How Store Now, Decrypt Later Threatens Encrypted Data

Store now, decrypt later is a strategy in which an adversary intercepts and archives encrypted data today with the intention of decrypting it in the future, once a sufficiently powerful quantum computer becomes available. The concept, also called “harvest now, decrypt later,” is not a theoretical exercise confined to research papers. Intelligence agencies and state-sponsored groups with massive storage capacity already have the means to collect encrypted traffic at scale, and a scoping review of data-confidentiality lifetimes found that many categories of sensitive information, from health records to national-security files, carry secrecy obligations that stretch decades or are effectively perpetual. The uncomfortable implication is that some of today’s encrypted communications may already be sitting in archives, waiting for the hardware that can crack them open.

Why Quantum Computers Threaten Today’s Encryption

Most of the encryption protecting internet traffic, financial transactions, and government communications relies on mathematical problems that classical computers find impossibly slow to solve. Factoring enormous numbers and computing discrete logarithms on elliptic curves are the workhorses behind RSA and elliptic-curve cryptography, respectively. A sufficiently capable quantum computer running Shor’s algorithm could solve these problems efficiently, undermining the security guarantees those systems provide.1arXiv. Resource analysis of Shor’s elliptic curve algorithm with an improved quantum adder on a two-dimensional lattice This is not a brute-force attack in the traditional sense; the quantum algorithm restructures the problem so that the answer falls out quickly rather than requiring exhaustive searching.

Symmetric encryption like AES is in a somewhat different position. A quantum algorithm called Grover’s search can speed up brute-force key searches, effectively halving the security level of a symmetric key. Researchers have mapped out the precise quantum resources needed to run Grover’s algorithm against all three standard AES key sizes (128, 192, and 256 bit).2arXiv. Applying Grover’s algorithm to AES: quantum resource estimates In practice, this means AES-256 would still offer roughly 128 bits of security against a quantum attacker, which remains very strong. The real danger from store-now-decrypt-later is therefore concentrated on public-key cryptography, the part of the system that handles key exchange and digital signatures, not on the symmetric ciphers protecting the bulk data once a session is established.

How the Attack Actually Works

The mechanics are straightforward and, in some ways, disturbingly low-tech on the collection side. When two parties communicate over the internet using a protocol like TLS, the initial handshake uses public-key cryptography to agree on a shared session key. That handshake traffic is visible on the wire. An attacker who can tap network links or sit at a strategic routing point records the handshake along with the encrypted payload and stores the whole package. The attacker does not need to understand or break anything at the time of collection. Years or decades later, when a cryptographically relevant quantum computer (sometimes abbreviated CRQC) exists, the attacker feeds the stored handshake through Shor’s algorithm, recovers the session key, and decrypts the payload.

The strategy is rational for any actor with cheap storage and patience. Hard drives are inexpensive relative to the potential intelligence value of diplomatic cables, trade secrets, or weapons-program data. And the adversary does not even need to be selective: bulk collection of encrypted traffic is feasible for nation-state actors, and the decryption step can be prioritized later once the targets of interest are known. Research on the practical feasibility of these attacks notes that defenses like Encrypted Client Hello can force an adversary into indiscriminate bulk collection, inflating the archive they must retain, but the fundamental economic equation remains favorable for well-resourced attackers.3arXiv. On the Practical Feasibility of Harvest-Now, Decrypt-Later Attacks

Which Data Is Most Exposed

Not all encrypted data carries the same risk. A store-now-decrypt-later attack only matters if the information is still sensitive by the time the attacker can decrypt it. Your grocery list from 2024, even if intercepted, has zero intelligence value in 2040. The data categories that matter are those with long or indefinite confidentiality requirements, and a scoping review of data-confidentiality lifetimes found that the list is longer than most people assume. National-security records, health and genomic data, biometric identifiers, and privileged legal communications have confidentiality obligations that stretch decades or are effectively perpetual. Financial records typically span years to decades.4International Journal of Computational Intelligence Systems. Harvest Now, Decrypt Later as a Cross-sector Threat: A Scoping Review of Data-confidentiality Lifetimes Against Post-quantum Migration Readiness

The review’s central finding is a structural mismatch: the confidentiality obligations on much of this data last far longer than the time horizon in which quantum computers capable of breaking current encryption could plausibly arrive. Genomic data is a particularly vivid example. Your DNA sequence does not change. A genome sequenced today and intercepted in encrypted transit remains just as revealing if decrypted in 2045. The same logic applies to biometric identifiers like fingerprints and iris scans, which cannot be rotated the way a password can.

Corporate trade secrets, merger-and-acquisition communications, and source code for critical infrastructure systems also fall into this long-lived category. Even data that seems mundane in isolation can become valuable when aggregated. Metadata about communication patterns, travel, and associations, decrypted years later, could reconstruct social networks and intelligence relationships that were meant to stay hidden.

How Close Are We to a Cryptographically Relevant Quantum Computer

This is the question everyone wants a clean answer to, and the honest answer is that estimates keep shifting. No quantum computer in existence today can break RSA or elliptic-curve cryptography at the key sizes actually used in practice. But the resource estimates for doing so have been dropping steadily as researchers find more efficient ways to map the problem onto quantum hardware.

One line of research has explored how to factor 2048-bit RSA integers, the standard key size still widely used, under realistic hardware assumptions: a square grid of qubits with nearest-neighbor connections, a physical gate error rate of 0.1%, and a surface-code cycle time of one microsecond.5arXiv. How to factor 2048 bit RSA integers with less than a million noisy qubits A more recent architecture using quantum low-density parity-check codes pushed the estimate down further, showing that 2048-bit RSA could be factored with fewer than one hundred thousand physical qubits under similar error-rate assumptions.6arXiv. The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes

For context, the largest quantum processors announced as of early 2025 have on the order of one to two thousand qubits, and those qubits are noisy enough that error rates remain well above what these factoring schemes assume. The gap between where the hardware is and where it would need to be is still large. But the trajectory matters more than the snapshot. Each year brings improvements in qubit counts, error rates, and algorithmic efficiency. Most expert timelines for a cryptographically relevant quantum computer cluster somewhere between the early 2030s and the 2050s, with considerable uncertainty in both directions. The store-now-decrypt-later threat does not require the quantum computer to exist today. It only requires that the encrypted data remain valuable for longer than it takes the hardware to catch up.

Mosca’s Inequality and the Window of Exposure

A useful way to think about the urgency comes from a framework sometimes called Mosca’s inequality. The idea is simple: if the number of years your data needs to stay confidential, plus the number of years it will take you to migrate to quantum-safe encryption, exceeds the number of years before a quantum computer can break your current encryption, you are already at risk. The scoping review of confidentiality lifetimes applied this reasoning across sectors and concluded that data categories with multi-decade or indefinite confidentiality requirements are, by that logic, already exposed to store-now-decrypt-later, because credible expert estimates place a meaningful probability of a CRQC within the same horizon.7International Journal of Computational Intelligence Systems. Harvest Now, Decrypt Later as a Cross-sector Threat: A Scoping Review of Data-confidentiality Lifetimes Against Post-quantum Migration Readiness

This framing makes it clear that the problem is not just a hardware timeline question. It is also a migration-speed question. Large organizations with decades of legacy systems, complex supply chains, and embedded cryptographic dependencies cannot flip a switch and move to new algorithms overnight. The transition will take years, possibly a decade or more for some sectors. Any delay in starting that migration extends the window of exposure.

Post-Quantum Cryptography as the Primary Defense

The main countermeasure the cryptographic community is pursuing is post-quantum cryptography, or PQC: new encryption algorithms designed to resist both classical and quantum attacks. These are not quantum systems themselves. They run on ordinary computers but rely on mathematical problems, such as finding short vectors in high-dimensional lattices, that are believed to be hard even for quantum computers. Lattice-based approaches, including variants built on the Ring Learning with Errors problem, have been central to the standardization effort.8Mathematics. Revisiting Multivariate Ring Learning with Errors and Its Applications on Lattice-Based Cryptography

NIST finalized its first set of post-quantum standards in 2024, selecting algorithms for both key encapsulation (how two parties agree on a shared secret) and digital signatures. The key encapsulation standard, based on the CRYSTALS-Kyber algorithm (now called ML-KEM), is already being integrated into browsers, operating systems, and VPN products. Google and Apple, among others, have begun deploying hybrid key exchanges that combine a traditional algorithm with a post-quantum one, so that the connection remains secure even if one of the two is broken.

Hybrid approaches are the pragmatic bridge strategy. By running a classical key exchange alongside a post-quantum one, you get the well-tested security properties of the former and the quantum resistance of the latter. Even if the new post-quantum algorithm turns out to have an unforeseen weakness, the classical layer provides a safety net, and vice versa.

PQC Is Not a Silver Bullet for Already-Captured Data

There is a critical asymmetry that post-quantum cryptography cannot fix. Migrating to PQC protects future communications. It does nothing for data that has already been captured using classical key exchanges. An analysis of the Bitcoin network illustrates this point clearly: while the network’s maintainers could deploy post-quantum cryptography to protect the security and integrity of future transactions, the data privacy of previously recorded transactions remains vulnerable to a future quantum computer due to store-now-decrypt-later.9Finance and Economics Discussion Series. “Harvest Now Decrypt Later”: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks The same logic applies everywhere: any encrypted traffic already sitting in an adversary’s archive is beyond the reach of algorithm upgrades. The encryption used at the time of transmission is what the attacker will eventually break, regardless of what new protocols the sender adopts afterward.

This is why urgency matters. Every day that organizations continue using quantum-vulnerable key exchanges for sensitive data is another day of traffic that could end up in a store-now-decrypt-later archive. The clock started long ago for state-level adversaries with the resources and motivation to collect at scale.

Defenses Beyond New Algorithms

Switching to PQC is necessary but not sufficient. Several additional strategies can raise the cost and difficulty of store-now-decrypt-later attacks, even before a full migration to post-quantum algorithms is complete.

Aggressive rekeying is one such measure. If a connection frequently rotates its encryption keys during a session, an attacker who breaks one key recovers only a small slice of the conversation. Multiplying the number of quantum computations required to recover a complete plaintext makes the attack far more expensive. Similarly, using larger key-exchange parameters increases the quantum resources an attacker would need per key broken. Research on the practical feasibility of these attacks identifies both rekeying and Encrypted Client Hello as strategies that provide defense in depth with current infrastructure.10arXiv. On the Practical Feasibility of Harvest-Now, Decrypt-Later Attacks

Quantum key distribution (QKD) is sometimes proposed as an alternative path. QKD uses the physics of quantum mechanics to distribute keys in a way that is theoretically secure regardless of an attacker’s computational power. In practice, QKD has significant limitations: it requires dedicated fiber-optic links or satellite channels, specialized hardware at both ends, and cannot easily scale to the internet’s billions of connections. A comparative analysis of QKD and PQC deployments found that while QKD offers strong security guarantees under ideal conditions, its reliance on specialized quantum hardware and dedicated infrastructure makes it impractical for most real-world settings.11International Journal of Scientific Research in Engineering and Management. Comparative study of Post-Quantum Cryptography (PQC) vs Quantum Key Distribution (QKD) in IOT ‘Smart Home’ A broader critical analysis of QKD use cases reached a similar conclusion, noting that PQC and QKD have distinct suitability profiles depending on implementation complexity, scalability, and long-term security needs.12PubMed Central. A critical analysis of deployed use cases for quantum key distribution and comparison with post-quantum cryptography For most organizations, PQC is the realistic path forward, with QKD potentially serving niche, high-value links where the infrastructure investment is justified.

Side-Channel Risks in the New Algorithms

Adopting post-quantum algorithms introduces a different class of concern. The mathematical foundations of lattice-based cryptography may resist quantum attacks, but the physical implementations of those algorithms can still leak information through side channels. Power consumption patterns, electromagnetic emissions, and timing variations during cryptographic operations can all be exploited by an attacker with physical or near-physical access to the hardware.

Research evaluating the CRYSTALS-Kyber key encapsulation mechanism, the algorithm at the heart of NIST’s new standard, found that unprotected hardware implementations were successfully compromised using power-analysis techniques. The attacks worked across all Kyber parameter sets, revealing significant information leakage.13IAES International Journal of Artificial Intelligence (IJ-AI). Securing post-quantum cryptography: side-channel resilience in CRYSTALS-Kyber key encapsulation mechanism This does not mean the algorithm itself is broken. It means that deploying PQC securely requires careful attention to how the algorithms are implemented in silicon, not just which algorithms are chosen. Countermeasures like masking and shuffling operations can mitigate side-channel leakage, but they add complexity and computational cost. For the store-now-decrypt-later problem specifically, side-channel attacks are less directly relevant, since the adversary is working with stored network traffic rather than physical access to the target’s hardware. But they underscore the broader point that cryptographic security is a system property, not just an algorithm property.

What Organizations Should Be Doing Now

If you run an organization that handles data with long confidentiality requirements, the time to start acting was years ago, but starting today is immeasurably better than starting after a CRQC is announced. The practical steps fall into a few categories.

First, inventory your cryptographic dependencies. Most large organizations do not know which of their systems use RSA, which use elliptic-curve cryptography, and which already use symmetric-only protocols that are less vulnerable. You cannot migrate what you have not mapped. This process is sometimes called achieving “cryptographic agility,” the ability to identify and swap out cryptographic components without rebuilding entire systems.

Second, prioritize based on data sensitivity and longevity. Not everything needs to migrate at once. Communications carrying genomic data, classified intelligence, or biometric identifiers should move first. Routine internal emails about lunch orders can wait. The Mosca framework described earlier gives you a rough decision tool: estimate how long the data needs to stay secret, estimate how long your migration will take, and compare that sum against the shortest plausible timeline for a CRQC.

Third, begin deploying hybrid key exchanges where possible. Major browser vendors and cloud providers already support them. For custom applications and VPNs, the engineering lift is real but increasingly well documented. Running classical and post-quantum key exchanges in parallel means you gain quantum resistance without betting everything on algorithms that are still relatively young and could see refinements.

Fourth, consider whether any of your most sensitive data should move to channels that avoid public-key key exchange entirely for the transit layer. Pre-shared symmetric keys distributed out of band, while operationally cumbersome, sidestep the store-now-decrypt-later problem completely for that traffic.

The Blockchain Wrinkle

Distributed ledger systems like Bitcoin face a version of this problem that is uniquely hard to solve. Blockchains are designed to be immutable public records. Every transaction ever made on the Bitcoin network is visible to anyone. The cryptographic protection comes from the assumption that public keys cannot be reverse-engineered to reveal private keys. Once a quantum computer can do that, every Bitcoin address whose public key has been exposed (which happens whenever that address sends a transaction) becomes vulnerable. The coins held at those addresses could be stolen.

The deeper issue, as a Federal Reserve analysis noted, is data privacy. Even if the Bitcoin protocol migrates to post-quantum signatures for new transactions, the entire historical ledger remains readable. Anyone who ever transacted on the network before the migration has their transaction graph exposed to a quantum-equipped adversary. For a system that many users adopted partly for pseudonymity, this is an existential privacy concern.14Finance and Economics Discussion Series. “Harvest Now Decrypt Later”: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks Unlike traditional encrypted communications, where the ciphertext might only exist in a single adversary’s archive, blockchain data is publicly archived by design. The adversary does not even need to harvest it covertly; it is already stored everywhere.

A Readiness Gap That Is Itself a Risk

Perhaps the most sobering takeaway from recent research is not any single technical finding but the state of preparedness across sectors. The scoping review that examined confidentiality lifetimes against post-quantum migration readiness identified what it called a “readiness evidence gap” that is itself a risk. Many organizations have not assessed which of their systems are quantum-vulnerable, have not begun migration planning, and in some cases are not even aware of the store-now-decrypt-later threat.15International Journal of Computational Intelligence Systems. Harvest Now, Decrypt Later as a Cross-sector Threat: A Scoping Review of Data-confidentiality Lifetimes Against Post-quantum Migration Readiness Healthcare, legal, and financial sectors all hold data with decades-long confidentiality requirements and complex legacy IT environments that will make migration slow and expensive. The gap between what these sectors need to protect and how far along they are in protecting it is wide, and that gap is a gift to any adversary patient enough to fill storage drives while they wait.