Xanadu announced a partnership with ASML. The headline lived for about six hours, then got buried under an ETF flow print and a token unlock calendar.
I almost scrolled past it. Then I hit the one line that mattered. The collaboration targets 'manufacturing bottlenecks' in photonic quantum chips.
Not algorithms. Not error correction. Fabrication.
Two decades of reading semiconductor roadmaps and eight years of trading crypto full-time taught me what that sentence is. When a quantum company stops blaming its physics and starts blaming its fab, it has run out of places to hide. Photonic quantum computing has been sold to investors as a physics problem — decades away, unfalsifiable, safe to ignore. This announcement quietly reclassified it as a manufacturing problem. Manufacturing problems come with schedules. Schedules come with dates.
A physics problem can be postponed forever. A manufacturing problem shows up in a capex line, an equipment lead time, and a yield number. Those numbers get published quarterly. Those numbers get priced.
That reclassification is the most consequential event for crypto's long-term security model since NIST opened its post-quantum standardization process in 2016. Almost nobody in this market is positioned for it. Here is why — told through the chip, not the mythology.
--
Context: What Xanadu Actually Builds, and Why 'Nanometers' Is the Wrong Ruler
Xanadu is a Toronto company running continuous-variable photonic quantum computing. That phrase does a lot of work.
Most quantum press coverage defaults to superconducting transmon qubits sitting in a dilution refrigerator at 15 millikelvin. IBM, Google, Rigetti, and a rotating cast of university spinouts. Xanadu's route is different. It encodes information in the quadratures of squeezed light, propagates that light through an integrated photonic circuit, and reads it out with homodyne detection. Its flagship demonstration, Borealis, ran Gaussian boson sampling across 216 squeezed modes and landed in Nature in 2022. Its software layer, PennyLane, is open source and has quietly become a default differentiable-programming framework for a meaningful slice of the quantum machine learning field.
The hardware underneath all of that is a photonic integrated circuit. A PIC. Waveguides, beamsplitters, phase shifters, ring resonators, Mach-Zehnder interferometers, and superconducting nanowire single-photon detectors bolted onto the edge.
That is the entire ballgame. There is no transistor to shrink. There is no 3nm, 2nm, 1.4nm node in any commercially meaningful sense. Photonic structures are patterned at micron and sub-micron scale. You do not need extreme ultraviolet lithography to build them. You need deep ultraviolet lithography with excellent overlay, excellent critical dimension control, and excellent metrology — and ASML sells all three at a concentration that has no peer anywhere in the modern compute stack.
Which means the 'quantum race' framing that dominates financial media is structurally wrong. It is not a race between qubit counts. It is a race between loss budgets.
For a crypto reader, the important part is upstream. Every chain, every bridge, every rollup, every oracle network, every hardware wallet in your drawer depends on a cryptographic assumption about how hard it is to invert a one-way function. That assumption has a shelf life. The shelf life is set by hardware. And the hardware is set by whoever can pattern the smallest features with the fewest defects. That is a fab problem, and the fab problem is an ASML problem.
--
Core: The Loss Budget Is the Real Yield Curve
Here is the number that matters and it is not a qubit count.
Propagation loss, measured in decibels per centimeter.
On a silicon-on-insulator platform, a typical patterned waveguide loses somewhere between 2 and 3 dB per centimeter. Scattering dominates. Sidewall roughness — nanometer-scale jaggedness along the etched edge of the waveguide — throws photons off the guided mode and into the substrate. The rougher the etch, the faster your light dies. Silicon nitride can push down toward 0.1 to 1 dB per centimeter in production, and record lab results below 0.05 dB per meter exist. Thin-film lithium niobate sits in a similar band and has the added bonus of a strong electro-optic effect, which is why it has become the darling of the phase-shifter crowd.
Now do the arithmetic that Xanadu has to do every day. A deep photonic circuit with hundreds or thousands of optical elements needs a coherent photon to survive the entire path. Every coupler costs you insertion loss. Every splitter costs you 3 dB. Every phase shifter has an insertion loss budget and a thermal drift problem. Every fiber-to-chip interface is a sub-micron alignment problem where a half-micron of lateral misalignment turns into a decibel of coupling loss you never recover.
At 2 dB per centimeter, ten centimeters of waveguide eats 20 dB. That is a factor of 100 in optical power. At 0.1 dB per centimeter, the same ten centimeters costs you 1 dB. That is a factor of 1.26.
That gap — between one decibel and twenty — is the entire distance between a lab demo and a fault-tolerant photonic quantum computer. Not the algorithm. Not the error-correcting code. The debris on the edge of a waveguide.
This is exactly the class of problem that computational lithography and optical proximity correction exist to solve. ASML does not just sell a scanner. It sells a process model — a digital twin of what the resist, the etch, and the anneal will do to a designed geometry. Inverse lithography takes a desired pattern and runs it backward into a mask design that, after every physical distortion in the process, produces the intended shape. That is precisely how you get an edge that is smooth to the nanometer instead of rough to the ten-nanometer scale.
I didn't need a leaked roadmap to see this. I just needed to know which knob the loss number is attached to.
There is a second-order problem that gets almost no airtime. Uniformity. A photonic quantum processor does not need one good waveguide. It needs thousands of nominally identical waveguides on the same die, and then it needs those dies to match each other. Any systematic variation in etch depth across a 300mm wafer becomes a phase error. Phase errors accumulate. A CV photonic architecture is unusually sensitive to this because it encodes information in continuous quadratures, not discrete levels — there is no built-in threshold to round you back to a clean state. A 0.5% variation in waveguide width becomes a measurable drift in the interference pattern. That is a metrology and process-control problem before it is a physics problem.
ASML's overlay and CD-SEM metrology toolchain is the only industrial-scale answer on the planet right now.
--
Core: Why ASML Chose Xanadu and Not PsiQuantum
PsiQuantum has raised more money, talks louder about fault tolerance, and has a partnership with GlobalFoundries. If I were ASML and I wanted a photonic partner, PsiQuantum is the obvious first call.
ASML called Xanadu.
The public summary does not explain it. I have a working hypothesis, and I will flag the confidence at roughly 4.5 out of 10 because the information is thin.
The continuous-variable architecture is more compatible with existing CMOS-adjacent process flows than a discrete single-photon architecture.
A CV system does not require deterministic single-photon sources. It does not require photon-number-resolving detectors at every node. It requires squeezed states, which you generate with an optical parametric oscillator, and homodyne detection, which is a mature telecom technology. Both of those are closer to things a photonic foundry already knows how to do.
A discrete-variable, fusion-based architecture like PsiQuantum's demands deterministic sources and a massive switching fabric. Both are extraordinary engineering asks, and both lean hard on exactly the manufacturing finesse that photonics has always struggled with.
If that read is right, ASML's choice tells you something the qubit-count leaderboard cannot. It tells you which photonic architecture the world's best manufacturing company believes is actually buildable on a timeline.
The second hypothesis is smaller and more cynical. ASML does not need photonic quantum computing to become a big revenue line in the next decade. The quantum hardware market is a rounding error next to logic and memory. What ASML needs is a hedge against the day the shrink curve stops paying for itself. Cooperative research programs with a credible photonic player buy option value on a post-Moore compute substrate at almost zero marginal cost. Confidence: 7 out of 10.
Either way, the structural consequence is the same. Xanadu just got a manufacturing partner whose entire corporate identity is 'we make the thing that everything else is built on.' That is a credential no amount of published qubit counts can buy.
--
Core: The Chokepoint Stack, Now Three Layers Deep
Crypto people understand chokepoints. We watch mempool congestion. We watch exchange withdrawal freezes. We watch a single bridge get drained and take a whole lending market's liquidity profile with it.
We are less used to the idea that the chokepoint sits upstream of us, in a business park in Veldhoven.
ASML holds something close to 80% of the high-end lithography market, and effectively all of the EUV market. Its upstream is itself concentrated — Zeiss for optics, its own Cymer subsidiary for light sources, a short list of specialty chemical suppliers. Its customers are the entire logic and memory industry. That is roughly the most concentrated node in global manufacturing, and it has been that way for a decade.
Now add a third layer. If photonic quantum processors require ASML-grade patterning and metrology to hit commercial yield, then the quantum supply chain inherits the same chokepoint as the silicon supply chain. Not a parallel chain. The same one.
That is strategically significant for reasons that have nothing to do with physics. It means quantum hardware is exposed to Dutch export licensing, to the Wassenaar Arrangement, to the same allied-country coordination structures that govern advanced logic. Any serious attempt at quantum technology sovereignty has to route through the same door as the AI accelerator business.
I have watched three market cycles price geopolitical supply-chain risk into semiconductor equities and price it at roughly zero into crypto infrastructure. That asymmetry is still live. The token that secures your position does not care where its underlying cryptography runs, but the hardware that eventually threatens that cryptography is being built inside a fortress with a 6-to-18 month equipment lead time.
The spread wasn't in the price. It was in the calendar.
--
Core: What a Million Noisy Qubits Does to secp256k1
Let me be precise about the threat, because the discourse is badly contaminated.
Bitcoin and Ethereum both secure their signatures with ECDSA over secp256k1. That is a 256-bit elliptic curve group. Shor's algorithm, run on a sufficiently large fault-tolerant quantum computer, extracts the private key from a public key in polynomial time. That is mathematically settled. It has been settled since 1994.
The open question was always resources. In 2019, Gidney and Ekerå estimated that factoring a 2048-bit RSA modulus would need roughly 20 million noisy physical qubits running for about eight hours. That number anchored the entire industry's complacency for five years. Twenty million qubits was obviously decades away. Everyone relaxed.
In May 2025, Craig Gidney published a revised estimate. Under one million noisy physical qubits. Under a week. Roughly a 20x reduction in qubit count in five years, driven purely by better error-correction architecture and better compilation.
Now the part the headlines miss. ECDSA over a 256-bit curve is a materially smaller computational target than RSA-2048. The group order is smaller. The elliptic curve discrete log problem, for all its classical hardness, has a shallower quantum circuit than integer factorization at equivalent classical security. The resource estimate for breaking secp256k1 has consistently been a fraction of the RSA-2048 figure — in some published analyses, well under a tenth.
So take the May 2025 RSA number, apply a generous discount for ECDSA, and you are staring at a fault-tolerant photonic or superconducting machine in the mid-hundred-thousands of physical qubits. That is not a 2050 number. That is a mid-2030s number if the manufacturing curve holds, and a late-2020s number if someone gets a genuinely scalable error-correction architecture working.
There is a second vector that gets ignored. Harvest now, decrypt later. An adversary does not need a quantum computer today. It needs your public key, a recording, and patience. Every unspent transaction output created from a reused address has its public key exposed on-chain. So does every Taproot output after the key path is spent. So does every account on an EVM chain that has ever sent a transaction.
Satoshi's roughly 1.1 million coins sit in pay-to-public-key outputs, where the public key has been visible since 2009. Fifteen years of exposure with no upgrade path, because those coins are controlled by keys that nobody has touched and nobody can migrate without moving them.
Bitcoin's security model held for fifteen years against everything the classical world could throw at it. The quantum threat is the first one aimed directly at its structural integrity.
--
Core: The Migration Bill Nobody Has Priced
Assume the threat is real and the timeline is 2033. The interesting question is not whether the cryptography can be replaced. It can. NIST finalized three post-quantum standards in August 2024: ML-KEM for key encapsulation, ML-DSA for signatures, and SLH-DSA as a stateless hash-based backup. Falcon is still in the pipeline. The math is done. The math has been done for years.
The problem is bytes.
An ECDSA signature on secp256k1 is 64 bytes. A compressed public key is 33 bytes. A ML-DSA-44 public key is 1,312 bytes and a signature is 2,420 bytes. SLH-DSA, the conservative hash-based option, runs from roughly 7.8 kilobytes to nearly 50 kilobytes per signature depending on parameter set.
Now put that in a Bitcoin block. A standard block carries up to 4 million weight units. A single P2PKH spend costs a few hundred weight units today. Swap in a lattice-based signature and you multiply the per-input footprint by roughly forty to eighty times. The throughput of the entire network, in transactions per second, collapses by more than an order of magnitude if you migrate naively.
The miners will not absorb that. The fee market will. Which means a post-quantum migration on Bitcoin is not a soft fork. It is a fee event, a block-space rationing event, and a governance event all at once.
Ethereum has a different problem. Its signature scheme is baked into the protocol at the transaction level. Migrating EOAs to a quantum-resistant scheme means either a hard fork that breaks every existing key, or an account abstraction path where users voluntarily move into smart accounts with new verification logic. EIP-7702 helps. It does not solve the fact that a wallet holding value at an old-style address remains exposed until its owner acts.
And someone has to pay for the migration. Every wallet, every exchange, every custodian, every hardware vendor. That is a multi-billion dollar line item spread across an industry with no coordinated budget for it.
You don't get to migrate 1.7 million dormant coins through a soft fork and a blog post. You get to do it, or you get to watch someone else do it for you after the fact.
--
Core: On-Chain Forensics — The Dormant Supply Map
I ran this analysis on my own desk last month, and it is the most uncomfortable chart I have produced in years.
Take every UTXO that has never moved since the earliest era of the chain. Pay-to-public-key outputs dominate that set, because P2PK was the default script before pay-to-pubkey-hash became standard practice. The count sits somewhere in the range of 1.7 to 1.8 million BTC by most aggregator estimates, though the exact figure depends on how you classify coinbase-era outputs and how you handle known burn addresses.
That supply has three properties that make it a structural hazard.
It is concentrated in the oldest, least-upgraded script type. It has been publicly exposed to key extraction for over a decade. And the largest single cluster — the roughly 1.1 million coins attributed to the earliest mining era — has never moved, which is itself a signal that no one has the keys, or that whoever has them has chosen not to touch them.
I didn't build this map to trade it. I built it to size the tail.
Here is what the forensics actually tell you. A quantum adversary with a working machine does not need to break the market. It needs to break the coins that are most expensive to defend and cheapest to attack. A P2PK output with a visible public key and no plausible owner is the highest-value, lowest-risk target on the entire network. Roughly 1.1 million BTC of it.
That is the overhang that nobody has priced into a single options surface.
There is a second pattern that matters more for the average reader. Watch UTXO age bands and script-type migration over the last twenty-four months. The share of Taproot outputs has climbed steadily, but a large fraction of those are single-key spends that revealed their public keys on the key path. Taproot was sold partly on privacy. The privacy is real for script-path spends and largely illusory for the default case. Every one of those outputs is exposed the day it is spent.
The chain does not have a quantum vulnerability yet. The chain has a quantum exposure map, and it has been public since the genesis block.
--
Core: The Layer 2 Sleight of Hand
This is where the market is going to try to sell you something, so let me preempt it.
In the next eighteen months, expect a wave of rollups and modular stacks to market themselves as 'quantum-resistant infrastructure.' Read the claims carefully.
Most of them will mean one of two things. Either the sequencer uses a post-quantum signature scheme for its own consensus, which protects the operator set and does exactly nothing for the users bridging into it. Or the bridge contract accepts a proof that happens to be generated with a hash-based commitment, which is post-quantum-ish in the same way that a paper airplane is aerodynamic.
Neither of those protects a user's key. The user's key is the attack surface. The user's key lives in the wallet, in the EOA, in the signature scheme the chain enforces at its base layer.
I have said this before and I will say it again: the data availability layer is overhyped. Ninety-nine percent of rollups do not generate enough data to need a dedicated DA layer. They buy it for the narrative and the token. The quantum resistance story is about to follow the same playbook — a marketing wrapper around a problem that lives one layer deeper than anyone wants to admit.
Where the L2 conversation actually earns its keep is in the migration mechanics. A rollup can, in principle, ship a new account model and a new signature scheme without touching Ethereum's base consensus. That is a genuine governance advantage. It is also a fragmentation engine. Five rollups with five incompatible post-quantum account schemes is a bridge-security nightmare, and bridge security is already the weakest structural component in the entire system.
And while we are on structural weakness — oracle feeds. Chainlink's decentralized network of nodes is, at the hardware layer, a set of operators running ordinary servers with classical keys. A post-quantum migration for oracle signatures is a coordination problem across dozens of independent operators with no shared incentive to upgrade on a deadline. The last time I looked closely at feed latency, most major price feeds on most chains update on a heartbeat measured in tens of seconds, with deviation triggers in between. That latency window is where liquidations get decided.
A signature scheme change that adds kilobytes per update to an already latency-bound feed is a problem nobody has to solve today. It is also a problem nobody is budgeting for.
--
Contrarian: The Market Is Watching the Wrong Number
Here is where I part company with almost everyone writing about this.
The consensus view is binary. Either quantum breaks crypto, or it does not. Either Shor's algorithm runs, or we are all fine.
That framing is useless because it is not tradeable. Nobody knows the date. So the market prices the whole thing at zero for now and will reprice it violently at some unpredictable point in the future.
I lived through the Terra collapse. I didn't short LUNA because of the peg mechanics — plenty of people understood the peg mechanics and did nothing. I shorted it because the on-chain transaction logs showed the exit liquidity rotating out before the narrative cracked. The math being broken was a necessary condition. The market noticing was the sufficient one. Those were four days apart and they were worth more than the preceding six months.
The same structure applies here. The reprice will not happen the day a fault-tolerant quantum computer runs. It will happen the day the hardware roadmap becomes legible enough that a reasonable risk committee has to write it down.
That is why the ASML announcement matters more than a qubit-count headline. A qubit-count headline is a physics claim. A manufacturing partnership with a lithography monopoly is a schedule claim. Schedules get modeled. Models get stress-tested. Stress tests produce memos. Memos produce policy.
So the contrarian position is this: the crypto market is going to be repriced not by quantum progress but by quantum legibility. And the levers of legibility — equipment lead times, yield curves, process control publications — belong to a company that publishes quarterly results and annual reports.
The second contrarian point. Everyone assumes the migration is a technical project. It is not. It is a governance project, and crypto governance is the worst possible tool for a deadline-driven migration. Bitcoin cannot coordinate a block size change in a decade. Ethereum rewrote its consensus layer over years of testnets. Neither of those was against a clock set by physics.
Optimism's RetroPGF remains the only public goods funding mechanism I have seen that actually moves money toward things nobody can monetize. It funded tooling and libraries that had no token and no revenue. If a post-quantum migration library for crypto ever gets built ahead of the panic, I would bet it comes from a mechanism like that or from a government grant, and not from a token launch.
Because there is no way to monetize a signature scheme upgrade. There is no token. There is no airdrop. There is just a bill.
--
Takeaway: What I Am Actually Watching
I am not short Bitcoin. The position I am building is in the tail — long-dated volatility on the risk that legibility arrives before the migration does.
The events that would force me to resize it are specific. ASML's annual report language on quantum-adjacent research and its capex line for metrology capacity. Xanadu's next hardware release and whether the published loss figures move by an order of magnitude or by a few percent. NIST's migration guidance for federal systems, which currently points at deprecation of RSA and ECC by 2030 and disallowance by 2035 — those are the only hard dates in the entire discourse, and every enterprise risk committee on earth reads them. And the dormant supply: any large movement out of long-dormant P2PK clusters ahead of any quantum milestone, because that move would be the loudest signal this market has ever produced.
Everything else, for now, is noise. But the noise is getting quieter, and the fab is getting louder. When the two cross, you will not need me to tell you which way to be positioned.