When is Q-Day?
Nobody knows, and anyone who gives a single year is guessing. What has changed since 2025 is the direction of travel. Resource estimates for breaking RSA-2048 have fallen sharply: Craig Gidney's 2025 analysis put it at under one million noisy qubits running for under a week. In March 2026 Google moved its own post-quantum migration deadline to 2029, and in September 2026 IonQ's chief executive claimed 2028, a claim most researchers treat as optimistic. Government planning dates cluster around 2030 to 2035.
The honest summary is a probability distribution, not a date: low but rising odds before 2030, and a meaningful chance in the early to mid 2030s. For planning purposes that is enough. See Mosca's inequality for why the exact year matters less than it seems.
What breaks on Q-Day, and what does not
| Cryptography | Used for | On Q-Day |
|---|---|---|
| RSA | TLS certificates, code signing, VPNs | Broken by Shor's algorithm |
| Elliptic-curve (ECDH, ECDSA, Ed25519) | TLS key exchange, Bitcoin and Ethereum signatures, IoT | Broken by Shor's algorithm |
| Diffie-Hellman | Key exchange, legacy VPNs | Broken by Shor's algorithm |
| AES-256, SHA-256 | Bulk encryption, hashing | Weakened only modestly by Grover's algorithm, still considered safe |
| ML-KEM, ML-DSA, SLH-DSA (FIPS 203, 204, 205) | Post-quantum replacements | Designed to resist quantum attack |
What actually happens on Q-Day
Two things, and they are different problems. First, retroactive decryption: any traffic recorded before migration, under harvest now, decrypt later, can be read. Second, forgery: an attacker can forge signatures on certificates, software updates and transactions. Decryption is a privacy disaster. Forgery is an integrity disaster, and in industrial control it is the one that becomes physical, because a forged firmware update looks legitimate to a PLC.
Q-Day and Bitcoin
Bitcoin and Ethereum rely on elliptic-curve signatures, so a large enough quantum computer could derive private keys from exposed public keys. Coins whose public keys are already visible on chain are the most exposed. In August 2026 the first quantum-safe Bitcoin transaction was mined using a scheme that needs no soft fork, and BIP-360 proposes a longer-term upgrade path. My view, as published in TechNewsWorld, is that the transaction trick is clever but narrow.
The QSB trick leans on quirks of legacy Bitcoin script and doesn't port anywhere else.
Shujaatali Badami, TechNewsWorld, September 2026How to prepare
- Inventory where RSA and elliptic-curve cryptography are used, including inside devices and vendors' products.
- Turn on hybrid post-quantum key exchange (classical plus ML-KEM) wherever your stack supports it, starting with links that carry long-lived secrets.
- Plan signature migration, especially for firmware and software updates.
- Require FIPS 203 and 204 support and crypto-agility in every new procurement.
For industrial systems, the ICS and OT migration guide walks through this zone by zone.