Threat intelligence · every claim sourced · verified Sept 29, 2026

Counting down to Q-Day

Q-Day is the day a cryptographically-relevant quantum computer can run Shor's algorithm against real elliptic-curve keys — the day exposed public keys become spendable private keys. Nobody knows the date. This lab gives you the honest horizon: sourced estimates, a wallet-exposure simulator, and where every major chain actually stands. Quantus was built for this day. Most chains are still scheduling the meeting.

NIST standardFIPS 204 (ML-DSA), Aug 2024
BTC pubkey-exposed>34% of supply
Google horizonQ-Day by 2029
Quantus sigsML-DSA from genesis

The Q-Day clock

Pick a scenario. The clock counts to a planning horizon, not a prediction — estimates span 2028 to “maybe never”, and every marker below is sourced.

—days
—hours
—minutes
—seconds
Honest-label policy. No single Q-Day date is “the” estimate. IonQ publicly targets a cryptographically-relevant machine by 2028 (the most aggressive claim); Google/Microsoft/IBM cluster around 2029; Justin Drake puts a ≥10% chance on exposed-key recovery by 2032; many researchers say later, some say never. The default view shows the 2029 industry-benchmark horizon.

Wallet-exposure simulator

Would your coins survive Q-Day? Pick a chain, describe the wallet, enter an amount — the lab scores the exposure from the public-key rules that actually matter. Nothing here touches a real wallet.

—Run the simulator
At risk at Q-Day—
Why—
Crack-time framing—
What to do—

Chain readiness table

Where the majors stand on post-quantum signatures, as of Sept 29, 2026. Statuses reflect production reality, not roadmaps.

ChainSignatures todayStatusThe plan

What actually breaks

Two quantum algorithms, two very different threat levels. The signature is the weak link — not the hash.

Shor's algorithm
Existential for exposed keys

Breaks RSA, ECDSA, Schnorr and EdDSA by solving the discrete-log / factoring problems in polynomial time. Given an exposed secp256k1 public key, a fast-clock cryptographically-relevant machine could derive the private key in roughly 9–12 minutes (Google's on-spend-attack analysis) — and for keys exposed years ago, there is no time limit at all. This is the attack that ends coins at P2PK outputs, reused addresses, Taproot outputs, and any EOA that has ever spent.

Grover's algorithm
Annoying, not catastrophic

Quadratic speedup on unstructured search: SHA-256 goes from 256-bit to an effective 128-bit. Still the standard security floor everywhere else. Proof-of-work survives. Never-spent hashed addresses survive. The 21M supply cap survives — quantum enables theft of exposed coins, never minting of new ones. Hash-based schemes (SLH-DSA, Winternitz one-time signatures) are built on exactly this hardness, which is why NIST standardized them as the conservative backup.

The rule: never-spent P2PKH / P2WPKH addresses are quantum-safe today — only a hash is on-chain. The public key is revealed the moment you spend, and from that moment the exposure never expires.

Quantum milestone timeline

From quantum supremacy to the 2030s horizon — past milestones verified, future ones are the industry's own stated targets.

Sources

Every claim above traces to one of these. Re-verified Sept 29, 2026; estimates and roadmaps move — check the live sources before acting on them.

    Honest-label policy. Q-Day dates are estimates made by the cited parties, never this lab's prediction. Bitcoin's >34% exposure figure is from BIP-361 (Mar 1, 2026 data); CryptoQuant's independent estimate is ~6.9M BTC. Chain statuses reflect production reality as of Sept 29, 2026. Crack-time figures describe a hypothetical fast-clock machine, not hardware that exists today.