The Hardy Index Quantum readiness benchmark

Guide · Understand the threat

Q-Day: when will quantum computers break crypto?

Q-Day is the date everyone wants and nobody has. Here is what the people who study it actually say, and how to read a forecast that keeps moving.

The short answer

Q-Day is the day a quantum computer can break the cryptography protecting crypto and the wider internet. Nobody knows the date. Estimates quoted by Citi Institute put the chance before 2034 at 19% to 34%, rising to 60% to 82% by 2044, and those estimates keep moving.

What is Q-Day?

Q-Day is the point at which a quantum computer becomes powerful enough to break the public-key cryptography that protects banking, messaging and crypto wallets. Citi Institute defines it as "the future date when quantum computers become powerful enough to break widely used public-key encryption".

The machine that would do it has a name in the standards world: a cryptographically relevant quantum computer, or CRQC. NIST uses that term, and it means something specific. Not any quantum computer, but one large and reliable enough to run Shor's algorithm against real keys.

Q-Day is not a switch that flips. It is more like a threshold that gets crossed quietly, possibly by someone who has no interest in announcing it. Citi Institute makes that point directly: the real Q-Day may happen before the world knows about it.

When will Q-Day happen?

The honest answer is a probability spread, not a date. Citi Institute reported in January 2026 that estimates quoted by United States regulators and the Global Risk Institute put the chance of Q-Day before 2034 at 19% to 34%. The same estimates rise to 60% to 82% by 2044.

Prediction markets sit in a similar place. Kalshi trading data from 12 January 2026, cited in the same Citi report, implied roughly a 40% chance of a useful quantum computer by 2030, and 50% before 2035. Citi adds that many experts think a cryptographically relevant machine in the 2020s is highly unlikely.

Three dated anchors are worth holding on to, because they come from the people doing the building and the standard setting.

  • 2029. IBM says it aims to deliver its first large-scale fault-tolerant quantum computer that year. A fault-tolerant machine is not automatically a crypto-breaking one, but it is the milestone that makes the rest plausible.
  • 2030. United States federal agencies must begin migrating high-risk systems to post-quantum cryptography. NIST's draft transition plan would also deprecate the weaker classical signature parameters after this year.
  • 2035. The target for full quantum-resistant security across federal systems under National Security Memorandum 10, and the year NIST would disallow ECDSA and EdDSA entirely.

Those 2030 and 2035 dates are policy deadlines rather than forecasts of an attack. They are useful anyway, because they tell you when the institutions with the most to lose expect to have finished.

Why do the estimates keep changing?

The estimates move because the cost of the attack keeps being revised downward, not because the machines have suddenly arrived. Better algorithms and better error correction mean the same job needs fewer qubits than it did a year earlier.

The clearest example came in March 2026. Google Quantum AI published resource estimates for an attack on the elliptic-curve cryptography behind most blockchains. It put the job at fewer than 1,200 logical qubits and fewer than 500,000 physical qubits, running for a few minutes. That was roughly a twentyfold reduction in the physical qubits previously thought necessary.

Nothing about the hardware changed that day. What changed was the size of the target. This is why forecasts written in 2019 read as complacent now, and why any date you are given should come with the year it was calculated.

It can move the other way too. Error correction is genuinely hard, and several announced milestones have slipped. A forecast that only ever tightens is a forecast worth questioning.

What does Q-Day mean for my crypto?

For crypto, the important thing about Q-Day is that you do not get to prepare on the day. A blockchain never forgets a key. Coins sitting at an address whose public key is already published are exposed to a machine that arrives years later.

That is the crypto version of harvest now, decrypt later, and it is why waiting for a date is the wrong strategy. Harvest now, decrypt later, explained covers how it works and what it does and does not mean for a wallet.

The practical question is not when Q-Day lands. It is whether the chain you hold will have shipped a post-quantum signature before it does. As of 12 August 2026, the Hardy Index rates 2 of 23 major chains as post-quantum today. Another 9 sit on funded roadmaps, and 5 have no published plan at all.

  1. 1 Native 2 of 23

    Post-quantum secure at mainnet today, with quantum-resistant signatures built in from genesis.

  2. 2 Shipping 3 of 23

    Post-quantum signature features are live on mainnet and a migration for existing holders is underway.

  3. 3 Committed 9 of 23

    A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.

  4. 4 Debating 4 of 23

    The threat is acknowledged and proposals exist, but there is no consensus and no published timeline.

  5. 5 Exposed 5 of 23

    The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme could be found.

You can check where your chain sits in a few seconds. How to protect your crypto from quantum computers sets out what to do while the industry catches up.

Check your chain's readiness

The Hardy Index scores 23 major blockchains on how far each has actually got with its post-quantum migration, as of 12 August 2026.

Check your chain's readiness

Questions people also ask

What is Q-Day in simple terms?

Q-Day is the day a quantum computer can break the public-key cryptography that protects banking, messaging and crypto wallets. The machine capable of it is called a cryptographically relevant quantum computer. No such machine has been built, and nobody knows the date one will be.

Will Q-Day happen before 2030?

Most experts think it is unlikely. Estimates quoted by Citi Institute in January 2026 put the probability of Q-Day before 2034 at 19% to 34%. Citi adds that many experts think such a machine in the 2020s is highly unlikely. Prediction market data in the same report implied roughly a 40% chance of a useful quantum computer by 2030.

Is there an official Q-Day deadline?

There is no official date for the attack, but there are official deadlines for the defence. NIST's draft transition plan would disallow ECDSA and EdDSA after 2035. National Security Memorandum 10 sets the same year as the target for completing the migration across United States federal systems. Those dates are how governments are planning, not predictions of when an attack lands.

Why do quantum timelines keep getting shorter?

Because the estimated cost of the attack keeps falling. In March 2026, Google Quantum AI put an attack on elliptic-curve cryptography at fewer than 1,200 logical qubits and fewer than 500,000 physical qubits. That was roughly a twentyfold reduction in physical qubits compared with earlier work. Algorithmic improvements move the target closer without any new hardware being built.

What should I do before Q-Day?

Three things, all free. Check how ready your chain is, stop reusing addresses so your public key stays hidden until you spend, and take your chain's post-quantum migration when it ships. Those steps work regardless of when Q-Day arrives. The Hardy Index rates 23 major chains on exactly that readiness.

Where to go next

Sources

  1. Quantum Threat: the trillion-dollar security race is on Citi Institute · primary · checked 12 August 2026
  2. NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards National Institute of Standards and Technology · primary · checked 12 August 2026
  3. Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly Google Research · primary · checked 12 August 2026
  4. IBM delivers new quantum processors, software and algorithm breakthroughs on path to advantage and fault tolerance IBM · primary · checked 12 August 2026
  5. The Hardy Score methodology The Hardy Index · primary · checked 12 August 2026

This is a security-readiness assessment, not investment advice.