We think 2026 has been the year of AI, and it has. But underneath all of that noise there’s a second shift moving almost as fast, and it’s getting a fraction of the attention: quantum computing.
Here's what changed. In 2019, the best estimate for breaking RSA-2048 was about 20 million qubits. In May of last year, a Google researcher got it under one million — running the same hardware assumptions as the 2019 paper. Same grid, same error rate, same cycle time. In February, an Australian startup called Iceberg Quantum published an architecture that puts it under 100,000. Two hundred-fold in seven years, and not one qubit of it came from better hardware. It came from better algorithms and better error correction.
Governments noticed before most enterprises did. NSA’s CNSA 2.0 requires new national security systems to be quantum-safe starting January 2027. NIST deprecates RSA-2048 and P-256 in 2030 and disallows them in 2035. The EU wants high-risk systems migrated by the end of 2030, and the UK’s NCSC set milestones at 2028, 2031, and 2035. 2026 has been designated the “Year of Quantum Security.” The timeline to Q-Day isn’t a question of if anymore, but a question of how much of your traffic somebody already has.
Because that’s the real threat. It isn’t that a quantum computer shows up one morning and reads your data live. It’s Harvest Now, Decrypt Later. An adversary with patience captures your encrypted traffic today — cloud-to-cloud, data center to cloud, region to region — and stores it. When the machine arrives, everything they’ve collected opens at once. Instead of happening the day the data is stolen, the breach happens years later, when the encryption around it simply stops working. Anything you need to keep confidential into the 2030s is exposed right now.
This harvest is already happening. In June 2019, a Swiss colocation provider leaked 70,000 routes to China Telecom, which propagated them to the world instead of filtering them. For over two hours, traffic for Swisscom, KPN, Bouygues Telecom and SFR, four of Europe’s largest mobile carriers, transited a network none of them had a relationship with, and nobody noticed until researchers did. Seven months earlier, the same thing happened to a large slice of Google’s traffic. Researchers at the Naval War College had already argued that China Telecom had been doing this on purpose for years. Whether you believe the intent or not, the traffic went through.
Then there’s Salt Typhoon. In 2024, we learned a Chinese state group had spent months inside AT&T, Verizon, Lumen, T-Mobile, and a half-dozen other US carriers. They were sitting on the lawful-intercept systems themselves, with the same view of the network the carriers had. BGP hijacking is harvest in transit; Salt Typhoon is harvest at the carrier. Either way, the lesson is the same: you don’t control the path, and you can’t assume the path is clean. The traffic collected in 2019 is seven years old. If it was protected with RSA key exchange, it’s still sitting there.
A Year for Turing
It’s hard not to think about Alan Turing this year. His test for machine intelligence is the yardstick everyone’s arguing about for AI. But most of his life’s work was on the other side of this coin, breaking Enigma. Encryption and the attempt to break it have been the quiet backbone of computing since before computing had a name. Quantum is just the next round.
My own start was less consequential. When I was a kid, my cousin and I used to send each other notes typed in Word and switched to Wingdings. Without the key, or an unreasonable memory for symbols, my sisters had no idea how we were planning to give them a hard time on our next family vacation. That’s the whole idea of encryption in one sentence: the ciphertext is worthless without the key. Harvest Now, Decrypt Later is a bet that one day the key won’t matter.
Two Places the Network Can Help
I’ve worked in Zero Trust for over ten years, and in that time there have really only been two places the network gets to participate:
Encryption — protect what’s on the wire.
Containment — control who’s allowed to talk to whom in the first place.
With quantum, both matter. Encryption is the obvious one: if the harvested traffic is protected with quantum-safe key exchange, the harvest is worthless. Containment is the one people skip: you can’t harvest a flow that was never allowed to leave. Egress control, east-west segmentation, and blocking connections to known-bad infrastructure shrink the attack surface an adversary can collect from at all.
Too often in cloud, neither principle is followed. Some of that is speed winning over security. A lot of it is that the primitives were built for developers, not for security teams, and the shared responsibility model puts encryption of your traffic squarely on you. The provider encrypts what it operates. The moment a packet leaves that fabric to another cloud, to a colo, or to a partner, it’s your job.
Fix the Trunk, Not the Leaves
There’s a hard truth about PQC migration that the vendor pitches skip. The standard advice is: inventory every application, find every library using RSA or ECDH, and upgrade them one by one. That’s patching the leaves.
I was on a call with a customer last week who described what that looks like in practice. App teams churn. Business-critical applications no longer have a clean owner. Nobody’s confident how they work, let alone what they depend on. This is an organization that struggles to patch those apps, and we’re asking them to swap the cryptography underneath? We’ve done a migration like this before. TLS 1.0 and 1.1 were deprecated, and the industry moved. But that was a one-time event with a known destination. Quantum is different in two ways:
We don’t know if these algorithms will hold. ML-KEM is new. Lattice cryptography is new at this scale. The standards bodies already assume at least two algorithm transitions between now and 2035, before you account for surprises.
The surprises might not come from quantum at all. Two weeks ago, OpenAI announced that one of its models had cracked the Navier-Stokes problem, a Millennium Prize problem, open for roughly ninety years, in under four days of compute, by solving a case where equations physicists have trusted for two centuries break down. The proof is machine-verified; the mathematicians are still absorbing it. Every encryption algorithm we use rests on the same kind of claim: “nobody has found a way to break this.” If AI can find the solution to Navier-Stokes in 88 hours, the assumption that today’s cryptographic hardness holds for a decade deserves less confidence than we’re giving it.
What that means is the answer isn’t “upgrade to PQC.” The answer is crypto agility: the ability to change the algorithm on a dime, across everything, without a migration project. And you can’t get that at the leaves. You get it at the trunk: the network fabric every application already runs on.
Introducing Aviatrix Harvest and Decrypt Protection
This is why we’ve been building toward this for years, and why the foundation is our High Performance Encryption technology: what our customers still call Insane Mode. It does 100+ Gbps of encryption in a single virtual connection, in software, on cloud compute. That last part is the point. There is no crypto ASIC for an EC2 instance. Inside the cloud and across the mid-mile, software crypto is the only crypto, and agility is a software property. Hardware can’t be crypto-agile: a new algorithm on a MACsec PHY is a hardware refresh. Cloud native VPN gives you the provider’s algorithm on the provider’s timeline at roughly a gigabit per tunnel. And MACsec on your DX or ExpressRoute cross-connect protects exactly one link, then decrypts at the provider’s edge.
Aviatrix Harvest and Decrypt Protection has two parts:
See your cryptographic posture — all of it. Because Aviatrix operates from Layer 3 through Layer 7, we see every flow crossing the fabric, encrypted by us or not. Every one of them reports its cryptographic status, so you can build and maintain a Cryptographic Bill of Materials (CBOM) from real traffic rather than from a spreadsheet of what the app teams think they’re running. It’s how you find the leaves that still need fixing and prove to an auditor that the trunk is done.
Prevent the harvest. Aviatrix 10.1, our largest release ever at 41 new capabilities, levels up the containment side again. The new Security Policy dashboard stands up Recommended Security Controls — geoblocking, threat blocking, risky workload ports — in minutes, powered by threat intelligence upgraded in partnership with Proofpoint. Every control starts in monitor mode so you see the impact before you enforce. Local breakout puts policy on the egress paths that used to bypass inspection entirely, and east-west Layer 7 inspection arrives in Preview. Traffic that can’t reach an attacker’s collector can’t be harvested. To make this easier to adopt, we’re also introducing new offerings that make egress security faster, safer, and more affordable to deploy in cloud.
Where to Start
You don’t start with an algorithm, but by understanding what’s actually talking on your network and where it’s going, because that’s the map of what can be harvested. That’s exactly what the Aviatrix Containment Assessment shows you: lateral movement paths, segmentation gaps, and uncontrolled egress flows, mapped to real workload behavior in minutes.
Q-Day is coming, and the harvest is already happening. The good news is that for the first time, the cloud network can fix this at the trunk, and fix it fast.
Start with a free, 5-minute Containment Assessment to find containment gaps and harvest exposure in your network.
References
Axios, "At least 8 U.S. telcos compromised in Chinese hack, White House says," December 4, 2024, https://www.axios.com/2024/12/04/china-telecom-hacks-white-house-statement
BankInfoSecurity, "Who Hijacked Google's Web Traffic?" November 13, 2018, https://www.bankinfosecurity.com/who-hijacked-googles-web-traffic-a-11699
European Commission, "EU reinforces its cybersecurity with post-quantum cryptography," April 11, 2024, https://digital-strategy.ec.europa.eu/en/news/eu-reinforces-its-cybersecurity-post-quantum-cryptography
Forbes, "Salt Typhoon: A Wake-Up Call for Strengthening Telecom Cybersecurity," March 5, 2025, https://www.forbes.com/councils/forbestechcouncil/2025/03/05/salt-typhoon-a-wake-up-call-for-strengthening-telecom-cybersecurity/
Gidney, Craig, "How to factor 2048 bit RSA integers with less than a million noisy qubits," May 2025, https://research.google/pubs/how-to-factor-2048-bit-rsa-integers-with-less-than-a-million-noisy-qubits/
Gidney, Craig, and Martin Ekerå, "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits," May 23, 2019, https://arxiv.org/abs/1905.09749
Google Research, "Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly," March 31, 2026, https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/
IETF, "Deprecating TLS 1.0 and TLS 1.1 (RFC 8996)," March 2021, https://datatracker.ietf.org/doc/rfc8996/
Military Cyber Affairs (USF), "China's Maxim — Leave No Access Point Unexploited: The Hidden Story of China Telecom's BGP Hijacking," October 2018, https://digitalcommons.usf.edu/mca/vol3/iss1/7/
NCSC, "Post-quantum cryptography: migration timelines," March 2025, https://www.ncsc.gov.uk/guidance/pqc-migration-timelines
NIST, "Transition to Post-Quantum Cryptography Standards (NIST IR 8547)," November 2024, https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
NSA, "Announcing the Commercial National Security Algorithm Suite 2.0," May 30, 2025, https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
OpenAI, "On the Navier–Stokes Millennium Prize Problem," September 8, 2026, https://openai.com/index/navier-stokes-solution/
Quanta Magazine, "AI Has Solved One of Math's $1 Million Millennium Prize Problems," September 8, 2026, https://www.quantamagazine.org/ai-has-solved-one-of-maths-1-million-millennium-prize-problems-20260908/
SecurityWeek, "China Telecom Routes European Traffic to Its Network for Two Hours," June 2019, https://www.securityweek.com/china-telecom-routes-european-traffic-its-network-two-hours/
The Quantum Insider, "After a Year of Quantum Awareness, 2026 Becomes the Year of Quantum Security," January 6, 2026, https://thequantuminsider.com/2026/01/06/after-a-year-of-quantum-awareness-2026-becomes-the-year-of-quantum-security/
ThousandEyes, "Internet Vulnerability Takes Down Google," November 12, 2018, https://www.thousandeyes.com/blog/internet-vulnerability-takes-down-google
Webster, Paul, et al., "The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100,000 physical qubits using quantum LDPC codes," February 12, 2026, https://arxiv.org/abs/2602.11457
Ready to see Aviatrix in action?
Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.
Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report
Download and gain actionable insights to advance your cloud security strategy.




















