Encrypted today.
Readable tomorrow?
Traffic and data protected with classical key exchange can be recorded now and kept. A large quantum computer running Shor's algorithm could decrypt it later. Move the lens to see what a future attacker would read, then switch to ML-KEM.
Illustration only. No quantum computer today can break ECDH, secp256k1 or Ed25519. The risk is data recorded now and decrypted once such a machine exists. ML-KEM (NIST FIPS 203) has no known efficient quantum attack. CRQC = cryptographically relevant quantum computer.
Not all crypto
fails the same way
Shor's algorithm breaks the public-key math behind today's wallets and TLS. Grover's algorithm only halves the strength of symmetric ciphers and hashes. The new NIST standards are built on problems with no known efficient quantum attack.
Your address hides
your key. Until you send.
Most addresses are a hash of a public key, and Shor's algorithm needs the key itself. The key becomes public the first time you sign a transaction, and it stays on chain for good.
Only a hash
On chain there is only your address, a hash of the public key. Shor's algorithm has nothing to work on yet.
Key goes public
Your signature lets anyone recover the public key. From now on it is permanently visible on chain.
Key derived
A large enough quantum computer could derive the private key from the public key. None exists today.
| Chain · address type | When the public key appears |
|---|---|
| Ethereum, Base, Robinhood Chain · EVM accounts | After 1st sendWith the first outgoing transaction |
| Bitcoin · P2PKH, P2WPKH | On spendWhen coins at that address are spent |
| Bitcoin · P2PK, P2TR (Taproot) | AlwaysFrom the first deposit, the key is in the output |
| Solana | AlwaysThe address is the Ed25519 public key |
Quantum Scan checks a public address for exactly this, read-only, without asking for keys or signatures.
How Quantum Scan worksFrom theory
to deadlines
Thirty years of milestones, from the first algorithm to NIST's planned retirement of RSA and elliptic curves. Resource estimates are research results, not machines that exist.
- 1994
Peter Shor publishes a quantum algorithm that factors integers and computes discrete logarithms in polynomial time. It breaks RSA and elliptic curves in theory.arXiv quant-ph/9508027
- 1996
Lov Grover shows a quadratic speedup for unstructured search, which halves the effective strength of symmetric keys.arXiv quant-ph/9605043
- Dec 2016
NIST opens its public process to standardize post-quantum cryptography.NIST CSRC
- Jul 2022
NIST selects CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and Falcon.NIST, 5 Jul 2022
- 13 Aug 2024
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) become official standards.NIST, 13 Aug 2024
- Nov 2024
NIST IR 8547 draft: RSA and elliptic curves at 112-bit strength deprecated after 2030, all of them disallowed after 2035.NIST IR 8547, initial public draft
- Mar 2025
NIST selects HQC as a backup key-encapsulation algorithm next to ML-KEM.NIST, 11 Mar 2025
- May 2025
Estimate: RSA-2048 could be factored with fewer than one million noisy qubits in under a week, down from 20 million in 2019.Gidney, arXiv 2505.15917
- Mar 2026
Estimate: 256-bit elliptic curves, including secp256k1, with fewer than 500,000 physical qubits in minutes. It assumes hardware speeds not yet demonstrated.Google Quantum AI, Ethereum Foundation, Stanford
- Today
No quantum computer can run these attacks. The estimates keep falling, and recorded data does not expire.
- 2030
Planned: RSA-2048 and P-256 class algorithms deprecated in NIST guidance (draft).
- 2035
Planned: RSA and elliptic-curve cryptography disallowed in NIST guidance (draft).