Skip to content

Topic

Post-Quantum Cryptography

Post-quantum cryptography covers cryptographic algorithms, such as ML-KEM and ML-DSA, designed to remain secure against attacks from quantum computers.

Current stories

security4 publishers

Cloudflare's planned certificate authority targets Q1 2027 for post-quantum Merkle Tree Certificates

Cloudflare plans to become a public certificate authority and start production issuance of post-quantum Merkle Tree Certificates in the first quarter of 2027. Teams planning a post-quantum migration now have an issuer-side date to test web PKI against.

Perspective Coverage

4 publishers
Builder
Builder 45%
Operator
Operator 45%
Investor
Investor 10%

Reality

Evidence50
Adoption8
Hype gap+30
Incentives
Insufficient
Confidence60
build1 publisher

One blog post reports an NSA post-quantum deadline of 2027 for national security systems

NSA has moved its post-quantum deadline for National Security Systems to 2027, two years ahead of Cloudflare, Google and Microsoft, a dev.to post reports. That account is secondhand, so whether suppliers to those systems have to re-plan their migrations depends on what the agency's own statement says.

Publishers:dev.to

Reality

Evidence15
Adoption
Insufficient
Hype gap+55
Incentives
Insufficient
Confidence30
security3 publishers

Just over half of PwC's 3,934 respondents call attacks on AI their biggest cyber gap

PwC surveyed 3,934 leaders and found 52% rank attacks on AI systems as their biggest cyber preparedness gap. Only 17% place AI risk with the CISO, so in most of the sample the security function does not own the threat it feels least ready for.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 57%
Investor
Investor 15%

Reality

Evidence55
Adoption35
Hype gap+15
Incentives40
Confidence60
invest1 publisher

Researchers forge RSA signatures from a hardware security module by making it sign 4 billion raw numbers

UC San Diego and INRIA researchers forged RSA signatures on a 1,024-bit key inside a hardware security module after about 4 billion signing requests. The key stayed inside the device throughout, so for custodians the exposure is in signing settings, starting with the FIPS mode the researchers switched off.

Publishers:decrypt.co

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40
invest2 publishers

Buterin expects Ethereum's 2027 Hegotá fork to be the last one a 2015 user would recognize

Vitalik Buterin says Ethereum's Hegotá upgrade, planned for 2027, is likely the last fork that someone who knew Ethereum in 2015 would recognize. The work he expects to follow has no dates yet, so ETH holders are pricing a long rebuild of the protocol off a single milestone.

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives35
Confidence55
build5 publishers

Go 1.27 lets you delete code: generic methods, four go fix modernizers, a leak profile

Generic methods collapse per-type API sprawl, go fix gains four modernizers, and the goroutineleak profile in runtime/pprof is now generally available. GoLand 2026.2 supports all three.

Publishers:blog.golang.orgblog.jetbrains.comdev.tolwn.netphoronix.com

Perspective Coverage

5 publishers
Builder
Builder 66%
Operator
Operator 34%
Investor
Investor 0%

Reality

Evidence72
Adoption
Insufficient
Hype gap+8
Incentives45
Confidence70
invest4 publishers

StarkWare put a quantum-safe bitcoin spend on mainnet, and priced it at $75 to $150

The construction runs inside today's Script limits, so no soft fork was needed. The cost of quantum defence moves instead onto the individual holder, at $75 to $150 per transaction.

Perspective Coverage

4 publishers
Builder
Builder 44%
Operator
Operator 34%
Investor
Investor 22%

Reality

Evidence62
Adoption5
Hype gap+18
Incentives50
Confidence60
security5 publishers

Seven national cyber agencies reframe post-quantum migration as an economic risk

The G7 Cyber Security Working Group's June call to action says the quantum threat is off the radar and under-resourced at most organizations, and it hands CISOs the wording to fund a cryptographic inventory this cycle.

Perspective Coverage

5 publishers
Builder
Builder 22%
Operator
Operator 55%
Investor
Investor 23%

Reality

Evidence72
Adoption30
Hype gap+10
Incentives60
Confidence68
product10 publishers

Apple's Reference Image mode signs a photo three times before it becomes a JPEG

The iPhone 18 Pro's Reference Image mode binds a photo to the sensor that captured it, then has Apple's cloud develop and sign the finished file. Apple's published account protects the original capture and stops at the edit.

Perspective Coverage

10 publishers
Builder
Builder 42%
Operator
Operator 45%
Investor
Investor 13%

Reality

Evidence55
Adoption12
Hype gap+30
Incentives65
Confidence60

Earlier coverage

  1. Google certified a quantum attack on elliptic curve cryptography without disclosing the algorithm

    Science · September 22, 2026 · 1 publisher

  2. TigerByte leaves stealth with $3M to bolt packet inspection onto legacy avionics

    Security · September 20, 2026 · 1 publisher

  3. Cloudflare swapped a years-old TLS guess for a daily probe of every origin

    Build · September 20, 2026 · 1 publisher

  4. Seal's only pre-release design review came from the agent that wrote much of its code

    Build · September 19, 2026 · 1 publisher

  5. Upgrading to JDK 27 switches TLS 1.3 handshakes to hybrid post-quantum key exchange

    Build · September 18, 2026 · 1 publisher

  6. DigiCert folds post-quantum migration into the 47-day certificate mandate

    Product · September 17, 2026 · 1 publisher

  7. Microsoft tests post-quantum TLS issuance with seven certificate authorities outside public trust

    Product · September 17, 2026 · 1 publisher

  8. EO 14412 gives US agencies until Dec. 31, 2030 to fix key establishment on high-value assets

    Product · September 17, 2026 · 1 publisher

  9. LGT put hybrid post-quantum key exchange in front of live online banking customers

    Product · September 17, 2026 · 1 publisher

  10. Java 27 couples post-quantum TLS 1.3 to two newly flipped JVM defaults

    Build · September 15, 2026 · 4 publishers

  11. Apple signs iPhone photos inside the camera hardware before software touches the pixels

    Security · September 16, 2026 · 1 publisher

  12. Apple's Reference Image mode signs photos with a key the camera sensor made in the factory

    Product · September 16, 2026 · 1 publisher

  13. Oracle's post-quantum backport reaches JDK 8 and 11 last, in the second half of 2027

    Product · September 15, 2026 · 1 publisher

  14. Fortaegis seats its contract manufacturer and Tokyo Electron's venture arm inside a $50M round

    Build · September 14, 2026 · 1 publisher

  15. Google's own post-quantum deadline runs two years ahead of the NSA's target

    Product · September 13, 2026 · 1 publisher

  16. Opting into quantum-ready Play signing invalidates the SHA-1 in your Android OAuth client

    Build · September 12, 2026 · 1 publisher

  17. More than 100 researchers with AI agents cut Bitcoin's quantum-attack benchmark sevenfold in two months

    Invest · September 11, 2026 · 2 publishers

  18. NIST sets 2030 and 2035 retirement dates for quantum-vulnerable algorithms, raising stakes for banks

    Leadership · September 11, 2026 · 1 publisher

  19. FINMA gives Swiss banks about a year to put a post-quantum plan before the board

    Invest · September 11, 2026 · 1 publisher

  20. Crowdsourced AI agents cut one step of a Bitcoin quantum attack by 86 per cent in about two months

    Invest · September 10, 2026 · 1 publisher

  21. A new IACR estimate sizes the secp256k1 break at 1,450 logical qubits and 40 million Toffoli gates

    Security · September 10, 2026 · 1 publisher

  22. IonQ's compiled secp256k1 break needs twice the qubits of its 2027 machine

    Security · September 10, 2026 · 1 publisher

  23. ISARA's chief executive would scope post-quantum migration by cryptography in live use

    Leadership · September 10, 2026 · 1 publisher

  24. A 2,420-byte DNSSEC signature overruns the UDP buffer DNS software commonly advertises

    Build · September 10, 2026 · 1 publisher

  25. Java 27 makes G1 the collector on the 1-CPU container that used to get Serial

    Build · September 10, 2026 · 1 publisher

  26. Google and Ethereum set 2029 dates one year ahead of NIST's ECDSA deprecation

    Invest · September 9, 2026 · 1 publisher

  27. IonQ credits SkyWater's standard lines with cutting its chip design cycle to two months

    Product · September 8, 2026 · 1 publisher

  28. IonQ's secp256k1 estimate spends 13 physical qubits on every logical one

    Build · September 8, 2026 · 1 publisher

  29. Ethereum's protocol cluster declined 28 of the 62 EIPs proposed for Hegota

    Invest · September 7, 2026 · 2 publishers

  30. The post-quantum signature NIST finalised runs 72 times the bytes of today's ECDSA

    Invest · September 4, 2026 · 2 publishers

  31. World open-sources ProveKit to keep age checks on the user's own phone

    Product · September 2, 2026 · 1 publisher

  32. A quantum-resistant bitcoin spend clears mainnet under today's consensus rules

    Product · August 30, 2026 · 1 publisher

  33. JDK 24 relocates the post-quantum blocker to your key custody plumbing

    Build · August 28, 2026 · 1 publisher

  34. Bitcoin's first post-quantum signature BIP arrives with its tradeoffs already conceded

    Invest · August 26, 2026 · 1 publisher

  35. The quantum race stopped being about money. It now hands boards two dates: 2029 and 2030

    Leadership · August 26, 2026 · 1 publisher

  36. TCG hands hardware buyers a version number: PC Client TPM Profile 1.07

    Build · August 25, 2026 · 1 publisher

  37. Red Hat counted 572 quantum-vulnerable spots in OpenStack. The obstacle is OpenStack's own pins.

    Product · August 25, 2026 · 1 publisher

  38. Ethereum's quantum plan gets a one-way switch: draft EIP would retire BLS for good

    Invest · August 25, 2026 · 1 publisher

  39. TCG writes down what "quantum-safe TPM" means, and buyers finally get a document to argue with

    Security · August 24, 2026 · 2 publishers

  40. Harvest now, decrypt soon: post-quantum migration is a funded program, not a research topic

    Leadership · August 21, 2026 · 1 publisher