The safe and the mailbox.
Cryptography has two kinds of lock. The first is a safe with a code: whoever locks and whoever opens use the same code. This is secret-key cryptography, such as AES, which protects data stored on disk.
The second is a mailbox with a slot: anyone can drop a letter through the slot, but only the owner has the key to open it. This is public-key cryptography, used by two people who have never met to agree on a secret over the internet (the HTTPS key exchange) and to sign documents.
A large quantum computer running Shor's algorithm finds the mailbox key just by looking at the slot. The whole lock falls, whatever the key size. For the safe there is only Grover's algorithm, which speeds up guessing the code: a 256-bit code becomes worth a 128-bit one, which is still safe.
In practice: the mailbox has to be replaced; for the safe, a long code is enough.
Harvest now, decrypt later.
The attack does not wait for the machine to exist. Whoever records today's traffic, encrypted with today's key exchange, can store it and open it once the quantum computer is ready. For a medical record, a contract or a state secret that must stay confidential for ten years, the problem has already started.
When? Nobody knows; what exists are third-party estimates. Cryptographer Filippo Valsorda (ex-Google, Go team) moved his estimate from 2035 to 2029 after two 2025 papers: one from Google, showing that 256-bit curves would fall in minutes with fewer qubits than thought, and one from Oratomic, pointing to about 10,000 physical qubits with neutral atoms.
In July 2026, Oratomic raised US$300 million for a 20,000-qubit machine, and Google published error correction that recalibrates itself without stopping the computation. The bottleneck moved from "how many qubits" to "running for days without stopping". None of these numbers is our measurement. The deadline and the assessment are in CRQC 2029.
More bytes, about the same time.
In August 2024, NIST, the US standards institute, published the new locks: ML-KEM for key exchange (FIPS 203), ML-DSA for signatures (FIPS 204) and SLH-DSA, a signature built only from fingerprints (FIPS 205).
The first two rest on a lattice problem: finding a hidden point in a gigantic grid, with hundreds of dimensions, from a deliberately blurred hint. Nobody knows a shortcut for this, not even with a quantum computer.
We measured it in our stack (Go with Cloudflare's CIRCL library), in one run, on 28 Sep 2026, on a Mac: ML-KEM-768 generates, locks and opens the key in 95 µs, against 63 µs for today's key exchange; ML-DSA-65 generates, signs and checks in 287 µs, against 165 µs for ECDSA. In practice, time hardly matters.
The cost is size: the key-exchange public key gets 18 times bigger, and the signature 46 times. Where every byte counts (field sensors, satellites, a certificate chain in a handshake), that changes the design.
| What | Today | Post-quantum | Times |
|---|---|---|---|
| Key exchange · public key | 65 B (ECDH P-256) | 1,184 B (ML-KEM-768) | 18× |
| Key exchange · private key | 32 B | 2,400 B | 75× |
| Key exchange · ciphertext | none | 1,088 B | — |
| Key exchange · time (generate, lock, open) | 63 µs | 95 µs | 1.5× |
| Signature · public key | 65 B (ECDSA P-256) | 1,952 B (ML-DSA-65) | 30× |
| Signature · the signature | 71 B | 3,309 B | 46× |
| Signature · time (generate, sign, check) | 165 µs | 287 µs | 1.7× |
A padlock with two locks.
While the new lock does not yet have decades of use, you can use both together: today's key exchange (X25519) and the new one (ML-KEM). The final secret is the fingerprint of both. If either one holds, the conversation stays protected. Chrome, Signal and AWS already do this for key exchange.
This insurance has already shown why it exists. In August 2026 a paper circulated claiming a quantum algorithm against lattice problems. As of this page it has not been confirmed, and a similar announcement in 2024 fell in about eight days because of an error in the proof. With the hybrid mode, even if it is one day confirmed, the conversation is not exposed.
One caveat: for signatures, Valsorda recommends going straight to the new one, without a hybrid. And what really protects against surprises is being able to change the lock without changing the door: crypto-agility.
Prove without showing, without an elliptic curve.
A zero-knowledge proof shows you know something without revealing what: for example, proving you are over 18 without showing your birth date. The most common versions today rest on elliptic curves or "pairings", and both fall to Shor's algorithm.
The stack has two ways out. The first is lattice Schnorr: the same classic recipe, swapping the curve for a lattice problem. The second is the STARK, which uses only fingerprints (SHA-256): it depends neither on a curve nor on a setup ceremony in which someone must be trusted.
The parameters of these two modules are for teaching (a small grid), not for production. The proof in the example alongside is about 2.5 KB in our simplified implementation.
An election nobody opens.
The last module puts the pieces together in a vote. The server publishes the post-quantum key-exchange key (1,184 bytes). Each terminal sets up an ML-KEM channel with it and receives, through that channel, the homomorphic encryption key: a cipher that lets you compute on data without opening it.
Each vote leaves the terminal encrypted, at 131,406 bytes (about 128 KB). The server adds the encrypted votes in under 1 ms, without ever seeing a vote; only the authority, holding the key, opens the total. Numbers from the 28 Sep 2026 run.
Every layer resists a quantum computer: key exchange and vote on lattices, transport with AES-256, commitment with SHA-256. Other uses of the same idea are in 20 FHE applications, and you can actually vote in the interactive tutorial (in Portuguese).
Swap, keep, revisit.
SwapAct now
- HTTPS and VPN key exchange: hybrid mode with ML-KEM.
- SSH host keys and code signing: ML-DSA.
- New certificates: those issued today expire close to the estimated deadline.
- Permanent identities (DIDs, wallets): keys that cannot be changed later.
KeepCan stay
- AES-256 and SHA-256 / SHA-3 / HMAC: still safe.
- AES-128: moving to AES-256 is enough.
WatchRevisit in 2026–2027
- Long-lived JWT tokens: the post-quantum standard is still a draft.
- Files encrypted with age: swap the recipients.
- Trusted hardware (SGX, SEV-SNP): without a post-quantum root, attestation loses its value.
Not sure where cryptography lives in your system? The first step is the list: 24-hour assessment.
The mailbox: anyone drops mail in, only the owner opens it. This is the lock a quantum computer breaks.
A huge grid with hundreds of dimensions. Finding a hidden point in it from a blurred hint is the problem the new locks rest on.
Being able to change the lock without changing the door. It is the insurance against a wrong deadline and against a new lock falling by surprise.
Where this could be wrong.
The deadline is someone else's estimate
2029 is Valsorda's estimate, backed by papers from Google and Oratomic. It may come earlier or later; "harvest now, decrypt later" holds either way.
Times from a single run
The microseconds come from one run on a Mac. They give the order of magnitude: the cost of the swap is in bytes, not time.
Teaching parameters
The zero-knowledge proofs and the STARK in the stack use small grids made for teaching. Do not use those parameters in production.
Lattices still under scrutiny
The August 2026 claim against lattices had not been confirmed as of this page. Hence: hybrid mode and crypto-agility.
← Post-quantum · stickybit.com.br
- Filippo Valsorda, "CRQC timeline" (the 2029 estimate and what to do now).
- NIST: FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA) · FIPS 205 (SLH-DSA).
- Libraries: Cloudflare CIRCL (ML-KEM and ML-DSA in Go) · Lattigo v6 (BGV).
- Threat clock: Oratomic, US$300 million for 20,000 qubits (TechCrunch, 10 Jul 2026) · Google, error correction that recalibrates without pausing (arXiv 2511.08493). The claim against lattices: IACR ePrint 2026/1591, not confirmed.
- Our measurements: modules 07 to 11 of our FHE and post-quantum repository (module 11 sizes and times and the module 10 vote, run on 28 Sep 2026).