Skip to main content

Quantus Founder: First Crypto Quantum Attack May Mimic a Breach



Quantum computing is increasingly framed as a looming break in the cryptography that underpins major blockchains, but one overlooked risk is operational: an attacker may not need to hack exchanges or wallets in the usual way. Instead, a sufficiently powerful quantum computer could derive private keys directly from public data on-chain, enabling theft without triggering clear evidence of a “cryptographic break,” according to Christopher Smith, CEO and co-founder of blockchain security startup Quantus Network.


Smith’s comments highlight why so-called “Q-day” — the moment when quantum machines can realistically defeat widely used public-key systems — could look less like a dramatic breach and more like confusing, untraceable losses. Combined with rapid progress in quantum-related research and algorithmic improvements, the discussion is shifting from whether quantum attacks are possible to how quickly they may become practically actionable.



Key takeaways



  • Quantum attacks may be hard to detect because compromising keys via public information could leave little or no forensic trace of “how” funds were stolen.

  • Early targets might not be the most famous holdings; researchers point to high-value administrative keys and hot-wallet access as more likely first moves.

  • Estimates for when quantum systems can break elliptic-curve cryptography vary widely, with uncertainty still high across industry leaders.

  • Several teams are already preparing post-quantum signature migrations, reflecting a view that waiting for certainty is not an option.



Why quantum theft could evade traditional incident response


In conventional attacks, a breach often leaves clues—malware, compromised systems, exposed credentials, or unusual access patterns. Smith argues that a quantum-enabled key derivation would be different. “When someone cracks your key, you don’t get a memo saying how they did it,” he told Cointelegraph.


In his scenario, an attacker could use the public keys available on-chain to infer the corresponding private keys using quantum computation, then move funds without necessarily breaching the victim’s internal infrastructure. This creates a high-stakes detection problem: even well-run organizations might only discover the problem after funds have already been drained, while forensic teams see no “breach” in the traditional sense.


Smith described this as potentially producing a confusing outcome where “the only forensic evidence would be that there was no breach.” For investors, exchanges, custody providers, and institutional operators, that distinction matters: if incident response teams are trained to look for signs of intrusion, they may need new playbooks designed around cryptographic compromise rather than system compromise.



What attackers might go after first


The public debate around Q-day often centers on Bitcoin and the fear that dormant holdings could suddenly become vulnerable. Cointelegraph notes that Satoshi Nakamoto’s estimated holdings are often cited in the tens of billions, with one reference in the report placing the figure at $63 billion at the time of writing. Smith’s framing, however, suggests the first targets might be different and could be driven by attacker economics and operational convenience rather than symbolic value.


He argued that state-grade targets could be prioritized, pointing to “military systems and state secrets.” Within crypto specifically, he suggested that the highest-value keys might be operational or administrative rather than widely celebrated. “If I’m focusing on blockchain, what’s the single most valuable key? It’s probably Tether’s minting key,” Smith said.


His reasoning is that a quantum-capable attacker might mint tokens from an administrative wallet and sell into the market before the issuer can fully react. The report further notes that USDT is multi-chain and that some networks supporting its issuance are already working on post-quantum migration efforts.


Security researcher Sean Cheetham from Blockchain Capital added another angle: rather than aiming at the most famous cold wallets, attackers could focus on hot wallets at exchanges. In his view, those targets are more likely to avoid triggering alarm bells because their access patterns can resemble ordinary operational risk.


Smith also described an alternative tactic: a quantum-enabled theft could be disguised through plausible deniability. He suggested an attacker might present the incident as an ordinary loss of keys, using the uncertainty of how the keys were compromised to reduce the chance of immediate escalation.



How the timeline for Q-day keeps slipping and sharpening


One reason Q-day remains difficult to plan for is that timelines are unsettled. The report highlights recent developments that have compressed estimates for when quantum machines could attack elliptic-curve cryptography.


It points to a March update in which Google accelerated a post-quantum migration timeline to 2029, citing an AI-assisted breakthrough indicating elliptic curve cryptography could be cracked with fewer physical qubits than previously thought. Cointelegraph also attributes an explanation for why forecasts may have missed the mark to the parallel growth of AI-assisted approaches to quantum problem-solving.


Still, consensus is lacking. Smith, whose company is building a blockchain network intended to be quantum-resistant from launch, said there is a “50-50” chance the capability arrives by 2028, while Cheetham expects the early 2030s as “almost a certainty” and frames an earlier arrival as a trailing probability.


Michael Coates, chief information security officer at the Solana Foundation, declined to give a precise estimate during an earlier interview, saying “there’s no way to know,” while noting that industry discussions have often treated quantum timelines as “five years away” for much longer than a decade. He added that while uncertainty should temper prediction, it should not delay action.


Across these views, the common theme is not a shared date but a shared urgency: improving forecasts may be faster than compliance cycles and security migrations, so teams are trying to reduce dependency on assumptions.



Post-quantum migrations are already becoming the default security posture


Even with timeline disagreement, the report emphasizes that blockchains are not waiting for a clear verdict. It quotes NGRAVE CEO Roy Blackstone arguing that threat models have underestimated how quickly AI could advance alongside quantum technology, but regardless of exact timing, the migration work is underway.


Smith said Quantus is focused on launching a blockchain designed to be quantum-resistant from the outset, reflecting a “bake it in” approach rather than a last-minute retrofit. Blackstone similarly stressed that damage would be “catastrophic” if systems did not migrate, and that blockchains have begun shifting toward post-quantum signatures.


For market participants, this creates a different way to think about quantum risk. Instead of treating Q-day as a single future cliff, readers may need to evaluate how resilient different networks are today—particularly whether they rely heavily on legacy public-key schemes, and whether migration strategies are actively implemented across critical components.



What to watch next is less about a single predicted year and more about measurable migration progress: whether major ecosystems complete post-quantum signature adoption in a verifiable way, and whether security teams update incident response procedures to account for cryptographic compromise that may not look like a conventional breach.



https://www.cryptobreaking.com/quantus-founder-first-crypto-quantum/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Quantus%20Founder:%20First%20Crypto%20Quantum%20Attack%20May%20Mimic%20a%20Breach%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...