At the recent working roundtable hosted by GFI’s Convergence of Emerging Technologies SubCommittee, legal, security, and quantum specialists gathered in Singapore to examine a defining question for the future of digital finance: When Q-Day arrives, what happens to the cryptography securing our digital assets?

Daniel Lee, representing Cactus Custody, shared pragmatic, institutional-grade insights on the threat timeline, the state of Post-Quantum Cryptography (PQC), and why defending against the quantum challenge requires an ecosystem-wide collaborative effort.
1. The Core Misconception: It’s Not Just a Wallet Problem
A common misconception in the Web3 space is that the quantum threat is isolated to on-chain private keys and blockchain wallet signatures (such as ECDSA). Daniel directly corrected this narrative, emphasizing that quantum computing poses a systemic threat to the entire enterprise architecture, not just the blockchain layer.

“Many people mistakenly believe that quantum computing only threatens cryptographic wallets,” Daniel noted. “In reality, any traditional public-key cryptography—including RSA and ECC—will be rendered obsolete by a sufficiently powerful quantum computer.”
This means that long before a hacker targets a wallet seed phrase, they could compromise non-wallet modules, including:
- Internal operational databases.
- API communication channels between institutions.
- Traditional Web Security layers (TLS/HTTPS) securing institutional web traffic.
- Multi-factor authentication (MFA) and strong identity verification systems.
For an institutional custodian, achieving quantum resilience means ensuring that every single strong-verification checkpoint across the entire infrastructure is fortified, rather than solely focusing on the blockchain.
2. PQC Migration is an Ecosystem-Wide Mandate (Not an Isolated Upgrade)
Addressing the technical readiness gap, Daniel shed light on the operational realities of migrating to Post-Quantum Cryptography (PQC). He explained that antiquantum resilience is not a feature a single custodian can build or implement in a vacuum. Instead, it requires a synchronized full-stack upgrade across three distinct pillars:
+-------------------------------------------------------+
| 1. HARDWARE LAYER (HSM Vendors upgrading firmware) |
+-------------------------------------------------------+
│
▼
+-------------------------------------------------------+
| 2. SOFTWARE LAYER (Custodians upgrading internal code)|
+-------------------------------------------------------+
│
▼
+-------------------------------------------------------+
| 3. BLOCKCHAIN LAYER (Networks executing hard-forks) |
+-------------------------------------------------------+
Without all three layers upgrading in tandem, true quantum security cannot be achieved. For instance, if a public blockchain network fails to execute a governance upgrade to a quantum-resistant signature scheme, the assets on that chain remain fundamentally exposed, regardless of the custodian’s internal security.
3. Cactus Custody’s Strategic Roadmap to Quantum Readiness
Faced with these timeline uncertainties, Cactus Custody has taken proactive and structured steps to ensure operational agility and immediate preparedness:
- Hardware Vendor Alignment: Cactus Custody is already in active communication with its Hardware Security Module (HSM) vendors to align on their PQC firmware upgrade roadmaps, ensuring that physical infrastructures are built to support NIST-endorsed quantum-resistant algorithms.
- Ecosystem Monitoring: The team is closely tracking international cryptographic standards and the technical upgrade timelines of major blockchain developer communities.
- Immediate System Deployment: Cactus Custody’s architecture is structured for swift deployment. The moment standard migration paths are formalized and corresponding blockchain communities deploy their upgrades, Cactus Custody is positioned to immediately upgrade its system.

Conclusion
Q-Day should not be treated as a distant science-fiction doomsday, but as a definite, foreseeable infrastructure deadline. As post-quantum capabilities transition into operational reality, financial institutions in Asia must move past fragmented defenses.
Cactus Custody remains committed to working alongside hardware partners, software developers, and decentralized networks to ensure that the transition to a quantum-safe digital asset ecosystem is seamless, robust, and secure.