> For the complete documentation index, see [llms.txt](https://docs.qms.finance/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.qms.finance/overview/the-quantum-challenge-and-opportunity.md).

# The Quantum Challenge and Opportunity

Quantum computers break most of the cryptography on which blockchains are built. Quantum hardware is also a tool.

## The Challenge

### Broken Cryptography

Quantum computing puts public-key cryptography, the foundation of the whole blockchain stack, at risk. Elliptic-curve signatures will be broken by Shor's algorithm, allowing funds to be stolen. Classical zero-knowledge proofs will be forged. And for privacy chains, the entire history of encrypted transactions will be exposed. Established networks face multi-year, ecosystem-wide migrations to post-quantum (PQ) cryptography, complicated by accumulated protocol versions, deep tooling dependencies, and dormant accounts whose owners may never apply the upgrade. The PQ algorithms that solve the problem carry costs of their own: larger signatures and meaningful computational overhead. Sub-second block times, the cornerstone of proof-of-stake's performance narrative, are not compatible with PQ validator signatures.

### The Window Is Closing

Quantum hardware is no longer hypothetical. Public roadmaps from major research labs and venture-backed startups now point to systems capable of running Shor's algorithm against deployed cryptography. The horizon is short. Any blockchain still relying on non-PQ cryptography when those systems arrive will be a target. Privacy chains are already exposed through harvest-now-decrypt-later attacks, in which an adversary captures encrypted data today to decrypt it once the hardware arrives. The migration window is closing, and migrating a live multi-year ecosystem is fundamentally harder than starting from a clean slate.

## The Opportunity

### Paying Clients for the Same Computation

The blockchain industry has organized its response around the threat alone, missing what quantum hardware can do for chains themselves. Many of the optimization problems quantum hardware is natively designed to tackle (e.g., portfolio optimization, risk selection, clustering) already have paying commercial clients. Miners whose work solves these problems and secures the chain earn from both the chain and these clients. Two revenue streams from a single computation.

### Quantum Prototypes Already Available

Quantum prototypes are also already here. Quantum annealers and gate-based machines are accessible over standard cloud APIs for small tasks. Miners delegating part of the work to these quantum prototypes are toy examples today; they will be standard tomorrow. The QMS protocol is designed so that as quantum hardware matures, the miners who run it produce better solutions and earn larger shares of client payments. Advances in quantum computing directly benefit the chain.

## Built for the Quantum Era

This is what QMS does. It is built from the ground up for that world: quantum-resistant by design, with a PQ-secure *proof-of-useful-work* consensus protocol, a PQ-secure finality layer, and prototype quantum computers working alongside classical ones in its miner network. [Why QMS](/overview/why-qms.md) sets out how QMS answers these challenges.

*Adapted from Section 1 of the* [*white paper*](https://docs.qms.finance/whitepaper)*.*\
*Further reading: Section 4.6 of the white paper explains how quantum hardware joins the miner network; Section 6 shows how QMS secures each layer against a quantum adversary.*
