Quantum threats are unique.
Store now, decrypt later is a strategy where an attacker records encrypted data today, stores it, and waits for a quantum computer capable of breaking the encryption to exist. The interception happens years before the cryptography even breaks, which means for long-lived secrets, the attack has already started.
The deadline to secure secrets arrives before the machine does, because an attacker can record encrypted traffic now and decrypt it once the hardware exists.

Why recording now pays off later
Public-key encryption in wide use today, including RSA and elliptic curves, is breakable by Shor's algorithm on a sufficiently large quantum computer. No machine can currently run it at that scale. But encrypted traffic and onchain data are durable: anything captured today remains exactly as crackable tomorrow as the day it was recorded. The value of the attack depends only on whether the secret still matters when the machine arrives.
Governments treat this as a live threat. The US CNSA 2.0 timeline requires national security systems to move to post-quantum algorithms, with new acquisitions expected to comply by the late 2020s and full migration by 2033. NIST finalized the replacement algorithms in 2024, including the hash-based signature standard FIPS 205.
What this means for crypto specifically
Blockchains are the most vulnerable to store now, decrypt later, because nothing needs intercepting. The data is public by design. Any address that has ever signed a transaction has published its public key on chain, permanently. When a machine capable of running Shor's algorithm at scale exists, every one of those exposed keys can be used to derive private keys and steal the funds.
That reverses the usual security question. It’s not "will my wallet be safe when quantum computers arrive?" It’s "has my public key already been exposed?" and for millions of addresses, including many from the Satoshi era, the answer is yes.
What actually defends against it
Two things, and the order matters.
First, stop new exposure. Avoid reusing addresses, since an address that has never sent a transaction has not revealed its public key.
Second, move long-horizon holdings behind signatures a quantum computer cannot break. Hash-based schemes rest on the same security assumption as Bitcoin's mining, and they can be applied at the account level today, without waiting for any base chain to hard-fork.
This is the layer we build at Quip: accounts that wrap assets on the chains they already live, providing protection from quantum computers not years from now but today.
If you want a running clock on the research milestones between here and the machine that matters, we maintain one at quantumdoomclock.com.
