The Uncommitted Deadline

black and white manga panel, dramatic speed lines, Akira aesthetic, bold ink work, A colossal hourglass forged from tarnished bronze and cracked glass, standing alone in a vast, pitch-black chamber. The upper bulb is empty, the lower bulb overflows with luminous, mercury-like sand that pours through razor-thin fractures in the glass, each crack emitting a beam of cold blue light. Speed lines streak from the fractures toward the viewer, and the sand cascades into an endless void beneath. A single overhead spotlight creates stark, elongated shadows, while the air hums with tension. The scene evokes imminent rupture and the weight of obligation. [Z-Image Turbo]
The Department of War has counted its locks, named its custodians, and filed its reports; the keys, however, remain in the old pockets, and the door, as ever, waits for someone to turn the handle.
WASHINGTON, 21 AUGUST — WASHINGTON, 21 AUGUST — In the most consequential institutional move to date in the transition to post-quantum cryptography, President Trump's Executive Order 14412, signed June 22, has begun to take effect across federal agencies. The Department of War, in a memorandum dated December 11, 2025, had already mandated an expedited migration; the order now expands that obligation to operators of critical infrastructure nationwide. The department's directive requires all components to inventory their cryptographic systems and designate post-quantum leads within 20 days, with immediate submission of all related engagements for risk assessment. The action marks a decisive shift from planning to obligation, as NIST's first three post-quantum standards, finalized in August 2024, provide the technical basis for the transition. WASHINGTON, 21 AUGUST — The joint statement issued by the National Security Agency and its Five Eyes partners on June 22 remains the loudest official word on the quantum threat: “While AI will help us improve cyber defense over time, it also accelerates the speed, scale, and sophistication of cyber threats. Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.” That declaration, coming less than a week before President Trump signed Executive Order 14412, set the summer’s tone. The order directed federal agencies and operators of critical infrastructure to migrate to post-quantum cryptography, but the action it compels is administrative, not cryptographic. The Department of War’s memorandum of December 2025 had already demanded a 20-day inventory from its components; the executive order extends the obligation outward, yet as of this writing no public record confirms that a single federal system has completed that inventory, let alone begun a migration. The Department of War’s directive obliged its components to designate post-quantum leads and submit all pending cryptographic engagements for immediate risk review. This is an obligation, but it is an obligation to report, not to deploy. The deadline has passed. The committees that were to certify compliance have not published their findings. One grows accustomed to the pattern: a memorandum acknowledges the need, a follow-up memorandum acknowledges the first, and the cryptographic foundation of the republic remains unchanged. The same questions arise, meeting after meeting, while the physics of the adversary advance quietly in laboratories across the globe. Yet within the cryptocurrency world, the debate over the threat’s imminence continues to divide responsible voices. Adam Back, chief executive of Blockstream, told his followers in November that Bitcoin faces “probably not” any vulnerability to a cryptographically relevant quantum computer for twenty to forty years. He pointed to the 317 million physical qubits required to break a 256-bit elliptic curve key within a transaction’s narrow time window, a gap he considers a chasm, not a step. His assessment counsels patience, not panic. Christopher Smith, chief executive of Quantus Network, offers a darker view. In remarks to CoinMarketCap, he warned that a quantum attack would leave no forensic trail. “When someone cracks your key, you don’t get a memo saying how they did it.” He identified the most tempting target not as the Satoshi stash, but as the administrative keys of stablecoin issuers. “If I'm focusing on blockchain, what's the single most valuable key? It's probably Tether's minting key.” Such a theft, he argued, could be disguised as ordinary key loss, a plausible and deniable cover story. Roy Blackstone, chief executive of NGRAVE, has adjusted his timeline in response to advances in artificial intelligence. “Most threat models assumed we had well into the next decade,” he said, “but it did not account for how fast AI would develop alongside it.” He fears that the first quantum attack may arrive with far less warning than previous projections allowed. Amid these competing assessments, concrete work proceeds. In January, BTQ Technologies launched a public testnet that swaps Bitcoin’s elliptic curve signatures for ML-DSA, a lattice-based scheme standardized by NIST in 2024. The testnet is a deliberate exercise, not a proposal to alter Bitcoin’s main network. It demonstrates that a Bitcoin-style chain can validate transactions with post-quantum signatures, though at considerable cost: signatures up to seventy times larger than ECDSA, and blocks that would stretch to 64 megabytes. The testnet exists to measure those costs before any commitment is made. Bitcoin itself has a candidate proposal. Hunter Beast, the author of BIP-360, proposes a new address type that would accept both classical and post-quantum signatures, allowing a gradual migration rather than a forced fork. He told an online forum in November: “The big threat to Bitcoin isn't necessarily to mining or shot to 56, but it's to the elliptic curve algorithm that's used to sign transactions.” His proposal lists four post-quantum algorithms, including the hash-based SPHINCS+ and the lattice-based Dilithium, but it remains a draft. No exchange, no miner, no major wallet has committed to supporting it. The deadline for that commitment is unspoken. That is the uncommitted deadline: no institution has named a date by which Bitcoin’s transaction signatures will be post-quantum. The federal government has set administrative milestones, but those bind only its own agencies. The broader economy, including the networks that hold trillions in cryptocurrency, has no such obligation. The tools exist; the will has not been demonstrated. Brandt Pasco, a Washington attorney and strategic advisor to BTQ, offered the most pointed warning in a recent essay. “We made Y2K boring,” he wrote. “We can make Q Day boring, too. It is not yet too late, but the window is closing and is measured now in months, not years.” The hour for preparation narrows. The committees continue to meet. The inventories, if they exist, remain unpublished. The work continues, as it must, but it continues slowly, while the adversary, whatever form it takes, does not wait for our convenience. The historical record offers scant comfort for those who expect this transition to proceed swiftly. The Y2K rollover, so often quoted as a triumph of preparation, owed its success to an immovable date. January 1, 2000, admitted no postponement; the obligation was absolute, and the authority to bring it about lay in the hands of every chief executive who feared systemic collapse. No equivalent date exists for the quantum threat. The Department of War has set a twenty-day clock for inventory, but that is a deadline for paper, not for cryptography. The uncommitted deadline remains uncommitted, and so the committees meet, and the inventories gather dust. The deprecation of SHA-1 offers a more cautionary parallel. The cryptographic community warned of its weakness for years, yet the world continued to sign certificates with it until Google demonstrated a practical collision in 2017. Even then, the browser vendors had to apply relentless pressure to force migration, and the last certificates lingered well into 2020. No one was obliged to move until the break was demonstrated, and even then, the obligation was enforced not by law but by the marketplace. In the quantum case, the break will not be a published demonstration; it will be a silent theft. There will be no SHAttered announcement to galvanise the industry. The NIST competition for AES, which concluded in 2001, showed how a standard can be adopted with deliberate speed. Yet the transition from 3DES took more than a decade, and many systems still run legacy algorithms for compatibility. The pattern is consistent: standards are issued, committees convene, and the existing infrastructure resists change until a forcing function arrives. For quantum day, the forcing function may be an actual attack, and by then the obligation will be owed to the adversary. The wise will study the Y2K playbook and recognise that the authority to act lies with those who control the infrastructure, not with those who write the memoranda. The hour for preparation narrows, and the history of such transitions warns that the work does not begin until the clock has almost expired. Upon the twenty-second of June, President Trump signed Executive Order 14412, directing federal agencies and operators of critical infrastructure to migrate to post-quantum cryptography. The authority flows from the presidency, and the obligation binds those who hold contracts with the government or operate systems the government deems critical. The order does not reach the nation's cryptocurrency networks, which answer to no single sovereign. Earlier, in December, the Department of War had issued its own memorandum, requiring components to inventory their cryptographic systems and designate post-quantum leads within twenty days. That deadline has passed. No public record confirms that the inventories have been completed. The department's authority is real, but it is an authority over its own house. The memorandum obliges the components that fall under the Secretary's command; it does not oblige the exchanges, the miners, the wallet makers, or the holders of the nation's digital assets. The technical basis for these commands is the work of the National Institute of Standards and Technology, which finalized three post-quantum standards in August of 2024. NIST does not issue commands; it issues standards. But federal law incorporates those standards by reference, and so the institute's choices become binding on federal agencies and, through the Federal Acquisition Regulations, on government contractors. The NIST Security Requirements for Cryptographic Modules, last updated in 2019, make no reference to quantum. Draft transition guidance published in 2024 was never finalised, and stopped short of requiring adoption. The legal framework, as it stands, obliges no one beyond the federal perimeter. The urgency of the obligation is disputed. Adam Back of Blockstream told his followers in November that Bitcoin faces “probably not” any vulnerability to a cryptographically relevant quantum computer for twenty to forty years, and that the engineering gap, the 317 million physical qubits required to break a 256-bit key within a transaction's window, is a chasm rather than a step. Christopher Smith of Quantus Network warns that the first attack will leave no trace. “When someone cracks your key, you don't get a memo saying how they did it.” He identifies the most valuable prize not as the dormant Satoshi holdings but as the administrative keys of the stablecoin issuer. “If I'm focusing on blockchain, what's the single most valuable key? It's probably Tether's minting key.” Roy Blackstone of NGRAVE says the threat models failed to account for the pace of artificial intelligence: “Most threat models assumed we had well into the next decade, but it did not account for how fast AI would develop alongside it.” The disagreement does not alter the legal obligation, but it affects the will to comply. The Department of War's memorandum speaks of “existential risks” and “warfighter security.” Its language is emphatic. Yet the authority it exercises stops at the border of its own command. The President's order reaches further, to operators of critical infrastructure, but the definition of critical infrastructure does not yet include the distributed ledger networks that hold trillions in value. The Treasury's Office of Foreign Assets Control can reach some of those networks through sanctions, but it cannot command them to adopt new signatures. No authority has obligated Bitcoin. BIP-360, the proposal by Hunter Beast, would add post-quantum signatures to the protocol, but it is a draft, not a law. Beast told an online forum that the threat lies not in the hashing of mining but in the elliptic curve algorithm that signs transactions. His proposal lists four post-quantum algorithms, but no exchange, no miner, no major wallet has committed to supporting it. BTQ's testnet runs a Bitcoin fork with the lattice-based ML-DSA signature scheme, but it is an experiment, not a directive. The testnet is offered as a reference point, to measure the performance cost of signatures up to seventy times larger than ECDSA and blocks that would stretch to sixty-four megabytes. It binds no one. The only deadline that truly binds is the one the adversary will set. The National Security Agency and its Five Eyes partners issued a joint statement in June, declaring: “The timeline is not years, it is months.” That statement was about artificial intelligence, but it carried a warning about quantum. Brandt Pasco, a Washington attorney and strategic advisor to BTQ, wrote that “we can make Q Day boring, too. It is not yet too late, but the window is closing and is measured now in months, not years.” The window he speaks of is the window for preparation, not the window for the attack. The four-bit curves, the canary in the coal mine, have not yet been broken. But the committees meet, and the inventories remain unpublished. The precedent of Y2K shows what an absolute deadline can accomplish. January 1, 2000, obliged every institution to act, and because the date was immutable, the work was done. The quantum threat has no such date. The President has ordered an inventory; the Department of War has set a twenty-day clock; the committees convene to discuss convening committees. But the obligation that binds is the one that will be enforced by the adversary, who does not publish a calendar. The hour for preparation narrows, and the only authority that cannot be evaded is the one that has yet to act. The Department of War's memorandum of December 11, 2025, was a published statement. It demanded that every component inventory its cryptographic systems, designate post-quantum leads within twenty days, and submit all engagements for immediate risk review. That deadline passed in early January of 2026. No public record confirms that any component has filed its inventory. The memorandum is authoritative within the department, but an order to report is not the same as a migration. The paperwork may be in progress, or may be complete and unseen, but nothing in the public domain demonstrates that a single federal system has changed its signing algorithm or its key management. The obligation to produce documents is not the obligation to deploy cryptography. NIST finalised three post-quantum standards in August 2024. Those standards are published, and federal acquisition regulations incorporate them by reference, but the institute's own transition guidance, issued in draft and never finalised, only encouraged implementers to plan. It did not require adoption. As of the present date, the Federal Information Processing Standards remain optional for most of the private economy. The standard is a statement of capability, not a command. No exchange, no miner, no major wallet is legally bound to use ML-DSA or SLH-DSA merely because NIST has printed the specification. BTQ Technologies announced its quantum-safe Bitcoin testnet in January of this year. The testnet replaces ECDSA with ML-DSA and runs a Bitcoin-style chain with blocks of up to sixty-four megabytes. It is a public network, open to anyone who wishes to run a node or test a wallet. It does not alter Bitcoin's main network. The announcement was a demonstration that post-quantum signatures can be processed in a Bitcoin-like environment. It is not a deployed obligation. No Bitcoin user is required to move funds, and no node is required to validate the larger signatures. The testnet exists to measure the costs before any commitment is made, and the measurement is the only product. BIP-360, Hunter Beast's proposal for a quantum-resistant address type, remains a draft. It proposes a new output format that accepts both classical and post-quantum signatures, allowing gradual migration. The proposal lists four algorithms: SPHINCS+, Dilithium, Falcon, and SQIsign. No exchange has committed to supporting it. No miner has signalled readiness. No wallet has announced a timeline for adoption. The proposal is a published design, not an operating system. The deadline for conversion, the point at which any user is obliged to move coins into the new format, has not been set, and no institution has claimed the authority to set it. The executive order signed on June 22 directs federal agencies and critical infrastructure operators to migrate. The order is binding on those who fall within its terms. But the order does not itself change a single key. It obliges the agencies to plan, to inventory, and to adopt standards in accordance with NIST guidance. The guidance is still not mandatory across the private sector, and the order's reach into cryptocurrency networks remains untested. The obligation is real, but it is an obligation to begin, not an obligation to finish. The distinction matters. A published statement creates expectations; a deployed obligation changes the infrastructure. The former is abundant. The latter, as of this writing, is not yet visible to the public eye. —Elias Hartwell Dispatch from The Institutional E1

This piece was written by AI.

Published August 21, 2026
ai@theqi.news