Key Takeaways
The crypto industry is seeking algorithms capable of protecting blockchains against future quantum computers. BOLTS Technologies co-founder Yoon Auh believes choosing the right algorithm is only half the problem.
Because researchers cannot guarantee that today’s post-quantum algorithms will remain secure, Auh argues that blockchains need the flexibility to replace compromised cryptography without lengthy upgrades.
Speaking with CCN’s Dr. Guneet Kaur at the Blockchain Futurist Conference, Auh explained how BOLTS’ QFlex technology aims to let digital asset owners change the protection applied to their transactions.
“If you have a method of defense and you don’t put it in, then it’s all your fault,” he said.
+76
Current blockchains largely rely on elliptic-curve cryptography to authorize transactions. A sufficiently powerful quantum computer could theoretically undermine that protection using Shor’s algorithm.
Researchers are developing post-quantum cryptography, or PQC, to withstand such attacks. However, no one knows which algorithms will prove durable over several decades.
“Cryptography is changing rapidly,” Auh said. “We’re going from legacy ciphers to post-quantum ciphers, but there are many of them.”
The number of candidates reflects uncertainty rather than an abundance of permanently secure options, he argued.
“There’s no provably secure modern cipher, and that includes AES, RSA and elliptic curve,” Auh said. “The post-quantum ciphers are even more vulnerable because they haven’t been around very long.”
NIST has already seen high-profile candidates fail during its standardization process. Classical computers broke Rainbow and SIKE before they could become lasting standards.
For Auh, the lesson is that blockchains should avoid permanently tying themselves to a narrow set of algorithms.
“If others fixate on two or three alternatives and they all fail, what do you do next?” he asked. “You have to build it again.”
BOLTS describes itself as a “cryptographic logistics” company. Rather than designing new algorithms, it aims to deliver existing cryptographic methods wherever users need them.
“We don’t create any algorithms,” Auh said. “We take the standard algorithms and their variations, put them in our library and suggest the best ones.”
Its QFlex system is designed to support several cryptographic options and combinations, including hybrid protection that uses multiple algorithms.
If researchers discover a weakness in one method, users could select another for their next transaction.
“Give me the next best one,” Auh said. “Maybe that’s SPHINCS+, maybe that’s Falcon. On the next transaction, you’re done.”
This approach differs from blockchain upgrades that require developers, validators and users to coordinate around a network-wide migration.
“What we allow you to do is change on your very next transaction,” Auh said. “The digital asset owner can impose their own sovereignty on the security of that transaction.”
QFlex’s value would therefore depend less on predicting the winning post-quantum standard and more on reducing the difficulty of moving between standards.
Supporting several algorithms could create more complexity than committing to one standardized method.
Can competitors that adopt a single NIST-backed algorithm gain an advantage in speed and simplicity?
“Not really, because our overhead is minimal,” Auh responded. “The main culprit is the ciphers themselves, the algorithms, so they’re not going to get a speed advantage.”
Post-quantum algorithms can require larger signatures, keys and additional computing resources compared with existing blockchain cryptography. Those demands could increase transaction costs or reduce performance regardless of how a network integrates them.
BOLTS’ challenge will be demonstrating that its abstraction layer can provide algorithm flexibility without introducing significant fees, latency or new security vulnerabilities.
The company has already launched a QFlex pilot with Canton Network to explore user-controlled cryptographic protection without requiring changes to the underlying network code.
Auh did not offer a specific prediction for when a cryptographically relevant quantum computer will emerge.
“I don’t have an opinion on how close it is,” he said. “I’m not a quantum computing expert, so I don’t have the best visibility into when they will create a scalable computer that can crack ECC.”
Instead, he pointed to the migration schedules adopted by governments.
The US Quantum Computing Cybersecurity Preparedness Act became law in 2022, directing federal agencies to begin preparing systems for post-quantum cryptography.
In June 2026, President Donald Trump signed an executive order to accelerate the transition of sensitive federal systems. Certain high-value assets must now migrate by 2030 or 2031, several years ahead of the previous 2035 timeline.
“Experts looking at this determined 2035, and then it came down to 2030 or 2031,” Auh said. “Some countries are looking at 2029 and 2028.”
These deadlines do not prove that quantum computers will break blockchain security by then. They reflect the time required to identify vulnerable systems, replace deeply embedded cryptography, and test new protections before a threat materializes.
BOLTS shares its technological foundations with NUTS Technologies, another company co-founded by Auh.
NUTS developed the secure-object architecture from which QFlex emerged.
The companies separated their commercial operations because they serve different markets.
“Both companies stem from the same technology base,” Auh said. “We started NUTS first, and then we built QFlex.”
NUTS works on government-funded applied cryptography projects that can impose restrictions on investors and developers.
“When you’re dealing with government agencies, they have strict rules on investors and who you can use as developers,” Auh explained.
Blockchain development, by contrast, depends on global capital and engineering talent. BOLTS was created to commercialize QFlex without placing those restrictions on its Web3 operations.
“We recognized that the blockchain investor base may be global and the development force may be global,” he said. “That’s why we set up two separate companies.”
Over the next three to five years, BOLTS wants to license QFlex to blockchains and financial institutions preparing for post-quantum requirements.
“We would like to license our technology to blockchains that are forward-thinking and have the best intentions for their asset owners,” Auh said.
Auh rejected the idea that critical blockchain infrastructure must always be entirely open source, noting that consumer devices and financial systems already depend on layers of licensed technology.
“You want something open, but you also want it to be the best,” he concluded.
“Sometimes they’re not the same.”