Skip to content

harvest-now-decrypt-later survey instrument

Your cryptography has arupture date.Find it before someone else does.

RSA and elliptic-curve keys are not "going to break someday" — an adversary can harvest the traffic now and read it once a cryptographically relevant quantum computer exists. What breaks first is not the newest key; it is the data with the longest confidentiality lifetime. Cryptotremor surveys your manifest against real Shor and Grover resource estimates, sequences the migration, and hands your partners a report they can verify.

Engine
SHA-384 sealed
Attack model
Shor + Grover
Deadline clock
2030 / 2035
Agent tools
10 MCP tools
2026 → 2045hover or click a year

Reference estate · computed from the bundled manifest

6 primitives scored by the same engine the API runs. By 2045 the modelled break exposes 83.3% of the estate, and the earliest rupture is 2029. Nothing here is stored — load it to make it yours.

Step 1 — establish an estate

Load a cryptographic manifest

anonymous session · no account

Every row is written to the production database and sealed into an audit chain. Start with the bundled reference estate, or paste a CSV/JSON manifest of your own.

The cost ledger is real arithmetic

Shor's algorithm needs a working register proportional to the modulus and a Toffoli count superlinear in it; Grover only halves symmetric security. Cryptotremor converts those into a physical-qubit figure at a distance-15 surface code, then reports the year a break would cost less than a day under three attacker scenarios. Coefficients are calibrated against published factoring estimates and documented in the engine.

RSA-2048

RSA 2048-bit

Attack
shor
Logical qubits
2,868
Physical (d=15)
1,290,600
Non-Clifford ops
1.68e+8
Break < 1 day
2038

→ ML-KEM-768 (FIPS 203)

ECDSA-P256

ECDSA NIST P-256

Attack
shor
Logical qubits
359
Physical (d=15)
161,550
Non-Clifford ops
2.62e+6
Break < 1 day
2029

→ ML-DSA-65 (FIPS 204)

AES-256-GCM

AES-256-GCM

Attack
grover
Logical qubits
34
Physical (d=15)
15,300
Non-Clifford ops
2.67e+41
Break < 1 day
> 2045

→ AES-256-GCM (retain)

ML-KEM-768

ML-KEM-768

Attack
none
Logical qubits
0
Physical (d=15)
—
Non-Clifford ops
—
Break < 1 day
> 2045

→ Deployed

Six weighted factors, itemized

Algorithm class, harvest lifetime, compliance clock, migration lead time, data classification and exposure surface. Each factor carries the sentence that produced it and the lever that moves it — no black-box score.

Grover-sequenced waves

One migration retires a whole system, so the planner searches over systems with Grover amplitude amplification and reports the measured amplification factor for each pick.

Sealed, replayable history

Every create, update, decision and delete appends a SHA-384 hash-chained event over canonical JSON. Deletions leave tombstones, so the chain still replays.

What a visitor can actually do

  1. 01

    Import

    Load a CSV or JSON manifest, or the bundled reference estate. Rows are validated individually so one typo never blocks the batch.

  2. 02

    Inspect

    Open any primitive for its quantum cost ledger, factor evidence, binding constraint and full audit trail.

  3. 03

    Decide and scrub

    Record a migration decision, then drag the rupture rail to any year and watch the queue re-sequence against real measurements.

  4. 04

    Export and share

    Download JSON, Markdown or CSV, or freeze a snapshot partners can read without an account — with the chain head attached.

Live signals behind the survey

kev: live · arxiv: live

Live preprint feed, newest first. Retrieved 12 entries.

CISA · known exploited vulnerabilities

  • CVE-2023-27997

    Fortinet · FortiOS and FortiProxy SSL-VPN — Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability

    Named crypto/TLS/authentication surface with 100% relevance to a cryptographic inventory.

  • CVE-2020-12812

    Fortinet · FortiOS — Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

    Named crypto/TLS/authentication surface with 100% relevance to a cryptographic inventory.

  • CVE-2018-13379

    Fortinet · FortiOS — Fortinet FortiOS SSL VPN Path Traversal Vulnerability

    Named crypto/TLS/authentication surface with 100% relevance to a cryptographic inventory.

  • CVE-2025-34026

    Versa · Concerto — Versa Concerto Improper Authentication Vulnerability

    Named crypto/TLS/authentication surface with 75% relevance to a cryptographic inventory.

  • CVE-2025-24472

    Fortinet · FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

    Named crypto/TLS/authentication surface with 75% relevance to a cryptographic inventory.

CISA Known Exploited Vulnerabilities catalog · fetched 2026-10-03T10:02:32.731Z

arXiv · quant-ph preprints

arXiv quant-ph · fetched 2026-10-03T10:02:32.795Z

Read the numbers before the deadline

Cryptotremor produces planning estimates, not a security audit, a compliance determination or a cryptographic review. Rupture years are scenarios derived from published resource estimates and an assumed attacker roadmap, not predictions. Have a qualified cryptographer review any migration decision before acting on it.