G7 Tells Organizations to Start Post-Quantum Migration Now
The G7's cybersecurity working group published a report this week calling quantum computing a security and economic threat to public and private organizations, and urging immediate migration to post-quantum cryptography (PQC). The group warned that data stolen and stored today could later be decrypted by a sufficiently powerful quantum computer — the harvest-now, decrypt-later problem — and that digital signatures could be broken, enabling impersonation across supply chains.
The report does not mention cryptocurrency, but the same class of public-key cryptography protects blockchain wallets and authorizes transactions. Current quantum computers cannot break Bitcoin's cryptography. Even so, Bitcoin developers are debating proposals such as BIP-360 to prepare the network for new signature schemes, Ethereum researchers have proposed rebuilding the deposit contract to support post-quantum keys, and the Solana Foundation has tested post-quantum signatures on a test network alongside an optional hash-based vault. The G7's framing — migration could take years, so start before it is urgent — lands directly on the industry's slowest-moving asset.
Google Patches Actively Exploited Chrome V8 Zero-Day
Google updated Chrome on Friday to fix an actively exploited high-severity zero-day flaw in the V8 JavaScript engine, along with 11 other vulnerabilities. Browser-based wallets and extensions remain the softest target surface in crypto, and an exploited V8 bug is precisely the class of flaw that can read what a web wallet extension signs. The fix is already rolling out; users who keep funds in browser wallets should treat the update as time-sensitive rather than optional.
Critical Citrix NetScaler Auth Bypass Exploited in the Wild
Attackers have begun targeting a critical-severity Citrix NetScaler authentication bypass, tracked as CVE-2026-19490, according to vulnerability intelligence firm Previdian. NetScaler appliances front a significant share of corporate and exchange infrastructure; an auth bypass on that edge is a direct path to internal services. Crypto firms running Citrix gear in front of trading, custody or admin systems should patch on the same cycle they would apply to a wallet library flaw.
Coder Registry Compromised to Push Malicious Terraform Modules
Developer-platform company Coder disclosed that attackers compromised its Cloudflare-hosted infrastructure and added unauthorized registry servers that served malicious Terraform modules containing credential-stealing code. The attack is a supply-chain compromise of infrastructure-as-code tooling — the layer many crypto ops teams use to deploy nodes, validators and monitoring. Teams that pulled Terraform modules from Coder-hosted registries in the exposure window should rotate any credentials that passed through those pipelines and audit what the modules executed.
TrustGrade tracks the security posture of DeFi protocols, exchanges, and chain infrastructure. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.