Unhackable Quantum Encryption
Table of Contents
This article is part of the Quantum Snake Oil Dictionary, a series examining terms used in quantum technology marketing. This entry is a Misused Term: “unhackable” is applied to a real technology (QKD) in a way that overstates its guarantees.
“Unhackable Quantum Encryption”
What the term gets right. Quantum key distribution (QKD) does provide a security guarantee that no classical system can match. In the idealized protocol (BB84, E91, and their variants), any attempt by an eavesdropper to intercept or measure quantum states introduces detectable disturbance. This is not a conjecture; it follows from the laws of quantum mechanics. The theoretical result is genuine, important, and well-established.
What the term gets wrong. “Unhackable” extends the theoretical guarantee of the protocol to the physical hardware implementing it. This extension is not supported by physics, by engineering, or by the published record of attacks on commercial QKD systems.
The Gap Between Protocol and Hardware
The security proof for QKD applies to an idealized model: perfect single-photon sources, perfect detectors, perfect alignment, a perfectly authenticated classical channel, and no side channels. Real QKD hardware deviates from this model in ways that attackers have repeatedly exploited.
The most dramatic demonstration came from Lydersen et al. at the Norwegian University of Science and Technology in 2010. Their team showed that by shining bright light at the single-photon detectors in a commercial QKD system (the ID Quantique Clavis2), they could “blind” the detectors and force them to respond only to bright classical pulses sent by the attacker. This allowed full extraction of the secret key without increasing the quantum bit error rate (QBER), the very metric that QKD uses to detect eavesdropping. The attack was invisible to the protocol’s security checks.
This was not an isolated result. Subsequent research demonstrated thermal blinding attacks, time-shift attacks that exploited detector efficiency mismatches, Trojan horse attacks that probed the internal state of QKD transmitters using injected light, and after-gate attacks that manipulated detector timing windows. Each of these attacked the hardware implementation, not the protocol, and each succeeded because real devices do not behave like the idealized models in the security proof.
The NSA noted this gap explicitly in its 2020 guidance on QKD, listing hardware vulnerabilities, the requirement for an authenticated classical channel (which itself needs pre-shared keys or PKI), denial-of-service susceptibility, and the lack of authentication as reasons it does not recommend QKD for National Security Systems. GCHQ published a similar assessment.
Why the Distinction Matters
This is not an argument against QKD. It is an argument against the word “unhackable.” The distinction matters for two reasons.
First, calling a system “unhackable” discourages the security mindset that any system needs. If a CISO deploys QKD believing it is unhackable, they may not invest in the monitoring, patching, hardware validation, and side-channel testing that any real security deployment requires. The word “unhackable” creates complacency, and complacency is the enemy of security.
Second, the claim is falsifiable, and it has been falsified. Every successful side-channel attack on a QKD system is a data point against the “unhackable” claim. QKD vendors who use the word are making a promise their hardware cannot keep, and when the promise breaks, it damages the credibility of QKD as a legitimate technology.
The Honest Framing
QKD provides information-theoretic security for key distribution, conditional on the physical hardware matching the theoretical model. Responsible QKD vendors acknowledge this and describe their countermeasures against known side-channel attacks. They discuss measurement-device-independent (MDI-QKD) and twin-field QKD protocols designed to eliminate detector-side vulnerabilities. They describe their testing against known attack vectors. This is how security engineering works: acknowledge the threat model, enumerate the assumptions, and defend against known attacks.
The honest claim is: “Our QKD system provides key distribution with security based on the laws of physics, and we have implemented specific countermeasures against the following known hardware attacks: [list].” That is a strong claim. It is also a verifiable, testable, improvable claim. “Unhackable” is none of those things.
Questions to Ask a Vendor
“Which hardware side-channel attacks has your system been tested against?” Detector blinding, Trojan horse, time-shift, and photon number splitting are the minimum. A vendor who has never heard of these attacks, or who dismisses them as irrelevant, does not understand the security landscape of their own product.
“Does your system use measurement-device-independent (MDI-QKD) or other protocols designed to eliminate detector-side vulnerabilities?” MDI-QKD removes the detector from the trust model entirely, addressing the most common class of attacks. If the system uses standard BB84 with no MDI variant, ask what detector-hardening measures are in place.
“How does your system authenticate the classical channel?” QKD distributes keys, but it does not provide authentication. The classical channel used for basis reconciliation and privacy amplification must be authenticated through some other means (pre-shared keys, post-quantum signatures, or similar). If the vendor cannot explain their authentication mechanism, the system has a gap that no amount of quantum physics can fill.
The Bottom Line
QKD is real, and its theoretical foundation is sound. But “unhackable” is a marketing claim that the hardware cannot sustain. The history of QKD security research is a history of finding and closing implementation gaps between the idealized protocol and the physical device. That process is exactly how security engineering is supposed to work. Calling the result “unhackable” short-circuits it.
This article is part of the Quantum Snake Oil Dictionary, a PostQuantum.com series examining terms used in quantum technology marketing. For more on QKD’s security model, see Quantum Hacking: Cybersecurity of Quantum Systems.