Quantum Threat
This article's style of writing may not reflect the encyclopedic tone used on Wikipedia. (June 2026) |
Q-Day (also Q Day and sometimes as Y2Q, or simply the quantum threat) refers to the theoretical date when quantum computers have reached the point where they can break the asymmetric encryption that secures the vast majority of the digital world today.[1] Although the exact date remains uncertain, governments, standards bodies, and major technology companies increasingly argue that the more immediate challenge is not predicting Q-Day but completing post-quantum cryptography (PQC) migration before vulnerable cryptography reaches end-of-life. This concept, similar to the Y2K concept in that it was both a pre-planned future date and the actual date of the Y2K event, differs in that the Q-Day cannot be circled on a calendar currently because no one knows when it will occur. Virtually during every discussion of this topic, people will mention it as an extension of the post-quantum cryptography (PQC).[2][3][4]
The whole awaraness traces back to a single paper published in 1994 by the mathematician Peter Shor who showed, on paper, that a quantum computer could factor enormous numbers and grind through discrete logarithm problems in polynomial time, which happen to be exactly the sums that today's public-key systems are betting nobody can do.[5] The specialists who follow this topic give the estimates for Q-Day to happen in the late 2020s or 2030s.[6]
Background
[edit]Modern secure communications rely on public-key infrastructure (PKI), in which mathematically related key pairs, one public, one private, are used to encrypt and authenticate data. The security of the most widely deployed systems rests on the computational hardness of two problems One is integer factorization, the thing RSA sits on, used all over the web, in email, in digital certificates. The other is the discrete logarithm, which is what elliptic-curve cryptography (ECC) rests on, the workhorse behind TLS/SSL, phones, and most everyday web security.
Until recently the experts assumed that classical computers, even the biggest supercomputers, cannot crack these at any size that matters, not in a human lifetime, not in many of them.[7] Shor's algorithm, on a large enough fault-tolerant quantum computer, would do both in polynomial time and leave those systems wide open.[5]
Symmetric encryption like AES-256 is a more resilient. Grover's algorithm does speed up a brute-force search, but only quadratically, it roughly halves the effective security, so AES-128 would behave like 64-bit, which sounds bad until you realise the fix is just to use longer keys rather than throw out the whole mathematical idea.[8]
"Y2Q" (years to quantum) can be found more in academic and standards fields, especially around Mosca's theorem, a back-of-the-envelope test that asks a blunt question: if you add up how long your migration will take and how long your data must stay secret, and that total runs past the time until a working code-breaker exists, then you are already late and should be moving now.[2] The phrase "quantum apocalypse" shows up in the popular press too, though serious literature tends to leave it alone.
Timeline assessments
[edit]There is no consensus on when it happen.The Global Risk Institute's Quantum Threat Timeline Report 2024 found that most specialists expect a cryptographically relevant quantum computer to emerge sometime in the 2030s or later.[6][2] By its seventh edition, in March 2026, the same report called such a machine "quite possible" within ten years.[9]
Regardless of when a cryptographically relevant quantum computer arrives, organizations face concrete migration timelines. NIST finalized its first PQC standards in 2024, governments including the United States, United Kingdom, Australia, and the European Union have published migration roadmaps, and several major technology companies have announced internal migration targets around 2029.[10] Because enterprise cryptographic transitions often take years, many organizations have shifted their planning from estimating Q-Day to estimating migration duration.[11]
In early 2026, three research papers published within twelve months significantly revised downward the estimated quantum resources required to break standard cryptographic systems. Together, they represented what commentators described as the most substantial shift in quantum threat assessment since Shor's 1994 paper.[12] The major was a Google Quantum AI whitepaper, written together with people from the Ethereum Foundation and Stanford University, arguing that the elliptic-curve cryptography guarding the big blockchains could, in principle, be broken with fewer than 500,000 physical qubits.[13] A separate preprint (arXiv:2603.28627) sketched leaner methods for fault-tolerant quantum computing, suggesting that there might be a need for less physical qubits to build one good logical one than everyone had assumed previously.[12][14] Around the same time Google put a 2029 deadline on finishing its own post-quantum migration.[15]
What is actually at risk
[edit]Blockchains get singled out, and proof-of-work ones like Bitcoin and Ethereum especially.[16] A wallet address comes from a public key, and where that key has been reused or simply left exposed on the ledger, someone with a real code-breaker could in theory work back to the private key and start forging transactions.[17][18] That March 2026 Google paper put actual numbers on this particular attack, which is part of why it got the attention it did.[12]
Another problem is harvest now, decrypt later (HNDL): an adversary, a national intelligence service, say, scoops up encrypted traffic right now and just files it away, perfectly content to wait years until a quantum machine can open it.[1][19] So anything you send today that needs to stay secret for five or ten years and more is, in a real sense, already exposed.[20]
Washington takes the point seriously enough that National Security Memorandum 10 orders every federal agency to finish its post-quantum move by 2035.[2]
Heading it off: post-quantum cryptography
[edit]From 2016, the National Institute of Standards and Technology (NIST) conducted a multi-year public evaluation of candidate post-quantum algorithms, receiving 82 submissions.[21][11][22] In August 2024 the first three standards were finalized: FIPS 203 (ML-KEM, out of CRYSTALS-Kyber), meant as the everyday general-purpose encryption; FIPS 204 (ML-DSA, from CRYSTALS-Dilithium) for signatures; and FIPS 205 (SLH-DSA, from SPHINCS+), kept as a backup signature scheme that leans on entirely different maths, just in case.[11] A fourth, FIPS 206, built on FALCON (FN-DSA), was still being written as 2024 closed.[11][2] In March 2025 NIST added a fifth algorithm, HQC, as a code-based backup.[23] It also set a timeline: RSA and ECC are to be deprecated after 2030 and disallowed by 2035.[24] Earlier, one candidate, SIKE, had been broken classically during the contest.[25]
In February 2024 the Linux Foundation stood up the Post-Quantum Cryptography Alliance (PQCA), an open-source effort to support the new standards, with AWS, Cisco, Google, IBM, NVIDIA, SandboxAQ, the University of Waterloo and QuSecure among the founders.[26] A year earlier, in March 2023, QuSecure said it had run the first live, end-to-end quantum-resilient link sent over a satellite, pushing data through a Starlink bird on its QuProtect platform.[27] The same firm joined NIST's National Cybersecurity Center of Excellence (NCCoE) consortium in March 2026 to help with the unglamorous but necessary part, hunting down where cryptography actually lives inside big organisations and testing the new tools against it.[28]
A Cryptographic Bill of Materials (CBOM) provides an inventory of cryptographic assets and helps organizations prioritize migration. Increasingly, security practitioners recommend that discovery and migration proceed in parallel rather than waiting for exhaustive inventories before beginning pilot deployments.[29][30] Many cybersecurity researchers argue that the current migration to PQC is unlikely to be the last large-scale cryptographic transition. As algorithms, standards, and threats continue to evolve, organizations are increasingly investing in cryptographic management capabilities designed to support future migrations with less operational effort.[31][32]
For many organizations, the practical question is no longer exactly when Q-Day will occur, but whether their cryptographic infrastructure can adapt quickly enough as standards, regulations, and threats continue to evolve.[33]
In the meantime a lot of deployments are hedging, running classical and post-quantum algorithms side by side, so-called hybrid cryptography. Google Chrome and Cloudflare had hybrid post-quantum protection in their TLS by 2024,[15][34] and Google has stuck with the hybrid approach on the theory that the freshly minted algorithms might still hide a flaw nobody has spotted yet. The same shift reached consumer apps: Signal added a post-quantum handshake in 2023, and Apple's iMessage followed with PQ3 in 2024.[35][36] A different route altogether is quantum key distribution (QKD), which uses the physics itself to share a key in a way that is, in principle, impossible to interception.[37][38]
Governments
[edit]In the United States the Quantum Computing Cybersecurity Preparedness Act of 2022 tells federal agencies to move to PQC, National Security Memorandum 10 puts 2035 on the finish line, and the NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) lays out which algorithm families are blessed and by when for defence and national-security systems.[39] The Australian Signals Directorate required organizations to begin planning immediately, and intends to cease approving the main current public-key algorithms (including RSA and elliptic-curve schemes) by the end of 2030.[40][41] Britain's NCSC set migration milestones of 2028, 2031 and 2035.[42] The European Commission and member states agreed a shared roadmap in 2025, targeting critical infrastructure by 2030.[43]
See also
[edit]References
[edit]- 1 2 Fortinet (2025). "What Is Q Day? The Quantum Threat To Cybersecurity". Retrieved 15 April 2026.
- 1 2 3 4 5 Palo Alto Networks (2025). "What Is Q-Day, and How Far Away Is It—Really?". Retrieved 15 April 2026.
- ↑ Gidney, Craig (21 May 2025). "How to factor 2048 bit RSA integers with less than a million noisy qubits". arXiv:2505.15917 [quant-ph].
- ↑ Kovacs, Eduard (31 March 2026). "Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption". SecurityWeek. Retrieved 4 June 2026.
- 1 2 Shor, Peter W. (1994). Algorithms for quantum computation: discrete logarithms and factoring. Proceedings 35th Annual Symposium on Foundations of Computer Science. IEEE. pp. 124–134. doi:10.1109/SFCS.1994.365700.
- 1 2 Global Risk Institute (2024). Quantum Threat Timeline Report 2024 (Report). Retrieved 15 April 2026.
- ↑ Zscaler (2025). "Preparing for 'Q Day': A Primer on the Quantum Threat and the Strategic Shift to Post-Quantum Cryptography". Retrieved 15 April 2026.
- ↑ "Getting Ready for Post-Quantum Cryptography". National Institute of Standards and Technology. 2024. Retrieved 3 June 2026.
- ↑ "Quantum computing threatens to unleash a cybersecurity crisis". CNN. 17 May 2026. Retrieved 4 June 2026.
- ↑ Campbell, Robert (January 2026). "Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks". Computers. 15 (1). doi:10.3390/computer (inactive 12 July 2026). ISSN 2073-431X. Archived from the original on 25 June 2026.
{{cite journal}}: CS1 maint: DOI inactive as of July 2026 (link) - 1 2 3 4 "NIST Releases First 3 Finalized Post-Quantum Encryption Standards". NIST. 13 August 2024.
- 1 2 3 The Quantum Insider (31 March 2026). "Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline". Retrieved 15 April 2026.
- ↑ Acharya, Rajeev; Abanin, Dmitry A.; Aghababaie-Beni, Laleh; Aleiner, Igor; Andersen, Trond I.; Ansmann, Markus; Arute, Frank; Arya, Kunal; Asfaw, Abraham; Astrakhantsev, Nikita; Atalaya, Juan; Babbush, Ryan; Bacon, Dave; Ballard, Brian; Bardin, Joseph C. (February 2025). "Quantum error correction below the surface code threshold". Nature. 638 (8052): 920–926. arXiv:2408.13687. Bibcode:2025Natur.638..920G. doi:10.1038/s41586-024-08449-y. ISSN 1476-4687. PMC 11864966. PMID 39653125.
- ↑ Webster, Paul; Berent, Lucas; Chandra, Omprakash; Hockings, Evan T.; Baspin, Nouédyn; Thomsen, Felix; Smith, Samuel C.; Cohen, Lawrence Z. (12 February 2026). "The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100,000 physical qubits using quantum LDPC codes". arXiv:2602.11457 [quant-ph].
- 1 2 Costello, Craig (12 April 2026). "Quantum computers are coming to break our codes faster than anyone expected". The Conversation. Retrieved 15 April 2026.
- ↑ Swayne, Matt (13 May 2025). "BlackRock Updates Bitcoin ETF With Broadened Warning About Quantum Computing". The Quantum Insider. Retrieved 4 June 2026.
- ↑ Canny, Will (18 May 2026). "Bitcoin More Exposed to Quantum Risks Than Ethereum, Citi Says". CoinDesk. Retrieved 4 June 2026.
- ↑ Malwa, Shaurya (24 April 2026). "Researcher Wins 1 Bitcoin Bounty for Largest Quantum Attack on Underlying Tech". CoinDesk. Retrieved 4 June 2026.
- ↑ "Quantum-Readiness: Migration to Post-Quantum Cryptography". CISA, NSA and NIST. 21 August 2023. Retrieved 4 June 2026.
- ↑ Lee, Newton (1 August 2024). Counterterrorism and Cybersecurity: Total Information Awareness. Springer Nature. ISBN 978-3-031-63126-9.
- ↑ Federal Register (14 August 2024). "Announcing Issuance of Federal Information Processing Standards (FIPS) 203, 204, and 205". Federal Register. Retrieved 15 April 2026.
- ↑ "NIST's Post-Quantum Cryptography Standards Are Here". spectrum.ieee.org. Retrieved 4 June 2026.
- ↑ "NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption". NIST. 11 March 2025. Retrieved 4 June 2026.
- ↑ "Transition to Post-Quantum Cryptography Standards (NIST IR 8547, initial public draft)". NIST. 12 November 2024. Retrieved 4 June 2026.
- ↑ Cepelewicz, Jordana (24 August 2022). "'Post-Quantum' Cryptography Scheme Is Cracked on a Laptop". Quanta Magazine. Retrieved 4 June 2026.
- ↑ Joshi, Naveen (6 January 2026). "Notable post-quantum cryptography initiatives paving the way toward Q-Day". CSO Online. Retrieved 15 April 2026.
- ↑ QuSecure (9 March 2023). "QuSecure Pioneers First-Ever U.S. Live End-to-End Satellite Quantum-Resilient Cryptographic Communications Link Through Space". Retrieved 3 June 2026.
- ↑ QuSecure (31 March 2026). "QuSecure Joins NIST on Post-Quantum Cryptography Migration". Retrieved 3 June 2026.
- ↑ "Foundational Infrastructure for Crypto-Agility (NIST CSWP 39)". National Institute of Standards and Technology. April 2024. Retrieved 3 June 2026.
- ↑ U.S. Department of Homeland Security (2023). "Post-Quantum Cryptography Roadmap". CISA. Retrieved 3 June 2026.
- ↑ Hasan, Fida; Simpson, Leonie; Rezazadeh Baee, Mir Ali; Islam, Chadni; Rahman, Ziaur; Armstrong, Warren; Gauravaram, Praveen; Mckague, Matthew (1 January 2024). "A Framework for Migrating to Post-Quantum Cryptography: Security Dependency Analysis and Case Studies". IEEE Access. PP: 23427–23450. arXiv:2307.06520. Bibcode:2024IEEEA..1223427H. doi:10.1109/ACCESS.2024.3360412.
- ↑ Joshi, Himani (19 April 2026). "PQC Migration: The Hard Realities Nobody Warns You About". Retrieved 8 July 2026.
- ↑ "Beyond Q-Day: A Practical Guide to Post-Quantum Cryptography, Crypto-Agility & Quantum Readiness". www.btrade.com. Retrieved 8 July 2026.
- ↑ Westerbaan, Bas (28 October 2025). "State of the post-quantum Internet in 2025". The Cloudflare Blog. Retrieved 4 June 2026.
- ↑ Lakshmanan, Ravie (20 September 2023). "Signal Messenger Introduces PQXDH Quantum-Resistant Encryption". The Hacker News. Retrieved 4 June 2026.
- ↑ Toulas, Bill (24 February 2024). "Apple adds PQ3 quantum-resistant encryption to iMessage". BleepingComputer. Retrieved 4 June 2026.
- ↑ European Telecommunications Standards Institute (2023). "Quantum Safe Cryptography". ETSI. Retrieved 3 June 2026.
- ↑ Gibney, Elizabeth (19 March 2025). "Mini-satellite paves the way for quantum messaging anywhere on Earth". Nature. doi:10.1038/d41586-025-00581-7. Retrieved 4 June 2026.
- ↑ National Security Agency (2022). "Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ" (PDF). NSA. Retrieved 15 April 2026.
- ↑ Costello, Craig (12 April 2026). "Quantum computers are coming to break our codes faster than anyone expected". The Conversation. Retrieved 15 April 2026.
- ↑ Australian Signals Directorate. "Planning for post-quantum cryptography". Australian Cyber Security Centre. Retrieved 3 June 2026.
- ↑ "Timelines for migration to post-quantum cryptography". National Cyber Security Centre. 20 March 2025. Retrieved 4 June 2026.
- ↑ "EU reinforces its cybersecurity with post-quantum cryptography". European Commission. 23 June 2025. Retrieved 4 June 2026.