Ripple has laid out a detailed four-phase plan to make the XRP Ledger quantum-proof by 2028, responding to research suggesting that the cryptographic foundations underpinning most blockchains could be cracked faster than previously assumed. The roadmap, announced on April 20, 2026, puts XRPL among the first major blockchain networks to formally commit to a timeline for post-quantum security.
The urgency stems from a March 2026 finding by Google’s Quantum AI team: just 500,000 physical qubits could be enough to break elliptic curve cryptography, the math that keeps private keys private across virtually every blockchain in existence. At that threshold, a sufficiently powerful quantum computer could derive a private key from an exposed public key in roughly nine minutes.
The four-phase playbook
Ripple’s roadmap starts with what it calls “Phase 1: Q-Day readiness,” essentially an emergency contingency plan. If credible quantum threats materialize before the full upgrade is complete, this phase would trigger a rapid migration of accounts to quantum-safe alternatives.
Phase 2 is already underway during the first half of 2026. Ripple is testing NIST-standard post-quantum algorithms, specifically ML-DSA and Dilithium, in collaboration with Project Eleven. That partnership focuses on benchmarking performance, running tests, and developing custody prototypes to ensure that bolting on quantum resistance doesn’t slow down the network or degrade the user experience.
The later phases aim to introduce a formal XRPL amendment for native post-quantum support and achieve full quantum readiness by 2028. Testnet deployments are expected throughout mid-2026, with Ripple promising continuous updates as the work progresses.
For context, NIST (the National Institute of Standards and Technology) spent years evaluating post-quantum cryptographic algorithms before standardizing its picks. ML-DSA, formerly known as CRYSTALS-Dilithium, is one of those selections, designed specifically to resist attacks from both classical and quantum computers.
How exposed is XRP today?
One of the more reassuring data points from Ripple’s announcement: an independent audit found that only 0.03% of XRP’s total supply sits in dormant accounts with exposed public keys. That’s the specific vulnerability quantum computers would exploit, since active accounts that haven’t broadcast transactions don’t reveal their public keys on-chain.
To put that in perspective, Bitcoin’s exposure is considerably larger. Coins sitting in older pay-to-public-key (P2PK) addresses, including those believed to belong to Satoshi Nakamoto, have their public keys fully visible on the blockchain.
The concept of “harvest now, decrypt later” describes a scenario where adversaries collect encrypted data and signed transactions today, storing them until quantum computers become powerful enough to retroactively break the encryption.
The broader quantum race in crypto
Google’s March 2026 research brought the timeline into sharper focus. Previous estimates suggested millions of qubits would be needed to crack ECC. The revised figure of 500,000 physical qubits compresses the runway considerably, given that quantum hardware capabilities have been roughly doubling every few years.
Project Eleven, Ripple’s collaboration partner on this initiative, focuses specifically on quantum security research and benchmarking. Their involvement adds a layer of external validation to Ripple’s claims about maintaining transaction performance during the transition. Dilithium signatures, for instance, are roughly 40 times larger than ECDSA signatures used today, which can affect transaction throughput, storage requirements, and network bandwidth if not carefully managed.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
20








English (US) ·