Three of the largest blockchains have now published plans to survive quantum computing. They have arrived at broadly the same deadline from completely different starting positions, and the gap between them has almost nothing to do with cryptography.
It comes down to one question. Can you change the keys protecting your money without moving the money?
On the XRP Ledger you can. On Ethereum and Bitcoin you cannot, and that single difference shapes everything each network is now trying to build.
What the Threat Actually Is
Public-key cryptography works because deriving a private key from a public one is computationally impossible for ordinary computers. A sufficiently powerful quantum machine running Shor’s algorithm would make it possible. Research published by Google Quantum AI this year showed the cryptography most blockchains rely on falls into that category.
No such machine exists. Ripple says so plainly in its own roadmap, and so does StarkWare’s chief executive. What changed is that the threat moved from theoretical to credible, which turns it into a scheduling problem.
There is a subtler risk researchers call harvest now, decrypt later. Every time an account signs a transaction its public key becomes visible on chain, and anyone can copy that data today and wait for hardware to catch up. Coins that have never moved are safe. Coins that have moved are already recorded in public.
XRPL Already Has the Migration Path
XRPL supports native key rotation. An account holder can move away from a vulnerable key without changing accounts or relocating funds, because the protocol was built with that separation in place. Ripple is direct about what this means competitively, noting that most other blockchains, Ethereum included, have no protocol-level equivalent, and that migration there means manually moving assets to entirely new accounts or relying on smart wallets.
That is not a post-quantum solution. It is a migration path that already exists, which is a considerable head start.
Ripple published a four-phase roadmap on 20 April, targeting full readiness by 2028. Phase 1 is a contingency for the day classical cryptography breaks, in which the network stops accepting classical signatures and forces a move to quantum-safe accounts. Ripple is exploring post-quantum zero-knowledge proofs so holders could prove ownership of existing keys without exposing them, and migrate even after the cryptography protecting them has failed. The middle phases cover algorithm testing with quantum security firm Project Eleven and parallel running on a test network. Phase 4, targeted for 2028, is an amendment moving the whole network across.
Ethereum Is Building the Box First
Ethereum has the hardest problem and knows it. More than 65% of all ETH sits in addresses whose public keys are already visible on chain.
Its work has run in public all year. Vitalik Buterin raised quantum resistance to a top-tier priority in August, the foundation dropped the Poseidon hash function for longer-established alternatives, and developers filed a draft proposal to replace the validator deposit contract, which hardcodes key sizes at 48 bytes against the roughly 8,192 post-quantum schemes need.
That proposal is instructive. It builds the container without deciding what goes in it, explicitly leaving the choice of scheme to a future proposal. Ethereum is designing the box first because the box requires a coordinated fork across two layers, and that is the part that takes years.
Bitcoin Has No Roadmap at All
Bitcoin has no roadmap at all, which is a function of how it changes rather than indifference. There is no foundation to publish one, and any protocol change needs a soft fork the community agrees to.
So the most concrete progress has come from outside. In late August, StarkWare mined the first quantum-safe Bitcoin transaction on mainnet, using hash-based security inside Bitcoin’s existing rules and requiring no fork or permission. Its own author is blunt about the limits. StarkWare’s chief executive said the achievement should not be read as Bitcoin being prepared, and continues to argue for a soft fork as the real fix. The method also cannot protect addresses whose keys are already exposed, and currently requires sending transactions directly to a miner, which ordinary holders cannot do. Roughly 7 million Bitcoin are estimated to sit in vulnerable addresses.
What None of Them Fixes
None of these plans retroactively protects a key that is already public. Ripple’s zero-knowledge recovery is the only approach among the three that tries, and Ripple describes it as one path it is exploring rather than a finished mechanism. Project Eleven, whose research put better-than-even odds on a capable quantum machine by 2033, is also the firm Ripple contracted to help build its defence. That is common in a small field, and a reason to read threat estimates and vendor roadmaps with the same eye.
Nothing described here has shipped. XRPL’s transition is an amendment that has not been written. Ethereum’s is a draft awaiting review, with no algorithm selected and no activation dates fixed. Bitcoin’s is a proof of concept most holders cannot use.
For anyone holding crypto the useful reading is narrow. These are network-level plans on multi-year timelines and none of them changes what your wallet does this week. The one thing within a holder’s control is whether coins sit in an address that has already broadcast its public key, and on XRPL that is fixable today with a key rotation.


