Is XRP's cryptography at risk from quantum computers?
Analysis Published 4 min read
Short answer
In principle, yes. Both XRP Ledger key types use elliptic-curve cryptography, and XRPL.org says developers can add a new signing algorithm if quantum computers become able to break it. Ripple said on April 20, 2026 that assets were not at risk that day, and it targets post-quantum signatures by 2028. Accounts can already switch to new keys.
The full answer
XRP Ledger accounts sign transactions with one of two algorithms. XRPL.org lists them as secp256k1, “the same scheme Bitcoin uses,” and Ed25519.[1] Both rely on elliptic-curve math. XRPL.org’s own documentation names the risk: the ledger will likely need new signing algorithms, and “if quantum computers using Shor’s algorithm (or something similar) will soon be practical enough to break elliptic curve cryptography, XRP Ledger developers can add a cryptographic signing algorithm that isn’t easily broken.”[1]
How close are quantum computers to breaking these signatures?
The estimate of what is needed has fallen. A Google Quantum AI paper dated March 30, 2026 calculated that circuits for the 256-bit elliptic-curve problem “can be executed on fewer than half a million physical qubits,” which it calls “nearly a 20 fold reduction over prior estimates,” and could run in “18 or 23 minutes” on such a machine.[2] Google’s Willow chip has 105 qubits, according to its spec sheet published December 9, 2024.[3] It is the only quantum machine described in the sources for this page. Half a million is about 4,760 times that (our calculation).
Expert opinion puts the risk within a planning horizon. The Global Risk Institute’s report, published March 9, 2026 from a survey of 26 experts, found a cryptographically relevant quantum computer “quite possible (28-49%) within the next 10 years, and likely (51-70%) in the next 15.”[4] In a November 2024 draft, NIST, the US standards body, listed ECDSA and EdDSA at 128-bit strength as “Disallowed after 2035,” because “future quantum computing may be able to break these algorithms.”[5]
The Google authors “urge all vulnerable cryptocurrency communities to join the migration to PQC without delay.”[2] Their cost estimate targets the secp256k1 curve, but the paper also names the XRP Ledger. It places the ledger among account-based blockchains that “expose them in the first transaction,” meaning public keys, and it calls Ed25519, the ledger’s other key type, a “quantum-vulnerable” scheme in its section on Algorand.[2]
Which XRP accounts would be exposed first?
An XRP Ledger address is not the public key itself. XRPL.org says “The conversion from a public key to an address involves a one-way hash function.”[6] The public key appears once the account acts. Ripple’s April 20, 2026 post says: “Every time an account signs a transaction, its public key becomes visible onchain.”[7] Google’s paper makes the same point about the XRP Ledger.[2] An attacker with a working quantum computer would target accounts whose public keys are already on the ledger, which includes any account that has sent a transaction (our reading of those sources).
Can holders move to new keys?
Yes, within today’s algorithms. XRPL.org says of the master key: “You cannot change or remove the master key pair, but you can disable it.” A regular key pair can be added, and “You can remove or replace your regular key pair at any time.” A list of several signers can also authorize transactions, and “A regular key or multi-signature can do anything else the same as the master key pair,” apart from a few master-only actions.[1] Ripple calls this “native key rotation, which means users can move away from potentially vulnerable keys over time without needing to change their underlying accounts.”[7] Google’s paper also credits the XRP Ledger with “native, protocol-level key rotation.”[2]
The limit is that every key type on offer is still elliptic-curve. Rotation helps once a quantum-safe algorithm exists on the ledger; until then it swaps one exposed key type for another of the same kind. The account tools are described on XRPL account security features.
What is Ripple’s post-quantum plan?
Ripple published a four-phase plan on April 20, 2026: “Post-quantum recovery (Q-Day readiness),” then planning and experimentation in the first half of 2026, “Exploration of post-quantum primitives” in the second half, and “Full transition for PQ signatures (targeting 2028).” It says it is testing “ML-DSA on AlphaNet,” a test network, and will “propose a new amendment to the XRPL ecosystem for native post-quantum cryptography.”[7] For the case where “classical cryptography breaks at any point,” Ripple says “funds must move to post-quantum secure accounts” and that one path it is exploring uses zero-knowledge proofs to show ownership of existing keys without exposing them.[7] It also says: “This does not mean assets are at risk today. But the threat has moved from theoretical to credible, and preparation timelines now matter.”[7]
The plan is a proposal. Ripple has said it would propose a native post-quantum amendment,[7] but xrpldashboard showed on September 29, 2026 that none of the 13 amendments in validator voting was a post-quantum signature amendment.[8] CoinDesk noted the cost: “post-quantum cryptography uses larger keys and signatures, which can strain the ledger.”[9]
Is XRP more or less exposed than Bitcoin?
The core exposure is shared. Bitcoin uses the secp256k1 curve the Google paper studied, and the XRP Ledger supports the same curve.[1][2] The XRP Ledger already lets an account change its signing key without changing its address,[1] which Ripple presents as the path for moving holders off vulnerable keys.[7] Key rotation alone does not add a quantum-safe key type. Ripple has said it would propose a post-quantum amendment,[7] but xrpldashboard’s amendment tracker showed on September 29, 2026 that none of the 13 amendments in validator voting was a post-quantum signature amendment.[8] The wider comparison is on XRP compared with Bitcoin, and basic key safety is covered on keeping XRP keys safe.
What we know
- Checked September 29, 2026: XRPL.org says accounts sign with secp256k1 or Ed25519, both elliptic-curve schemes, that new algorithms will likely be needed in future, and that developers can add one if quantum computers using Shor’s algorithm can break elliptic-curve cryptography.
- Checked September 29, 2026: an account’s master key cannot be changed but can be disabled; a regular key can be replaced at any time, and a regular key or multi-signature can do almost everything the master key can (XRPL.org).
- April 20, 2026: Ripple published a four-phase plan targeting post-quantum signatures by 2028 and said every signed transaction reveals the account’s public key.
- March 30, 2026: Google Quantum AI estimated the 256-bit elliptic-curve problem could be solved on fewer than half a million physical qubits, and listed the XRP Ledger among blockchains that expose public keys from an account’s first transaction. December 9, 2024: Google’s Willow chip had 105 qubits.
- March 9, 2026: the Global Risk Institute’s report, drawn from a survey of 26 experts, put a cryptographically relevant quantum computer as ‘quite possible (28-49%)’ within 10 years.
- November 2024: a NIST draft (IR 8547) would disallow ECDSA and EdDSA signatures at 128-bit strength after 2035.
- September 29, 2026: no post-quantum amendment appeared among the 13 amendments in validator voting (xrpldashboard).
What we reason Analysis
- Ed25519 is also an elliptic-curve scheme, so XRPL.org’s warning covers both of the ledger’s key types, not only the secp256k1 curve Google’s cost estimate targets. This comes from XRPL.org’s cryptographic keys page and the Google paper, which calls Ed25519 quantum-vulnerable.
- An account that has never signed a transaction shows only a hash of its public key, so a quantum attacker would first need the public key, which appears once the account signs. This comes from XRPL.org’s addresses page, Ripple’s April 2026 post and the Google paper. None of the sources says how much protection this gives against future attacks.
- Key rotation lets a holder move to a new key without a new address, but only to another elliptic-curve key until a post-quantum algorithm is added by amendment. This comes from XRPL.org’s key types and Ripple’s plan.
What's still open
- The design of the post-quantum amendment Ripple said it would propose: not published as of September 29, 2026.
- What happens to accounts whose owners cannot or do not move to new keys is unclear: Ripple’s phase 1 says funds would have to move to post-quantum accounts if classical cryptography breaks, and names zero-knowledge proofs of key ownership as one path it is exploring, but no specification was public as of September 29, 2026.
- Whether NIST has finalized IR 8547: only the November 2024 draft was opened; a final version was not found on September 29, 2026.
In plain English
XRP accounts are protected by the same kind of math that protects Bitcoin and Ethereum, and a large enough quantum computer could in theory break it. The only quantum chip described in the sources for this page, Google’s 2024 Willow chip, had 105 qubits, while Google’s own researchers estimate the job could be done with fewer than half a million. Experts surveyed for a Global Risk Institute report published in March 2026 thought such a machine was possible within ten years but not certain. The XRP Ledger already lets people swap an account’s key for a new one, and Ripple plans new quantum-safe signatures by 2028.
Key terms
Sources
- Cryptographic Keys — XRPL.org, undated (checked September 29, 2026) Primary
- Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities — Google Quantum AI, March 30, 2026 Primary
- Willow spec sheet — Google Quantum AI, December 9, 2024 Company-reported
- Quantum Threat Timeline Report 2025 — Global Risk Institute, March 9, 2026 Primary
- NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards — NIST, November 2024 Primary
- Addresses — XRPL.org, undated (checked September 29, 2026) Primary
- Post-Quantum Readiness on the XRP Ledger — Ripple, April 20, 2026 Company-reported
- Current XRPL amendment status — xrpldashboard, September 29, 2026 Secondary
- Ripple wants the XRP Ledger to be quantum-proof by 2028. Here is its plan — CoinDesk, April 21, 2026 Secondary
- Transition to Post-Quantum Cryptography Standards | Draft NIST IR 8547 is Available for Comment — NIST, November 12, 2024 Primary
- NIST IR 8547 (Initial Public Draft) - Transition to Post-Quantum Cryptography Standards — NIST Computer Security Resource Center, November 12, 2024 Primary
Update log
- — Published.
I keep this site free, with no ads, paywall or affiliate links; gifts cover hosting and research time. Support the project, or report an error.
