Home » [Op-Ed] Paul Soliman: Q-Day Is Coming: Why Governments, Blockchains, and Real-World Assets Must Prepare Now

[Op-Ed] Paul Soliman: Q-Day Is Coming: Why Governments, Blockchains, and Real-World Assets Must Prepare Now

by Jennifer Mackenzie


Governments are no longer treating post-quantum security as a distant research problem. They are turning it into policy, procurement requirements, migration deadlines, and national infrastructure programs.

Paul Soliman is the Founder and CEO/CTO of Hacktiv Colab Inc. and Chairman and Group CEO of BayaniChain, where he leads initiatives in blockchain, enterprise tech, and digital nation-building. He also serves as CTO of Blockfy, driving innovation in decentralized finance solutions in the Philippines. This is a repost from Paul's blog here.
Photo for the Article - [Op-Ed] Paul Soliman: Q-Day Is Coming: Why Governments, Blockchains, and Real-World Assets Must Prepare Now

Weekly Crypto Roundup

Get the weekly briefing for Philippine crypto insiders, from the country’s longest-standing crypto and blockchain news publication.

I recently travelled to Taiwan to speak about post-quantum cryptography, blockchain, and real-world assets.

My central message was straightforward:

The clock is ticking, and we need to be ready for Q-Day.

I had already written about quantum readiness months earlier on Substack because I believed this conversation needed to begin before quantum computers became an immediate crisis. Now, governments are moving from discussion to execution.

The United States, the European Union, the United Kingdom, and Taiwan are establishing policies, standards, and migration roadmaps. This is a clear signal that post-quantum cryptography, or PQC, is no longer merely an academic concern.

It is becoming a national-security, financial-infrastructure, and digital-sovereignty priority.

What is Q-Day?

Q-Day, or Quantum Day, refers to the point when a sufficiently powerful quantum computer becomes capable of defeating the public-key cryptography that protects much of the digital world.

Today, governments, banks, cloud platforms, identity systems, blockchains, and digital wallets depend heavily on asymmetric cryptography. This includes RSA and elliptic-curve cryptography, or ECC.

These technologies help establish secure connections, authenticate users, sign transactions, protect private keys, issue digital certificates, and verify that instructions truly came from an authorized person or institution.

A sufficiently capable quantum computer could solve the mathematical problems on which many of these systems depend. NIST has warned that quantum computers could eventually break the encryption currently protecting online activities and has encouraged organizations to begin adopting its finalized post-quantum standards because full migration will take time.1

Q-Day does not mean that every database and blockchain will suddenly disappear. The deeper risk is that the cryptographic foundations used to establish identity, ownership, authorization, and confidentiality could become unreliable.

When trust in digital signatures fails, digital ownership can fail with it.

Why the threat already exists

Some people argue that powerful quantum computers do not yet exist, so there is no urgency.

That misses the point.

One of the most serious threats is known as Harvest Now, Decrypt Later.

An adversary can intercept encrypted information today, preserve it, and attempt to decrypt it when sufficiently powerful quantum computing becomes available. Government records, diplomatic communications, healthcare information, intellectual property, financial records, and critical-infrastructure data may need to remain confidential for decades.

Preparing for Q-Day is therefore not only about defending systems in the future. It is also about protecting information being generated and transmitted today.

The United States recognized this risk explicitly in Executive Order 14412, issued on June 22, 2026. The order states that adversaries may already be collecting American information with the intention of decrypting it later. It requires federal agencies to appoint PQC migration leads, maintain cryptographic inventories, and produce prioritized migration plans.2

This is the most important shift in the global conversation:

Quantum readiness is no longer being measured by when Q-Day arrives. It is being measured by how long migration will take and how long today’s information must remain protected.

Why blockchain and RWA are exposed

Blockchain is often described as immutable, but immutability does not automatically mean quantum resistance.

A blockchain can preserve a transaction permanently while still depending on cryptographic keys and digital signatures to determine who is authorized to initiate that transaction.

Ethereum accounts, for example, use public and private keys to control account activity. Private keys sign transactions and effectively provide custody over the assets associated with an account. Ethereum currently derives public keys using the Elliptic Curve Digital Signature Algorithm.3

Bitcoin similarly uses elliptic-curve signatures, including ECDSA with the secp256k1 curve, to prove control over assets and authorize transactions.3

This creates a serious long-term concern for real-world assets.

When land, bonds, commodities, investment instruments, invoices, carbon credits, or government entitlements are represented on-chain, their ownership and transfer may depend on cryptographic signatures.

A future quantum-capable attacker could potentially target vulnerable signing mechanisms to:

  • Forge transaction authorizations.
  • Impersonate asset owners or authorized officials.
  • Compromise custodial wallets.
  • Attack blockchain bridges and settlement infrastructure.
  • Manipulate issuer, registry, or oracle credentials.
  • Undermine the digital signatures connecting an on-chain token to its off-chain legal asset.

The blockchain ledger itself may remain intact. But if the keys controlling the assets can be compromised, the integrity of ownership becomes questionable.

RWA systems also extend beyond the blockchain. They rely on KYC records, legal documents, custodians, government registries, APIs, cloud infrastructure, banking channels, and confidential settlement communications. These surrounding systems may be vulnerable to both Harvest Now, Decrypt Later attacks and future signature forgery.

This is why quantum readiness must be designed across the complete RWA architecture—not added only to the blockchain layer.

Governments are beginning the migration

The global direction is becoming clear.

United States

Under Executive Order 14412, American federal agencies must identify a PQC migration lead and develop plans for transitioning high-value assets and high-impact systems.

The order requires PQC key establishment for these systems by December 31, 2030, followed by PQC digital signatures by December 31, 2031. It also directs the Federal Acquisition Regulatory Council to propose procurement rules requiring covered government contractors to comply with applicable NIST FIPS standards incorporating PQC by the end of 2030.2

This means quantum readiness will increasingly become a procurement and supply-chain requirement—not merely an internal cybersecurity decision.

European Union

The European Commission issued its Recommendation on a Coordinated Implementation Roadmap for the transition to PQC on April 11, 2024. It called for clear goals, milestones, timelines, and coordinated adoption across public administrations and critical infrastructure.4

On June 23, 2025, EU member states, supported by the Commission, published a coordinated implementation roadmap and timeline for moving toward PQC. The objective is a synchronized, risk-based transition in which governments and critical sectors do not migrate in isolation.5

United Kingdom

The United Kingdom’s National Cyber Security Centre has established three major milestones:6

  • By 2028, organizations should complete cryptographic discovery, define migration goals, and prepare an initial plan.
  • By 2031, they should complete their earliest and highest-priority migration activities.
  • By 2035, they should complete PQC migration across their systems, services, and products.

The NCSC describes PQC migration as a mass technology change that will take years and span multiple leadership and investment cycles.6

Taiwan

During my recent visit, Taiwan’s financial sector was already advancing a staged migration framework.

The Financial Supervisory Commission’s 2026 guidance emphasizes governance, cryptographic inventory, a Cryptographic Bill of Materials, organizational capability building, pilot projects, infrastructure validation, and phased migration.7 <!– [confirm exact release month against the FSC notice — public reporting confirms the guide and its phasing, but not that it published specifically in June 2026] –>

The initial period focuses on understanding where cryptography is being used. The next phase moves toward proof-of-concept deployments and technical validation. High-risk and mission-critical financial systems are expected to be prioritized as adoption expands toward 2035.7

Taiwan’s approach is important because it recognizes that institutions cannot replace cryptography they have not identified.

What governments and institutions must do now

The first step is not to replace every algorithm immediately.

The first step is to understand the exposure.

Every government agency, financial institution, enterprise, and blockchain infrastructure provider should begin with five priorities:

Establish accountability. Assign an executive owner and a technical PQC migration lead.

Build a cryptographic inventory. Identify where RSA, ECC, certificates, digital signatures, key exchanges, hardware security modules, wallets, and cryptographic libraries are being used.

Create a Cryptographic Bill of Materials. Organizations need visibility into the cryptography embedded in software, hardware, cloud services, APIs, vendors, and supply chains.

Prioritize according to risk and data lifetime. Systems protecting national-security information, financial assets, citizen identities, health records, critical infrastructure, and long-lived confidential data should move first.

Design for crypto-agility. Systems should be capable of changing algorithms without requiring complete architectural replacement. During migration, many organizations may use hybrid models combining classical and post-quantum mechanisms.

NIST finalized its first three major PQC standards in August 2024: ML-KEM for key establishment, ML-DSA for digital signatures, and SLH-DSA as an alternative signature standard. These standards are ready for implementation, and NIST has explicitly advised organizations not to wait before beginning integration.1

From awareness to cooperation

Recognizing the urgency of this transition, CeQureX Taiwan founders Vivian Ma and Grace H. Weng, CQX Philippines President Art Generoso and CTO Larry Galang, and BYC have entered into a strategic cooperation to accelerate post-quantum initiatives.

Our goal is to help governments and institutions move from awareness to actual readiness.

This cooperation will focus on helping organizations assess cryptographic risk, build inventories, identify high-value systems, develop migration roadmaps, conduct proof-of-concept implementations, and introduce quantum-safe technologies into government, financial, blockchain, and enterprise environments.

For BYC, this is a natural extension of our work.

We build blockchain infrastructure because the world increasingly demands proof. But proof must remain verifiable not only against the threats of today—it must also remain defensible against the computational capabilities of tomorrow.

The best time to prepare is before Q-Day

Q-Day has not arrived.

That is precisely why this is the right time to prepare.

Cryptographic migration is not a software update that governments can deploy overnight. It affects identity, certificates, banking, procurement, hardware, cloud infrastructure, operational technology, blockchains, digital wallets, and cross-border systems.

The transition will take years.

Governments that begin early can migrate methodically, test interoperability, train their people, modernize procurement, and protect their highest-value systems first.

Those that wait for a quantum breakthrough may discover that the migration window has already closed.

The message I delivered in Taiwan remains the same:

The clock is ticking.

Q-Day is not a reason to panic. It is a reason to prepare, build, test, and execute.

The best time to become quantum-ready is not when Q-Day arrives.

It is now.

– paul

This op-ed is published on BitPinas: [Op-Ed] Paul Soliman: Q-Day Is Coming: Why Governments, Blockchains, and Real-World Assets Must Prepare Now

What else is happening in Crypto Philippines and beyond?



Source link

You may also like

Leave a Comment

© 2025 decentralnewshub.online. All rights reserved.