The Silent Breakthrough

Scientists publish breakthroughs. Intelligence agencies exploit them.

The thinking goes like this. Quantum computing is hard. Progress happens in universities and corporate labs. When someone achieves cryptographic relevance, they'll publish papers, claim prizes, make announcements. We'll have time to prepare.

This model works for academic research, where success means publication. Scientists share results to establish priority and attract funding.

But nation-states operate by different rules. For intelligence agencies, success means silence.

The Economics of Secrecy

Consider the incentives. A quantum computer that breaks elliptic curve cryptography (the math protecting Bitcoin and most of the internet) is not a scientific achievement to be celebrated. It's a strategic weapon.

Such a machine lets its owner read encrypted communications of foreign governments. Access financial systems. Monitor adversaries without detection.

This advantage survives only as long as targets don't know it exists. The moment you announce the capability, every target upgrades their cryptography. The weapon becomes useless.

The rational move is obvious: stay silent, exploit the capability, and let the world believe the threat is still theoretical.

The Gap Between Public and Classified

This creates a dangerous information asymmetry. Public research timelines show steady progress toward fault-tolerant quantum computers, with estimates ranging from 5 to 15 years out. We treat these estimates as ground truth.

They're not. Classified programs operate with larger budgets, specific objectives, and zero publication requirements. If a cryptographically relevant quantum computer exists, we will not learn about it from a press release.

The Attack Is Already Happening

This matters because of how quantum attacks work in practice.

Traditional hacks are visible. Someone breaks in, exfiltrates data, and you notice the breach. You can respond.

Quantum attacks follow a different pattern: harvest now, decrypt later. Adversaries are already copying encrypted traffic and storing it. Bank transactions, medical records, private keys, state secrets. All of it archived, waiting.

When a quantum computer capable of breaking current encryption comes online, there's no intrusion to detect. The data was captured years ago. The attacker simply runs the decryption and reads everything at once.

By the time you know the threat is real, the breach already happened.

Waiting Is Not a Strategy

Many organizations plan to address quantum risk "when it becomes urgent." This fails for two reasons:

  • First, the urgency will never be publicly visible. The actors most likely to achieve quantum advantage have every incentive to hide it.
  • Second, cryptographic migration takes years. Coordinating key changes, updating protocols, and validating security across complex systems is slow work. Starting after confirmation means finishing long after compromise.

The Only Question That Matters

"When will quantum computers break encryption?" is the wrong question. Nobody outside classified programs knows the answer, and those who know won't tell.

The right question: "What happens if this capability exists today?"

We cannot control when the machine arrives or who builds it first. We can only control our own systems.

Quantus exists because sovereign internet money must survive the quantum era. We use NIST-standardized post-quantum cryptography (ML-DSA-87) now, not when the threat becomes undeniable. By then, it's too late.