'In the case of crypto-currencies where the primary goal of the proof-of-work is decentralization of trust it becomes critical that the proof-of-work cannot be optimized and accelerated by FPGA or ASIC designs with any meaningful economic return on
investment.' - Momentum - a memory-hard proof-of-work via finding birthday collisions http://www.hashcash.org/papers/momentum.pdf

"If you look on page 115 of Bernstein's Post Quantum Cryptography, it confirms a sqrt(N) speedup for Wagner's solution to the Generalized Birthday Problem for the hypothetical quantum computer. So if Equihash is using a large list of values to be sorted, then the speedup could be so great that a quantum computer could rewrite the entire block chain quite easily by redoing the past proof-of-work exponentially faster than it was originally done.
It appears that a memory hard algorithm such as Cryptonite would not have this problem."
