BlackRock’s Quantum Warning Marks the Beginning of the Cryptographic Migration Era

Written by Yoon Auh

For years, discussions about quantum computing tended to fall into two camps. On one side were the optimists predicting revolutionary breakthroughs that would transform industries overnight. On the other were skeptics who viewed quantum threats as a distant problem that could safely be deferred for another decade. For me, the reality has always been somewhere in the middle.

That’s why I found BlackRock’s recent paper on quantum computing particularly noteworthy. BlackRock is one of the world’s largest asset managers and now manages billions of dollars in spot Bitcoin ETF assets, giving it a direct interest in understanding how quantum risks could affect digital asset infrastructure.

BlackRock’s paper is important not because it predicts when quantum computers will arrive. It is important because it demonstrates that one of the world’s largest financial institutions now views quantum migration as an operational planning problem rather than a theoretical research topic. That shift in perspective may ultimately matter more than any prediction about when a cryptographically relevant quantum computer will emerge.

Quantum security is increasingly being viewed as a practical infrastructure challenge that organizations need to prepare for, not simply a futuristic scenario that can be ignored until later. 

I’ve argued for some time that quantum risk is not a single event. The near-term challenge is migration. The enduring challenge is building cryptographic resilience through crypto-agility, so organizations can continue adapting long after today’s migration is complete.

The Real Risk Isn’t Q-Day, it’s Everything Before It

Much of the public discussion around quantum computing revolves around the idea of a future impending “Q-Day”; when a sufficiently powerful quantum computer becomes capable of breaking today’s public-key cryptography. While that makes for dramatic headlines, it can also create the wrong incentives. Organizations start asking when Q-Day will happen.

The more important question is what happens before it arrives. Attackers don’t need a cryptographically relevant quantum computer today to create future problems. Sensitive information can be collected now and stored for future decryption. This “harvest now, decrypt later” threat model widely discussed by NIST and other cybersecurity agencies has become one of the most widely discussed quantum risks, particularly for industries that depend on long-term confidentiality.

Financial institutions, governments, healthcare organizations, and critical infrastructure providers all possess data with value that may extend well beyond the lifespan of current cryptographic systems. Organizations should evaluate their migration timeline against the confidentiality lifetime of the data they protect. Information that must remain confidential for ten, twenty, or thirty years may already be exposed to harvest-now, decrypt-later collection. As a matter of urgency, organizations need to prepare not only for quantum computing itself, but also for unexpected algorithm failures by building the flexibility to migrate quickly, rather than waiting for a quantum computer to dictate the timeline.

This is one reason we’ve seen increasing activity from organizations such as the National Institute of Standards and Technology (NIST), government agencies across Europe, and now major financial institutions like BlackRock. The discussion is no longer about whether migration will eventually happen. It’s about how organizations can execute that migration without disrupting existing systems. That’s a much harder problem.

Post-Quantum Cryptography Is Certainly Not a One-Time Upgrade

One misconception I still encounter is the belief that post-quantum cryptography involves selecting a new algorithm and replacing the old one. If only it were that simple.

Cryptography has always evolved. Algorithms that were once considered secure eventually become obsolete. Standards change. Threat models change. Computing capabilities change.

Quantum computing doesn’t eliminate that reality. It accelerates it.

I’ve often said that organizations should think about post-quantum security less like a software update and more like a long-term infrastructure program. The challenge isn’t choosing the correct algorithm today, it’s building systems capable of adapting when today’s choice eventually needs to be replaced. This is where crypto-agility becomes mission-critical.

One of the strongest signals from NIST’s post-quantum standardization effort is its decision to standardize multiple algorithms rather than rely on a single solution. That decision reflects an important reality: no one can predict with complete certainty how the threat landscape will evolve. We saw that philosophy reinforced again this year when NIST selected HQC as its fifth post-quantum algorithm, not to replace ML-KEM, but to provide algorithm diversity through a completely different mathematical foundation. As Dustin Moody, who leads NIST’s Post-Quantum Cryptography project, explained, “As we advance our understanding of future quantum computers and adapt to emerging cryptanalysis techniques, it’s essential to have a fallback in case ML-KEM proves to be vulnerable.” We saw the same principle at work when NIST continued advancing additional digital signature candidates through its ongoing standardization process. Some candidates survive. Others don’t. That’s simply how cryptographic research works. The lesson isn’t that any one algorithm is likely to fail tomorrow. It’s that the industry is deliberately designing for uncertainty. Organizations should be doing the same by building crypto-agile infrastructure that can accommodate new algorithms, retire old ones, and respond quickly as standards, research, and future discoveries continue to evolve.

The organizations that succeed during the quantum transition won’t necessarily be the ones that adopt first. They’ll be the ones that retain flexibility. That’s a lesson many industries learned the hard way during previous technology transitions.

From Awareness to Implementation

At this point, awareness is no longer the primary challenge. Most large institutions understand that quantum computing represents a future security consideration. The bigger question is what they do next. That challenge ultimately shaped the research that led us to develop QFlex at BOLTS Technologies.

Our research showed that selecting a single cryptographic solution was an impractical strategy for protecting digital assets over their full lifecycle. Different assets carry different risk profiles. Different transactions require different levels of protection. Public, private, and hybrid blockchains all have different architectures and technical constraints that need to approach the same problem from a different perspective. Different organizations will adopt post-quantum standards at different speeds.

Rather than forcing users into a single cryptographic framework, QFlex was designed as a cryptographic logistics layer that allows security policies to evolve alongside changing threats, standards, and operational requirements.

A low-risk transaction may not require the same protections as a high-value institutional settlement. A long-term digital asset custody solution may require different safeguards than a short-lived consumer transaction. Security should be aligned with risk rather than applied uniformly across every use case.

More importantly, migration strategies should be designed to accommodate future change.

That’s the lesson I take away from BlackRock’s report. The paper isn’t really about predicting the exact timeline for quantum computing. It’s about recognizing that organizations need to begin preparing for uncertainty.

No one knows exactly which cryptographic standards organizations will be relying on five years from now. No one knows precisely when a cryptographically relevant quantum computer will arrive. No one can predict every future threat. None of today’s post-quantum algorithms can be guaranteed immune from future mathematical advances or cryptanalytic breakthroughs. What organizations can do is build systems that remain adaptable. That’s ultimately what crypto-agility is about.

The reality is that quantum migration will probably take longer than most organizations expect. Large institutions have thousands of systems, vendors, applications, and dependencies that rely on cryptography in one way or another. None of that gets upgraded overnight. That’s why reports like BlackRock’s matter. They show that quantum security is no longer being treated as a research topic. 

The recent Executive Orders establishing federal quantum-resilience timelines through 2030 and 2031, accelerating the previous 2035 deadline, underscores the growing urgency to plan and execute migration. When the Government moves, the Federal and Defense Industrial bases will comply, and most commercial industries will not be far behind.

It’s becoming part of mainstream risk management discussions alongside cybersecurity, operational resilience, and business continuity planning. At this stage, the challenge isn’t convincing people that quantum risk exists. The organizations that succeed won’t simply deploy post-quantum cryptography. They’ll build infrastructure capable of adapting as cryptography itself continues to evolve. That’s where most of the work still needs to happen.

Opinion
Yoon Auh

Yoon Auh

Yoon Auh is a former VP at Goldman Sachs and Head Trader at Credit Suisse, Geode Capital and Magnetar Capital. An inventor of data-centric security with a portfolio of patents and research validated in defense-grade settings and NIST-validated work. His background spans deep-tech innovation, applied cryptography, and high-performance trading systems, experience that informs how we secure digital assets, protect against insider threats, and prepare for quantum-enabled attacks across financial markets and blockchain infrastructure.