Quantum Key Distribution (QKD) Explained vs Post-Quantum Cryptography
How QKD works
In protocols such as BB84 (1984), two parties send photons prepared in random quantum states. Because measuring a quantum state disturbs it, an eavesdropper leaves detectable errors. If the error rate is low, the parties keep a shared secret key.
QKD versus post-quantum cryptography
| QKD | Post-quantum cryptography | |
|---|---|---|
| Basis | Physics of quantum states | Hard math problems |
| Hardware | Dedicated optical equipment | Ordinary computers |
| Range | Limited without relays | Works over the normal internet |
| Standards | Still maturing | NIST standards published in 2024 |
Does it matter for crypto?
Blockchains do not use QKD. Their quantum risk is about signatures, covered in will quantum break Bitcoin and Solana.
A worked example of the BB84 idea
Alice sends Bob 1,000 photons, each encoded in one of two randomly chosen measurement bases. Bob also picks a basis at random for each photon. About half the time they match, so roughly 500 bits survive. They then publicly compare a random sample, say 100 of those bits. If an eavesdropper measured every photon in a random basis, she would guess the wrong basis half the time, and each wrong guess corrupts about half of Bob's results in that case. That produces errors in roughly 25 percent of the compared bits. Honest hardware noise is far smaller, so a high error rate is the alarm. If the sample looks clean, they keep the remaining roughly 400 bits, run error correction and privacy amplification, and end up with a shorter, secret key. If not, they throw the key away and start over.
The protocol was proposed by Charles Bennett and Gilles Brassard in 1984. The key point is that the eavesdropper cannot copy a quantum state without disturbing it, a result explained in the no-cloning theorem.
Real-world limits
- Distance. Key rates fall off exponentially with fiber length. Reported fiber records are a few hundred kilometers at very low speeds, so long links use trusted relay nodes, which you must physically secure. Satellites have linked ground stations thousands of kilometers apart. See Satellite QKD and Quantum Repeaters and Quantum Memory Explained.
- Authentication. QKD makes a key but does not prove who you are talking to. You still need an authentication method, usually classical or pre-shared keys.
- Hardware attacks. Real devices have been attacked through bright-light probing, photon-number splitting and timing tricks. Countermeasures such as decoy states exist, and device-independent designs aim to reduce trust in the hardware.
- Denial of service. Because eavesdropping is detectable, an attacker can also block the link by cutting the fiber or disturbing it.
What governments say
The US National Security Agency has said it does not recommend QKD for protecting national security systems unless its limitations are overcome, and prefers post-quantum cryptography as more cost effective and easier to maintain. Researchers and vendors dispute some of those objections, so the debate is live. For the head-to-head view see QKD vs Post-Quantum Cryptography.
Common mistakes
- Saying QKD is "quantum encryption". It only distributes keys, which are then used with ordinary ciphers.
- Assuming QKD is needed to protect against quantum computers. Post-quantum algorithms such as ML-KEM do that on normal hardware.
- Assuming a "quantum-secure" product is secure. Ask what the hardware, authentication and key management actually do.
QKD remains an active research and infrastructure field with real deployments, and that is good news for the wider quantum ecosystem. This guide is education only and not financial advice, and it says nothing about the price of any token.
Sources and further reading
- Wikipedia: BB84 (Bennett and Brassard, 1984)
- Wikipedia: Quantum key distribution (distance records, trusted nodes, known attacks)
Facts checked 2026-10-09 against the linked pages. Education only, not financial advice. Nothing here predicts the price of any asset, and the QNT memecoin is an independent community token with no link to Quantinuum Ltd or any lab, chain or exchange named on this page.
Frequently asked questions
Is QKD unhackable?
The physics is sound in theory, but real systems have hardware weaknesses and need separate authentication, so it is not magic.
Is QKD the same as post-quantum cryptography?
No. QKD uses quantum physics. Post-quantum cryptography uses classical math designed to resist quantum attacks.
How far can QKD send a key?
Over ordinary fiber the key rate drops quickly with distance, with records of a few hundred kilometers at low speeds. Longer links use trusted relay nodes or satellites.
Does QKD need a classical channel?
Yes. The parties compare measurement bases and a sample of bits over an authenticated classical channel, so QKD cannot work alone.
Why does the NSA prefer post-quantum cryptography?
It lists limits for QKD including special hardware, the need for separate authentication, cost, hardware vulnerabilities and denial-of-service risk, and says post-quantum cryptography is more cost effective and easier to maintain.
Will QKD be used for blockchains?
Not in any current design. Blockchain risk is about signatures, which QKD does not provide, so chains look at post-quantum signature schemes instead.
Can QKD and post-quantum cryptography be combined?
Yes. Some designs use both so that a failure in one does not break the key, a defense-in-depth approach.
Keep reading
- Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care. - Will Quantum Computers Break Bitcoin and Solana?
A calm, factual look at the quantum threat to Bitcoin, Solana and other blockchains, what is safe now, and what could change.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary