A sealed letter in someone else’s safe.
Imagine someone photographs every sealed envelope that goes through the post. Today they cannot open any of them. But they keep the photos, because they know the tool will exist one day. When it does, they open everything at once, including what you sent years earlier.
On the internet this has a name: harvest now, decrypt later. Whoever records encrypted traffic today does not need to break anything today. Today’s conversation is the leak of the day the quantum computer switches on.
That is why the deadline that matters is not the computer’s date. It is how long the data must stay secret. A five-minute access code does not care; a medical record kept for 20 years does.
From 2035 to 2029.
For years the informal consensus among cryptographers was that it was fine to wait until around 2035. In early 2026, Filippo Valsorda, a cryptographer who worked on the Go team at Google and author of the age tool, publicly revised his own view: the critical deadline became 2029.
Two research papers moved the estimate: one from Google, estimating that 256-bit elliptic curves (today’s most used lock) would fall in minutes with far fewer qubits than previously thought; another from the Oratomic group, estimating a path with about 10,000 physical qubits on neutral atoms. They are resource estimates, not demonstrations: nobody has broken a real key.
In 2026 two more signals pointed the same way: Google published quantum error correction that recalibrates itself without stopping the computation (a prerequisite for running for days), and Oratomic raised US$300 million for a computer of about 20,000 qubits. There are serious sceptics: the largest number ever factored by a quantum computer is still 21. Nobody knows the day. The decision is about risk, not certainty.
The problem is all one kind of lock.
Today’s cryptography uses two kinds of lock. Single-key locks (like AES, which scrambles a file with a key both ends already share) hold up well: a quantum computer only halves their strength, and AES-256 stays strong. Key-pair locks (RSA and elliptic curves, used to agree on a key when connecting and to sign) fall completely.
And key-pair locks are exactly the ones that are everywhere: in the browser padlock, in open-banking and instant-payment APIs, in server certificates, in crypto wallets and in remote access to machines.
Two locks on the same door.
The switch the industry adopted is called a hybrid key exchange: the connection agrees on a key using the old lock (elliptic curve) and the new one, ML-KEM, standardised by NIST in August 2024 (FIPS 203). The final secret combines both. If a quantum computer opens the old one, the new one holds. If a flaw is found in the new one, the old one still counts.
Google, Cloudflare and Apple’s iMessage already run hybrid exchange in production. For signatures there is ML-DSA (FIPS 204). We implemented both in Go, open and auditable, and ran the harvest-now-decrypt-later scenario end to end:
$ go run ./fhe/11_crqc_migration 2026 encrypted message (AES-GCM): dfae9b4357d2… (96 bytes) 2029 the computer runs Shor(public key) → private key, in minutes 2029 message opened: "CONFIDENTIAL: master key…" with hybrid exchange (ML-KEM-768 + curve): nothing to open
Three levels. You choose where to start.
- Inventory of keys and algorithms
- Exposure score per system (how long each piece of data must stay secret)
- Prioritised 24-month plan
- Workshop with CTO and CISO
- Executive report ready for the regulator
- Everything in level 1
- One critical service on hybrid exchange in production
- Integration in the TLS terminator or API gateway
- Load tests and measurements
- Training for the in-house team
- Everything in level 2
- End-to-end switch across all services
- Continuous governance and compliance
- Embedded team (2 to 4 engineers)
- Continuous key monitoring and 24 months of support
Your company’s exposure map, in 24 hours.
Fill in the form below. We reply within 24 business hours with a three-page PDF: the critical inventory, a 90-day roadmap and an investment estimate. No sales pitch.
Recording encrypted traffic now to open it once the tool exists. That is why the deadline has already started.
Agreeing on a key with the old lock and the new one at the same time. Protects even if one of them fails.
Years until the computer arrives, minus how long the data must stay secret and how long the switch takes. Negative means late.
Where this could be wrong.
The dates are estimates
2029 and 2035 are experts’ readings of research papers, not announcements. It may come later, or sooner. The margin calculation works for any year you pick.
There are serious sceptics
The largest number factored by a quantum computer is still 21. Part of the community finds 2029 alarmist. The prudent answer does not depend on who is right: starting the key-exchange switch is cheap.
Hardware moves slowly
Key vaults (HSMs), tokens and certificate authorities change generation every 3 to 5 years. Even with the software ready, the full switch may take longer than the specimen assumes.
The new locks are new too
ML-KEM and ML-DSA are recent standards. That is why hybrid exchange keeps the old lock alongside: a flaw in the new one does not leave the door open.
← Post-quantum · stickybit.com.br
- Filippo Valsorda, "CRQC timeline", 2026 · Hacker News discussion (sceptics included).
- Google Quantum AI, error correction that recalibrates without pausing (arXiv 2511.08493; Nature, 2026) · Oratomic, US$300 million round for a ~20,000-qubit computer (TechCrunch, 10 Jul 2026).
- NIST: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), August 2024.
- NIST IR 8547 (draft, Nov 2024): timeline to retire RSA and elliptic curves by 2035.
- Michele Mosca, the rule "secrecy time + switch time > time until the computer" (2015).
- Harvest-now-decrypt-later demo: module
11_crqc_migrationof our Go stack.