mekiba Open the terminal →
01Quantum riskHarvest now, decrypt later

Encrypted today.
Readable tomorrow?

Traffic and data protected with classical key exchange can be recorded now and kept. A large quantum computer running Shor's algorithm could decrypt it later. Move the lens to see what a future attacker would read, then switch to ML-KEM.

Captured session · 0x7F2A
Lens: Shor's algorithm on a hypothetical CRQC Result: plaintext recovered

Illustration only. No quantum computer today can break ECDH, secp256k1 or Ed25519. The risk is data recorded now and decrypted once such a machine exists. ML-KEM (NIST FIPS 203) has no known efficient quantum attack. CRQC = cryptographically relevant quantum computer.

02CryptographyWhat breaks, what holds

Not all crypto
fails the same way

Shor's algorithm breaks the public-key math behind today's wallets and TLS. Grover's algorithm only halves the strength of symmetric ciphers and hashes. The new NIST standards are built on problems with no known efficient quantum attack.

Security level, in bits
Scale: 0 to 256 bits · tick = classical level Grover figures are idealized; real attacks are slower
03WalletsAre you exposed?

Your address hides
your key. Until you send.

Most addresses are a hash of a public key, and Shor's algorithm needs the key itself. The key becomes public the first time you sign a transaction, and it stays on chain for good.

Life of an addressStep 1 / 3
01 · Receive

Only a hash

0x7a3f9c2e4d18b07e55a1c3f0b41c91e

On chain there is only your address, a hash of the public key. Shor's algorithm has nothing to work on yet.

02 · Send

Key goes public

04 9b2c 61fe a03d 7c15 e8b4 2f97 d6a0 31c8 5e7b 0d44 92af

Your signature lets anyone recover the public key. From now on it is permanently visible on chain.

03 · CRQC, hypothetical

Key derived

e3 1f 8a 07 c2 59 b4 6d ...

A large enough quantum computer could derive the private key from the public key. None exists today.

Chain · address typeWhen the public key appears
Ethereum, Base, Robinhood Chain · EVM accountsAfter 1st sendWith the first outgoing transaction
Bitcoin · P2PKH, P2WPKHOn spendWhen coins at that address are spent
Bitcoin · P2PK, P2TR (Taproot)AlwaysFrom the first deposit, the key is in the output
SolanaAlwaysThe address is the Ed25519 public key

Quantum Scan checks a public address for exactly this, read-only, without asking for keys or signatures.

How Quantum Scan works
04TimelineSourced, not hyped

From theory
to deadlines

Thirty years of milestones, from the first algorithm to NIST's planned retirement of RSA and elliptic curves. Resource estimates are research results, not machines that exist.

  1. 1994

    Peter Shor publishes a quantum algorithm that factors integers and computes discrete logarithms in polynomial time. It breaks RSA and elliptic curves in theory.arXiv quant-ph/9508027

  2. 1996

    Lov Grover shows a quadratic speedup for unstructured search, which halves the effective strength of symmetric keys.arXiv quant-ph/9605043

  3. Dec 2016

    NIST opens its public process to standardize post-quantum cryptography.NIST CSRC

  4. Jul 2022

    NIST selects CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and Falcon.NIST, 5 Jul 2022

  5. 13 Aug 2024

    FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) become official standards.NIST, 13 Aug 2024

  6. Nov 2024

    NIST IR 8547 draft: RSA and elliptic curves at 112-bit strength deprecated after 2030, all of them disallowed after 2035.NIST IR 8547, initial public draft

  7. Mar 2025

    NIST selects HQC as a backup key-encapsulation algorithm next to ML-KEM.NIST, 11 Mar 2025

  8. May 2025

    Estimate: RSA-2048 could be factored with fewer than one million noisy qubits in under a week, down from 20 million in 2019.Gidney, arXiv 2505.15917

  9. Mar 2026

    Estimate: 256-bit elliptic curves, including secp256k1, with fewer than 500,000 physical qubits in minutes. It assumes hardware speeds not yet demonstrated.Google Quantum AI, Ethereum Foundation, Stanford

  10. Today

    No quantum computer can run these attacks. The estimates keep falling, and recorded data does not expire.

  11. 2030

    Planned: RSA-2048 and P-256 class algorithms deprecated in NIST guidance (draft).

  12. 2035

    Planned: RSA and elliptic-curve cryptography disallowed in NIST guidance (draft).