Ripple Sets Out a Four-Stage Path to a Quantum-Safe XRP Ledger
Ripple has a four-stage plan for moving the XRP Ledger onto cryptography a quantum computer could not break, and the network-wide change is targeted for 2028. Ayo Akinyele, the firm's senior director of engineering, set out the sequence to CoinDesk in a piece published early on Friday. The stages are an assessment of what is exposed, testing of alternative schemes against the traffic the ledger already carries, a period running old and new cryptography side by side, and then the switch. No working machine capable of the attack exists yet.
What is new and what is from April
Most of the coverage that followed on Saturday reads as an announcement. It is largely a restatement. Ripple published the roadmap on its own site on 20 April under Akinyele's byline, and that document already carried the four phases and the 2028 date. Friday added Akinyele speaking directly, and a framing of the work as an infrastructure problem wider than the algorithm at the centre of it. Bloomingbit renders his surname Akinnyele. Ripple's own site spells it Akinyele.
"The financial system was not built with quantum computing in mind," Akinyele said.
The stages do not line up across accounts
Four stages and 2028 are agreed everywhere. The numbering is not. Ripple's April roadmap makes the emergency plan Phase 1, a contingency that would let holders move funds to quantum-safe protection if the current cryptography broke sooner than expected, and puts the full transition last. CoinDesk gives no dates at all and places the emergency route at the end. Coinpedia has Phase 2 already finished, describing tests of a post-quantum signature scheme on Ripple's AlphaNet in the first half of this year, with hybrid deployment on Devnet and Testnet in the second. Cryptonomist puts the testnet work in mid-2026 instead. Anyone comparing two of those accounts gets a different plan.
One algorithm or two
The naming has the same trouble. Crypto Briefing describes the candidate as ML-DSA, formerly CRYSTALS-Dilithium, which is a single scheme under its standardised name. Cryptonomist lists ML-DSA and Dilithium as two algorithms under test. They are the same thing. Crypto Briefing alone notes that its signatures run about 40 times larger than the elliptic-curve signatures the ledger uses now, and signature size is the practical constraint: bigger signatures mean heavier transactions and more work for every validator.
What Q-Day looks like in numbers
The figure behind the timeline comes from Google's quantum team in March. Roughly 500,000 physical qubits would be enough to derive a private key from a public key already visible on a chain, in about nine minutes. Crypto Briefing and Cryptonomist both carry it, and both put the XRP Ledger's exposure at 0.03% of supply, held in dormant accounts whose public keys have been revealed. The ledger has one defence most chains lack. An account's controlling keys can be replaced without moving the account, a feature CoinDesk and Ripple both point to. Researchers call the moment the machines become practical Q-Day, and nobody quoted here puts a date on it.
The replacement is young too
CoinDesk reports that an Anthropic model cut the work needed to break a leading post-quantum signature candidate by a factor of 67 million last month. No other outlet carries that figure. Coinpaper separately reports that Anthropic researchers found weaknesses in experimental quantum-resistant schemes in July and names HAWK as one of them, without the 67 million. The two accounts sit together without confirming each other. What Ripple has not published is an amendment number, a validator vote window or the point in 2028 when the switch happens, and on this ledger an amendment needs 80% of trusted validators behind it for two consecutive weeks before it activates, as the 3.3.0 release showed in August. StarkWare's quantum-safe bitcoin transaction landed on Wednesday. That was a demonstration on one output. This is a consensus change on a live payments network, and the testing has to finish first.
Read also: Ethereum Draft Would Let Validator Deposits Carry 8,192-Byte Keys