Lack of Post-Quantum Encryption Adoption in the Cryptocurrency Sector
The cryptocurrency industry is facing a significant security risk due to its failure to adopt post-quantum cryptography (PQC) standards, leaving user data and transactions vulnerable to future quantum computing threats. A recent ImmuniWeb report revealed that none of the 2,138 web applications and 146 mobile apps tested in the sector currently support the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), the new post-quantum encryption standard published by NIST. This lack of adoption means that encrypted transactions and sensitive user data could be exposed once quantum computers become capable of breaking current cryptographic algorithms. The report also highlighted that over 7.8 million user records from cryptocurrency platforms are already circulating on the dark web, underscoring the urgency of the threat. Despite the overall poor sector performance, exchanges like Coinbase, UPbit, and Crypto.com were identified as the most secure, with the fewest security findings, demonstrating that robust security is achievable. However, the absence of ML-KEM support across all tested exchanges indicates a sector-wide lag in migrating to quantum-resistant encryption. Compounding the issue, nearly one-third of exchanges still support outdated protocols such as TLS 1.0 and 1.1, further exposing encrypted traffic to interception. The research also found that 45% of exchanges lacked a web application firewall, making them susceptible to AI-driven threats like automated scraping, impersonation, and infrastructure mapping. The increasing use of generative AI in development, without adequate security oversight, is introducing new vulnerabilities and expanding attack surfaces. Persistent issues such as 74% of web applications using outdated software or libraries and 67% failing GDPR compliance continue to plague the industry. Internationally, the NIST PQC standards, including ML-KEM, ML-DSA, and SLH-DSA, have set the baseline for quantum-resistant encryption, with most countries aiming for full quantum resistance by 2035. While there is broad agreement on the need for PQC, there are differences among countries regarding recommended algorithms and the use of hybrid post-quantum/traditional encryption schemes. Most governments, including the U.S. and U.K., advise against quantum key distribution in favor of PQC. The slow adoption of these standards in the cryptocurrency sector stands in stark contrast to the urgency expressed by global standards bodies and governments. The current state of security in the sector, combined with the looming threat of quantum computing, presents a critical challenge that requires immediate attention and coordinated action. Without rapid migration to PQC, the confidentiality and integrity of cryptocurrency transactions and user data remain at significant risk. The industry must prioritize the implementation of NIST-approved PQC standards to safeguard against both present and future threats. Failure to do so could result in catastrophic breaches once quantum computers become operationally viable for cryptanalysis. The situation is further complicated by the global nature of cryptocurrency, necessitating harmonized international standards and compliance efforts. As adversaries continue to harvest encrypted data for future decryption, the window for proactive defense is rapidly closing. The sector's response in the coming years will determine its resilience against the quantum threat.
Jun 29, 2026