Stickybit.← Post-quantumPortuguêsGuide · the whole stack · 2026
Post-quantum stack · five Go modules

What breaks, what stays, what to swap.

A large quantum computer breaks today's public-key locks: the HTTPS key exchange, digital signatures, crypto wallets. It does not break the secret-key ones. We built a complete stack in Go with the new locks standardized by NIST and measured what each one costs.

Specimen · pick a layer of your system
Today
Swap for
When
Cost
3 of 7layers that break
—days to Jan 2029 (estimate)
18×new public key
95 µsmeasured time, ML-KEM

Layers and swaps come from our stack (modules 07 to 11) and from Filippo Valsorda's recommendation. The Jan 2029 deadline is his estimate, not our measurement; the day count is computed in your browser. Sizes and time measured by us on 28 Sep 2026.

In everyday terms

The safe and the mailbox.

Cryptography has two kinds of lock. The first is a safe with a code: whoever locks and whoever opens use the same code. This is secret-key cryptography, such as AES, which protects data stored on disk.

The second is a mailbox with a slot: anyone can drop a letter through the slot, but only the owner has the key to open it. This is public-key cryptography, used by two people who have never met to agree on a secret over the internet (the HTTPS key exchange) and to sign documents.

A large quantum computer running Shor's algorithm finds the mailbox key just by looking at the slot. The whole lock falls, whatever the key size. For the safe there is only Grover's algorithm, which speeds up guessing the code: a 256-bit code becomes worth a 128-bit one, which is still safe.

In practice: the mailbox has to be replaced; for the safe, a long code is enough.

The safe secret key: the samecode opens and closes AES-256, SHA-256 Grover speeds up guessing:256 bits become worth 128 stays: a longer key is enough The mailbox public key: anyone dropsmail in; only the owner opens RSA, ECDH, ECDSA Shor finds the key from the slot:the whole lock falls swap: a new lock
The two locks and what a quantum computer does to each.
Why now

Harvest now, decrypt later.

The attack does not wait for the machine to exist. Whoever records today's traffic, encrypted with today's key exchange, can store it and open it once the quantum computer is ready. For a medical record, a contract or a state secret that must stay confidential for ten years, the problem has already started.

When? Nobody knows; what exists are third-party estimates. Cryptographer Filippo Valsorda (ex-Google, Go team) moved his estimate from 2035 to 2029 after two 2025 papers: one from Google, showing that 256-bit curves would fall in minutes with fewer qubits than thought, and one from Oratomic, pointing to about 10,000 physical qubits with neutral atoms.

In July 2026, Oratomic raised US$300 million for a 20,000-qubit machine, and Google published error correction that recalibrates itself without stopping the computation. The bottleneck moved from "how many qubits" to "running for days without stopping". None of these numbers is our measurement. The deadline and the assessment are in CRQC 2029.

harvest now · decrypt later 2024-08NIST publishesthe new locks2025Google andOratomic: fewerqubits thanthought2026today: someonerecords theencryptedtraffic2029estimate: therecordedtraffic isopened
The threat timeline. The dashed arc is "harvest now, decrypt later": what is recorded in 2026 is opened in the estimated year.
The measured cost

More bytes, about the same time.

In August 2024, NIST, the US standards institute, published the new locks: ML-KEM for key exchange (FIPS 203), ML-DSA for signatures (FIPS 204) and SLH-DSA, a signature built only from fingerprints (FIPS 205).

The first two rest on a lattice problem: finding a hidden point in a gigantic grid, with hundreds of dimensions, from a deliberately blurred hint. Nobody knows a shortcut for this, not even with a quantum computer.

We measured it in our stack (Go with Cloudflare's CIRCL library), in one run, on 28 Sep 2026, on a Mac: ML-KEM-768 generates, locks and opens the key in 95 µs, against 63 µs for today's key exchange; ML-DSA-65 generates, signs and checks in 287 µs, against 165 µs for ECDSA. In practice, time hardly matters.

The cost is size: the key-exchange public key gets 18 times bigger, and the signature 46 times. Where every byte counts (field sensors, satellites, a certificate chain in a handshake), that changes the design.

Size in bytes, log scale. Measured in module 11 of our stack, 28 Sep 2026.
WhatTodayPost-quantumTimes
Key exchange · public key65 B (ECDH P-256)1,184 B (ML-KEM-768)18×
Key exchange · private key32 B2,400 B75×
Key exchange · ciphertextnone1,088 B—
Key exchange · time (generate, lock, open)63 µs95 µs1.5×
Signature · public key65 B (ECDSA P-256)1,952 B (ML-DSA-65)30×
Signature · the signature71 B3,309 B46×
Signature · time (generate, sign, check)165 µs287 µs1.7×
During the transition

A padlock with two locks.

While the new lock does not yet have decades of use, you can use both together: today's key exchange (X25519) and the new one (ML-KEM). The final secret is the fingerprint of both. If either one holds, the conversation stays protected. Chrome, Signal and AWS already do this for key exchange.

This insurance has already shown why it exists. In August 2026 a paper circulated claiming a quantum algorithm against lattice problems. As of this page it has not been confirmed, and a similar announcement in 2024 fell in about eight days because of an error in the proof. With the hybrid mode, even if it is one day confirmed, the conversation is not exposed.

One caveat: for signatures, Valsorda recommends going straight to the new one, without a hybrid. And what really protects against surprises is being able to change the lock without changing the door: crypto-agility.

TodayX25519: holdsML-KEM: holdsconversation protectedWith a quantum computerX25519: brokenML-KEM: holdsconversation protectedIf lattices fallX25519: holds todayML-KEM: brokenconversation protected
The hybrid padlock in the three possible situations.
Proofs without curves

Prove without showing, without an elliptic curve.

A zero-knowledge proof shows you know something without revealing what: for example, proving you are over 18 without showing your birth date. The most common versions today rest on elliptic curves or "pairings", and both fall to Shor's algorithm.

The stack has two ways out. The first is lattice Schnorr: the same classic recipe, swapping the curve for a lattice problem. The second is the STARK, which uses only fingerprints (SHA-256): it depends neither on a curve nor on a setup ceremony in which someone must be trusted.

The parameters of these two modules are for teaching (a small grid), not for production. The proof in the example alongside is about 2.5 KB in our simplified implementation.

?y²+126y²+1677y²+1654y²+152968secretpublicthe verifier sees only the result and the root of the fingerprint treeand checks 3 random points: the chance of a fraud slipping through is about 1 in 10¹¹
Teaching STARK example: the verifier checks the computation without learning the secret.
Putting it together

An election nobody opens.

The last module puts the pieces together in a vote. The server publishes the post-quantum key-exchange key (1,184 bytes). Each terminal sets up an ML-KEM channel with it and receives, through that channel, the homomorphic encryption key: a cipher that lets you compute on data without opening it.

Each vote leaves the terminal encrypted, at 131,406 bytes (about 128 KB). The server adds the encrypted votes in under 1 ms, without ever seeing a vote; only the authority, holding the key, opens the total. Numbers from the 28 Sep 2026 run.

Every layer resists a quantum computer: key exchange and vote on lattices, transport with AES-256, commitment with SHA-256. Other uses of the same idea are in 20 FHE applications, and you can actually vote in the interactive tutorial (in Portuguese).

terminal Aterminal Bterminal Cencrypted vote131 KB eachserver addswithout opening: < 1 msauthorityopens only the totalML-KEM channel (1,184 B)
The module 10 vote: adding without opening, the total only for whoever holds the key.
What to do now

Swap, keep, revisit.

SwapAct now

  • HTTPS and VPN key exchange: hybrid mode with ML-KEM.
  • SSH host keys and code signing: ML-DSA.
  • New certificates: those issued today expire close to the estimated deadline.
  • Permanent identities (DIDs, wallets): keys that cannot be changed later.

KeepCan stay

  • AES-256 and SHA-256 / SHA-3 / HMAC: still safe.
  • AES-128: moving to AES-256 is enough.

WatchRevisit in 2026–2027

  • Long-lived JWT tokens: the post-quantum standard is still a draft.
  • Files encrypted with age: swap the recipients.
  • Trusted hardware (SGX, SEV-SNP): without a post-quantum root, attestation loses its value.

Not sure where cryptography lives in your system? The first step is the list: 24-hour assessment.

Three words on this page
Public key

The mailbox: anyone drops mail in, only the owner opens it. This is the lock a quantum computer breaks.

Lattice

A huge grid with hundreds of dimensions. Finding a hidden point in it from a blurred hint is the problem the new locks rest on.

Crypto-agility

Being able to change the lock without changing the door. It is the insurance against a wrong deadline and against a new lock falling by surprise.

Limits

Where this could be wrong.

The deadline is someone else's estimate

2029 is Valsorda's estimate, backed by papers from Google and Oratomic. It may come earlier or later; "harvest now, decrypt later" holds either way.

Times from a single run

The microseconds come from one run on a Mac. They give the order of magnitude: the cost of the swap is in bytes, not time.

Teaching parameters

The zero-knowledge proofs and the STARK in the stack use small grids made for teaching. Do not use those parameters in production.

Lattices still under scrutiny

The August 2026 claim against lattices had not been confirmed as of this page. Hence: hybrid mode and crypto-agility.

See also

← Post-quantum · stickybit.com.br

Sources