Quantum Springtime: Harvest Now, Decrypt Later: A Look into How & Who’s Actually Farming Your Encrypted Data, and Why Most of the Crop Rots

What “harvesting” encrypted data really costs an adversary, what it would take to read the stockpile, and where the actual threat is hiding. This article walks a five-gate framework (physical access, storage economics, decryptability, data shelf life, and adversary motive) from first principles, and grounds it in an original internet-wide scan of what post-quantum cryptography is actually deployed today.


1. The bit of the name that’s wrong

Every farmer knows what harvest means. It’s the good bit: the payoff at the end, when the work’s done and you find out whether the year was worth it. So “harvest now, decrypt later” is a funny name for what’s actually going on, because the harvest isn’t the bit happening now. What’s happening now is sowing. Somebody is quietly gathering up encrypted traffic, sticking it in a store, and waiting. They’re not reaping anything; they’re planting, and hoping the weather turns.

What they’re waiting on is a cryptographically relevant quantum computer, a CRQC: the machine big enough to run Shor’s algorithm against the maths that protects today’s key exchanges and signatures (RSA, Diffie–Hellman, elliptic curve). Once that machine exists, the store full of ciphertext becomes readable. Until then it’s a very expensive pile of noise. Call that moment Quantum Springtime, and call the wait Quantum Winter. Not the AI-winter sort, where the thing you’re waiting for never turns up at all, but the farming sort, where you know the season’s coming and just have to sit through the cold.

Post-quantum cryptography, PQC, is the defender’s answer: new seed varieties (cryptography algorithms) out of NIST. ML-KEM, ML-DSA, SLH-DSA (NIST FIPS 203/204/205)1, and more candidates proposed to NIST are currently being evaluated. The quantum harvester can’t process them. The catch, and it’s a big one, is that PQC does nothing for what’s already in the store. Anything harvested yesterday stays harvestable; PQC only protects what you plant from here on. So there are two clocks running: yours, racing to change varieties before the machine arrives; and theirs, racing to bank as much of the old stuff as they can while you’re still planting it in the open.

The frame most people use is Michele Mosca’s inequality2. Take X, how long your data has to stay secret; add Y, how long your migration takes; compare that to Z, how long until the machine exists. If X + Y > Z, you’ve already lost the race for anything you’re sending today. It’s a good bit of arithmetic. The trouble is that Z keeps moving (and decreasing), and in one direction. In 2019 the going estimate for cracking RSA-2048 was about 20 million noisy qubits running for eight hours; by May 2025 the same researcher had it down to under a million qubits and about a week3. A twentyfold cut in six years, and it came out of better algorithms, not better hardware. Nobody has built the machine. But the target keeps shuffling closer, which is exactly the condition under which a patient adversary decides sowing is worth the bother.

It’s moved twice more since then, though not on the same terms. February 2026 brought a qLDPC architecture4 claiming RSA-2048 under 100,000 physical qubits, and in March a Google, Ethereum Foundation and Stanford paper5 put 256-bit elliptic curve, which is the weaker of the two by a long way, under 500,000 physical qubits with a runtime of minutes. Both get there by changing the assumptions rather than holding them steady, trading qubit count for connectivity and decoding tricks nobody has pulled off at scale yet. That’s a caveat, not a reprieve. Z is a planning number, and these papers keep shoving it around without anyone building anything.

One quick word on quantum key distribution, QKD, because it often gets paired when talking about PQC. There is a lot of research and development in this field and it is promising, but it is out of the scope of this article. The NSA’s CNSA 2.0, the UK NCSC and France’s ANSSI all say plainly they’d rather you used PQC6. QKD needs special hardware, only works point to point, and does precisely nothing about a store that’s already full. It protects future conversations on one dedicated line. The ideal secure future may be a combination of both approaches.

A note on concurrent work. This article began as an independent research interest into the practical realities and difficulties of harvesting encrypted data in the current era of 2026, and a scanning effort to gather data. While drafting, I found that 2026 has been a busy year for these areas. Blanco-Romero et al.17 model the storage economics of harvesting and reach a conclusion I partly dispute (Section 4). Wickramasinghe et al.16 ran an Internet-scale, longitudinal measurement of post-quantum TLS that anticipates and confirms my own scan’s results (Section 10). Broader surveys map the surrounding landscape (Bertino et al.18; Chhetri et al.19). Rather than retrofit the argument around these, I’ve kept the original structure and engage each where it bears on the text. Where others got there first, I am transparent, and where my independent data agrees with theirs, I treat that agreement as a result in its own right.

The season the “Harvest Now, Decrypt Later” slogan is named after is the last to arrive. The dangerous work happens years earlier, in the sowing. The shape of the capability curve is illustrative; its position is anyone’s guess (i.e. the actual timing; no promises on a CRQC by 2032!), its direction is not.

2. Five gates

Here’s where the discussion usually goes wrong. People treat HNDL as one thing that either is or isn’t happening to you. It isn’t one thing. It’s a sequence, and every byte an adversary wants has to get through all of it. Think of moving stock: gate one, can you even get to the paddock; gate two, have you got somewhere to put them; gate three, can you actually do anything with them once they’re in the yard; gate four, are they worth anything by the time you get around to it; gate five, given all that, would you have bothered in the first place. Fall at any gate and the whole exercise was a waste of diesel and dog food (for the sheep herding).

The rest of this article walks the gates one at a time. Before that, below is an overview of the wider family of quantum-era security problems.

The problemWhat it attacksWhen damage landsWhat you’d need to pull it offWhen to act
HNDL, data in transitKey exchange (RSA, (EC)DHE)At CRQCA tap, a store full of storage, and a machine that doesn’t exist yetsow now
HNDL, data at restLong-term keys on stored dataAt CRQCOne successful break-in, plus that same machinesow now
Forging old signaturesRSA/ECDSA signaturesAt CRQCCaptured certificates, plus the machinelater
Attacking PQC chipsPQC verify in siliconNowPhysical access and a fault-injection rignow
Fake certs, future MITMThe trust chainAt CRQCThe machine, plus a position on the wirelater

The two in bold at the top are HNDL proper, and they’re the only two where the adversary has to act today for a payoff much later. That’s what makes them worth investigating and discussing now. It’s also what makes them checkable, because acting today leaves marks.

3. Gate one: can you even get at it?

Tapping cables like fibre optics is hard yakka. You can’t do it from a laptop in a bedroom; you need your hands on the actual glass, or a court order pointed at whoever owns the glass. That alone knocks out almost everybody. What’s left is governments, and not many of those.

The best-documented example is also one of the oldest, and it’s a beauty. In 1971 the Americans sent a modified submarine, USS Halibut, into the Sea of Okhotsk to find a Soviet military cable lying in 120 metres of water: Operation Ivy Bells7. Divers wrapped a six-metre induction device around a cable about as thick as your wrist, close enough to read the signal without ever cutting into it. It worked for the better part of a decade.

Two details matter more than the spy-novel stuff. The first is that they found the cable because of a sign on the beach reading Cable Here. Do Not Anchor. The second is the logistics: for years, the way you got the intelligence was that divers physically swam down and swapped the tapes, every month. Someone had to go and fetch it. Later versions ran off a nuclear isotope generator and could hold a year’s worth, which was considered a huge advance because it meant only going once a year. Hold onto that. The hardest part of harvesting was never the tap; it was what to do with the pile afterwards.

The modern version

Fibre changed the method, not the constraint. In 2006 an AT&T technician, Mark Klein, described a locked room at 611 Folsom Street in San Francisco (Room 641A) where optical splitters copied backbone traffic into a rack containing a Narus STA 6400 for deep packet inspection8. It had been running since 2003. The splitters duplicated the full light beam off roughly sixteen backbone circuits (on the order of 15 Gbit/s of traffic) and the Narus box did deep packet inspection on it in real time. Klein’s documents became the evidence in the Electronic Frontier Foundation’s case against AT&T, and later reporting found similar rooms in other American cities9. Worth noting the historical mirror: in 2003, most of what those splitters copied was plaintext. Today the same tap copies ciphertext, which is the entire reason HNDL exists as a worry at all.

The architectural point stands. A splitter on the fibre copies your traffic at the optical layer. No firewall sees it; no intrusion detection catches it; your endpoint has no idea. But, and this is the whole game, it copies what’s on the wire, and what’s on the wire is already encrypted. The splitter doesn’t defeat your crypto. It puts a copy of it in a store and waits.

Same story in Britain, at a scale worth pausing on. By mid-2011 GCHQ had probes on more than 200 fibre links, each carrying 10 Gbit/s, under the programme known as TEMPORA10, and it could process data from at least 46 of them at a time. In theory that gave access to a flow of more than 21 petabytes a day; the Guardian put it at the British Library’s entire book collection, 192 times over, every 24 hours. But here’s the part that matters for everything below: they couldn’t keep it. Content was buffered for just three days, metadata for thirty. Even a state actor operating at national scale, on infrastructure it half-owned, was reduced to a rolling three-day window on the content. Hold that thought; it is Gate 2 arriving early. A related joint effort went after the links running between the big cloud providers’ own data centres, which at the time were unencrypted inside the perimeter11: the TLS was, as the reporting put it, added and removed at the public edge. That’s the most instructive thing in the record. They didn’t beat the encryption; they went round it, to the one place where the data was briefly in the clear. The providers noticed and encrypted their internal links, and that gap closed.

You don’t always need the cable

Here’s where I have to widen the gate, because everything above is about wires, and a good deal of the world’s traffic never touches one an attacker can reach. Radio is broadcast. Anyone in range hears it, no splice required, no landing station, no warrant12. That drops the physical-access bar through the floor for anything that spends part of its journey through the air, and it turns out that’s a lot.

Start with the obvious one: WiFi. Every frame your laptop sends is radiated in every direction, and anyone within range with a cheap adapter in monitor mode captures the lot. Two things save you. The WiFi layer’s own encryption (WPA2, WPA3) scrambles the frames over the air, but that’s a separate, shorter-lived padlock than the TLS inside; it protects the hop from your device to the access point, not the end-to-end session, and it’s been repeatedly downgraded, cracked, or bypassed (KRACK against WPA2, Dragonblood against WPA3, evil-twin access points that just relay everything through the attacker)22. Strip the WiFi layer off and you’re left with the TLS underneath, which brings you right back to the harvest question: modern TLS 1.3 over broken WiFi is still forward-secret and still needs the quantum machine, but an open café network, or a WPA2 network an attacker has the key to, hands them your encrypted TLS stream for free. From an HNDL point of view, WiFi sniffing is a cheap way to collect ciphertext; it doesn’t defeat the TLS, but it removes the “can you physically get at it” gate almost entirely for anyone within a few hundred metres of the target.

Then mobile. 2G was a gift to interceptors. An IMSI-catcher (a fake cell tower, a “Stingray”) could force phones to downgrade to a broken cipher and read traffic in the clear. 4G and 5G are far better, but downgrade attacks against them are an active research area, and the same principle holds: the radio layer is the soft part, and whatever end-to-end encryption rides on top is what actually protects you. Again, cheap to collect, and increasingly the encryption underneath is the only thing standing between the attacker and the plaintext.

And then the one that is surprising, because it inverts the whole “tapping (interception) is hard” premise for a specific, high-value slice of traffic: satellites. In October 2025, researchers from UC San Diego and the University of Maryland published Don’t Look Up (it won a Distinguished Paper award at ACM CCS), and the finding is close to unbelievable. They pointed an $800 off-the-shelf satellite dish at the sky from a rooftop in San Diego21 for three years and found that roughly half of the geostationary satellite links they could see were carrying sensitive data completely unencrypted. No TLS, no VPN, no anything. Not scrambled-and-harvestable-later; just readable, now. In the clear they found the call and text contents of a major mobile operator’s satellite backhaul, in-flight WiFi traffic from aircraft passing overhead, military asset-tracking, and (this is the part that matters for HNDL’s real targets) industrial control and SCADA traffic running utility infrastructure. And they saw only about 15% of the satellites in orbit from one fixed spot in California. A state actor with dishes on several continents sees far more.

That’s a different threat from the cable story in two ways, and both cut against the comfortable version of Gate 1. First, the access is trivial: hundreds of dollars and a view of the sky, not a submarine. Second, and worse for the victims, most of this traffic isn’t even a harvest-now problem, because it needs no future quantum machine to read: it’s already plaintext. The quantum angle only matters for the satellite links that are encrypted; for the unencrypted half, decrypt-later is beside the point, because there’s nothing to decrypt.

4. Gate two: have you got a store big enough?

Say you’ve got your tap. Now you have to keep the stuff, possibly for fifteen years, on the off chance the machine turns up. This is where the story runs into arithmetic, and the arithmetic is unkind.

Use a real number rather than a hand-wave. AMS-IX, the Amsterdam Internet Exchange (one of the big public peering points where networks hand traffic to each other), published its 2025 figures13: 35.66 exabytes of traffic across the year, peaking at 14.2 Tbit/s. DE-CIX in Frankfurt, another such exchange, did about 48 exabytes14. These aren’t estimates; they’re the operators’ own numbers. And AMS-IX is one exchange. There are over a thousand.

So you’ve decided to full-take AMS-IX for one year. What do you need?

The two bottlenecks nobody costs. Left: a full-take of one exchange for one year, in tape. Right: why the machine at the end is a bottleneck, not a magic wand. Ephemeral key exchange forces one job per session.

On LTO-9 tape at 18 TB a cartridge, 35.66 exabytes needs about two million cartridges a year. At roughly $100 each that’s $198 million a year in blank tape, before a single drive or a single wage. An LTO-9 drive writes at about 400 MB/s; to keep up with the incoming flow you need 2,826 drives running flat out, every second of every day, all year. That’s not a server room, it’s a factory.

Then the bit nobody costs. Tape is sequential; to find anything you wind through it. Those same 2,826 drives, doing nothing but reading, would take a full year to read back one year of tape, exactly a year, because writing and reading run at the same speed. So the archive can be read precisely once, and only if you stop collecting while you do it. Want to search it twice? Build a second factory.

Disk isn’t a rescue. At 24 TB a drive you’d need about 1.5 million hard drives, roughly $600 million of them, drawing perhaps 11 MW once you’ve counted the cooling, a small town’s worth of electricity to keep one year of one exchange spinning. Scale to even one percent of global traffic and it gets silly: several AMS-IXes over, every year, forever, on the theory that a machine which doesn’t exist yet will one day let you read it once.

Other factors this article’s arithmetic doesn’t cover: the cost in time of compressing/uncompressing data, and loading/unloading tapes. Of course, there are also other mediums of storage, and this is an extreme example of a full year’s worth of data from a single point, but it helps to illustrate the shear volume (pun intended) of data and the economics that come with storing and processing it.

Here I part company with the most careful prior treatment of these economics. Blanco-Romero et al.17 model the same storage problem and conclude that retention is “economically trivial”: at raw media prices (they cite LTO tape near $5/TB) even a 1% global harvest lands around $1 billion a year, comfortably inside a state budget. Their arithmetic is sound and I don’t dispute the media cost. I dispute that media cost is the binding constraint. Raw tape is the cheapest line in the budget; the factory of drives to write it in real time, the second factory to ever read it back, the indexing to find anything in an incompressible pile of ciphertext, and the physical plant to keep it all running for fifteen years are the lines that actually bite. Their model, by their own statement, isolates at-rest media and excludes the interception and retrieval machinery. That’s a fair scoping choice for their question, which is about protocol-level defences; but once those excluded costs are back in, “trivial” becomes “affordable only if you have already decided this specific traffic is worth a fifteen-year industrial commitment”, which is simply selection by another name. We reach the same destination they do (harvesting is selective, not indiscriminate) from the opposite reading of the storage line, and their own conclusion, that defenders should triage the highest-lifetime data first, is exactly mine.

5. Gate three: will the stuff actually decrypt?

Suppose they’ve tapped it and paid to keep it. The machine finally arrives. Does the pile open? Depends entirely on how the key was agreed, and this is the single most under-explained thing in the whole HNDL conversation.

Whether the crop is worth anything depends on how the key was agreed. RSA key transport is fully HNDL-exposed; ephemeral (EC)DHE forces one CRQC job per session. Either way the handshake signature stays forgeable, so who-talked-to-whom still leaks.

The old way, RSA key transport, is the nightmare scenario. The client encrypts the session secret to the server’s long-term public key; crack that one key, once, and every conversation ever recorded with that server springs open at the same time. One key, whole mob. That’s the scenario the slogan quietly assumes, and it’s why it sounds so alarming.

But that’s not how modern TLS works. TLS 1.3 requires ephemeral Diffie–Hellman, and TLS 1.2 with ECDHE does the same job. Under those, every session invents its own throwaway secret. The server’s long-term key signs the handshake but never encrypts the content, so cracking it gets you nothing about what was said. To read an ephemeral session you have to break that session’s key exchange, then the next, then the one after. There’s no whole-mob shortcut: one shearing stand, one sheep at a time, and each sheep takes a while.

How long? Gidney’s 2025 estimate3 is roughly a week of machine time to crack one RSA-2048 key. Elliptic curve is cheaper, but the same postcode. So a million captured ephemeral sessions doesn’t need “a quantum computer”. It needs something like a million discrete quantum jobs. Even at a wildly optimistic day apiece, that’s thousands of machine-years. A CRQC will be a scarce national instrument with a booking sheet, like a telescope; nobody is running your video-streaming session through it. This is where the counter-intuition starts to set in: sure, the quantum machine, the CRQC, is now powerful and “fast” enough to run Shor’s algorithm for us, but when we factor in the number of jobs (each a single execution of a quantum algorithm) we can start to appreciate the reduction in economics: number of encrypted sessions to crack multiplied by the runtime on a quantum computer for the algorithm, whether that’s the currently anticipated hours to weeks, is still a point of debate and will no doubt change the more Z decreases.

Two things stop this being good news. First, forward secrecy protects the content, not the signature: a future machine can still forge the authentication on a captured handshake, so who-talked-to-whom leaks, and that’s often the interesting part. Second, and worse, the certificate layer hasn’t moved at all. The signatures authenticating essentially the entire web are still classical RSA and ECDSA, as my own measurement confirms (Section 10). The confidentiality side has started its migration; the authentication side hasn’t left the gate.

There’s a third catch, and it’s the one that quietly undoes a lot of the good work. “The server migrated” isn’t the same as “the session is safe”, because the negotiated crypto algorithm is only ever as modern as the weaker of the two ends. Dubey and Varshney15 caught a clean example: an Indian bank (icici.bank.in) served a modern device QUIC with TLS 1.3, X25519 and AES-256 (quantum-forward, forward-secret, everything you’d want) while the same domain, hit from a second device, fell back to TLS 1.2 with ECDHE-RSA and AES-128. Same server, same day, two clients, two completely different security postures. The fallback session is still forward-secret so it’s not the RSA-transport nightmare, but it’s a fallback nobody chose and nobody saw, and if either end had been a little older it could have dropped to RSA key transport and become fully harvestable. Migration you can’t see the far end of isn’t migration you can rely on.

6. Gate four: and then what?

This is the gate nobody talks about, and the one most piles fall at. Picture it. You tap the fibre outside a big retail bank and capture every TLS session to its website for a year: millions of customers logging in, checking balances, moving money. You store the lot. Fifteen years later the machine arrives, you spend a fortune of CRQC time, and you decrypt it all. Congratulations. What have you got? Session cookies that expired in 2026. Passwords rotated three times since, most now behind MFA anyway. Account balances from a decade ago. You have, at enormous expense, learned that someone checked their balance on a Tuesday morning in 2026.

There is durable stuff in there (names, dates of birth, national ID numbers) but it’s a thin seam in a mountain of spoil, and you’d have to reassemble it from millions of separate sessions. Meanwhile the same information sits in the bank’s customer database, structured, indexed, current, and one break-in away. So here’s the question that ought to be asked far more often: why stand at the gate for ten years catching drips off the milk tanker, hoping one day to un-spill them, when the whole tank is sitting in the factory up the road?

Data has a shelf life, and the spread is enormous. A session cookie is worth something for an hour; a password, a few months; a card number, until it expires; a bank account number, decades; a national ID, a lifetime; a fingerprint or iris, a lifetime you can’t reissue; a genome, a lifetime plus everyone you’re related to, and it never expires. A diplomatic cable stays embarrassing for forty years. A weapons design outlives the engineer who drew it. HNDL only makes sense where the shelf life is long. Everywhere else, the crop rots in the store before the machine ever arrives.

7. Gate five: so who’d actually bother?

Put the last two gates together, volume against shelf life, and the picture gets very clear very quickly. Some worked examples, with the actual logistics spelled out.

Who’d actually bother? Volume against shelf life. Top left is where harvesting makes sense: not much of it, and it keeps forever. Bottom right is where the slogan gets sold hardest and makes the least sense. Positions are order-of-magnitude judgements.

The embassy link. Target: the encrypted tunnel between a diplomatic mission and its foreign ministry. Tap: the local ISP, or the exchange its circuit crosses. If you’re the host country, that’s a phone call, not an operation. And if the mission is in a remote posting and backhauls over satellite, as many do, an adversary doesn’t even need the host country’s cooperation: a dish and a rooftop will do (Section 3). Volume: tiny, a gigabyte or two a day; fifty years of it fits on a shelf. Shelf life: decades. Verdict: the textbook case, almost certainly happening right now to everyone’s embassies. If you run a foreign ministry and you’re not migrating, you’re the reason this slogan exists.

The defence contractor. Target: the site-to-site VPN between a prime and its subcontractors. Volume: manageable, tens of terabytes a year of CAD and test data. Shelf life: an airframe designed this year is still flying in 2075. Verdict: viable and worth it. Small pile, long memory.

The retail bank. Target: all consumer traffic. Volume: petabytes a year. Shelf life: hours to months for almost all of it. Verdict: no. You’d spend a hundred million a year on tape to eventually learn some 2026 passwords. Rob the database instead. Someone probably already has.

The genomics lab. Target: sequencing data heading to cloud storage. Volume: a single genome at decent coverage is a couple of hundred gigabytes raw; a busy centre generates petabytes a year. Shelf life: forever, and it implicates the subject’s whole family. Verdict: the most valuable target in this article, and the transit interception is still hopeless purely on volume. But steal the database at rest and it’s suddenly sixty terabytes with an infinite shelf life. That’s the arrow on the chart above, and the most important movement on it.

8. The wool’s already in the store

Which brings us to the part of HNDL that deserves far more attention than it gets. Every big data breach of the last decade left encrypted archives sitting in somebody else’s storage: personnel files, health insurers, credit bureaux, hotel chains, all presumptively still there, waiting on exactly the same machine as the tapped fibre. And it’s a far better target, for three reasons.

First, no forward secrecy. Data at rest is protected by long-term keys, not per-session throwaways; break the key once and the whole archive opens. It’s the RSA-key-transport case by default: whole mob, one go. Second, the selection problem is already solved. An adversary who exfiltrated a genome bank didn’t have to sift a mountain. Somebody else already sorted, indexed and deduplicated it. The hard part of gate two was done by the victim. Third, the shelf life is usually enormous: a stolen genome doesn’t go stale in 2045.

You don’t need a submarine for any of this. You need one phishing email that makes its way through to some unsuspecting staff member. Which is why the number of actors capable of at-rest HNDL is vastly larger than the number who can tap a cable, and why the priority order in most migration advice is exactly backwards. Everyone’s out chasing sheep across the hills; the whole clip of wool (the encrypted data, the database) is sitting baled in the store with the door open.

9. What we still don’t know

Being honest about the limits: everything in Sections 3 to 8 reasons from a public record that is, by design, incomplete. Classified programmes are classified. The disclosed material is old, mostly from 2013, and the technology has moved. Storage costs fall; quantum resource estimates fall faster. Any of the arithmetic here could shift by an order of magnitude, and some conclusions with it. What isn’t a matter of speculation is what’s actually deployed on the wire right now, because that can be measured. So I did, and it sharpens the whole argument, telling us which gate the defence is winning and which it hasn’t started fighting.

10. Measuring the paddock

When I started scanning the internet to gather data for this article’s research on current quantum-safe security postures, the only comparable published work I found was a single-vantage study of about 32,000 domains15. (A vantage here just means a place you scan from. A single-vantage scan asks every server the question from one location; a multi-vantage scan asks from several, to catch servers that answer differently depending on where the request comes from, typically because a global CDN is still rolling a setting out region by region.) My own plan was to scan wider, and from several vantages at once, to see whether a service’s answer depends on which regional front end picks up the phone. While I was doing that, Wickramasinghe et al.16 published an Internet-scale, longitudinal study: more than two billion TLS handshakes across a million domains, from eleven vantage points, over three rounds from July 2025 to March 2026. It’s a larger and more careful measurement than qgrove in every dimension. So I present what follows as independent confirmation: a smaller, single-round scan built on different infrastructure that lands on the same numbers.

I built qgrove20, a scanner that runs on a global edge network and, for each domain, opens a raw connection and reads which key-exchange group the server actually picks. That one value decides whether a captured session is HNDL-exposed, and it’s readable straight off the plaintext part of the handshake without decrypting anything. The scanner is open source and every number below is reproducible from the published dataset. 116,589 domains were selected as targets to scan, using a mixture of methods and sources.

What’s moving: the handshake (key exchange for confidentiality)

Of the reachable servers that speak modern TLS, 35.5% already negotiate hybrid post-quantum key exchange: the classical X25519 curve paired with ML-KEM-768, exactly what a current version of Chrome sets up. That’s a large figure for a standard finalised so recently, and it’s climbing. But 35.5% is measured from the edge, and the edge can’t see the sites behind the large CDN. When I filled that blind spot by re-probing those sites another way, the picture shifted hard: the CDN-fronted cohort is almost 100% hybrid, because the CDN flipped PQC on for everyone at once. Pool the two and the population estimate rises to 61.1%. Both numbers are true and mean different things. The honest headline is that a scan run only from that CDN’s edge systematically undercounts PQC, because the most PQC-enabled sites on the internet are the ones it structurally cannot see.

The two layers move at completely different speeds. Left: hybrid PQC key exchange, edge-measurable vs. the pooled population estimate. Right: certificate signatures, where migration hasn’t started. Source: qgrove, July 2026.

What isn’t moving: the signatures (for authentication)

Now the other half, and the part that should worry people. I looked at the signature algorithm on 31,839 certificates. The number using post-quantum signatures was zero. Not “low”, zero. The web authenticates itself entirely on classical ECDSA and RSA, both of which a future quantum machine forges as easily as it breaks the old key exchange. The confidentiality layer has started migrating; the authentication layer hasn’t taken a single step. This is not a quirk of my sample: the single-vantage study before me15 and the Internet-scale study alongside me16 both report the same flat zero on post-quantum certificates, and the architectural reviews18 explain why the signature side is the harder, slower job: it drags the entire certificate-authority hierarchy and every validating client behind it. That’s the split worth carrying away: encrypting the conversation and proving who you are are two different jobs done by two different bits of maths, and right now only one is being fixed.

Two more findings, both quietly useful

First, the sectors. You’d expect the security-conscious industries (banks, defence, government) to lead. They don’t. Hybrid PQC adoption ran between about 27% and 39% across every sector I tagged, and the leaders were general popular websites and CDN control planes, not finance (28%) or defence (29%). Adoption isn’t driven by who needs it; it’s driven by whose CDN switched it on. This is now the consistent finding across every independent measurement. The large concurrent study quantifies it most sharply: roughly 70% of all post-quantum TLS is attributable to just two providers, Cloudflare and Fastly16, and jurisdictions with the earliest 2030–31 transition deadlines show lower adoption than later-horizon ones, because policy urgency and CDN market share are unrelated. A separate study finds the same lag one layer down, in protocol versions: even plain TLS 1.3 adoption trails in Government (70%), Defence (68%), Energy and Critical Infrastructure (76.5%) and Telecom (78.6%)15, while Cloud and Social Media sit at 95–100%. Three different scans, same pattern. If your provider flipped the setting you’re protected; if not, you’re not, and your industry has almost nothing to do with it.

Second, the thing I built the multi-vantage apparatus to measure: does a server’s answer change depending on where on earth you ask from? I probed 1,787 domains from eight locations spanning North America, Europe, Japan and New Zealand. The share giving a different answer by location was 0.17%, three domains, and when I re-tested those three, two turned out to be ordinary load-balancer wobble rather than geography, leaving about one domain in 1,787 with genuine, stable regional variation. Here the independent check is worth something. The large study, from eleven vantages against a million domains, reports the same effect at the same scale: 0.05% of their stable panel negotiate a different default depending on client location16, and they attribute it, as I do, to CDN configuration propagating gradually across regions. Two groups, wildly different apparatus, 0.05% and 0.06%: where you scan from essentially doesn’t matter.


11. Bringing it in

The “Harvest Now, Decrypt Later” slogan is pointing the right way and lying about the size. HNDL is real: states demonstrably have taps, they demonstrably keep what they select, and the machine they’re waiting on is getting closer every year on paper even if nobody’s built it (yet). But it only survives all five gates in a narrow set of cases, where the pile is small enough to store for a generation and the contents still matter when it’s opened: diplomatic traffic, defence programmes, anything biometric or genomic, long-lived secrets in small volumes. For a big chunk of the internet and its users, the threat dies at gate two or gate four, not because the cryptography holds but because the economics don’t. Storing it costs more than the plaintext is worth, and by the time you can read it, it’s gone off.

Meanwhile the actually-alarming version of HNDL gets almost no airtime, because it isn’t a fibre tap and doesn’t make a good slide: the encrypted archive somebody already walked out with. No forward secrecy, no volume problem, no submarine, shelf life measured in lifetimes.

So the practical advice, such as it is, is unglamorous. Work out which of your data has an X measured in decades. That’s a short list for most organisations, and usually not the list the vendor is quoting you for. Migrate that first (anything at rest under a long-term key, and anything still doing RSA key transport in transit) then do the rest at a sensible pace. And keep an eye on the part nobody’s started: every measurement now in the literature, mine included, finds post-quantum key exchange live on a large slice of the web and climbing, but not one post-quantum certificate signature worth counting. The confidentiality half of the migration is well underway, mostly because a few big CDNs flipped a switch; the authentication half hasn’t begun. When a quantum machine arrives it forges signatures as easily as it cracks keys, so a web that has migrated its handshakes but not its certificates is a house with a new lock on a door anyone can now walk straight through. That’s the next paddock, and right now it’s got no fence at all.

None of this is an argument for doing nothing. It’s an argument for counting the flock before you buy the drench. Migration that follows real exposure is money well spent; migration that follows a slogan is how you end up with a very expensive dip and a paddock full of worms.

The qgrove scanner, domain list, full methodology, and the 202,258-row dataset are available at github.com/spinsphere/qgrove. All figures are the author’s own. Claims about intelligence programmes rest on public reporting, litigation records and declassified accounts; the author has no non-public information and none is implied.

Claude was used to assist the research, scaffolding and writing of this article .

Kaysec advises on post-quantum readiness and cryptographic agility, mostly for organisations whose data has the sort of shelf life this article says actually matters. kaysec.spinsphere.xyz

References

  1. NIST. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA): Post-Quantum Cryptography Standards. 2024. csrc.nist.gov
  2. M. Mosca. “Cybersecurity in an era with quantum computers: will we be ready?” IEEE Security & Privacy, 2018. eprint.iacr.org/2015/1075
  3. C. Gidney. “How to factor 2048-bit RSA integers with less than a million noisy qubits.” arXiv:2505.15917, May 2025. arxiv.org/abs/2505.15917
  4. P. Webster, L. Berent, O. Chandra, E. T. Hockings, N. Baspin, F. Thomsen, S. C. Smith, L. Z. Cohen (Iceberg Quantum, Sydney). “The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100,000 physical qubits using quantum LDPC codes.” arXiv:2602.11457, February 2026. Simulation and resource estimates, not a hardware demonstration. arxiv.org/abs/2602.11457
  5. R. Babbush, A. Zalcman, C. Gidney, M. Broughton, I. Khattar, H. Neven, T. Bergamaschi (Google Quantum AI / UC Berkeley), J. Drake (Ethereum Foundation), D. Boneh (Stanford). “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations.” arXiv:2603.28846, March 2026. arxiv.org/abs/2603.28846
  6. NSA, CNSA 2.0; UK NCSC, Next steps in preparing for post-quantum cryptography; ANSSI, Position paper on post-quantum cryptography.
  7. Operation Ivy Bells, 1971–1981. USS Halibut, Sea of Okhotsk. Induction tap, non-invasive; monthly diver retrieval, later RTG-powered. See Sontag & Drew, Blind Man’s Bluff (1998).
  8. M. Klein, sworn declaration and exhibits, Hepting v. AT&T (N.D. Cal. 2006); EFF case materials. Room 641A, 611 Folsom St; operational 2003, disclosed 2006; ~16 split backbone circuits (~15 Gbit/s combined), Narus STA 6400.
  9. R. Gallagher and H. Moltke. “The NSA’s Hidden Spy Hubs in Eight U.S. Cities.” The Intercept, June 2018. theintercept.com
  10. GCHQ TEMPORA disclosures, 2013–2014 (The Guardian; Der Spiegel). 200+ probes at 10 Gbit/s, ~21.6 PB/day theoretical capacity; content buffered ~3 days, metadata ~30.
  11. MUSCULAR disclosures, 2013 (The Washington Post). Inter-datacentre links; TLS terminated at the public edge.
  12. Lawfare, “Evaluating the Russian Threat to Undersea Cables”, on why landing-station access makes routine deep-sea tapping unattractive.
  13. AMS-IX 2025 figures: 35.66 EB annual traffic, 14.2 Tbit/s peak. ams-ix.net
  14. DE-CIX Frankfurt ~48 EB for 2025; 18.22 Tbit/s Frankfurt peak; 25 Tbit/s global platform peak, April 2025.
  15. A. Dubey and V. Varshney. “Measurement Study of Post-Quantum Readiness of Internet: 2026.” arXiv:2606.16473, June 2026. Single-vantage scan of 32,011 domains; TLS 1.3 52.41%, TLS 1.2 15.70%, QUIC 31.89%; 49.3% hybrid KEX, 0% PQC certs; documents client-side TLS-version fallback on a fixed domain. arxiv.org/abs/2606.16473
  16. N. Wickramasinghe, F. Li, S. Jha, A. Shaghaghi. “Mind the Gap: Policy vs Reality in Post-Quantum TLS Deployment.” arXiv:2607.29005, July 2026. UNSW Sydney and Georgia Tech. Longitudinal, three rounds Jul 2025–Mar 2026; >2 billion handshakes, 1M domains, 11 vantage points. arxiv.org/abs/2607.29005
  17. J. Blanco-Romero, F. Almenares Mendoza, C. García Rubio, C. Campo, D. Díaz Sánchez. “On the Practical Feasibility of Harvest-Now, Decrypt-Later Attacks.” arXiv:2603.01091, March 2026. Universidad Carlos III de Madrid. arxiv.org/abs/2603.01091
  18. E. Bertino, R. Kompella, A. Kundu, C. Nita-Rotaru, J. Vaidya, A. A. Yavuz. “Quantum-Resistant Networks: A Review of Primitives, Protocols and Best Practices.” arXiv:2605.04129, May 2026. arxiv.org/abs/2605.04129
  19. G. Chhetri, S. Somvanshi, P. Hebli, S. Brotee, S. Das. “Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey.” arXiv:2510.10436, 2025. Texas State University. arxiv.org/abs/2510.10436
  20. qgrove: distributed multi-vantage TLS post-quantum posture measurement. Dataset and methodology, July 2026. github.com/spinsphere/qgrove
  21. W. M. Zhang, A. Dai, K. Ryan, D. Levin, N. Heninger, A. Schulman. “Don’t Look Up: There Are Sensitive Internal Links in the Clear on GEO Satellites.” Proc. 32nd ACM SIGSAC Conf. on Computer and Communications Security (CCS ’25), Taipei, October 2025 (Distinguished Paper Award). ~$800 receiver; 50% of observed GEO satellite links carried cleartext IP traffic, including cellular backhaul with call and text contents, utility industrial-control/SCADA, military asset tracking, and in-flight WiFi. satcom.sysnet.ucsd.edu
  22. On WiFi interception and its limits: WPA2/WPA3 protect the radio hop, not the end-to-end session; see the KRACK (Vanhoef & Piessens, 2017) and Dragonblood (Vanhoef & Ronen, 2020) attacks, and the evil-twin / downgrade class generally. Radio’s broadcast nature makes ciphertext collection cheap; TLS remains the load-bearing layer.