No cryptographically relevant quantum computer exists today, but the risk is already operational: attackers can collect encrypted data now and attempt to decrypt it later. Quantum computing’s benefits remain prospective and application specific, especially for quantum chemistry and materials simulations, optimizatio...
Research answer

Create a landscape editorial hero image for this Studio Global article: How does the emerging threat from quantum computing to RSA and elliptic-curve encryption—particularly through Shor’s algorithm and “harvest. Article summary: Quantum computing is both a prospective scientific tool and a security migration problem. Its hoped-for value is in simulating quantum chemistry and materials, optimizing difficult problems, and potentially augmenting so. Topic tags: general, general web, user generated, government, academic. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, water
Quantum computing has a double edge. Its potential benefits—such as improving quantum-chemistry and materials simulations, selected optimization problems, and some artificial-intelligence workflows—remain prospective and highly dependent on the application. Its cybersecurity implication is easier to act on today: a sufficiently large, fault-tolerant quantum computer could undermine widely used public-key cryptography, even though no cryptographically relevant quantum computer exists at present. 52
The practical conclusion is not to wait for a machine capable of breaking encryption. Organizations need to start identifying and replacing vulnerable cryptographic dependencies now because some data must remain confidential for longer than the time it may take to complete a migration.
RSA relies on the difficulty of factoring large integers. Diffie–Hellman and elliptic-curve systems rely on discrete-logarithm problems. On sufficiently capable fault-tolerant quantum hardware, Shor’s algorithm would provide a fundamentally faster approach to these problems than classical computers can.
That threat reaches beyond encrypted messages. Quantum-vulnerable public-key systems are used for key establishment, authentication, certificates, software signing, secure-boot chains, and other digital-trust functions. A future attacker could therefore target both confidentiality and the ability to verify whether software, documents, transactions, or records are authentic.
This is different from saying that all cryptography fails at once. The direct concern is concentrated in public-key algorithms such as RSA and elliptic-curve cryptography. Symmetric cryptography is not threatened by Shor’s algorithm in the same direct way, although organizations still need to assess the security strength and implementation of every cryptographic component.
A harvest-now-decrypt-later attack does not require an attacker to decrypt traffic immediately. An adversary can intercept encrypted communications or obtain encrypted archives, store them, and attempt decryption after a cryptographically relevant quantum computer becomes available. 51
That makes the relevant deadline a function of two variables:
Data with long confidentiality lifetimes is especially exposed. Examples include government and diplomatic records, defense and engineering designs, health and genomic information, identity data, financial and legal files, trade secrets, infrastructure records, and proprietary research. The risk also applies to archives and signed records whose authenticity must remain verifiable for years.
The existence of this threat does not prove that every encrypted archive is being collected or that a quantum attack is imminent. It does mean that waiting for definitive evidence of Q-Day could be too late for information captured today.
Predictions for a cryptographically relevant quantum computer vary widely. Guidance from German authorities notes that no CRQC is currently available, while estimates about when one might appear remain uncertain. 52 Other assessments place meaningful risk in the 2030s, but these are forecasts rather than a confirmed arrival date. 5356
For that reason, a sensible migration plan should not depend on predicting a single Q-Day. It should prioritize information according to its sensitivity and retention period, then account for the years required to discover dependencies, test replacements, update suppliers, and retire systems that cannot be upgraded.
NIST’s proposed transition framework has been widely described as a phased move away from quantum-vulnerable public-key algorithms: RSA-2048 and ECC-256 are proposed for deprecation after 2030 and disallowance after 2035. Because IR 8547 is a transition proposal, organizations should verify the final applicable guidance for their sector rather than treating those dates as universal legal deadlines. 2035
The federal policy direction is nevertheless clear. U.S. civilian agencies were instructed to submit prioritized inventories of systems and assets containing cryptography vulnerable to a CRQC by May 4, 2023, and annually thereafter through 2035. 33 National Security Memorandum 10 established a federal objective of mitigating quantum risk by 2035. 39
On August 13, 2024, NIST finalized three principal post-quantum cryptography standards designed to address future quantum attacks: 2425
These standards are not a one-for-one switch that can be applied everywhere overnight. They must be integrated into protocols, libraries, certificates, identity systems, hardware security modules, firmware, applications, and vendor products. NIST describes the standards as the beginning of a large transition, while continuing to develop additional algorithms as backups or alternatives. 28
Cryptography is often hidden inside systems that were not designed with rapid algorithm replacement in mind. A useful inventory should look beyond obvious encryption settings and include:
The next step is risk prioritization. Systems protecting information that must remain secret for decades, or systems that control software provenance and infrastructure trust, deserve earlier attention than short-lived or easily replaceable data.
Organizations also need crypto-agility: the ability to change algorithms, key sizes, certificates, and cryptographic libraries without redesigning an entire product or network. Hybrid deployments that combine classical and post-quantum mechanisms may help during a transition, but they increase integration, testing, and operational complexity.
In July 2026, Anthropic reported that its Claude Mythos Preview model found a previously unknown structural weakness in HAWK, a lattice-based post-quantum signature candidate. Anthropic said HAWK had survived two years and two rounds of expert review, while the model improved the best-known attack in roughly 60 hours. The HAWK team then withdrew the candidate from NIST’s additional-signature process. 5
The important qualification is that HAWK was a candidate, not a finalized NIST FIPS standard or a deployed production algorithm. The episode did not break FIPS 203, FIPS 204, or FIPS 205, and reporting on the event states that deployed systems were not affected. 56
Its broader lesson is significant: “post-quantum” is not a permanent security label. Candidate algorithms need continuous mathematical scrutiny, independent implementation testing, diverse assumptions, and the ability to be replaced when new attacks emerge. AI-assisted cryptanalysis may become one part of that evaluation process, but it does not eliminate the need for human review and transparent standards work.
A post-quantum migration can require software and protocol changes, new libraries, certificate and PKI work, HSM and firmware upgrades, interoperability testing, vendor coordination, compliance work, and replacement of equipment that cannot be patched. Larger keys or signatures can also affect bandwidth, storage, latency, and device performance.
The cost is difficult to summarize with a single universal number because it depends on the organization’s technology estate, retention obligations, supplier contracts, and regulatory environment. The more defensible conclusion is that the transition is expensive because public-key cryptography is embedded across many long-lived trust relationships—not because every system must be replaced at once.
Quantum computing may eventually deliver important scientific benefits, but those benefits are uncertain, specialized, and still developing. The security requirement is more immediate: RSA and elliptic-curve systems may become vulnerable to Shor’s algorithm, and encrypted data captured today could be exposed later.
No CRQC exists today. That is a reason to plan carefully, not to delay. The practical sequence is to inventory cryptography, classify data by confidentiality lifetime, prioritize high-value dependencies, test NIST’s finalized post-quantum standards, build crypto-agility, and use migration timelines as planning targets rather than waiting for a definitive Q-Day announcement.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
No cryptographically relevant quantum computer exists today, but the risk is already operational: attackers can collect encrypted data now and attempt to decrypt it later.
No cryptographically relevant quantum computer exists today, but the risk is already operational: attackers can collect encrypted data now and attempt to decrypt it later. Quantum computing’s benefits remain prospective and application specific, especially for quantum chemistry and materials simulations, optimization, and some AI workflows.
The 2026 withdrawal of the HAWK signature candidate after an AI assisted attack did not break deployed NIST standards.