up:: Start Here
What’s actually happening?
Someone is copying scrambled data off the internet and keeping it in storage until a machine exists that can unscramble it. That’s the whole thing in one sentence, and everything below explains how each part of it works.
It takes about 5 minutes to read, assumes nothing, and by the end you’ll understand this better than most people currently writing about it.
The short version:
- Your data travels scrambled, so anyone intercepting it sees nothing readable.
- The scrambling rests on arithmetic that’s quick forwards and effectively impossible to reverse.
- A quantum computer can reverse one specific kind of that arithmetic. The method was published in 1994.
- Nobody’s built a machine big enough yet, so people are copying the scrambled data now and storing it.
- Storage is cheap, so waiting 10 or 15 years costs almost nothing.
- The replacement encryption is finished and already rolling out, and today’s version retires after 2030 and is banned after 2035.
Step 1: what happens when you send something?
When you message someone, check your balance, or open a medical portal, that information crosses cables and networks owned by other companies. It travels scrambled, so anybody watching sees nothing readable.
That scrambling does two jobs at once: it keeps the contents private, and it proves the thing at the other end really is your bank rather than someone pretending. Both matter, and the second one is the job most people never think about.
Full detail at What is encryption?
Step 2: why can’t anyone unscramble it?
Multiply two large prime numbers together and a computer answers instantly. Give that same computer only the answer and ask which two primes made it, and it’ll still be working long after the sun burns out.
That gap is the entire protection. The easy direction is public; the hard direction is the secret. Not a rule, not a policy, and not a promise from a company. Just arithmetic that takes too long to undo.
Step 3: what changes with a quantum computer?
A quantum computer works differently from an everyday one. Instead of testing possibilities one at a time, it holds many at once and steers them so the wrong answers cancel out and the right one remains.
For almost everything people use computers for, that gains nothing. For a short list of specific mathematical problems it’s devastating, and reversing the arithmetic above is on that list.
A mathematician named Peter Shor published the exact method in 1994. It’s been public and checked for over 30 years. Nobody’s disputing whether it works.
Full detail at What’s a quantum computer?
Step 4: if the machine doesn’t exist, why is this happening now?
Here’s where it stops being a future problem.
Building a machine large and stable enough to run Shor’s method is genuinely hard, and nobody’s done it. Current machines are orders of magnitude short.
But you don’t need the machine to start collecting. Scrambled data copied today can sit in storage until the machine arrives, and then all of it becomes readable at once, going back to whenever the collecting started. Storing very large amounts of data costs a fraction of a cent per gigabyte per month, so waiting a decade is an everyday business expense.
Three U.S. federal agencies described this in published guidance in 2023, warning that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.”
Source: Quantum-Readiness: Migration to Post-Quantum Cryptography, CISA, NSA, and NIST joint factsheet, August 21, 2023.
Step 5: would anyone tell you?
Copying scrambled data breaks nothing. No file is deleted, no account is accessed, no system misbehaves, and no security tool has anything to detect. From your side the day is completely everyday.
With no incident, a company has nothing to report and the law requires nobody to tell you. Every breach-notification law ever written is built around a break-in that this doesn’t involve.
Full detail at Will anyone ever tell me if it happens?
Step 6: does this matter for everything you send?
This is the part that turns an alarming story into a manageable one.
Someone storing your data for 10 years only profits if it’s still worth something when they open it. Your dinner plans won’t be. A genome, a set of fingerprints, a medical history, and immigration paperwork will be, because none of those can be changed or expire.
So the question that sorts your entire digital life is: in 15 years, would this still be sensitive? Most of what you send fails that test, which is genuinely good news.
Full detail at What of mine is actually worth stealing?
Step 7: is anything being done about it?
NIST published replacement encryption standards in August 2024, after a multi-year open international competition. The replacements run on everyday computers.
Rollout started before most people heard about any of this. Signal upgraded in 2023, Apple in February 2024, and the major browsers between November 2024 and February 2025. If your phone and browser are current, some of your traffic is already protected.
What can’t update itself is the problem: pacemakers, insulin pumps, cars, and industrial equipment carry encryption fixed at manufacture, with service lives running past the deadlines.
Full detail at Did my phone already fix this?
Step 8: what’s already on the calendar?
| Date | What happens |
|---|---|
| August 2024 | Replacement standards published |
| 2030 | Today’s encryption deprecated in the U.S., and banned outright in Australia |
| 2035 | Today’s encryption disallowed in the U.S. |
Source: NIST, August 13, 2024; NIST IR 8547 (Initial Public Draft), November 2024; Australian Signals Directorate, “Guidelines for cryptography,” cyber.gov.au.
Those arrive whether or not a machine does, because governments concluded that waiting for certainty would leave no time to act on it.
How many people, and how much of the internet?
Everyone who uses the internet is affected, because the encryption in question is what secure connections are built from.
| Figure | Number | Source |
|---|---|---|
| People using the internet, 2025 | 6 billion, 74% of the world’s population | ITU, Facts and Figures 2025 |
| Share of secure web connections relying on the vulnerable half | Effectively all of them, except those upgraded to the new key exchange | Structural, see below |
| People whose DNA sits in commercial databases | 26 million+ by the start of 2019, projected past 100 million within 24 months | MIT Technology Review |
| People exposed in one genetic-data incident | 6.9 million, from 14,000 compromised accounts | Texas Attorney General |
| People exposed in the Equifax breach | 147 million, including 145.5 million Social Security numbers | FTC |
| U.S. homebuyers holding a 30-year mortgage | Nearly 90% | Freddie Mac |
| Likelihood of a capable machine within 15 years | 51% to 70% | Global Risk Institute, 2025 survey |
| Estimated qubits to break RSA-2048 | 20 million in 2019, under 1 million in 2025 | Gidney and Ekerå; Gidney |
| When today’s encryption retires | Deprecated after 2030, disallowed after 2035 | NIST IR 8547 |
Sources for each row appear in the sections below.
Why “effectively all of them” is the honest answer for the internet. Every secure connection made today, to a bank, a hospital portal, an email provider, or any site showing a padlock, has to do the two jobs described in the next section: prove the other side is who it claims, and agree on a secret. Until a connection is upgraded to the new post-quantum method, both of those jobs run on the mathematics that breaks. That is the default state of the web, and it is what the migration is changing.
The share already upgraded is climbing quickly and changes month to month, which is why no fixed percentage belongs here. Cloudflare publishes a live measurement of how much web traffic is protected with post-quantum encryption at Cloudflare Radar, and reading it at the moment of writing gives the current split. Whatever share is protected, the remainder is running on the vulnerable half.
Source: ITU, Measuring digital development: Facts and Figures 2025, itu.int; live adoption measurement, Cloudflare Radar. Current platform status at Cloud and Browser PQC Status.
So what should you take from all this?
Three things.
It’s real, and it’s not urgent for most of what you do. The people who tell you everything is at risk and the people who tell you it’s all hype are both wrong, and the truth sits in a specific, checkable middle.
The exposure is decided by time, not by technology. How long your data stays sensitive is the only variable that matters, and you already know the answer for your own life.
Almost all the repair happens above your head. Keep your devices updated, be careful about the permanent things like DNA, and don’t buy anything. See What should I actually do?
Questions people ask
Is someone definitely copying my data? Nobody can prove it for any specific person, and the collection is passive, cheap, and described in federal guidance as a present-day activity. The defensible assumption is that long-lived records crossing networks are reachable.
Do I need to do something today? Keep your devices updated, and think carefully before anything permanent like a DNA test. That’s genuinely most of it.
Is my bank account at risk? No. Reading old traffic reveals information about you, and it doesn’t hand anyone access to your money.
Could this all turn out to be nothing? It’s possible, and the honest case for that is at Is this overhyped?
Where to go next
- Is this overhyped? states the strongest argument against everything above.
- When is this going to happen? has the actual forecast numbers.
- What’s at risk sorts your own information.
- What to do is the short list.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.