Skip to main content
Home/Topics/Q-Day

Topic · Quantum threat timeline

Q-Day: when quantum computers break today's encryption

What the term means, what the latest estimates actually say, and why the date matters less than what you do before it.

By Shujaatali Badami, IEEE and ISA Senior Member · Last reviewed

Q-Day is the day a cryptographically relevant quantum computer (CRQC) can break the public-key cryptography the internet depends on, RSA and elliptic-curve cryptography, by running Shor's algorithm at useful scale. Symmetric encryption such as AES-256 is not broken.

When is Q-Day?

Nobody knows, and anyone who gives a single year is guessing. What has changed since 2025 is the direction of travel. Resource estimates for breaking RSA-2048 have fallen sharply: Craig Gidney's 2025 analysis put it at under one million noisy qubits running for under a week. In March 2026 Google moved its own post-quantum migration deadline to 2029, and in September 2026 IonQ's chief executive claimed 2028, a claim most researchers treat as optimistic. Government planning dates cluster around 2030 to 2035.

The honest summary is a probability distribution, not a date: low but rising odds before 2030, and a meaningful chance in the early to mid 2030s. For planning purposes that is enough. See Mosca's inequality for why the exact year matters less than it seems.

What breaks on Q-Day, and what does not

CryptographyUsed forOn Q-Day
RSATLS certificates, code signing, VPNsBroken by Shor's algorithm
Elliptic-curve (ECDH, ECDSA, Ed25519)TLS key exchange, Bitcoin and Ethereum signatures, IoTBroken by Shor's algorithm
Diffie-HellmanKey exchange, legacy VPNsBroken by Shor's algorithm
AES-256, SHA-256Bulk encryption, hashingWeakened only modestly by Grover's algorithm, still considered safe
ML-KEM, ML-DSA, SLH-DSA (FIPS 203, 204, 205)Post-quantum replacementsDesigned to resist quantum attack

What actually happens on Q-Day

Two things, and they are different problems. First, retroactive decryption: any traffic recorded before migration, under harvest now, decrypt later, can be read. Second, forgery: an attacker can forge signatures on certificates, software updates and transactions. Decryption is a privacy disaster. Forgery is an integrity disaster, and in industrial control it is the one that becomes physical, because a forged firmware update looks legitimate to a PLC.

Q-Day and Bitcoin

Bitcoin and Ethereum rely on elliptic-curve signatures, so a large enough quantum computer could derive private keys from exposed public keys. Coins whose public keys are already visible on chain are the most exposed. In August 2026 the first quantum-safe Bitcoin transaction was mined using a scheme that needs no soft fork, and BIP-360 proposes a longer-term upgrade path. My view, as published in TechNewsWorld, is that the transaction trick is clever but narrow.

The QSB trick leans on quirks of legacy Bitcoin script and doesn't port anywhere else.

Shujaatali Badami, TechNewsWorld, September 2026

How to prepare

  1. Inventory where RSA and elliptic-curve cryptography are used, including inside devices and vendors' products.
  2. Turn on hybrid post-quantum key exchange (classical plus ML-KEM) wherever your stack supports it, starting with links that carry long-lived secrets.
  3. Plan signature migration, especially for firmware and software updates.
  4. Require FIPS 203 and 204 support and crypto-agility in every new procurement.

For industrial systems, the ICS and OT migration guide walks through this zone by zone.

Frequently asked

What is Q-Day?

Q-Day is the day a cryptographically relevant quantum computer can break widely used public-key cryptography, RSA and elliptic-curve cryptography, using Shor's algorithm. It is sometimes called Y2Q.

When will quantum computers break RSA-2048?

No one knows. Resource estimates have fallen sharply, with a 2025 analysis putting it at under one million noisy qubits running for under a week. Most government planning dates cluster around 2030 to 2035, and some vendors claim earlier dates that most researchers treat as optimistic.

Will Q-Day break AES and SHA-256?

No. Grover's algorithm only modestly weakens symmetric cryptography and hashing. AES-256 and SHA-256 are still considered safe. The cryptography that breaks is public-key: RSA, Diffie-Hellman and elliptic-curve schemes.

Is Bitcoin safe from quantum computers?

Not indefinitely. Bitcoin uses elliptic-curve signatures, which a large quantum computer could break, so coins with exposed public keys are most at risk. Quantum-safe transaction schemes and proposals such as BIP-360 exist, but the network has not yet migrated.

What is a CRQC?

A cryptographically relevant quantum computer, meaning a quantum computer large and reliable enough to break real-world public-key cryptography. Today's quantum computers are not CRQCs.

Related