Quantum Computing and ICP: Explained In Plain English
An AI broke a post-quantum standard in 60 hours. Here's what any of it means for your ICP.
Quantum computing has become crypto’s loudest talking point, and almost nobody is explaining it in simple terms. Two things happened in the last few weeks, and DFINITY’s position has shifted throughout the years in a way worth understanding.
What quantum computers actually threaten
When you hold ICP, BTC, ETH, or any other token, what you really own is a private key. Your wallet proves you own your coins by signing with it, and the network checks that signature without ever seeing the private key itself. That works because deriving a private key from a public one requires solving a math problem called the “discrete logarithm”. On normal computers, it would take longer than the universe has existed.
A quantum computer solves it quickly, using Shor’s algorithm, published in 1994.
So the risk is not that someone “picks the lock”, but that they can work out your key from information that is already public, then sign as you. Your coins move and the network sees a perfectly valid transaction.
This applies to all of crypto. Bitcoin, Ethereum, and ICP, all rely on the same family of maths securing the private keys.
Where ICP stands, in DFINITY’s own words
ICP is NOT quantum-safe today, and DFINITY has never pretended it was.
In December 2021 the foundation put a research proposal to the NNS titled “Long Term R&D: PQ security”.
“Quantum algorithms can break some of the cryptographic assumptions the Internet Computer relies on, specifically the hardness of computing discrete logarithms. A quantum-capable adversary could thus forge signatures used in the IC.”
The proposal argued for moving early, noting that attackers can already harvest encrypted data today, and hold it for decryption later once quantum computers exist. It named lattice-based cryptography as the most likely replacement. Asked in the same thread when he would want ICP hardened, Jens Groth, who led the proposal, said his personal target would be around 2025. He added that post-quantum work was not where the foundation was investing much at that moment.
That was their 2021 position: start early, and aim for the middle of the decade.
The plan for replacing it just took two hits
In July, Anthropic’s Mythos model was pointed at HAWK, a post-quantum signature scheme that had passed two rounds of NIST review over two years of expert scrutiny. In roughly 60 hours, Mythos found a hidden mathematical structure nobody had noticed. A post-quantum specialist at Google summed it up as: “Basically with this paper, HAWK is dead”.
To be fair to everyone involved, Anthropic was careful to say the result is specific to HAWK and does not extend to other candidates or to lattice cryptography generally. But it does show that schemes surviving years of human review can fall in days once something new starts looking.
Then a bigger claim appeared. At the end of July, Daniel Simon, whose 1994 work directly inspired Shor’s algorithm, posted a draft paper describing a fast quantum method for a problem that, if it works, would undermine the maths beneath most lattice-based schemes. The family that NIST standardised and that DFINITY named as its likely path back in 2021.
Three mentions, all of them important. The paper says “Preliminary Draft” on the front. Several key proofs are marked as sketches rather than complete. And this has happened before: in April 2024 a similar preprint caused a nine-day panic before two researchers found a flaw the author could not fix.
Bjorn Tackmann from DFINITY, who flagged the paper publicly, put it as honestly as anyone can right now: “it could go either way”.
Why DFINITY is now saying slow down
Dominic Williams has been arguing that quantum has become crypto’s Y2K: a narrative that lets projects market themselves as advanced without much engineering behind it.
His technical point is the one to actually take away. The cryptography used today has been attacked by researchers for 40 years without breaking. Post-quantum schemes have not. Switching now means trading a risk we understand well for one we barely understand at all, in exchange for protection against a machine that does not exist yet. He argues the urgent threat is AI finding holes in ordinary code today, not quantum computers arriving in the 2030s.
The HAWK result supports him, which is I assume why he cited it.
It is worth noting the position has moved. In 2021 DFINITY told the NNS it made sense to start early. In 2026 the message is that rushing is the greater danger. Both can be reasonable given what has happened since, and the recent evidence genuinely argues for caution.
What I would actually take from all this
The threat is real, but it’s not close. Nobody’s ICP is at risk from a quantum computer for the time being.
Be sceptical of anyone selling “quantum safe” as a completed feature. It is a bet on schemes that have not been tested for long. It is still a bet, and a project marketing it as a solved problem is telling you something about its marketing, not its cryptography.
ICP is not currently quantum-safe. Neither is Bitcoin, nor Ethereum. Everyone will have to move eventually, and the honest disagreement is only about when and to what.
If you found this helpful, please consider becoming a subscriber!



Your articles are great. Thank you.