Quantum theft may appear as unexplained wallet breaches

Quantus CEO Christopher Smith warned the first quantum-capable attack could resemble ordinary wallet breaches, deriving private keys from onchain public keys without obvious intrusion.

Christopher Smith, CEO and co-founder of Quantus, warned a quantum-capable computer could recover private keys from public keys published on blockchains, allowing attackers to move funds without breaching wallets, devices or exchange systems.

That pattern would leave little forensic trace, Smith warned: “When someone cracks your key, you don’t get a memo saying how they did it.” He added that in some thefts involving highly secure organisations “the only forensic evidence would be that there was no breach.”

Most blockchains use elliptic-curve cryptography that links public addresses and transaction signatures to private keys. Classical computers cannot practically derive private keys from public keys today. Quantum algorithms, including adaptations of Shor’s algorithm combined with AI-driven optimisations, could reduce the number of qubits and the time needed to recover keys.

Targets may not be the best-known addresses. Smith pointed to administrative minting keys for large issuers as an especially attractive target, saying a quantum-capable actor could mint tokens from an administrative wallet and quickly sell them. Security researcher Sean Cheetham suggested attackers might instead focus on hot exchange wallets that are less likely to trigger immediate alarms.

Estimates for when a cryptography-breaking quantum computer will appear differ. Google moved its internal post-quantum migration timeline to 2029 after research indicated fewer physical qubits may be required. Smith assessed the chance of such a machine by 2028 at roughly 50-50. Cheetham expects a breakthrough in the early 2030s. Solana Foundation CISO Michael Coates declined to provide a date, noting many experts consistently forecast the capability several years ahead.

Some blockchains and infrastructure providers have begun migrating to post-quantum signature schemes. Roy Blackstone, CEO of hardware-security firm NGRAVE, argued earlier threat models did not fully account for how AI can accelerate quantum research. Several multi-chain networks are planning or implementing post-quantum measures.

Security teams face two tasks: harden current systems and migrate to quantum-resistant cryptography before a capable quantum attacker appears. A stealthy quantum theft could be mistaken for lost keys or insider compromise, complicating incident response and attribution.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author