Flash News

Ledger CTO: No Quantum Computer This Time

Ledger's CTO Charles Guillemet responded to a post about "a large integer dividing RSA-260": this matter has nothing to do with quantum computers.

RSA-260 is a 260-digit decimal semiprime in the RSA factoring challenge, approximately 862 bits, and has long been publicly recorded as not yet factored. The previous milestone, RSA-250, was factored in 2020 using the number field sieve method, consuming about 2700 CPU core years. Writing "finding a factor" directly as quantum decryption mislabels classical computational number theory achievements as Q-day.

Guillemet's consistent stance is that two layers are simultaneously valid: there is currently no cryptographic quantum computer capable of running Shor's algorithm to break Bitcoin or the asymmetric cryptography used by banks; however, trust is being eroded by estimated algorithmic resource reductions. Google Quantum AI announced in March 2026 that it would reduce the logical qubit requirements for 256-bit elliptic curve discrete logarithm to about 1200 and Toffoli gates to about 90 million, only providing zero-knowledge proofs without disclosing circuits; subsequently, the open-source community used this verifier as a reinforcement learning reward function, reproducing and further lowering resource estimates within days. He emphasized that blockchain uses ECDSA rather than RSA, and the journalist's claim that the RSA paper signifies "Bitcoin's doomsday" is inherently flawed.

Ledger's path is to first run post-quantum primitives on secure chips. The operating system team has included experimental support for NIST standard ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in the SDK, adjustable in both Rust and C; he insists that post-quantum algorithms are meaningless if private keys are signed on computers that lie, requiring trusted displays. Donjon Labs has also conducted non-invasive deep learning side-channel analysis on the unprotected ML-KEM reference implementation, where about 400 electromagnetic traces can learn the key on an unmasked target, proving that standardization does not equal deployable security.

He calculates larger implications in migration politics: hash signatures are the most conservative but difficult to threshold, with sizes about an order of magnitude larger; lattice-based ML-DSA is the industry default, and threshold signatures can barely be achieved with about six parties; Bitcoin also has to deal with whether Satoshi and lost coins are frozen, burned, or left. The NIST roadmap aims to phase out old asymmetric systems by 2030 and ban them entirely by 2035; encrypted traffic exists in a "now harvesting, later decrypting" scenario, and on-chain authentication must complete signature migration before Q-day.

Who is buying and who is selling: the event is driven by narrative arbitrage, not the launch of quantum machines. Funds are flowing towards post-quantum hardware, custody migration solutions, and security companies that can turn "quantum panic" into products; those benefiting are wallet manufacturers that have integrated ML-DSA/ML-KEM into secure elements, while those under pressure are public chain governance and hot wallets that still treat ECDSA as an eternal assumption. In the absence of quantum machines, pricing power lies with those who complete migration paths first, not with those who shout about breaking encryption first.

Source: Public Information

ABAB AI Insight

Guillemet started from Ledger Donjon's white-box offense and defense, with a career focused on making secure elements and trusted screens into signature boundaries, rather than betting on quantum timelines. In 2023, Ledger Recover extracted seed shards from devices, which he described as irrational panic; when the Ethereum application’s signature flaw was publicly disclosed by an external AI company in 2026, he stated that internal teams had already patched it using self-developed AI. The recurring theme he emphasizes is that "threat models are rewritten by attention," with quantum being just the latest vehicle.

The capital path is to move post-quantum from papers into passport-grade chip firmware: first without hardware acceleration, using software to run lattice algorithms hard in secure elements, then waiting for the next generation of chips to provide acceleration. The motivation is not to predict which year a decryption machine will appear, but to lock down the developer toolchain before institutions begin to write PQC readiness into terms during due diligence. Threshold signatures and MPC are the load-bearing walls of the custody industry; hash schemes cannot be thresholded, while ML-DSA can barely be done and signatures can be distinguished—money will flow to the layer that can maintain both multi-party custody and quantum resistance, rather than just swapping curves in soft wallets.

The reference point is the RSA challenge itself: RSA-250 was factored by classical clusters, not requiring quantum; Shor has existed since 1994, but fault-tolerant machines are lacking. The industry position is that algorithm estimates step down every 12 to 18 months, while hardware is still far from ready, and the blockchain is in a window where "cryptographers know what to migrate, but governance does not know how to migrate."

Structural changes indicate that trust mechanisms fail before attacks do. Cryptography does not break on Q-day; rather, it begins to devalue when public records are proven to be thinner than the real frontier, and classification and AI search simultaneously rewrite resource tables. The mechanism is: once verifiers are made public, search becomes industrialized, and panic along with migration budgets are ignited in advance.

Source

·ABAB News
·
7 min read
·2 hrs ago
分享: