Cybersecurity · Encryption · Q-Day
The Quantum Countdown: Encrypted Data Harvested Today Could Collapse Banks, Power Grids and the Internet
A news investigation into harvest now, decrypt later, Shor’s algorithm, NIST post-quantum cryptography, and why the most valuable data breach in history may already be sitting in a vault — waiting for a quantum computer.
Somewhere in climate-controlled vaults, encrypted messages intercepted over the last decade are being stored, cataloged and held against the day a faster machine can finally read them. Most people still assume that modern encryption is a lock that lasts forever. It is not. Intelligence agencies have spent years practicing harvest now, decrypt later: copy the ciphertext today, wait for a quantum computer tomorrow, and open everything at once. The most valuable data breach in history has not happened yet. The copies may already exist.
That waiting game is no longer science fiction. Quantum computers use the laws of quantum mechanics to solve problems that would take today’s supercomputers millions of years. In 2024 the Global Risk Institute estimated a 19 to 34 percent chance that, by 2034, a machine powerful enough to break public-key encryption will exist. If those forecasts are even roughly right, the fallout will not stop at private messages. Researchers warn of failing infrastructure, frozen financial markets, and a world in which passwords and digital certificates suddenly mean nothing.
This is how the failure cascade is expected to play out when the clock hits zero.
When identity on the internet stops meaning anything
At T-minus 0, identity fails first. Every secure website, banking app, software update and VPN depends on digital certificates — online identity cards that prove a server is who it claims to be. Those certificates are guarded by encryption so strong that even the world’s fastest supercomputers would need longer than the age of the universe to crack them. A quantum computer running Shor’s algorithm would change that arithmetic. Fake sites could impersonate banks. A forged software update could be pushed to millions of machines, and every one of them would accept it as genuine. Break a single certificate authority and systems beneath it start to lie.
T-plus two hours: the power grid believes a lie
At T-plus two hours, the damage reaches the physical world. Much of the electrical grid still runs on decades-old industrial control systems built when forged commands were not a realistic threat. Safety relays can be tricked into tripping. Substations shut down in response to instructions they believe are legitimate. Grid operators face a no-win choice: trust systems they can no longer verify, or run the network by hand. Cities go dark. Hospitals fall back on generators. Recovery happens one section at a time.
T-plus 12 hours: SWIFT, banks and $5 trillion a day
When the clock hits T-plus 12 hours, money stops moving. The global financial system depends on authenticated digital messages to verify transfers between banks. Every day the SWIFT network routes around $5 trillion — more than Japan’s entire yearly output. If institutions cannot be certain a transfer is real, trading floors freeze and supply chains seize up. In early 2026, Citi modeled what would happen if just one of America’s five largest banks lost access to the rails that move money between institutions. A single-day attack could cost $2 trillion to $3.3 trillion, a 10 to 17 percent drop in U.S. output, and a six-month recession. That is one bank. In one day.
The padlock in the address bar was holding far more than a login form. It was holding the internet together.
Harvest now, decrypt later
At T-plus 48 hours, the second shock arrives. For years, governments harvested encrypted traffic that remained locked behind mathematics. Those walls vanish. Archived emails, diplomatic cables, weapons designs and financial arrangements become readable. To most people none of this looks like cryptography. A card is declined. A hospital reverts to paper. A banking app still opens; it simply cannot tell a real bank from an impostor.
The disaster does not begin on the day the quantum computer arrives. It began years earlier. In 2021 the NSA said adversaries were already harvesting encrypted data and waiting for the key. Other intelligence services are doing the same. Vast volumes of the world’s traffic still flow through undersea fiber-optic cables, a bottleneck that makes bulk collection practical. Storage is cheap. For a state actor, warehousing petabytes of intercepted ciphertext costs almost nothing next to the value of what might later be unlocked. Updating encryption when the machine arrives will protect future messages. It will not rescue data already copied. The clock starts the day the information was sent, not the day the lock is picked.
Shor’s algorithm and the shrinking qubit count
The lock itself depends on a lopsided property of numbers. Multiplying two enormous primes is easy; factoring the product is, for classical machines, effectively impossible. That one-way function underpins credit-card forms, bank logins, private messages and passport chips. Shor’s algorithm finds the hidden period inside those giant numbers and reverses the trap. Early estimates said tens of millions of qubits would be required. In May 2025 a Google researcher showed the job might be done with fewer than one million. A year later, published figures dropped below 100,000. None of this means the codebreaker exists today. IBM’s largest quantum processors still sit a little above 1,100 qubits, fragile and error-prone. A machine that can break real-world encryption could take another decade. It is getting closer.
NIST’s new locks: ML-KEM, ML-DSA and cryptographic agility
That is why a race is on to rebuild the locks. For eight years the U.S. National Institute of Standards and Technology ran a global competition. In August 2024 NIST published the first post-quantum cryptography standards: ML-KEM to establish a secure connection and ML-DSA to prove that connection is authentic. The new schemes hide keys in high-dimensional lattices obscured by mathematical noise. Google switched Chrome. Apple rebuilt iMessage. Cloudflare, Amazon and Signal have moved, often without users noticing. A 2022 U.S. law ordered federal agencies to replace vulnerable cryptography by 2035. Banks have been told not to wait. The warning is already on the record: an algorithm called SIKE, once a leading candidate, was broken in about an hour by an ordinary computer. The lesson is cryptographic agility — design systems so algorithms can be swapped like a tire.
The $1 trillion upgrade — and the devices left behind
Inventing a better lock was never the hard part. Replacing the old one is. The internet is billions of devices and decades of software never designed for a change this large. The U.S. government expects to spend $7.1 billion upgrading civilian systems alone. Spread the same job across every bank, hospital and power company and estimates climb past $1 trillion — larger than the Y2K cleanup. The new quantum-proof keys are larger and hungrier. A laptop will not notice. A smart meter, a pacemaker or a pipeline sensor expected to run fifteen years on one battery may not carry the extra weight. For years, systems will run both locks at once. Many devices will never be upgraded at all.
China’s satellite bet: quantum key distribution
While Western networks are patched one appliance at a time, China has pursued physics rather than software. Quantum key distribution encodes keys in particles of light. Measuring those photons disturbs them, so eavesdropping leaves a fingerprint. In March 2025 Chinese scientists used the Jinan-1 satellite to share such a key between stations near Beijing and Cape Town, roughly 8,000 miles apart. On the ground, about 1,200 miles of dedicated quantum fiber already connect Beijing and Shanghai. That is not a browser update. It requires special hardware, dedicated fiber or a satellite link. A handful of nations will protect their most sensitive traffic with the laws of physics. Everyone else remains on the open internet, patching and hoping.
The end of taking digital trust for granted
For half a century digital security rested on a faith that some mathematical doors were locked forever. Those problems were never impossible — only impossible for the computers we knew how to build. A quantum computer is not a faster laptop. On these problems it walks through doors that looked sealed. Passwords will not vanish overnight, but they will no longer be enough. Passkeys, fingerprints, faces and hardware security keys move proof of identity back into the physical world. Estonia already keeps state records in an offline data embassy abroad. Privacy and proof are no longer the default. They are things we will have to build, on purpose, into everything we make. The age of assuming the locks would simply hold is over.