Monad's post-quantum roadmap
Mohsen Ahmadvand
Protocol Engineering
- Published on
- · 9 min read
TL;DR
Recent advances in quantum attack research have made Post Quantum (PQ) readiness more urgent, with several organizations now targeting 2028–2029 (see here, here, and here). Falling attack costs make theft more economically attractive, increasing the risk to users. Attack costs and potential future reductions are modeled by combining published resource estimates with hardware prices. Monad’s PQ strategy starts with wallet protection, where the potential gains from stealing funds can justify even multimillion-dollar attacks. Category Labs’ Flexible Authentication draft is already public, and PQ consensus is being developed in parallel. Other upgrades will follow these two priorities.
Disclaimer
The cost and attack-time estimates in this post combine published research with additional assumptions and extrapolations. These illustrative scenarios are used to guide engineering priorities and the order of upgrades. They are not forecasts of actual machine prices, attack costs, or when quantum attacks will become practical.
Introduction
In a preprint first submitted on 21 May 2025, Google Quantum AI researcher Craig Gidney estimated that an optimized attack based on Shor's algorithm could break RSA-2048 in less than a week using fewer than one million noisy physical qubits. The earlier estimate was 20 million qubits for an eight-hour computation. Improvements in arithmetic and error correction cut the estimated qubit requirement by more than 20-fold, with a longer runtime. That lowers the hardware barrier to breaking RSA-2048 and makes early post-quantum preparation more urgent than before, as about 2-3 safe years remain (with the current state of affairs).
Shor's algorithm also applies to elliptic-curve cryptography, where it can derive a private signing key from an exposed public key. That threatens Ethereum's and Monad's ECDSA accounts on secp256k1, as well as the BLS12-381 signatures both networks use for consensus. More broadly, this is an industry-wide problem: major blockchains rely on public-key cryptography that is vulnerable to sufficiently capable quantum computers, while Monad is already working through a concrete migration plan.
Google's March 2026 research estimates 18 or 23 minutes to recover one secp256k1 private key with fewer than 500,000 physical qubits, depending on the circuit variant. By comparison, the RSA paper calculates 4.96 days, rounded up to a week for headroom. Recovering a wallet's key would let an attacker sign transactions from that wallet and effectively control asset holdings.
For BLS12-381, the authors expect modestly greater resources than for secp256k1 and warn that the same first generation of cryptographically capable quantum computers could threaten it. They do not provide an exact BLS runtime or total qubit count. Recovering a BLS key from a validator would allow forged signatures from that validator, potentially disrupting consensus.
Quantum Clock Target
Google has set a 2029 target for its post-quantum migration. Blockchain teams are setting timelines too: Algorand targets broad quantum resilience by the end of 2027, and Ripple targets XRPL's transition to post-quantum signatures by 2028. The Ethereum Foundation's PQ team estimates that L1 protocol upgrades could be completed by 2029, with full execution-layer migration taking additional years. Moving wallets, validators and applications to new cryptography takes time, so preparation has to begin before these attacks become practical.
Post-quantum cryptography uses algorithms designed to withstand quantum attacks. Monad starts with wallet authentication because recovering one key can expose the full spendable balance it controls. As an illustration, a single-key wallet holding $100 million could lose that entire balance after one successful key recovery. The machine can be reused across targets, spreading its purchase cost over many attacks. PQ consensus follows, with work on both already in progress.
Monad is building PQ protections now while laying the technical foundations for further upgrades in the months and years ahead.
p0. Protect user funds
Economic viability
Published superconducting-system prices include about €5 million for the 24-qubit VLQ computer, €25 million for Euro-Q-Exa with its initial 54-qubit system and planned 150-qubit upgrade, and Rigetti’s $8.4 million order for 108 qubits. Contract scope and system design differ, so these provide comparison points rather than a common price per qubit. Using the Rigetti order for an illustrative calculation, scaling its price per physical qubit to 500,000 qubits gives a hypothetical $38.9 billion machine.
To estimate the capital allocated to an attack, assume a five-year useful life and 50% productive utilization:
- Available operating time: 5 (years) × 365 × 24 × 60 × 50% (~utilization ratio) = 1,314,000 minutes.
- Capital per modeled run: $38.9 billion × (18–23-minute key recovery ÷ 1,314,000 minutes) ≈ $530,000–$680,000.
Against wallets with high holding, a $530,000–$680,000 capital allocation per recovery shows why an expensive machine can still create a strong incentive to target funds. Protecting account control removes that direct route from a recovered classical key to a user's balance. Therefore, providing a migration path to post-quantum resistant wallets is set as the first goal.
Solution
The public Flexible and Upgradeable Account Authentication draft proposes a concise migration path at the protocol level. An account stores its authentication configuration in state; its address stays fixed while the credentials that control it can change.
Under the design, a user can add post-quantum credentials and retire the old ones without moving assets to a new address. Validators check the account's signing policy before voting. Authentication reads only the sender's account state, and the protocol supplies a defined set of verification algorithms. These choices follow Monad's design constraints: authentication must be checked cheaply before EVM execution, and must avoid shared-state contention that would serialize parallel transactions.
Recent cryptanalysis of lattice-based HAWK and the isogeny problem underlying SQIsign reinforces the need for crypto agility. Both schemes reached Round 3 of NIST’s additional-signature process, although HAWK has since been withdrawn and the practical impact on SQIsign remains under assessment. The Flexible Authentication proposal lets accounts upgrade to supported PQ schemes without changing their addresses, while new schemes can be added through protocol upgrades.
Flexible Authentication would let an existing account retire that authority while keeping its address. This allows for a graceful migration without disrupting address books or bookkeeping in DeFi protocols. Users need to migrate their signing and reconfiguration policies to gain PQ protection.
p1. Protect consensus
While wallet migration protects who can authorize spending, consensus migration protects which history the network accepts. Even after accounts adopt PQ authentication, forged consensus certificates can threaten settlement.
A sufficiently powerful quantum computer running Shor’s algorithm could recover consensus signing keys from their public keys. Compromising enough signing authority could allow an attacker to forge certificates, disrupt Cadence and undermine the settlement guarantees that users and applications rely on. Recovered keys could support repeated forgeries while they remain accepted, extending the damage beyond the initial quantum computation.
Price of quantum attacks on consensus
For a dollar conjecture, published ECC circuit formulas are used as a rough scaling proxy, assuming about 1.5 times as many qubits and 2.3 times the runtime of the wallet case, or roughly 3.4 times the capital allocation. Applied to the $38.9 billion baseline, this gives a hypothetical machine costing $58.3 billion. With the same five-year lifetime and 50% utilization, the wallet case’s $530,000–$680,000 becomes approximately $1.8–$2.3 million per key-recovery run. These are extrapolations, not published BLS hardware benchmarks; operating costs, financing and repeated attempts are additional. The total cost of disrupting consensus depends on how much signing authority must be compromised.
To be clear, forged consensus certificates do not by themselves authorize spending from users’ accounts, making the attacker’s route to financial gain less direct than attacks on user signing keys. But if forged certificates were used to make conflicting histories appear finalized to different parties, they could enable double-spend attacks, alongside broader chain disruption and settlement failures. That makes consensus protection a priority alongside wallet migration. Work has already started on a post-quantum version of Cadence.
Protect staking (reuse of P0 and P1)
Staking builds on the first two PQ priorities. Flexible Authentication provides the migration path for validator withdrawal authorities and delegator accounts, while the consensus work provides PQ credentials for validators. Once these are ready, validator registration must accept the new consensus credentials and staking transactions must use PQ account authentication, protecting both consensus participation and control of staked funds.
Migrate execution layer cryptography (PQ EVM)
Beyond wallet and validator authentication, PQ readiness extends to smart contracts using ecrecover, P-256 verification, BN254/BLS12-381 cryptography and KZG commitments within their contract logic. These dependencies can leave applications (smart contracts) exposed to forged authorizations or proofs. The goal is to provide PQ-safe verification options and support application migration. The Ethereum Foundation’s execution-layer roadmap similarly emphasizes PQ signature verification and gradual adoption. Ecosystem teams will be kept informed about PQ-safe options and supported through migration.
Migrate proof infrastructure
The zkVM proving stack is a later priority. Engineering's assessment is that an incorrect execution claim can be detected by re-running the block, and the proving backend can be upgraded. Post-quantum proving approaches already exist, including STARK-based systems. Independent execution makes this failure more observable, although recovery could still be disruptive.
Research is also reducing the cost of proving computations built from established hashes. Flock, a proof system using binary fields, demonstrates fast batch proving for SHA-256, Keccak and BLAKE3. Its authors identify hash-based signature aggregation as an application, while noting that full support still requires additional work.
Protect pre-confirmation privacy
The final PQ migration priority is the encrypted mempool. The BTX preprint presents batch threshold encryption: a committee can jointly decrypt selected transactions while the rest remain encrypted. Applied to a mempool, this keeps transactions encrypted until block inclusion to reduce opportunities for maximal extractable value, or MEV.
A quantum break here could reveal pending transactions early and weaken MEV protection. This risk is rated below forged account control, consensus failure and failures of monetary integrity, so PQ migration for the encrypted mempool follows other pieces. The encryption construction will get a post-quantum upgrade.
Wrap up
PQ account authentication and consensus are being actively developed. Wallet teams should start by reviewing the Flexible Authentication draft for in-place upgrades, key rotation and recovery. The wallet migration secures users’ funds from immediate PQ risks. Making the consensus PQ will ensure that settlement and chain progression remains intact by the time quantum machines are available.