Quantum Threat Tracker
2029 is the soonest credible milestone on the road to Q-Day
The day a quantum computer can break today's encryption is called Q-Day. No machine can do it yet, and no one can name the year one will. This board tracks the honest state of it: the expert estimate, the standards, who has actually migrated to quantum-safe cryptography, which blockchains are ready, and the hardware milestones.
The road to Q-Day
Soonest milestone
2029Estimated
to the first large fault-tolerant quantum computer, which Google, IBM and Microsoft target for 2029. That is a hardware milestone, not Q-Day: it would still be far from breaking RSA-2048.
No major lab forecasts a year for breaking RSA. The soonest dated targets, from Google, IBM and Microsoft, are for a large fault-tolerant machine around 2029, which would still be far short of breaking RSA-2048. The only real code-breaking estimate, an expert survey, puts the odds in single digits before the mid-2030s. Q-Day is a forecast, not a fact.
Who forecasts what
- 2029GoogleHardware milestoneRoadmap target for a useful, error-corrected machine scaling toward a million qubits. It is not a claim to break RSA.Google Quantum AI roadmap ↗our page →
- 2029IBMHardware milestoneStarling: a fault-tolerant machine of about 200 logical qubits, far short of what breaking RSA-2048 would need.IBM Quantum ↗our page →
- 2029MicrosoftHardware milestoneAfter its Majorana 1 chip, Microsoft says useful, fault-tolerant quantum computing is years, not decades, away.Microsoft Azure Quantum ↗our page →
- 2030NISTPolicy deadlinePlans to deprecate RSA-2048 and P-256 after 2030 and disallow them after 2035. A precautionary deadline, not a forecast.NIST IR 8547 (draft) ↗our page →
- 2030QuantinuumHardware milestoneTargets universal, fully fault-tolerant computing with its Apollo system; some milestones have since moved toward 2029.Quantinuum ↗our page →
- 2030EUHardware milestoneThe Quantum Europe Strategy aims for Europe's first full-stack fault-tolerant machine, around 100 logical qubits.European Commission ↗our page →
- 2035NSAPolicy deadlineCNSA 2.0 requires national-security systems to be fully quantum-resistant by 2035, phasing in from 2027. A policy hedge.NSA CNSA 2.0 ↗
- 2035Mosca / GRIExpert surveyA 32-expert survey put the odds of a code-breaker within 5 years at 5 to 14%, rising toward even by the mid-2030s. The only real threat estimate.Global Risk Institute ↗our page →
Who has migrated to quantum-safe cryptography
- Cloudflare 1.1.1.1DeployedPost-quantum DNSSEC validation
Cloudflare's 1.1.1.1 resolver now validates DNSSEC signatures made with ML-DSA-44, which IANA has assigned DNSSEC algorithm number 18; the signatures run 2,420 bytes against 64 for ECDSA P-256. Announced 10 September 2026 as an early step toward full post-quantum DNS security by 2029.
Cloudflare ↗ - Apple iMessageDeployedPQ3 protocol
Apple's PQ3, a hybrid of ML-KEM and elliptic curve with ongoing post-quantum re-keying, began rolling out in iOS 17.4 and reached full deployment across supported devices through 2024.
Apple Security Research ↗ - SignalDeployedPQXDH key agreement
Signal shipped PQXDH (X25519 plus Kyber-1024) for the initial handshake in 2023 and has since extended post-quantum protection into the ongoing message ratchet.
Signal specifications ↗ - Google ChromeDeployedHybrid X25519MLKEM768 in TLS
Chrome enabled hybrid post-quantum key exchange by default in Chrome 124 (April 2024) and switched to standardised ML-KEM in Chrome 131 (November 2024).
Google Online Security Blog ↗ - Mozilla FirefoxDeployedHybrid X25519MLKEM768 in TLS
Firefox added the X25519MLKEM768 hybrid group in late 2024 and enabled it by default in early 2025.
Encryption Consulting ↗ - CloudflareDeployedHybrid ML-KEM across its network
By 22 August 2026, 71.1% of human HTTPS traffic on Cloudflare's network used post-quantum key agreement (Cloudflare Radar, checked that day), up from over 65% in April 2026. On 8 September 2026 its Automatic Key Exchange began preferring the post-quantum hybrid X25519MLKEM768 for edge-to-origin TLS where the origin supports it: 33% of scanned domains now prefer the hybrid, and Cloudflare counts about 45 billion post-quantum connections a day across its network.
Cloudflare ↗ - OpenSSHDeployedML-KEM-768 + X25519 hybrid, default
OpenSSH added the ML-KEM-768 plus X25519 hybrid in 9.9 and made it the default key exchange in OpenSSH 10.0 (April 2025), later warning on connections that are not quantum-safe.
OpenSSH project ↗ - Google (internal)DeployedPost-quantum ALTS
Google has protected internal service-to-service traffic with a hybrid post-quantum ALTS since 2022 and has set 2029 as its broader migration target.
Google Cloud ↗ - Meta (internal)DeployedHybrid post-quantum TLS
Meta reported deploying hybrid ML-KEM TLS across most of its internal service-to-service traffic as part of a multi-year migration.
Engineering at Meta ↗ - ZoomDeployedPost-quantum end-to-end encryption
In May 2024 Zoom added post-quantum end-to-end encryption to Zoom Meetings, for calls where every participant runs a recent enough client. It uses Kyber 768, the pre-standardisation name for what NIST went on to publish as ML-KEM-768 in FIPS 203.
Zoom ↗ - Amazon Web ServicesRolling outHybrid ML-KEM TLS on by default
AWS turned ML-KEM hybrid TLS on by default across KMS, Secrets Manager, ACM, Payment Cryptography and S3 in April 2026.
AWS Security ↗ - Microsoft (Windows)Rolling outML-KEM and ML-DSA in SymCrypt / CNG
Microsoft brought ML-KEM and ML-DSA to Windows 11 and Windows Server 2025 through SymCrypt and CNG in 2025, extending to hybrid ML-KEM TLS key exchange in 2026.
Microsoft Security Blog ↗ - US GovernmentMandated by deadlineFederal PQC migration mandate
NSM-10 and OMB M-23-02 require agencies to inventory cryptography and migrate to NIST PQC, with a government-wide goal of mitigating quantum risk by 2035.
White House OMB ↗ - UK GovernmentMandated by deadlineNational PQC migration roadmap
NCSC guidance directs organisations, especially critical national infrastructure, to complete discovery by 2028, high-priority migration by 2031 and full migration by 2035.
UK NCSC ↗ - European UnionMandated by deadlineCoordinated PQC roadmap
The EU roadmap requires Member States to migrate high-risk use cases to PQC by 2030 and medium-risk systems by 2035.
European Commission ↗
Is your crypto quantum-safe?
0 quantum-safe · 7 in progress · 10 exposed. No top-100 coin is quantum-safe by default today. Every major chain still signs with quantum-vulnerable ECDSA or Ed25519, and the strongest efforts (Bitcoin BIP-360, Ethereum and Cardano roadmaps, Solana and NEAR opt-ins, Algorand Falcon state proofs) are opt-in, testnet or roadmap only. The only chains quantum-safe by default are small, purpose-built projects such as QRL, outside the top 100.
Bitcoin BTCStatus: In progressSignature scheme: ECDSA / Schnorr (secp256k1)Every spend relies on quantum-vulnerable ECDSA or Schnorr over secp256k1, and address reuse leaves many coins with exposed public keys. BIP-360, which adds post-quantum outputs, was merged as a proposal in early 2026 and has a testnet, but no protocol change is live on mainnet. On 26 August 2026 StarkWare mined a first quantum-safe transaction on mainnet in block 964,199, a hash-based lock needing no soft fork, though the format is non-standard, needs a direct path to a miner and protects only coins moved into its special output. source ↗Bitcoin →
Ethereum ETHStatus: In progressSignature scheme: ECDSA secp256k1 (accounts)Externally owned accounts still sign with quantum-vulnerable ECDSA. A concrete core-dev roadmap (Vitalik Buterin's 2026 plan, an Ethereum Foundation post-quantum hub, and account abstraction to let accounts opt into PQC) is under way, but nothing is deployed on mainnet. source ↗Ethereum →
Solana SOLStatus: In progressSignature scheme: Ed25519 + opt-in Winternitz vaultStandard accounts use quantum-vulnerable Ed25519. An opt-in, hash-based Winternitz Vault (2025) lets users store funds under quantum-resistant one-time signatures, but it is experimental and used by very few accounts. source ↗Solana →
NEAR Protocol NEARStatus: In progressSignature scheme: ML-DSA-65 opt-in; Ed25519 defaultNEAR's July 2026 mainnet upgrade added the NIST-standardised ML-DSA-65 signature, which users can enable with a single transaction. It is a live, in-production opt-in; most accounts still use Ed25519. source ↗NEAR Protocol →
Algorand ALGOStatus: In progressSignature scheme: Falcon state proofs; Ed25519 defaultAlgorand's State Proofs have used the lattice-based Falcon scheme on mainnet since 2022, and opt-in Falcon account keys are available. Ordinary accounts and consensus still rely on quantum-vulnerable Ed25519. source ↗
Hyperliquid HYPEStatus: ExposedSignature scheme: ECDSA secp256k1 (EIP-712)Hyperliquid uses Ethereum-style signatures verified through ecrecover, that is ECDSA secp256k1, which is quantum-vulnerable. No post-quantum option was found. source ↗Hyperliquid →
Dogecoin DOGEStatus: ExposedSignature scheme: ECDSA secp256k1As a Bitcoin derivative, Dogecoin signs with quantum-vulnerable ECDSA secp256k1. No post-quantum roadmap or option was found. source ↗Dogecoin →
Chainlink LINKStatus: ExposedSignature scheme: ECDSA secp256k1 (ERC-20)LINK is an ERC-20 token on Ethereum and its oracle reporting uses quantum-vulnerable ECDSA secp256k1. No post-quantum option is deployed. source ↗Chainlink →
Bitcoin Cash BCHStatus: ExposedSignature scheme: ECDSA secp256k1As a Bitcoin fork, Bitcoin Cash signs with quantum-vulnerable ECDSA over secp256k1. No post-quantum roadmap or option was found. source ↗Bitcoin Cash →
Toncoin TONStatus: ExposedSignature scheme: Ed25519TON wallets sign with quantum-vulnerable Ed25519. No post-quantum option is deployed. source ↗
"In progress" means a live opt-in, testnet or funded roadmap, not a default. Not financial advice.
Milestone log
Standards, policy deadlines and hardware records on the road to Q-Day, newest first. Each milestone opens its own record page, with the detail and the source.
- StandardNIST will adopt the strengthened HQC parameters in the FIPS 207 draftNIST pqc-forum ↗
- HardwareIonQ publishes a compiled blueprint for breaking 256-bit elliptic curve signaturesIonQ ↗
- StandardIESG approves standalone ML-KEM key agreement for TLS 1.3IETF Datatracker ↗
- HardwareIBM Nighthawk r2 raises circuit throughput about 25 timesIBM Quantum ↗
- StandardRFC 10042 standardises hybrid ML-KEM key exchange for SSHRFC Editor ↗
- HardwareRigetti reports wafer-scale frequency targeting on a 36-qubit processorarXiv:2608.27789 ↗
- HardwareIBM completes its acquisition of HRL LaboratoriesIBM Newsroom ↗
- MilestoneFirst quantum-safe Bitcoin transaction mined on mainnetStarkWare ↗
- PolicyUS Treasury launches a Quantum-Readiness Task ForceUS Treasury ↗
- StandardHAWK withdrawn from NIST's additional-signature processNIST pqc-forum ↗
- HardwareReality check: hardware is still far from breaking RSAQuEra ↗our page →
- HardwareQuantinuum Helios reaches 48 logical qubitsQuantinuum ↗our page →
- HardwareIonQ crosses 99.99% two-qubit gate fidelityIonQ ↗our page →
- StandardNIST advances FN-DSA (FALCON) toward draft FIPS 206DigiCert (on NIST) ↗
- PolicyEU publishes a coordinated PQC roadmapEuropean Commission ↗
- HardwareIBM sets a path to a fault-tolerant machine by 2029IBM Quantum ↗our page →
- PolicyUK NCSC publishes its PQC migration timelineUK NCSC ↗
- StandardNIST selects HQC as a backup KEMNIST ↗
- HardwareMicrosoft unveils Majorana 1, a topological processorMicrosoft Azure Quantum ↗our page →
- HardwareGoogle Willow shows below-threshold error correctionGoogle Quantum AI ↗our page →
- StandardNIST finalises FIPS 203, 204 and 205NIST CSRC ↗
- PolicyNSA publishes the CNSA 2.0 timelineNSA CNSA 2.0 ↗
Download the milestone data: CSV ·JSON ·RSS · CC BY 4.0 with attribution to YFarmX.
Q-Day figures are expert estimates and probabilities, not established facts, and they shift with each result. Sensational "encryption is broken" claims are logged only with their status.Last update · 18 Sept 2026








