Circle Details Arc’s Phased Post-Quantum Security Roadmap
Circle has released a post-quantum security whitepaper for its Arc blockchain, detailing specific cryptographic schemes and a phased migration strategy. Indeed, two of these schemes are already active on Arc: a hash-based signature option for smart accounts and a hybrid encryption scheme for private transactions. This document is a planning outline with explicit disclaimers, not a declaration that Arc or USDC are currently quantum-safe.
Whitepaper Specifications
Specifically, the whitepaper, available at arc.io/post-quantum-whitepaper, outlines a three-phase migration process: Readiness, Transition, and Switch. Circle identifies Readiness as the current phase. The Transition phase will involve the parallel operation of classical and post-quantum cryptography, while the Switch phase will fully transition to post-quantum-only systems.
The document commits to specific algorithms. For signatures, it names SLH-DSA-SHA2-128s, a hash-based scheme standardized by NIST as FIPS 205, and states that it is currently running on Arc mainnet as a precompiled verifier for smart accounts. It also discusses ML-DSA-44 and Falcon as potential candidates for a future native transaction-signature scheme, without making a definitive choice. For encryption, X-Wing is specified, a hybrid approach combining classical X25519 with post-quantum ML-KEM-768, which is currently in use for encrypted transaction memos. While consensus signatures will receive an eventual upgrade, there’s no specific algorithm in plans for this yet.
Circle’s earlier research on this topic dates back to January 2026, when it explored which blockchain layers are vulnerable to Shor’s algorithm and which remain secure. Hash functions and symmetric encryption are expected to endure, whereas elliptic-curve and RSA systems represent vulnerabilities.
Circle’s Stated Limitations
The whitepaper includes clear disclaimers. It states that it’s possible to modify, delay, or cancel all product features at Circle’s discretion. The document does not guarantee future performance, and Circle emphasizes that no post-quantum design can eliminate all future security risks. Arc is presented as a testnet, offered by Circle Technology Services, and has not been reviewed or approved by the New York State Department of Financial Services.
The document does not provide target dates for the completion of its Transition or Switch phases, nor for validator or infrastructure migration. The only dates mentioned are external regulatory benchmarks, the EU’s 2030 and the US and Canada’s 2035, which Circle cites as contextual information.
It cautions that rushing the process “will result in a design flaw that will expose the system to a conventional attack or permanently locked assets.” Secondary coverage from Cryptobriefing, republished via Bitget, reported a mainnet-2026 launch featuring post-quantum signatures from the first block. This specific timeline is not present in Circle’s primary whitepaper.
Currently, no cryptographically relevant quantum computer exists that can break RSA or elliptic-curve cryptography. The threat Circle addresses is “harvest-now-decrypt-later,” where attackers record encrypted data today with the intent to decrypt it once quantum hardware becomes available. No production deployment across USDC’s other mainnet contracts currently utilizes post-quantum signatures, and Circle has not disclosed any commitments from validators, customers, or external auditors. The account-recovery section, unusually detailed for a technical paper, frames the most challenging aspect as a legal one: distinguishing between disabling unsafe cryptography and extinguishing an individual’s economic interest.