Harvest Now, Decrypt Later: The Quantum Threat Already Underway
Adversaries don't need a quantum computer today to threaten you today. Here's how harvest-now-decrypt-later works and what to do about it.
The attack that's happening right now
You don't need a working quantum computer to be a victim of one. An adversary can record your encrypted traffic today — customer data, financial transactions, internal communications — and simply store it. When a sufficiently powerful quantum computer arrives (estimated around 2030), that stored traffic gets decrypted retroactively.
This is Harvest Now, Decrypt Later (HNDL), and it's why the quantum threat is a present-day problem, not a future one.
Why long-lived data is at risk today
Anything that must stay confidential for years is already exposed the moment it's sent:
- Health records (decades of sensitivity)
- Trade secrets and intellectual property
- Government and defense data
- Financial and legal records
If your data has a shelf life longer than the time until Q-Day, harvesting it today is a rational strategy for a patient attacker.
What you can do
The fix is hybrid key exchange — combining a classical algorithm with a post-quantum one like ML-KEM-768. It's available in OpenSSL 3.5+, recent Nginx, and most major CDNs. A connection negotiated with X25519MLKEM768 resists both today's attacks and tomorrow's quantum ones.
Want to know if your domain is already protected? Scan it free with PQScore and see your post-quantum readiness in under a minute.