Circle issued a quantum migration disclosure to developers on August 31, warning that USDC’s security across 37 mainnet networks depends on coordinated cryptographic upgrades that the stablecoin issuer cannot unilaterally enforce.
The disclosure cited an 813-logical-qubit circuit record achieved in August 2026, representing a low-width optimization targeting secp256k1 elliptic-curve signatures used by Bitcoin and Ethereum. While the 813-qubit figure does not describe a complete attack, circuit depth, error-correction overhead, or runtime on physical hardware, it reflects accelerating progress in quantum circuit design for breaking blockchain signatures.
NIST standardized SLH-DSA in FIPS 205 and recommends organizations begin replacing quantum-vulnerable cryptography now, with a 2035 horizon for deprecation and removal from standards.
The Coordination Problem
USDC, valued at approximately $73.6 billion on September 2, is deployed across 37 mainnet networks, each with its own upgrade authority and cryptographic scheme. Circle can protect infrastructure it controls and exercise token-contract powers on supported networks, but cannot rotate customer private keys, rewrite custodian signing stacks, or unilaterally change signature rules of host blockchains like Ethereum, Solana, or XRPL.
Different host networks use different signing schemes. Solana uses Ed25519, Polkadot supports sr25519, Ed25519 and ECDSA, and Ethereum-style externally owned accounts and smart-contract wallets have different migration options. XRPL amendments require more than 80% trusted-validator support for two weeks. Algorand protocol changes require on-chain supermajority. Stellar upgrades depend on validator consensus.
Circle’s quantum warning implies a structural dependency: “USDC may be only as quantum-safe as its slowest wallet, bridge or blockchain.”
Circle’s Post-Quantum Infrastructure
Arc, Circle’s execution-layer blockchain, includes a precompile that can verify SLH-DSA-SHA2-128s signatures. Arc’s custody guide specifies standard secp256k1 ECDSA transaction signing at launch, with opt-in beta post-quantum wallet signatures at mainnet and post-quantum validator signatures planned later.
Circle’s EVM FiatToken design includes roles for mint, burn, pause, blacklist and contract upgrade, reserving blocking and service-suspension powers in defined circumstances.
Attack Resource Estimates
A March 2026 paper estimated resource requirements for attacking 256-bit elliptic-curve discrete-log signatures. Estimates ranged from 1,200 to 1,450 logical qubits, with Toffoli-gate requirements between 70 million and 90 million, depending on the scenario. The paper assumed 500,000 physical qubits and a 10^-3 physical error rate.
Google’s Willow processor, described by the company as a 105-qubit processor, was used in a distance-7 surface-code logical-memory experiment involving 101 qubits. The distinction between physical qubits, logical qubits, and attack-ready logical qubits remains material to assessing quantum threat timelines.
Deployment and Deprecation
Circle’s USDC page listed 35 networks as of June 29, 2026, though the current contract-address table enumerates 37 names. A legacy USDC cross-chain transfer route faces a 95-day deprecation period.
Circle did not specify which of the 37 networks have begun post-quantum migration work or provide timelines for when each host chain plans to implement post-quantum signature verification.