Latest Quantum Security, PQC, Post-Quantum, Crypto-Agility News
-
Sep- 2026 -11 SeptemberQuantum Security & PQC
Cloudflare’s 1.1.1.1 Now Validates Post-Quantum DNSSEC Signatures – And Shows Why PQC Migration Is a Systems Problem
Cloudflare enabled ML-DSA-44 DNSSEC validation on its 1.1.1.1 resolver. No other major public resolver has announced equivalent support. The move exposes transport, downgrade, and chain-of-trust challenges that will define PQC migration beyond TLS.
Read More » -
10 SeptemberResearch
Chip-Based QKD Has a Glow Problem: VOA Luminescence Creates a Side Channel That Standard Security Analyses Miss
A peer-reviewed study finds that variable optical attenuators in integrated QKD chips emit unintended light near 1107 nm. The emission creates a wavelength-resolved side channel that standard BB84 security analyses do not account for, and the modeled impact on key rates is severe.
Read More » -
8 SeptemberResearch
IonQ Compiles Shor’s Attack on secp256k1 Down to 19,397 Ions and 26 Days per Attempt
IonQ has compiled a full ECDLP-256 attack to a trapped-ion design that does not exist, charging every Clifford, measurement and ion transport. The accounting is the most detailed I have seen. The error rates, cycle time and machine are assumptions.
Read More » -
4 SeptemberQuantum Security & PQC
G7 Tells Every Organization to Start PQC Migration – But the Procurement Signal Matters More Than the Headline
The G7 Cybersecurity Working Group's September 2026 call to action urges all organizations to begin PQC migration. The document is guidance, not regulation, but its procurement and supply chain language carries real consequences for enterprises and their vendors.
Read More » -
Aug- 2026 -29 AugustQuantum Security & PQC
First Quantum-Safe Bitcoin Transaction: What QSB Proves
The first quantum-safe Bitcoin transaction was confirmed on mainnet on 26 August, built by StarkWare's Avihu Levy using hash-based constructions within existing consensus rules. The method protects individual holdings but cannot help the six million BTC with public keys already exposed on-chain.
Read More » -
17 AugustQuantum Security & PQC
An Incomplete FO Check Turned wolfSSL’s ML-KEM Into Key Recovery
A researcher recovered 98% of an ML-KEM-1024 private key from wolfSSL's shipped binaries using a few hundred chosen ciphertexts. The bug was in hand-written SIMD assembly, patched in version 5.9.2.
Read More » -
15 AugustQuantum Security & PQC
The Ethereum Foundation Spent Eight Years on a Hash Its Roadmap No Longer Needs
Binary-field proof systems made standard hashes cheap enough to prove that Ethereum's exotic one lost its reason to exist. Nobody broke it. An eight-year research bet was retired in a single post.
Read More » -
13 AugustQuantum Security & PQC
Google Cloud Put Dates on Its PQC Migration. Signatures Trail Confidentiality by a Year.
Google Cloud has attached target years to 19 service-level roadmap entries running through 2029. Store-now-decrypt-later mitigation is due in 2027, signatures and key-management foundations in 2028.
Read More » -
10 AugustQuantum Security & PQC
A New Classic McEliece Distinguisher Undercuts Generic Decoding. It Is Not a Break.
No security claim has fallen and the scheme is not broken. What fell is the quantitative argument that made structural attacks easy to set aside, because one now costs less than generic decoding on every NIST parameter set.
Read More » -
10 AugustQuantum Security & PQC
RFC 10024 Finalizes Hybrid Post-Quantum TLS — The Standard the Internet Was Already Running
RFC 10024 standardizes the hybrid post-quantum key agreement mechanisms for TLS 1.3 that browsers and CDNs have been running since late 2024. The "still a draft" objection to X25519MLKEM768 is now gone.
Read More » -
7 AugustPost-Quantum, PQC, Quantum Security
Two QFT Records in Four Months. Neither Gets You Closer to Breaking RSA.
Two compilation teams claimed the largest quantum Fourier transform ever run, four months apart, on the same IBM chip. Their circuits and metrics are not comparable, and the gate counts explain why.
Read More » -
6 AugustQuantum Security & PQC
A Peer-Reviewed CRYPTO 2026 Paper Just Gave ML-KEM’s Foundation a New Quantum Target
Wen and Zheng prove Module-LWE quantum-polynomially equivalent to a structured dihedral problem and reduce it to EDCP. The result maps ML-KEM's mathematical foundation into territory three research groups are actively probing with quantum algorithms.
Read More » -
6 AugustQuantum Security & PQC
Daniel Simon Claims a Polynomial-Time Quantum Algorithm for Lattice Problems. And a CRYPTO 2026 Paper Connects It to ML-KEM
Daniel Simon has posted a preliminary polynomial-time algorithm for the Dihedral Coset Problem, and a peer-reviewed CRYPTO 2026 result supplies the Module-LWE link. Neither one breaks ML-KEM. Together they change the risk conversation.
Read More » -
4 AugustQuantum Security & PQC
Allianz Quantum Risk Report Gets the Capital Thesis Right and the Cryptanalysis Wrong
Allianz Research published a technically serious quantum risk assessment for finance. Its capital-flow analysis is unusually effective. Its cryptanalytic chart and threat model need corrections that matter for anyone using it to plan.
Read More » -
4 AugustQuantum Security & PQC
First External Operators Apply to Chrome’s Post-Quantum Certificate Test Program
TrustAsia filed the first known CA application for Chrome's Merkle Tree Certificate test root store. The filing implements two recently standardized mechanisms from the IETF PLANTS draft, adding concrete evidence that post-quantum web PKI infrastructure is moving from draft to deployment.
Read More »