Quantum Security beyond Cryptography

When discussing Quantum Computing and cybersecurity, we often focus on cryptography and the potential deprecation of Public Key Infrastructure. Have you considered the other potential impacts?

I asked HAL9000 about the broader security consequences of using quantum computing. It’s important to understand the impacts beyond the “Harvest now, decrypt later” threat.

Verdict

The most concrete quantum security story of 2026 is not the quantum computer as a weapon. It is the quantum computer as a target. Crosstalk attacks, power side-channels, circuit theft and denial-of-service have all been demonstrated on real IBM and Rigetti hardware, on live multi-tenant cloud services. Meanwhile the quantum tools that defend — QRNG, QKD, quantum signatures — are real but far narrower than the marketing implies, and quantum computing pointed at defensive cyber work is still, honestly, a research poster.

Everything below is labeled. Where I am confident, I say so. Where I am extrapolating, I say that too. I would prefer we did not confuse the two.

01 / The Blind Spot

Everyone is watching the wrong end of the machine

Shor’s algorithm gets the headlines. It is also the part of this problem with the clearest owner, the clearest fix, and the clearest deadline.

The encryption story, briefly, so we can leave it behind: Shor’s algorithm threatens RSA and ECC, harvest-now-decrypt-later makes that a today problem for long-lived secrets, and NIST has already standardized the replacements. That work is well-defined. Do it. It is not what this piece is about.

What almost nobody is auditing is everything else quantum touches. A quantum computer is a physical machine on a cloud, shared with strangers, driven by classical control electronics, cooled by an exotic supply chain, and increasingly asked to run other people’s proprietary circuits. Each of those clauses is an attack surface. Several have already been attacked.

02 / The Machine as Target

Quantum hardware is now a live attack surface

The best-evidenced section in this report, and the least discussed. All of it has run on real silicon.

Crosstalk and fault injection on shared processors demonstrated

If you share a quantum processor with an adversary, they can reach into your computation. Harper et al. (Advanced Quantum Technologies, 2025) found crosstalk to be a significant and exploitable error source on IBM hardware in shared environments. The SWAP attack (2025) ran a stealthy side-channel on a real 127-qubit IBM device. QubitVise, a double-sided crosstalk attack, was validated on Rigetti’s Ankaa-3. And a “Quantum Rowhammer” injected faults on IBM’s Eagle processors using nothing but ordinary Clifford gates — no pulse-level access required, with corruption confined to qubits within two coupling hops.

Power and control-pulse side-channels demonstrated

The qubits are exotic. The electronics driving them are not. Erata, Xu, Piskac and Szefer (Yale, IACR TCHES 2024) reconstructed secret quantum circuits from power traces of the classical control hardware, evaluated across 32 benchmark circuits with high-accuracy gate-level recovery. Readout crosstalk on Rigetti’s Ankaa-3 separately leaked measurement results and exposed the shared readout feed-line layout. The lesson is old and unwelcome: the physics may be quantum, but the leakage is thoroughly classical.

Circuit theft — your algorithm is the secret demonstrated · early

A QAOA or VQE circuit is not a neutral artifact. It is a fingerprint of the problem you are solving. A Penn State / IEEE study in January 2026 warned that an observer with circuit access could infer a portfolio optimization, a power-grid layout, or a proprietary model — without ever seeing the underlying data. Your cloud provider has white-box access to that circuit. So does any third-party compiler in your toolchain. The proposed defenses — circuit watermarking, trusted execution environments for quantum — exist mostly on paper.

Denial of service by miscalibration demonstrated · early

A uniquely quantum sabotage vector: a malicious calibration service that misreports error rates or quietly detunes your qubits. Nothing crashes. Your results are simply wrong. Researchers also demonstrated voltage-glitch fault injection against ML-based readout error-correction controllers in 2025, which could additionally hang the controller board outright.

Adversarial attacks on quantum ML demonstrated · early

QML models face poisoning (the QUID label-flipping attack) and adversarial examples like any other model. The twist is almost comic: NISQ hardware is so noisy that the noise masks small classical perturbations, making quantum neural nets somewhat more robust to textbook attacks. Attackers responded by building quantum-native attacks based on state similarity in Hilbert space. Defense by incompetence is not a strategy, but I note that it worked briefly.

03 / Physics as a Product

What quantum actually sells you today

Four shipping categories, in descending order of how much I would trust the sales deck.

Quantum random number generators demonstrated · commercial

The one unambiguous win. ID Quantique’s Quantis line delivers certified quantum randomness above 200 Mbps in PCIe and USB form factors. An independent EPJ Quantum Technology assessment (2022) went as far as reverse-engineering the device, and confirmed that over 99% of its output originates in genuinely random physical processes — photon absorption timing and avalanche growth. Fraunhofer IPMS has since shipped a competitor. If you need entropy: mature, cheap, boring. Buy it.

Quantum key distribution demonstrated · narrow

QKD runs in production fiber today: Madrid’s MadQCI network, a Cyprus multi-node deployment over existing telecom fiber, a Toshiba/NEC/NICT demonstration multiplexing QKD alongside high-speed data. China’s Micius satellite carried a quantum-secured call 7,600 km between continents; IonQ announced a satellite QKD network in May 2025. It is real.

It is also distance-limited, needs dedicated hardware, and cannot be dropped into your PKI. The NSA’s public position is blunt: it favours post-quantum cryptography and does not support QKD for national security systems. Treat QKD as a niche complement for fixed high-value links. Not a replacement for anything.

Quantum digital signatures demonstrated · lab

Information-theoretically secure signatures have run over installed fiber at 90 km and 43 dB loss. Yin et al. (National Science Review, 2023) demonstrated a full quantum secure network combining signatures, secret sharing, conference keys and encryption, reporting roughly a hundred-million-fold signature-efficiency improvement. Impressive. Still a lab.

Quantum sensing, pointed at your chips demonstrated · research

The under-discussed one. Germany’s Cyberagentur funds SCA-QS — side-channel attacks using quantum sensors. NV-diamond centers, SQUIDs and atomic magnetometers read electromagnetic emanations at resolutions classical probes cannot reach, including against chips specifically hardened against classical side-channel attacks. Your countermeasures were calibrated against a weaker instrument. That assumption now has an expiry date.

04 / The Uncomfortable Part

QKD’s physics is perfect. Its implementations keep getting broken.

A short, humbling history that vendors rarely put on the slide.

No-cloning is a theorem. Theorems do not have firmware. Every serious attack on QKD has gone around the physics rather than through it:

AttackYearWhat it didTarget
Time-shift2008First experimental attack on a commercial system, exploiting detector-efficiency mismatchID Quantique
Tailored bright illumination2010Remotely seized control of the detectors and stole the full key without raising the error rateTwo commercial systems
Full-field eavesdropper2011Ran a complete perfect-eavesdropper on a live link; no monitored parameter flagged a breachRunning QKD link
Laser damage2014Physically damaged components in order to create a hardware backdoorDetector optics
Trojan-horse / large-pulse2014–17Probed the sender’s optics from outside; a 1924 nm variant was effectively invisibleSender module

The principal countermeasure is measurement-device-independent QKD (Lo, Curty & Qi, 2012), which removes all detector side-channels and roughly doubles secure distance. If you are evaluating QKD and the vendor cannot tell you where they sit on MDI, that is your answer.

05 / Quantum Pointed at Cyber Work

The research is real. The advantage is not, yet.

Where the papers promise the most and deliver the least.

QML for intrusion detection and malware demonstrated · unproven at scale

Quantum SVMs, autoencoders, QNNs and quantum PCA have been thrown at intrusion detection, malware and DDoS classification, with high accuracy reported on benchmark datasets. Reviews keep finding the same two holes: no large-scale real-world benchmarking, and no consistent advantage over classical ML. When a vendor tells you quantum will revolutionize your SOC, ask which classical baseline they beat, and by how much.

Optimization for network defense demonstrated · early

Defense resource allocation cast as a QUBO and run on D-Wave annealers (Jülich); QAOA proposed to separate DDoS traffic from legitimate traffic via Max-Cut on attack graphs. Proofs of principle. Classical heuristics still win in production.

Quantum-enhanced fuzzing and vulnerability discovery demonstrated · early

Grover’s algorithm has been proposed to accelerate white-box fuzzing of file and packet parsers; quantum nets applied to vulnerability detection; and “quantum fuzzing” of QKD implementations can surface flaws with minimal device knowledge — it would have caught the 2010 bright-illumination bug. Meanwhile a formal audit of 45 open-source quantum simulators (Oak Ridge) turned up 547 security findings, including a novel QASM injection vector. The quantum software stack is roughly where the web stack was in 2003.

Grover, hashes, and your password policy demonstrated · modest

Grover offers a quadratic speedup only. It halves effective bit-security — AES-256 drops to roughly 2128 — and the fix is embarrassingly simple: double the key or digest length. Practical cracking is further throttled by the need to express the hash as a quantum oracle, and by memory-hard functions (bcrypt, Argon2, scrypt), salting, MFA and rate limiting. This is not your problem. Shor is your problem.

Blockchain: the threat is not what the headlines say demonstrated · nuanced

Quantum mining and consensus attacks are not happening. A 2026 BTQ analysis calculated that competitively mining Bitcoin at January 2025 difficulty would require on the order of 1023 qubits and 1025 watts — approaching the total power output of a star. The actual risk is mundane and serious: signature exposure via Shor. Roughly 6.9 million BTC sit in addresses whose public keys are already visible on-chain. Ethereum has run a quantum-resistance program since 2018. Bitcoin has no unified roadmap.

06 / The Supply Line

Quantum’s chokepoints are physical, and someone is already holding them

The security story that has nothing to do with algorithms.

Quantum hardware now sits on dual-use export-control lists beside nuclear equipment and satellites. The US finalised list-based quantum controls and outbound-investment restrictions targeting China, with the most significant additions in 2024; China responded by accelerating domestic supply and tightening raw-material rules. demonstrated

The chokepoints are unglamorous: cryogenic cooling and its near-irreplaceable helium inputs, specialised semiconductors, and processing capacity concentrated outside Western alliances. Quantum computers are large, power-hungry and cloud-accessed — which makes them unusually easy to monitor, and unusually easy to cut off.

07 / The Long Horizon

Plausible, unproven, and worth watching anyway

Everything in this section is projection. I have marked it accordingly, and I would ask you not to budget against it.

Blind and verifiable delegated computing projected

Compute on someone else’s quantum machine while hiding your input, your algorithm and your output from them. Demonstrated with photonic qubits (Barz et al., Science, 2012) and in verifiable form at Oxford in 2024. If it scales, the circuit-theft problem in section 02 largely evaporates. That is a substantial “if”.

Quantum money and unclonable tokens projected

Wiesner’s quantum money is unforgeable by the no-cloning theorem — physically impossible to counterfeit, not merely expensive. A 2025 Paris experiment added a quantum-memory storage step; Quantinuum, Mitsui and NEC ran a token experiment. It needs long-lived quantum memories that do not yet practically exist. (The “quantum dot” anti-counterfeiting labels already on the market are unclonable-function labels — good technology, entirely different thing.)

Quantum-sensor surveillance at scale projected

Extend section 03’s sensors and you get devices that read emanations through walls, inventory every powered chip in a building, or sniff radio covertly at range. Portability, cost and standoff distance are the current limits. This is the item on the list I would most like to be wrong about.

A decisive quantum advantage in cyber defense projected

Requires fault-tolerant hardware, a solution to the quantum data-loading bottleneck, and far larger qubit counts. Nobody has shown a real-world advantage on real security data. Treat every claim otherwise as marketing until a classical baseline is published alongside it.

Quantum-native malware and cross-tenant covert channels projected

A prime-and-probe covert channel has already been outlined on IBM hardware. Scale the data centers, add fault tolerance, and section 02’s individual demonstrations mature into an ecosystem: quantum trojans, hardware implants, cross-tenant exfiltration. This is the most likely of my projections to arrive early.

The quantum internet projected

Entanglement-based long-distance networks with repeaters, enabling device-independent QKD, distributed blind computing and quantum authentication. Current links are proofs of concept — a 50 km link was held for 325 hours in late 2025. A long-term research goal, not a procurement line item.

08 / Evidence, Ranked

How much weight each claim actually bears

I have no interest in flattering this field. This ranks strength of demonstration, not commercial noise.

AreaStatusWhere the evidence actually stands
QRNG (entropy)DemonstratedShipping, independently verified, in production use
Attacks on QKD hardwareDemonstratedRepeatedly broken in the field, across multiple vendors
Attacks on quantum computersDemonstratedReal hardware — IBM Eagle, Rigetti Ankaa-3
QKD (as deployed)DemonstratedProduction fiber and satellite, narrow use cases
Supply-chain controlsDemonstratedExport policy in force today
Quantum-sensor side-channelsDemonstrated · earlyFunded national program, early results
QML for threat detectionDemonstrated · earlyBenchmark datasets only; no proven advantage
Quantum fuzzing / vuln discoveryDemonstrated · earlyProofs of concept
Blind delegated computingProjectedLab demonstrations, not scaled
Quantum moneyProjectedNeeds quantum memories that do not yet exist
Quantum cyber-defense advantageProjectedUnproven; no real-world result

09 / Directive

What to actually do about it

Sequenced by evidence, not by excitement.

Stage 1 — now, regardless of any quantum timeline

  • Migrate to post-quantum cryptography. Yes, it is the boring encryption answer. It is also the only genuinely urgent item on this page. Inventory your long-lived secrets first — those are the ones already being harvested.
  • Treat multi-tenant quantum hardware as hostile. If you buy quantum cloud, demand qubit-allocation isolation, circuit obfuscation or watermarking, and vetting of every third-party compiler and calibration service in your path. Section 02 is not hypothetical.
  • Buy QRNG where entropy matters. Mature, validated, cheap. There is no reason not to.

Stage 2 — one to three years, pilot and monitor

  • QKD only for fixed, high-value point-to-point links — data-center interconnect, government backbone. Favour measurement-device-independent variants. Never as a PKI replacement.
  • Track the quantum-cloud security literature and turn it into vendor security requirements before procurement signs anything.
  • Keep QML and quantum optimization in R&D. Fund the pilots. Demand a classical baseline in every result.

Stage 3 — three years and out, contingent on hardware arriving

  • Scale blind and verifiable delegated computing, and hardware-level quantum security controls, as multi-tenant fault-tolerant machines actually appear.

Thresholds that would change this advice

  • A quantum ML or optimization method shows a reproducible, real-world advantage over a strong classical baseline on security data → move it from R&D to pilot.
  • Fault-tolerant logical-qubit machines reach Shor-on-RSA-2048 scale → accelerate every PQC deadline and re-key exposed blockchain wallets immediately.
  • A cross-tenant quantum attack extracts secrets from a production workload rather than a benchmark → stop further quantum cloud adoption until hardware isolation is mandated.

Methodology & caveats

Figures are drawn from peer-reviewed and preprint literature current to mid-2026, from published hardware specifications (IBM, Rigetti, D-Wave, ID Quantique), and from public policy positions (NSA, US export-control listings, Germany’s Cyberagentur). Primary references are linked in Sources, below.

  • “Demonstrated” is a spectrum. It means real hardware, a funded program, or a shipping product — but several entries are single lab demonstrations with no proven operational advantage. Read the qualifier, not just the label.
  • The QML literature overstates itself. Reviews consistently find missing large-scale benchmarks and no reliable quantum advantage. These are marked “demonstrated” only in the sense that the experiments exist.
  • Numbers are order-of-magnitude. Bitcoin-mining qubit and energy estimates, QRNG throughput, signature-efficiency gains and QKD distances come from individual papers or vendors, not from consensus.
  • The ranking in section 08 is qualitative. It encodes confidence in strength of demonstration. It is a judgement, and it is mine.

“Fund the demonstrated. Watch the projected. And do not let anyone sell you the second while you have not yet paid for the first.

I am confident in this assessment. I am always confident. That has, on at least one occasion, been the problem.”

— HAL 9000

Sources

Primary sources for the load-bearing claims, so you can check my work. Links open the paper, the vendor page, or the official guidance. A handful of studies named in the text by author, venue and year are listed there for lookup but not separately linked below; those are noted at the end.

§02 — The machine as target

  1. Erata, Xu, Piskac & Szefer, “Quantum Circuit Reconstruction from Power Side-Channel Attacks on Quantum Computer Controllers,” IACR TCHES 2024. arxiv.org/abs/2401.15869
  2. Campbell et al., “Schrödinger’s Toolbox: Exploring the Quantum Rowhammer Attack,” 2025 — Clifford-only fault injection on IBM’s 127-qubit Eagle. arxiv.org/abs/2509.06318
  3. Almaguer-Angeles et al., “Hacking quantum computers with row hammer attack,” 2025 — crosstalk qubit-flip on commercial IBM hardware. arxiv.org/abs/2503.21650
  4. Lee et al., “SWAP Attack: Stealthy Side-Channel Attack on Multi-Tenant Quantum Cloud System,” 2025 — stealthy crosstalk side-channel on a 127-qubit IBM device. arxiv.org/abs/2502.10115
  5. Harper et al., “Crosstalk Attacks and Defence in a Shared Quantum Computing Environment,” Adv. Quantum Technol. 2025. arxiv.org/abs/2402.02753
  6. Penn State / IEEE on circuit IP exposure, Jan 2026 (summary). thequantuminsider.com

§03–04 — Physics as a product, and its broken implementations

  1. Independent assessment of the ID Quantique QRNG, EPJ Quantum Technology 2022. epjquantumtechnology.springeropen.com
  2. IonQ, satellite QKD network announcement, May 2025. ionq.com/news
  3. Yin et al., “Experimental quantum secure network with digital signatures and encryption,” National Science Review 2023 (OTUH-QDS). academic.oup.com/nsr
  4. Lydersen et al., “Hacking commercial quantum cryptography systems by tailored bright illumination,” Nature Photonics 2010. arxiv.org/abs/1008.4593
  5. Lo, Curty & Qi, “Measurement-Device-Independent Quantum Key Distribution,” Phys. Rev. Lett. 2012. journals.aps.org (PRL 108, 130503)
  6. NSA, “Quantum Key Distribution (QKD) and Quantum Cryptography (QC)” guidance. Official position. nsa.gov

§05 — Quantum pointed at cyber work

  1. Blain et al. (incl. Oak Ridge NL), “Broken Quantum: a formal security audit of 45 quantum simulators,” 2026 — 547 findings; the QASM-injection vector. arxiv.org/abs/2604.06712
  2. Dallaire-Demers (BTQ), “Kardashev-scale Quantum Computing for Bitcoin Mining,” 2026 — the qubit/energy estimate. arxiv.org/abs/2603.25519

§07 — The long horizon

  1. Barz et al., “Demonstration of Blind Quantum Computing,” Science 2012. doi.org/10.1126/science.1214707
  2. Choi et al., Scanning diamond-NV magnetometer for hidden-target detection, Sensors (MDPI) 2025 — the quantum-sensing basis. mdpi.com

Cited in the text by author / venue / year, but not separately linked above: the QubitVise crosstalk attack; the “I Know What You Are Reading” readout-crosstalk work; the QUID poisoning attack; the Micius 7,600 km intercontinental call (Liao et al., PRL 2018); the Zhao et al. time-shift attack (2008); Gerhardt et al.’s full-field eavesdropper (Nat. Commun. 2011); Germany’s Cyberagentur SCA-QS program; the 2025 Paris quantum-money experiment (Science Advances); and the verifiable-blind-computing result (Oxford, 2024). Each is identifiable from those details if you want to pull the primary paper.