Cryptographer D.J. Bernstein argues against replacing ECC with standalone post-quantum encryption
Bernstein's cr.yp.to blog post argues that switching protocols entirely to post-quantum (PQ) cryptography, rather than combining it with existing ECC, creates unnecessary security risk. He contends that PQ implementations will inevitably contain exploitable bugs, and keeping ECC alongside PQ limits the damage those flaws can cause, at minimal extra cost.