Your data is being stolen now to be read later
The quantum computer that breaks today’s encryption does not exist yet. That has not stopped the attack. Adversaries are recording encrypted data now to decrypt the day it does. Dated, sourced, no hype.
Most people file quantum computing under someday. The security world does not, and here is why: an encrypted file stolen today can be stored and cracked years later, the moment a large enough quantum computer arrives. The industry has a blunt name for it, “harvest now, decrypt later.” It means the clock on your long-lived secrets started years ago, not on the day the machine turns on. The good news is the defense is already standardized. The bad news is almost no one has migrated. Here are the dated facts.
The receipts
NIST published the first finalized post-quantum cryptography standards: FIPS 203 (ML-KEM) for key exchange, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. These are the quantum-resistant replacements for the encryption that protects nearly everything online today, and they are ready to deploy now.
Source: NIST Migration to PQC projectThe hardware keeps closing the gap. Google Quantum AI has been hitting published quantum-error-correction milestones, and Quantinuum with Microsoft demonstrated more reliable logical qubits, the building blocks a code-breaking machine would need. Each step shrinks the runway between today and the day current encryption falls.
Source: Google Quantum AIThe migration is now on a clock. Standards bodies and security agencies are pushing organizations to inventory their cryptography and begin moving to the new standards through 2026 and beyond, precisely because the harvest-now-decrypt-later threat means waiting for the quantum computer to arrive is waiting too long.
Source: NIST Migration to PQC projectThe trap in quantum is treating it as a future problem. For anything with a long secret life, medical and financial records, legal files, state and trade secrets, backups, and yes, the seed phrases behind crypto wallets, the risk is present tense. If it is worth stealing to read in five or ten years, it is worth harvesting encrypted today, and the standards to defend it already exist. The gap is not the technology. It is that almost no one has started the migration, because the deadline does not feel real until the machine is on, and by then the harvested data is already gone.
The front-run is boring and early, which is exactly why it is an edge. Inventory what you hold that still matters in a decade, and move the encryption on it to the post-quantum standards before it is convenient to. The people who treat quantum as a someday story will migrate in a panic after the first public break. The secret you must protect longest is the one to move first. Foresee it. Do not wait for it.
