YFarmX logoYFarmX
Security Desk · live board

Quantum Threat Tracker

2029 is the soonest credible milestone on the road to Q-Day

The day a quantum computer can break today's encryption is called Q-Day. No machine can do it yet, and no one can name the year one will. This board tracks the honest state of it: the expert estimate, the standards, who has actually migrated to quantum-safe cryptography, which blockchains are ready, and the hardware milestones.

The road to Q-Day

Soonest milestone

2029Estimated

to the first large fault-tolerant quantum computer, which Google, IBM and Microsoft target for 2029. That is a hardware milestone, not Q-Day: it would still be far from breaking RSA-2048.

No major lab forecasts a year for breaking RSA. The soonest dated targets, from Google, IBM and Microsoft, are for a large fault-tolerant machine around 2029, which would still be far short of breaking RSA-2048. The only real code-breaking estimate, an expert survey, puts the odds in single digits before the mid-2030s. Q-Day is a forecast, not a fact.

Who forecasts what

  1. 2029GoogleHardware milestoneRoadmap target for a useful, error-corrected machine scaling toward a million qubits. It is not a claim to break RSA.Google Quantum AI roadmap ↗our page →
  2. 2029IBMHardware milestoneStarling: a fault-tolerant machine of about 200 logical qubits, far short of what breaking RSA-2048 would need.IBM Quantum ↗our page →
  3. 2029MicrosoftHardware milestoneAfter its Majorana 1 chip, Microsoft says useful, fault-tolerant quantum computing is years, not decades, away.Microsoft Azure Quantum ↗our page →
  4. 2030NISTPolicy deadlinePlans to deprecate RSA-2048 and P-256 after 2030 and disallow them after 2035. A precautionary deadline, not a forecast.NIST IR 8547 (draft) ↗our page →
  5. 2030QuantinuumHardware milestoneTargets universal, fully fault-tolerant computing with its Apollo system; some milestones have since moved toward 2029.Quantinuum ↗our page →
  6. 2030EUHardware milestoneThe Quantum Europe Strategy aims for Europe's first full-stack fault-tolerant machine, around 100 logical qubits.European Commission ↗our page →
  7. 2035NSAPolicy deadlineCNSA 2.0 requires national-security systems to be fully quantum-resistant by 2035, phasing in from 2027. A policy hedge.NSA CNSA 2.0 ↗
  8. 2035Mosca / GRIExpert surveyA 32-expert survey put the odds of a code-breaker within 5 years at 5 to 14%, rising toward even by the mid-2030s. The only real threat estimate.Global Risk Institute ↗our page →
Chains quantum-safeTracked here0 of 17 trackedNone of the top 100 yet
Web traffic securedCloudflareOver 65%Human traffic, April 2026Cloudflare ↗
Biggest machine todayPhysical qubits4,400+ qubitsD-Wave annealer, May 2025An annealer cannot run Shor's algorithm. The largest gate-model processors are smaller: IBM's Condor at 1,121 superconducting qubits, demonstrated in December 2023, and Atom Computing's 1,180-qubit neutral-atom array. Around 100 describes only the highest-fidelity trapped-ion machines, such as Quantinuum's Helios at 98. Breaking RSA-2048 is estimated to need of the order of a million.D-Wave ↗
Logical qubitsError-correctedUp to 96QuEra and Harvard, 2025Definitions differ, so these counts are not a single league table. The 96 comes from a Harvard-led Nature paper, reported by QuEra in December 2025, running algorithms below threshold on a neutral-atom system. IBM executed 70 logical qubits on 30 July 2026. Quantinuum's Helios holds 48 fully error-corrected logical qubits at a 2:1 encoding rate, announced 5 November 2025, which remains the record for that encoding density.QuEra ↗
Migration backstopPolicy2035US, UK and EU outer dateThe binding American date is earlier and separate: Executive Order 14412 requires federal sensitive systems to move to post-quantum encryption by 31 December 2030.

Who has migrated to quantum-safe cryptography

  • Cloudflare 1.1.1.1Deployed
    Post-quantum DNSSEC validation

    Cloudflare's 1.1.1.1 resolver now validates DNSSEC signatures made with ML-DSA-44, which IANA has assigned DNSSEC algorithm number 18; the signatures run 2,420 bytes against 64 for ECDSA P-256. Announced 10 September 2026 as an early step toward full post-quantum DNS security by 2029.

    Cloudflare ↗
  • Apple iMessageDeployed
    PQ3 protocol

    Apple's PQ3, a hybrid of ML-KEM and elliptic curve with ongoing post-quantum re-keying, began rolling out in iOS 17.4 and reached full deployment across supported devices through 2024.

    Apple Security Research ↗
  • SignalDeployed
    PQXDH key agreement

    Signal shipped PQXDH (X25519 plus Kyber-1024) for the initial handshake in 2023 and has since extended post-quantum protection into the ongoing message ratchet.

    Signal specifications ↗
  • Google ChromeDeployed
    Hybrid X25519MLKEM768 in TLS

    Chrome enabled hybrid post-quantum key exchange by default in Chrome 124 (April 2024) and switched to standardised ML-KEM in Chrome 131 (November 2024).

    Google Online Security Blog ↗
  • Mozilla FirefoxDeployed
    Hybrid X25519MLKEM768 in TLS

    Firefox added the X25519MLKEM768 hybrid group in late 2024 and enabled it by default in early 2025.

    Encryption Consulting ↗
  • CloudflareDeployed
    Hybrid ML-KEM across its network

    By 22 August 2026, 71.1% of human HTTPS traffic on Cloudflare's network used post-quantum key agreement (Cloudflare Radar, checked that day), up from over 65% in April 2026. On 8 September 2026 its Automatic Key Exchange began preferring the post-quantum hybrid X25519MLKEM768 for edge-to-origin TLS where the origin supports it: 33% of scanned domains now prefer the hybrid, and Cloudflare counts about 45 billion post-quantum connections a day across its network.

    Cloudflare ↗
  • OpenSSHDeployed
    ML-KEM-768 + X25519 hybrid, default

    OpenSSH added the ML-KEM-768 plus X25519 hybrid in 9.9 and made it the default key exchange in OpenSSH 10.0 (April 2025), later warning on connections that are not quantum-safe.

    OpenSSH project ↗
  • Google (internal)Deployed
    Post-quantum ALTS

    Google has protected internal service-to-service traffic with a hybrid post-quantum ALTS since 2022 and has set 2029 as its broader migration target.

    Google Cloud ↗
  • Meta (internal)Deployed
    Hybrid post-quantum TLS

    Meta reported deploying hybrid ML-KEM TLS across most of its internal service-to-service traffic as part of a multi-year migration.

    Engineering at Meta ↗
  • ZoomDeployed
    Post-quantum end-to-end encryption

    In May 2024 Zoom added post-quantum end-to-end encryption to Zoom Meetings, for calls where every participant runs a recent enough client. It uses Kyber 768, the pre-standardisation name for what NIST went on to publish as ML-KEM-768 in FIPS 203.

    Zoom ↗
  • Amazon Web ServicesRolling out
    Hybrid ML-KEM TLS on by default

    AWS turned ML-KEM hybrid TLS on by default across KMS, Secrets Manager, ACM, Payment Cryptography and S3 in April 2026.

    AWS Security ↗
  • Microsoft (Windows)Rolling out
    ML-KEM and ML-DSA in SymCrypt / CNG

    Microsoft brought ML-KEM and ML-DSA to Windows 11 and Windows Server 2025 through SymCrypt and CNG in 2025, extending to hybrid ML-KEM TLS key exchange in 2026.

    Microsoft Security Blog ↗
  • US GovernmentMandated by deadline
    Federal PQC migration mandate

    NSM-10 and OMB M-23-02 require agencies to inventory cryptography and migrate to NIST PQC, with a government-wide goal of mitigating quantum risk by 2035.

    White House OMB ↗
  • UK GovernmentMandated by deadline
    National PQC migration roadmap

    NCSC guidance directs organisations, especially critical national infrastructure, to complete discovery by 2028, high-priority migration by 2031 and full migration by 2035.

    UK NCSC ↗
  • European UnionMandated by deadline
    Coordinated PQC roadmap

    The EU roadmap requires Member States to migrate high-risk use cases to PQC by 2030 and medium-risk systems by 2035.

    European Commission ↗

Is your crypto quantum-safe?

0 quantum-safe · 7 in progress · 10 exposed. No top-100 coin is quantum-safe by default today. Every major chain still signs with quantum-vulnerable ECDSA or Ed25519, and the strongest efforts (Bitcoin BIP-360, Ethereum and Cardano roadmaps, Solana and NEAR opt-ins, Algorand Falcon state proofs) are opt-in, testnet or roadmap only. The only chains quantum-safe by default are small, purpose-built projects such as QRL, outside the top 100.

  1. Bitcoin BTCStatus: In progressSignature scheme: ECDSA / Schnorr (secp256k1)

    Every spend relies on quantum-vulnerable ECDSA or Schnorr over secp256k1, and address reuse leaves many coins with exposed public keys. BIP-360, which adds post-quantum outputs, was merged as a proposal in early 2026 and has a testnet, but no protocol change is live on mainnet. On 26 August 2026 StarkWare mined a first quantum-safe transaction on mainnet in block 964,199, a hash-based lock needing no soft fork, though the format is non-standard, needs a direct path to a miner and protects only coins moved into its special output. source ↗Bitcoin →

  2. Ethereum ETHStatus: In progressSignature scheme: ECDSA secp256k1 (accounts)

    Externally owned accounts still sign with quantum-vulnerable ECDSA. A concrete core-dev roadmap (Vitalik Buterin's 2026 plan, an Ethereum Foundation post-quantum hub, and account abstraction to let accounts opt into PQC) is under way, but nothing is deployed on mainnet. source ↗Ethereum →

  3. Solana SOLStatus: In progressSignature scheme: Ed25519 + opt-in Winternitz vault

    Standard accounts use quantum-vulnerable Ed25519. An opt-in, hash-based Winternitz Vault (2025) lets users store funds under quantum-resistant one-time signatures, but it is experimental and used by very few accounts. source ↗Solana →

  4. Cardano ADAStatus: In progressSignature scheme: Ed25519

    Cardano signs with quantum-vulnerable Ed25519. Post-quantum security is a named pillar of the funded Vision 2026 programme, but nothing is deployed on mainnet. source ↗Cardano →

  5. Stellar XLMStatus: In progressSignature scheme: Ed25519

    Stellar accounts use quantum-vulnerable Ed25519. The Stellar Development Foundation has published a dated Quantum Preparedness Plan (Soroban verification in 2026, quantum-safe signers in 2027), but nothing is live yet. source ↗Stellar →

  6. NEAR Protocol NEARStatus: In progressSignature scheme: ML-DSA-65 opt-in; Ed25519 default

    NEAR's July 2026 mainnet upgrade added the NIST-standardised ML-DSA-65 signature, which users can enable with a single transaction. It is a live, in-production opt-in; most accounts still use Ed25519. source ↗NEAR Protocol →

  7. Algorand ALGOStatus: In progressSignature scheme: Falcon state proofs; Ed25519 default

    Algorand's State Proofs have used the lattice-based Falcon scheme on mainnet since 2022, and opt-in Falcon account keys are available. Ordinary accounts and consensus still rely on quantum-vulnerable Ed25519. source ↗

  8. BNB BNBStatus: ExposedSignature scheme: ECDSA secp256k1 (EVM)

    BNB Smart Chain is EVM-compatible and signs with quantum-vulnerable ECDSA secp256k1. No post-quantum option is deployed or announced. source ↗BNB →

  9. XRP XRPStatus: ExposedSignature scheme: ECDSA secp256k1 / Ed25519

    XRP Ledger accounts use secp256k1 by default, with Ed25519 as an option, both quantum-vulnerable. Post-quantum support exists only as XLS standards discussion, not deployed. source ↗XRP →

  10. TRON TRXStatus: ExposedSignature scheme: ECDSA secp256k1

    TRON signs transactions with quantum-vulnerable ECDSA over secp256k1. No post-quantum option is deployed. source ↗TRON →

  11. Hyperliquid HYPEStatus: ExposedSignature scheme: ECDSA secp256k1 (EIP-712)

    Hyperliquid uses Ethereum-style signatures verified through ecrecover, that is ECDSA secp256k1, which is quantum-vulnerable. No post-quantum option was found. source ↗Hyperliquid →

  12. Dogecoin DOGEStatus: ExposedSignature scheme: ECDSA secp256k1

    As a Bitcoin derivative, Dogecoin signs with quantum-vulnerable ECDSA secp256k1. No post-quantum roadmap or option was found. source ↗Dogecoin →

  13. Zcash ZECStatus: ExposedSignature scheme: ECDSA secp256k1; Jubjub (shielded)

    Transparent addresses use ECDSA secp256k1 and shielded spends use Jubjub-based signatures, both quantum-vulnerable. Zcash's own documentation states the protocol is not post-quantum secure today. source ↗Zcash →

  14. Monero XMRStatus: ExposedSignature scheme: Ed25519 (ring signatures)

    Monero's ring signatures and stealth addresses are built on quantum-vulnerable Ed25519, which would threaten both spend authority and historic privacy. No post-quantum option is deployed. source ↗Monero →

  15. Chainlink LINKStatus: ExposedSignature scheme: ECDSA secp256k1 (ERC-20)

    LINK is an ERC-20 token on Ethereum and its oracle reporting uses quantum-vulnerable ECDSA secp256k1. No post-quantum option is deployed. source ↗Chainlink →

  16. Bitcoin Cash BCHStatus: ExposedSignature scheme: ECDSA secp256k1

    As a Bitcoin fork, Bitcoin Cash signs with quantum-vulnerable ECDSA over secp256k1. No post-quantum roadmap or option was found. source ↗Bitcoin Cash →

  17. Toncoin TONStatus: ExposedSignature scheme: Ed25519

    TON wallets sign with quantum-vulnerable Ed25519. No post-quantum option is deployed. source ↗

"In progress" means a live opt-in, testnet or funded roadmap, not a default. Not financial advice.

Milestone log

Standards, policy deadlines and hardware records on the road to Q-Day, newest first. Each milestone opens its own record page, with the detail and the source.

  1. StandardNIST will adopt the strengthened HQC parameters in the FIPS 207 draftNIST pqc-forum ↗
  2. HardwareIonQ publishes a compiled blueprint for breaking 256-bit elliptic curve signaturesIonQ ↗
  3. StandardIESG approves standalone ML-KEM key agreement for TLS 1.3IETF Datatracker ↗
  4. HardwareIBM Nighthawk r2 raises circuit throughput about 25 timesIBM Quantum ↗
  5. StandardRFC 10042 standardises hybrid ML-KEM key exchange for SSHRFC Editor ↗
  6. HardwareRigetti reports wafer-scale frequency targeting on a 36-qubit processorarXiv:2608.27789 ↗
  7. HardwareIBM completes its acquisition of HRL LaboratoriesIBM Newsroom ↗
  8. MilestoneFirst quantum-safe Bitcoin transaction mined on mainnetStarkWare ↗
  9. PolicyUS Treasury launches a Quantum-Readiness Task ForceUS Treasury ↗
  10. StandardHAWK withdrawn from NIST's additional-signature processNIST pqc-forum ↗
  11. HardwareReality check: hardware is still far from breaking RSAQuEra ↗our page →
  12. HardwareQuantinuum Helios reaches 48 logical qubitsQuantinuum ↗our page →
  13. HardwareIonQ crosses 99.99% two-qubit gate fidelityIonQ ↗our page →
  14. StandardNIST advances FN-DSA (FALCON) toward draft FIPS 206DigiCert (on NIST) ↗
  15. PolicyEU publishes a coordinated PQC roadmapEuropean Commission ↗
  16. HardwareIBM sets a path to a fault-tolerant machine by 2029IBM Quantum ↗our page →
  17. PolicyUK NCSC publishes its PQC migration timelineUK NCSC ↗
  18. StandardNIST selects HQC as a backup KEMNIST ↗
  19. HardwareMicrosoft unveils Majorana 1, a topological processorMicrosoft Azure Quantum ↗our page →
  20. HardwareGoogle Willow shows below-threshold error correctionGoogle Quantum AI ↗our page →
  21. StandardNIST finalises FIPS 203, 204 and 205NIST CSRC ↗
  22. PolicyNSA publishes the CNSA 2.0 timelineNSA CNSA 2.0 ↗

Download the milestone data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.

Q-Day figures are expert estimates and probabilities, not established facts, and they shift with each result. Sensational "encryption is broken" claims are logged only with their status.Last update · 18 Sept 2026