Quantum and Crypto Security: 20 Questions Answered
Calm, informed and a little optimistic
Few quantum topics attract as many scary headlines as security. The honest summary is more reassuring. Two kinds of cryptography are involved. Public-key cryptography, used for key exchange and digital signatures, is vulnerable in theory to a large quantum computer running Shor's algorithm. Symmetric cryptography and hashing are affected much less, since Grover's algorithm only gives a square-root speedup. No machine capable of the dangerous attack exists today, and the best public estimates say it would need a large error-corrected system.
Meanwhile, the defence is well underway. In August 2024, NIST published its first finished post-quantum standards, including ML-KEM for key exchange and ML-DSA and SLH-DSA for signatures. Browsers, messaging apps and cloud providers have started deploying quantum-safe key exchange, and blockchain communities are debating how to upgrade signatures.
The 20 answers below cover the threat, the timing, Bitcoin and other chains, the new standards and practical steps for individuals and companies. For deeper reading see will quantum break Bitcoin and Solana, harvest now, decrypt later and how NIST chose the standards.
This is education, not financial advice. Nothing here predicts the price of any asset, and the QNT memecoin is independent of Quantinuum Ltd and of every standard or project named here.
Sources and further reading
- NIST: Post-Quantum Cryptography project
- NIST: FIPS 203 (ML-KEM)
- NIST: FIPS 204 (ML-DSA)
- Gidney (2025): How to factor 2048 bit RSA integers with less than a million noisy qubits
- Shor (1995): Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer
Reported as of 2026-10-09. Fields move fast, so check primary sources. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
How could a quantum computer break encryption?
Shor's algorithm lets a quantum computer find the hidden structure behind RSA and elliptic curve keys, turning problems that are infeasible for classical machines into feasible ones. It needs a large, error-corrected machine.
Is encryption broken today?
No. No quantum computer today can break RSA or elliptic curve cryptography at real key sizes. Public demonstrations have factored only tiny numbers. The concern is about future machines, which is why preparation starts early.
What is Q-Day?
Q-Day is the informal name for the day a quantum computer can break widely used public-key cryptography. Nobody knows when or whether it will arrive, and expert opinions vary. See Q-Day explained.
How many qubits would it take to break RSA-2048?
A 2025 paper by Craig Gidney of Google estimated that RSA-2048 could be factored with fewer than a million noisy qubits in under a week, a big drop from earlier estimates. Today's machines are far smaller. See the estimate history.
What is harvest now, decrypt later?
It is the idea that someone could record encrypted data today and decrypt it years later when quantum computers exist. It matters most for secrets that must stay private for decades, which is why key exchange is being upgraded first. See the explainer.
Does quantum break symmetric encryption like AES?
Not in the same way. Grover's algorithm gives only a square-root speedup, so doubling key length restores the margin. AES-256 is widely regarded as comfortable against quantum attacks. See Grover's algorithm.
What about hash functions?
Hash functions are affected only modestly. Grover-style attacks reduce their effective security level by about half in bits, which is manageable with standard output sizes. See hash functions and quantum.
What are the NIST post-quantum standards?
In August 2024, NIST finalised FIPS 203 (ML-KEM for key exchange), FIPS 204 (ML-DSA for signatures) and FIPS 205 (SLH-DSA, a hash-based signature). Further standards, such as FN-DSA (based on Falcon) and HQC, were still being drafted or finalised when we last checked, so check NIST for current status. See standards status.
What is ML-KEM?
ML-KEM, formerly called Kyber, is a lattice-based method for two parties to agree on a shared secret key safely, even against quantum computers. It is already used in some browser and server connections. See ML-KEM explained.
What is a hybrid key exchange?
A hybrid combines a classical method and a post-quantum one, so a connection stays safe unless both are broken. It is a cautious way to roll out new cryptography. See hybrid key exchange.
Is quantum key distribution the same as post-quantum cryptography?
No. Post-quantum cryptography is ordinary software built on maths believed to resist quantum attacks. Quantum key distribution uses quantum physics and special hardware. Most agencies favour the software route for general use. See QKD vs PQC.
Will quantum computers break Bitcoin?
In theory, a large quantum computer could forge the elliptic curve signatures Bitcoin uses, mainly for coins whose public keys are exposed. No such computer exists, and developers are discussing upgrades. See BIP-360 and BIP-361.
Which coins are most exposed?
Generally those where the public key is already visible on the chain, for example from reused addresses or certain old output types. Addresses that have never revealed their key are better protected for now. See exposed public keys.
What about Solana and Ethereum?
Both use signature schemes that a large quantum computer could attack in theory, and both communities have published research and roadmaps for quantum-resistant upgrades. See Ethereum and Solana plans.
Why do post-quantum signatures cause trouble for blockchains?
They are many times larger than today's signatures, so blocks fit fewer transactions unless designs compress or aggregate them. It is a cost problem that engineers are actively working on. See signature sizes and block space.
Does my seed phrase become unsafe?
A seed phrase is a secret number, and quantum computers do not make it guessable. The risk is to the signatures made with the keys derived from it. Keep your phrase private and offline as usual. See seed phrases.
Should I move my crypto because of quantum risk?
There is no need to panic. Follow your wallet and chain upgrade guidance, avoid address reuse, and keep software current. This is not financial advice, and we do not predict what any asset will do. See what individuals can do.
What should companies do?
Make a list of where public-key cryptography is used, prioritise long-lived secrets, and build the ability to swap algorithms, called crypto agility. Then test and roll out standardised post-quantum options. See the migration checklist.
Are governments setting deadlines?
Yes. The United States, the United Kingdom, the European Union and others have published migration timelines that run through the 2030s. See government deadlines.
Is a coin that calls itself quantum-proof safe?
Be skeptical. The label is easy to use and hard to verify, and many such pitches are marketing or outright scams. Look for audited code and clear technical documentation. See quantum-proof coin scams. This is not financial advice.
Keep reading
- Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care. - The NIST Post-Quantum Process Explained
How NIST ran its multi-year post-quantum cryptography competition, from public call to the first standards in 2024, and what work is still continuing. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary