The encryption protecting communications against criminal and nation-state snooping is under threat. As private industry and governments get closer to building useful quantum computers, the algorithms protecting Bitcoin wallets, encrypted web visits, and other sensitive secrets will be useless. No one doubts the day will come, but as the now-common joke in cryptography circles observes, experts have been forecasting this cryptocalypse will arrive in the next 15 to 30 years for the past 30 years.
The uncertainty has created something of an existential dilemma: Should network architects spend the billions of dollars required to wean themselves off quantum-vulnerable algorithms now, or should they prioritize their limited security budgets fighting more immediate threats such as ransomware and espionage attacks? Given the expense and no clear deadline, it’s little wonder that less than half of all TLS connections made inside the Cloudflare network and only 18 percent of Fortune 500 networks support quantum-resistant TLS connections. It’s all but certain that many fewer organizations still are supporting quantum-ready encryption in less prominent protocols.



The underlying problem (Shortest Vector Problem) is known to be NP-Hard.
We know, via mathematical proof, that if there is a solution to SVP that’s solvable in polynomial time then it would necessarily mean that it is possible to solve any NP problem in polynomial time.
This would be astonishing, to put it mildly. It would be as if physics suddenly discovered that things could move faster than light and have negative mass. Physics would get wormholes and computer science would get “Arthur C. Clark magic”* programs.
(*“Any sufficiently advanced technology is indistinguishable from magic.” )