Quantum Threat Tracker
2029 is the soonest credible milestone on the road to Q-Day
The day a quantum computer can break today's encryption is called Q-Day. No machine can do it yet, and no one can name the year one will. This board tracks the honest state of it: the expert estimate, the standards, who has actually migrated to quantum-safe cryptography, which blockchains are ready, and the hardware milestones.
The road to Q-Day
Countdown to the soonest milestone
to the first large fault-tolerant quantum computer, which Google, IBM and Microsoft target for 2029. That is a hardware milestone, not Q-Day: it would still be far from breaking RSA-2048.
No major lab forecasts a year for breaking RSA. The soonest dated targets, from Google, IBM and Microsoft, are for a large fault-tolerant machine around 2029, which would still be far short of breaking RSA-2048. The only real code-breaking estimate, an expert survey, puts the odds in single digits before the mid-2030s. Q-Day is a forecast, not a fact.
Who forecasts what
- 2029GoogleHardware milestoneRoadmap target for a useful, error-corrected machine scaling toward a million qubits. It is not a claim to break RSA.Google Quantum AI roadmap ↗our page →
- 2029IBMHardware milestoneStarling: a fault-tolerant machine of about 200 logical qubits, far short of what breaking RSA-2048 would need.IBM Quantum ↗our page →
- 2029MicrosoftHardware milestoneAfter its Majorana 1 chip, Microsoft says useful, fault-tolerant quantum computing is years, not decades, away.Microsoft Azure Quantum ↗our page →
- 2030NISTPolicy deadlinePlans to deprecate RSA-2048 and P-256 after 2030 and disallow them after 2035. A precautionary deadline, not a forecast.NIST IR 8547 (draft) ↗our page →
- 2030QuantinuumHardware milestoneTargets universal, fully fault-tolerant computing with its Apollo system; some milestones have since moved toward 2029.Quantinuum ↗our page →
- 2030EUHardware milestoneThe Quantum Europe Strategy aims for Europe's first full-stack fault-tolerant machine, around 100 logical qubits.European Commission ↗our page →
- 2035NSAPolicy deadlineCNSA 2.0 requires national-security systems to be fully quantum-resistant by 2035, phasing in from 2027. A policy hedge.NSA CNSA 2.0 ↗
- 2035Mosca / GRIExpert surveyA 32-expert survey put the odds of a code-breaker within 5 years at 5 to 14%, rising toward even by the mid-2030s. The only real threat estimate.Global Risk Institute ↗our page →
Who has migrated to quantum-safe cryptography
- Apple iMessageDeployedPQ3 protocol
Apple's PQ3, a hybrid of ML-KEM and elliptic curve with ongoing post-quantum re-keying, began rolling out in iOS 17.4 and reached full deployment across supported devices through 2024.
Apple Security Research ↗ - SignalDeployedPQXDH key agreement
Signal shipped PQXDH (X25519 plus Kyber-1024) for the initial handshake in 2023 and has since extended post-quantum protection into the ongoing message ratchet.
Signal specifications ↗ - Google ChromeDeployedHybrid X25519MLKEM768 in TLS
Chrome enabled hybrid post-quantum key exchange by default in Chrome 124 (April 2024) and switched to standardised ML-KEM in Chrome 131 (November 2024).
Google Online Security Blog ↗ - Mozilla FirefoxDeployedHybrid X25519MLKEM768 in TLS
Firefox added the X25519MLKEM768 hybrid group in late 2024 and enabled it by default in early 2025.
Encryption Consulting ↗ - CloudflareDeployedHybrid ML-KEM across its network
By 22 August 2026, 71.1% of human HTTPS traffic on Cloudflare's network used post-quantum key agreement (Cloudflare Radar, checked that day), up from over 65% in April 2026; post-quantum authentication to origin servers followed on the roadmap from mid-2026.
Cloudflare ↗ - OpenSSHDeployedML-KEM-768 + X25519 hybrid, default
OpenSSH added the ML-KEM-768 plus X25519 hybrid in 9.9 and made it the default key exchange in OpenSSH 10.0 (April 2025), later warning on connections that are not quantum-safe.
OpenSSH project ↗ - Google (internal)DeployedPost-quantum ALTS
Google has protected internal service-to-service traffic with a hybrid post-quantum ALTS since 2022 and has set 2029 as its broader migration target.
Google Cloud ↗ - Meta (internal)DeployedHybrid post-quantum TLS
Meta reported deploying hybrid ML-KEM TLS across most of its internal service-to-service traffic as part of a multi-year migration.
Engineering at Meta ↗ - ZoomDeployedPost-quantum end-to-end encryption
In May 2024 Zoom added post-quantum end-to-end encryption to Zoom Meetings, for calls where every participant runs a recent enough client. It uses Kyber 768, the pre-standardisation name for what NIST went on to publish as ML-KEM-768 in FIPS 203.
Zoom ↗ - Amazon Web ServicesRolling outHybrid ML-KEM TLS on by default
AWS turned ML-KEM hybrid TLS on by default across KMS, Secrets Manager, ACM, Payment Cryptography and S3 in April 2026.
AWS Security ↗ - Microsoft (Windows)Rolling outML-KEM and ML-DSA in SymCrypt / CNG
Microsoft brought ML-KEM and ML-DSA to Windows 11 and Windows Server 2025 through SymCrypt and CNG in 2025, extending to hybrid ML-KEM TLS key exchange in 2026.
Microsoft Security Blog ↗ - US GovernmentMandated by deadlineFederal PQC migration mandate
NSM-10 and OMB M-23-02 require agencies to inventory cryptography and migrate to NIST PQC, with a government-wide goal of mitigating quantum risk by 2035.
White House OMB ↗ - UK GovernmentMandated by deadlineNational PQC migration roadmap
NCSC guidance directs organisations, especially critical national infrastructure, to complete discovery by 2028, high-priority migration by 2031 and full migration by 2035.
UK NCSC ↗ - European UnionMandated by deadlineCoordinated PQC roadmap
The EU roadmap requires Member States to migrate high-risk use cases to PQC by 2030 and medium-risk systems by 2035.
European Commission ↗
Is your crypto quantum-safe?
0 quantum-safe · 7 in progress · 10 exposed. No top-100 coin is quantum-safe by default today. Every major chain still signs with quantum-vulnerable ECDSA or Ed25519, and the strongest efforts (Bitcoin BIP-360, Ethereum and Cardano roadmaps, Solana and NEAR opt-ins, Algorand Falcon state proofs) are opt-in, testnet or roadmap only. The only chains quantum-safe by default are small, purpose-built projects such as QRL, outside the top 100.
Bitcoin BTCEvery spend relies on quantum-vulnerable ECDSA or Schnorr over secp256k1, and address reuse leaves many coins with exposed public keys. BIP-360, which adds post-quantum outputs, was merged as a proposal in early 2026 and has a testnet, but no protocol change is live on mainnet. On 26 August 2026 StarkWare mined a first quantum-safe transaction on mainnet in block 964,199, a hash-based lock needing no soft fork, though the format is non-standard, needs a direct path to a miner and protects only coins moved into its special output. source ↗In progressECDSA / Schnorr (secp256k1)
Ethereum ETHExternally owned accounts still sign with quantum-vulnerable ECDSA. A concrete core-dev roadmap (Vitalik Buterin's 2026 plan, an Ethereum Foundation post-quantum hub, and account abstraction to let accounts opt into PQC) is under way, but nothing is deployed on mainnet. source ↗In progressECDSA secp256k1 (accounts)
Solana SOLStandard accounts use quantum-vulnerable Ed25519. An opt-in, hash-based Winternitz Vault (2025) lets users store funds under quantum-resistant one-time signatures, but it is experimental and used by very few accounts. source ↗In progressEd25519 + opt-in Winternitz vault
Cardano ADACardano signs with quantum-vulnerable Ed25519. Post-quantum security is a named pillar of the funded Vision 2026 programme, but nothing is deployed on mainnet. source ↗In progressEd25519
Stellar XLMStellar accounts use quantum-vulnerable Ed25519. The Stellar Development Foundation has published a dated Quantum Preparedness Plan (Soroban verification in 2026, quantum-safe signers in 2027), but nothing is live yet. source ↗In progressEd25519
NEAR Protocol NEARNEAR's July 2026 mainnet upgrade added the NIST-standardised ML-DSA-65 signature, which users can enable with a single transaction. It is a live, in-production opt-in; most accounts still use Ed25519. source ↗In progressML-DSA-65 opt-in; Ed25519 default
Algorand ALGOAlgorand's State Proofs have used the lattice-based Falcon scheme on mainnet since 2022, and opt-in Falcon account keys are available. Ordinary accounts and consensus still rely on quantum-vulnerable Ed25519. source ↗In progressFalcon state proofs; Ed25519 default
BNB BNBBNB Smart Chain is EVM-compatible and signs with quantum-vulnerable ECDSA secp256k1. No post-quantum option is deployed or announced. source ↗ExposedECDSA secp256k1 (EVM)
XRP XRPXRP Ledger accounts use secp256k1 by default, with Ed25519 as an option, both quantum-vulnerable. Post-quantum support exists only as XLS standards discussion, not deployed. source ↗ExposedECDSA secp256k1 / Ed25519
TRON TRXTRON signs transactions with quantum-vulnerable ECDSA over secp256k1. No post-quantum option is deployed. source ↗ExposedECDSA secp256k1
Hyperliquid HYPEHyperliquid uses Ethereum-style signatures verified through ecrecover, that is ECDSA secp256k1, which is quantum-vulnerable. No post-quantum option was found. source ↗ExposedECDSA secp256k1 (EIP-712)
Dogecoin DOGEAs a Bitcoin derivative, Dogecoin signs with quantum-vulnerable ECDSA secp256k1. No post-quantum roadmap or option was found. source ↗ExposedECDSA secp256k1
Zcash ZECTransparent addresses use ECDSA secp256k1 and shielded spends use Jubjub-based signatures, both quantum-vulnerable. Zcash's own documentation states the protocol is not post-quantum secure today. source ↗ExposedECDSA secp256k1; Jubjub (shielded)
Monero XMRMonero's ring signatures and stealth addresses are built on quantum-vulnerable Ed25519, which would threaten both spend authority and historic privacy. No post-quantum option is deployed. source ↗ExposedEd25519 (ring signatures)
Chainlink LINKLINK is an ERC-20 token on Ethereum and its oracle reporting uses quantum-vulnerable ECDSA secp256k1. No post-quantum option is deployed. source ↗ExposedECDSA secp256k1 (ERC-20)
Bitcoin Cash BCHAs a Bitcoin fork, Bitcoin Cash signs with quantum-vulnerable ECDSA over secp256k1. No post-quantum roadmap or option was found. source ↗ExposedECDSA secp256k1
Toncoin TONTON wallets sign with quantum-vulnerable Ed25519. No post-quantum option is deployed. source ↗ExposedEd25519
"In progress" means a live opt-in, testnet or funded roadmap, not a default. Not financial advice.
Milestone log
Standards, policy deadlines and hardware records on the road to Q-Day, newest first.
- StandardIESG approves standalone ML-KEM key agreement for TLS 1.3The IESG approved draft-ietf-tls-mlkem, "ML-KEM Post-Quantum Key Agreement for TLS 1.3", on 3 September 2026. The Datatracker history logs the move to "Approved-announcement to be sent" at 07:26 UTC and approval at 09:12 UTC, the same day it sat on the IESG telechat agenda. No RFC number is assigned yet. The document registers ML-KEM-512, ML-KEM-768 and ML-KEM-1024 as named groups in the TLS supported groups registry, which is ML-KEM standing on its own rather than the hybrid X25519MLKEM768 that browsers and clouds already run. Its intended status is Informational and the author is D. Connolly of SandboxAQ.IETF Datatracker ↗
- HardwareIBM Nighthawk r2 raises circuit throughput about 25 timesIBM's Nighthawk r2 carries 120 programmable qubits, 218 couplers and 120 reset elements, 458 physical quantum elements in total. IBM reports more than 100,000 circuits per second against roughly 4,000 for its Heron processor, while holding Heron-class gate fidelity. The speed comes from active reset: linking a qubit through a tunable coupler to a cold environment pulls its effective T1 from a median of about 200 microseconds down to roughly 25 nanoseconds, and cuts initialisation error by around 25 times. IBM says the chip returns accurate results on circuits of more than 7,500 gates, which it counts as a 2026 milestone on its published roadmap. This is throughput, not error correction, and it moves nothing on the Q-Day estimate above.IBM Quantum ↗
- StandardRFC 10042 standardises hybrid ML-KEM key exchange for SSHRFC 10042, "Post-Quantum/Traditional Hybrid Key Exchange with the Module-Lattice-Based Key-Encapsulation Mechanism for Use in SSH", was published on 31 August 2026. It pairs ML-KEM with a traditional exchange rather than replacing it, so a break in either one still leaves the other standing. The authors are P. Kampanakis and T. Hansen of AWS and D. Stebila of the University of Waterloo. It is an Informational RFC rather than Standards Track, and the Datatracker records errata tags added on 2 September.RFC Editor ↗
- HardwareRigetti reports wafer-scale frequency targeting on a 36-qubit processorA preprint posted on 27 August 2026 reports wafer-scale precision in setting transmon frequencies, the step that decides how many usable qubits come off a wafer. The authors report junction resistance tuned to 0.50 per cent, plus or minus 0.05, at 150mm scale, component-level yield of at least 98.8 per cent, and frequency targeting to about 30 MHz in both qubit and qubit-qubit detuning frequencies, on the Cepheus-1-36Q quad-module processor. It is an unreviewed preprint and the only published account of the result.arXiv:2608.27789 ↗
- HardwareIBM completes its acquisition of HRL LaboratoriesIBM completed its acquisition of HRL Laboratories on 26 August 2026. HRL brings silicon-spin qubits, which sit alongside rather than inside IBM's superconducting line, plus quantum sensing, quantum materials, cryogenics, control electronics, packaging and interconnect. Financial terms were not disclosed. Boeing and General Motors, HRL's former owners, continue to partner with IBM and HRL. IBM restated its roadmap in the same release: Starling is expected by 2029 to perform 100 million quantum operations, and Blue Jay is targeted for the mid-2030s.IBM Newsroom ↗
- MilestoneFirst quantum-safe Bitcoin transaction mined on mainnetA Bitcoin transaction protected by a quantum-resistant, hash-based lock was mined on mainnet in block 964,199 (txid 305a24ff...abab07). The Quantum-Safe Bitcoin scheme, designed by StarkWare's Avihu Levy with the implementation finished by engineer Tomer Giladi, uses signature grinding, so security rests on hash preimage resistance rather than key secrecy, and needs no soft fork. The transaction format is non-standard, so MARA's Slipstream service mined it, and the scheme protects only coins moved into its special output; StarkWare still argues a soft fork is the better long-term answer.StarkWare ↗
- PolicyUS Treasury launches a Quantum-Readiness Task ForceThe US Treasury launched a public-private Quantum-Readiness Task Force to accelerate the financial sector's post-quantum transition, with workstreams on sector alignment, vendor readiness and digital-asset risk, and no new deadlines. The same day the GSA set out its execution of OMB memo M-26-15, which directs agencies to move faster to quantum-resistant security: a federal identity-management working group first met on 12 August with 40 participants from 17 agencies, and GSA's evaluation lab is expanding testing of post-quantum building access controls and PIV badges.US Treasury ↗
- StandardHAWK withdrawn from NIST's additional-signature processThe HAWK team withdrew its lattice signature scheme from round 3 of NIST's additional-signature process after Anthropic disclosed that its Claude model had recovered signing-equivalent keys from HAWK-256 challenge keys, halving the lattice-reduction block size the best prior attack needed. The team said the mitigations required would leave the scheme uncompetitive. NIST's finalised standards, ML-KEM, ML-DSA and SLH-DSA, are unaffected.NIST pqc-forum ↗
- HardwareReality check: hardware is still far from breaking RSAThe gap is still wide: the largest gate-model processors demonstrated hold on the order of a thousand physical qubits (IBM's Condor at 1,121; Atom Computing's 1,180-qubit neutral-atom array), logical-qubit counts reach 96 (QuEra and Harvard, December 2025), and the highest-fidelity trapped-ion machines hold around 100 physical qubits, whereas even the most optimistic recent estimates require hundreds of thousands to a million physical qubits to factor RSA-2048.QuEra ↗our page →
- HardwareQuantinuum Helios reaches 48 logical qubitsQuantinuum launched Helios, a trapped-ion system with 98 physical qubits, up to 48 error-corrected logical qubits, and two-qubit gate fidelity of 99.921%.Quantinuum ↗our page →
- HardwareIonQ crosses 99.99% two-qubit gate fidelityIonQ reported the first four-nines (99.99%) two-qubit gate fidelity on its Tempo system, part of a roadmap targeting roughly 20,000 physical qubits by 2028.IonQ ↗our page →
- StandardNIST advances FN-DSA (FALCON) toward draft FIPS 206NIST moved the draft of FN-DSA, the FALCON-based signature scheme set to become FIPS 206, toward public review, with a final standard not expected until late 2026 or 2027.DigiCert (on NIST) ↗
- PolicyEU publishes a coordinated PQC roadmapThe EU roadmap directs Member States to begin transition and inventories by 2026, complete PQC migration for all high-risk use cases by 2030, and address medium-risk systems by 2035.European Commission ↗
- HardwareIBM sets a path to a fault-tolerant machine by 2029IBM laid out a route from its 156-qubit Heron and 120-qubit Nighthawk processors to Starling, a targeted fault-tolerant machine of around 200 logical qubits running 100 million gates by 2029.IBM Quantum ↗our page →
- PolicyUK NCSC publishes its PQC migration timelineThe NCSC set a three-phase national roadmap: discovery and planning by 2028, highest-priority migration by 2031, and full migration to PQC by 2035.UK NCSC ↗
- StandardNIST selects HQC as a backup KEMNIST chose the code-based algorithm HQC as a fifth standard and a mathematically independent backup to ML-KEM, with a draft standard expected around 2026 and a final version around 2027.NIST ↗
- HardwareMicrosoft unveils Majorana 1, a topological processorMicrosoft presented Majorana 1, an eight-qubit topological processor it says is a step toward a million-qubit chip, though several physicists said the accompanying paper did not yet demonstrate a working topological qubit.Microsoft Azure Quantum ↗our page →
- HardwareGoogle Willow shows below-threshold error correctionGoogle's 105-qubit Willow chip was the first to show below-threshold error correction, with the logical error rate roughly halving each time the surface-code array was scaled up from 3x3 to 5x5 to 7x7 physical qubits.Google Quantum AI ↗our page →
- StandardNIST finalises FIPS 203, 204 and 205NIST published its first three finalised post-quantum standards: FIPS 203 (ML-KEM, from CRYSTALS-Kyber), FIPS 204 (ML-DSA, from CRYSTALS-Dilithium) and FIPS 205 (SLH-DSA, from SPHINCS+).NIST CSRC ↗
- PolicyNSA publishes the CNSA 2.0 timelineNSA's Commercial National Security Algorithm Suite 2.0 mandates ML-KEM-1024 and ML-DSA-87 for national-security systems, phasing in from 2025 toward exclusive use of quantum-resistant algorithms across most such systems by 2033.NSA CNSA 2.0 ↗
Q-Day figures are expert estimates and probabilities, not established facts, and they shift with each result. Sensational "encryption is broken" claims are logged only with their status.Last update · 03 Sept 2026

