectural advantage remain strictly with native-PQC chains like QRL?
Ionq roadmap. 1600 logical qubits by 2028?
IonQ's latest roadmap is one of the clearest signs that the quantum race is moving from theory to engineering at scale.
According to their roadmap, IonQ aims to reach:
- 800 logical qubits by 2027
- 1,600 logical qubits by 2028
- 8,000 logical qubits by 2029
- 80,000 logical qubits by 2030
supported by roughly 2 million physical qubits and logical error rates below 10⁻¹².
For the QRL community, the interesting part is not whether these exact numbers are achieved on schedule. The important point is that major quantum companies are now openly planning around fault-tolerant logical qubits, not just noisy physical qubits.
Historically, discussions about quantum threats focused on machines with dozens or hundreds of physical qubits. This roadmap is talking about thousands to tens of thousands of logical qubits, which is an entirely different category of capability.
If even a fraction of these targets are met, it would strengthen the argument that migration toward post-quantum cryptography should happen long before large-scale cryptanalytic quantum computers actually arrive.
QRL was built around that assumption from the beginning: don't wait until quantum computers break current cryptography—prepare before they do.
Whether IonQ ultimately reaches 80,000 logical qubits in 2030 is less important than the fact that one of the industry's leading companies is publicly charting a path toward that scale. The conversation is gradually shifting from "Will fault-tolerant quantum computers exist?" to "How quickly can they be built?"
That's exactly the kind of trend QRL has been preparing for since day one.
Digital reset of the global economy
I just asked an AI which financial ecosystems could be affected by a quantum computer. Because we are always talking about BTC or crypto. And this is what it answered. It's worth clarifying that the quantum race is not only about hacking crypto, but about achieving governmental and strategic superiority.
If a quantum computer with 1,000 logical qubits (which would require hundreds of thousands of physical qubits with error correction) fell into malicious hands, the global financial ecosystem would face far more than a simple "hack"—it would trigger a systemic crisis of trust.
At that scale, traditional public-key cryptography algorithms such as RSA and ECC (Elliptic Curve Cryptography) become completely vulnerable through Shor's Algorithm.
Here is a breakdown of the financial structures that would be impacted first and most critically:
1. The Crypto Ecosystem: Legacy Accounts and Exchanges
Unlike QRL (Quantum Resistant Ledger), which was designed from the beginning to be resistant to this threat, the vast majority of current blockchains would be exposed.
Bitcoin P2PKH (Pay-to-Public-Key-Hash) Addresses: Older Bitcoin addresses (such as those associated with Satoshi Nakamoto) or addresses where an output has already been spent (thereby revealing the public key) rely on traditional ECDSA signatures. A machine with 1,000 logical qubits could derive the private key from the public key within minutes, allowing historical wallets to be drained and triggering massive panic across the market.
Centralized Exchanges (CEXs): Even if exchanges upgrade their hot-wallet signing systems, the internal communication infrastructure and APIs connecting institutional trading bots often rely on TLS/SSL implementations built on vulnerable cryptography. An attacker could intercept credentials and redirect funds on a massive scale.
2. The Interbanking System and Payment Networks (SWIFT, Visa, Mastercard)
Fiat money does not move in armored trucks—it moves as bits protected by digital certificates.
The SWIFT Network: The global financial messaging system used by banks to transfer trillions of dollars every day depends on traditional Public Key Infrastructure (PKI). If an attacker could forge digital signatures within SWIFT, they could issue apparently legitimate international transfer instructions to fraudulent accounts on an unprecedented scale.
Credit Card Processors: The tokens and communications between point-of-sale terminals (POS), payment gateways, and issuing banks rely heavily on RSA/ECC. The collapse of this security layer could disrupt global retail commerce within hours.
3. The Bond Market and Centralized Custodians (Sovereign Debt)
This is the true engine of the financial system, far larger than the stock market.
Clearing Houses: Institutions such as DTCC in the United States or Euroclear in Europe record ownership of trillions of dollars in bonds and equities. Their databases and authentication systems used to validate derivative contracts and debt instruments could become vulnerable to record manipulation or institutional identity spoofing.
4. Central Banking Infrastructure and CBDCs
RTGS (Real-Time Gross Settlement) Systems: The internal systems used by central banks (such as Fedwire in the United States or Target2 in Europe) to settle balances between commercial banks could become vulnerable.
First-Generation CBDCs: Central Bank Digital Currencies designed using traditional cryptography rather than post-quantum cryptography could face compromised issuance mechanisms, potentially enabling the digital counterfeiting of sovereign money.
The "Store Now, Decrypt Later" (SNDL) Threat
By the time a 1,000-logical-qubit quantum computer becomes operational, some attacks will already have effectively occurred in the past. State actors and advanced cybercriminal groups are already intercepting and storing encrypted financial traffic and confidential banking communications. Once sufficient logical qubits become available, they could simply run quantum algorithms to decrypt historical data, revealing trade secrets, past financial positions, and access credentials that may still remain valid.
This is why the development of hybrid networks and hash-based one-time signature schemes (such as the XMSS scheme used by QRL) is not merely a theoretical experiment—it represents one of the most practical defenses against a potential digital reset of the global economy.