Almost no blockchains are quantum resistant. Every major blockchain in use today settles ownership with elliptic-curve signatures, which a large enough quantum computer breaks. The work to change that is real and it is public, so it can be checked chain by chain rather than argued about.
The test
Quantum resistance means one thing at the chain level: the signature scheme that authorizes a spend rests on math a quantum computer cannot break. NIST finalized signature replacement schemes in 2024, including hash-based signature standards.
A chain is quantum resistant when moving funds requires one of those schemes, or something with an equivalent security argument. If it relies or falls back on elliptic curves, it’s not quantum resistant.

Where chains stand today
Bitcoin: Vulnerable today. Security rests on ECDSA over secp256k1. The migration work is further along than most coverage suggests: BIP-360 defines a quantum-resistant output type and was merged into the bitcoin/bips repository in February 2026, and a companion proposal, BIP-361, sets out a migration path for the supply sitting in addresses with exposed public keys. Merged proposals are not consensus, however, and they are not yet live.
Ethereum: Vulnerable today, with the most concrete plan of any large chain. The Ethereum Foundation stood up a dedicated post-quantum security team in January 2026 and publishes its work at pq.ethereum.org, alongside the roadmap page at ethereum.org. The EF’s plan is based on hash-based signatures for validators and account abstraction that lets individual accounts adopt quantum-safe schemes before the protocol finishes migrating.
Algorand: The furthest along of the large chains. Algorand has signed State Proofs with the post-quantum Falcon scheme since 2022, added a native falcon_verify opcode to the AVM in the September 2024 consensus upgrade, and announced Falcon-backed accounts on mainnet in November 2025. Ordinary Algorand accounts still use Ed25519, so the chain is not uniformly quantum resistant, but the primitives are live rather than just proposed.
QRL: Quantum resistant from genesis. QRL's mainnet launched in June 2018, with every transaction signed using XMSS, a hash-based scheme, with no elliptic-curve fallback. But cryptography was never the hard part. A new chain starts with no users, no liquidity, and no contracts, and that takes far longer to build than it takes to implement a quantum resistant signature scheme.
"On the roadmap" is not the same as protection today
The challenge is migration. A chain-level fix has to move wallets, exchanges, custodians, contracts, and every holder onto new address types at roughly the same time before the quantum threat materializes. That is a coordination problem that takes years, and coins in addresses that have already published their public keys stay exposed the whole time.
That time gap is why protection at the account level exists. A smart account can require a post-quantum signature to move funds, so the account survives a break in the underlying curve without the chain forking first. Quip Accounts work this way, using hash-based signatures on Ethereum, EVM L2s, and Bitcoin L2s. With Quip Accounts, assets stay on the chain they already live on while gaining post-quantum protection.
How to check any claim yourself
When investigating claims of quantum resistance, there’s three questions to ask: What signature scheme guards a spend, and is it a standardized post-quantum scheme? Has the implementation been audited and the findings published? And does the protection cover assets where they already live, or does it require moving them to a new chain first?
Want to know when quantum computers will be able to break blockchains at scale? Track the time to quantum doom at quantumdoomclock.com.

