What If Quantum Computers Cracked All Encryption?
Technology

What If Quantum Computers Cracked All Encryption?

• 7 min read

Every secret you've ever told the internet is protected by the same basic principle: certain maths problems are really, really hard to solve. Your bank password, your medical records, your private messages, your government's classified intelligence. All of it sits behind encryption that would take a classical computer longer than the age of the universe to break.

Then someone builds a quantum computer powerful enough to solve those problems in minutes.

Everything opens at once.

What encryption actually does

When you log into your bank, your browser and the bank's server perform a handshake using RSA or elliptic curve cryptography. The security of RSA depends on the difficulty of factoring very large numbers into their prime components. A 2048-bit RSA key is the product of two prime numbers, each about 300 digits long. Finding those two primes by brute force would take a classical computer roughly 300 trillion years.

Quantum computers change that calculation. In 1994, mathematician Peter Shor published an algorithm showing that a sufficiently powerful quantum computer could factor large numbers exponentially faster than any classical method. A quantum machine with about 4,000 stable, error-corrected qubits could crack 2048-bit RSA in hours. Current quantum computers have a few thousand physical qubits, but error correction requires many physical qubits per logical qubit, so we're not there yet.

But "not there yet" is a statement about engineering timelines, not about physics. The algorithm works. The question is when, not whether.

For this thought experiment, the answer is now.

The first twenty-four hours

The immediate consequences are financial. Every HTTPS connection on the internet relies on public-key cryptography. Online banking, stock trading, cryptocurrency wallets, payment processing. All of it becomes transparent overnight.

Shattered padlock superimposed on lines of digital code

Bank accounts aren't just vulnerable. They're readable. Anyone with access to the encrypted traffic (which intelligence agencies have been hoovering up and storing for years, precisely in anticipation of this moment) can now decrypt it all retroactively. Your bank transfers from 2019? Readable. Your password from 2015? Exposed. The NSA's stored intercepts from the last two decades? Suddenly a goldmine.

This retroactive decryption is the part most people miss. Intelligence agencies have been running programmes (the NSA's "harvest now, decrypt later" approach is well documented) that collect encrypted data today on the assumption they'll be able to read it tomorrow. When quantum computing arrives, "tomorrow" becomes "today" for every intercepted communication in their archives.

The cryptocurrency market collapses instantly. Bitcoin's security relies on the Elliptic Curve Digital Signature Algorithm (ECDSA). Break that and you can forge transactions, steal from any wallet, and undermine the entire blockchain's integrity. Bitcoin's market capitalisation as of early 2026 sits around $1.9 trillion. It goes to zero in a day because the mathematical guarantee underpinning every transaction no longer holds.

Military and intelligence

Every encrypted military communication from the last several decades is now an open book. Troop movements, intelligence assessments, diplomatic cables, nuclear launch protocols, spy identities, covert operation details. All readable by anyone with the stored ciphertext and a quantum computer (or access to someone who has one).

The intelligence consequences are staggering. MI6 officers operating under cover abroad are identified within hours because their encrypted communications with London are decrypted. CIA assets in hostile countries are exposed. The names and locations of every intelligence source that communicated electronically become available to any government that stored the traffic.

People die. Not hypothetically. Real intelligence officers and their sources get killed because their cover depended on encryption that no longer works.

Nuclear command and control systems use encrypted communications to transmit launch orders. If those channels are compromised, the ability of a government to securely control its nuclear arsenal evaporates. You can't launch nuclear weapons if you can't verify that the order to launch is genuine and not a spoofed command from an adversary who cracked your encryption.

Conversely, you can't stand down a false alarm if your communications can't be trusted. The entire nuclear deterrence framework depends on secure communication between early-warning systems, command authorities, and weapons platforms. Break the encryption and you break the chain of command.

The internet goes dark

Not dark as in "stops working." Dark as in "becomes untrustworthy."

TLS certificates, the system that puts the padlock icon in your browser, rely on public-key cryptography. Without functional encryption, there's no way to verify that the website you're visiting is actually that website and not an impersonator. Man-in-the-middle attacks become trivial. Someone could sit between you and your bank, reading and modifying every piece of data in transit, and neither you nor the bank would know.

Browser address bar showing a broken padlock warning icon

E-commerce stops. Nobody will enter a credit card number into a form they can't trust. Online voting? Impossible. Telemedicine? You can't transmit patient records if anyone can read them in transit. Cloud storage? Every file you uploaded to Google Drive or Dropbox is accessible to whoever intercepted the encrypted upload.

The internet doesn't physically break. The cables still carry data. The servers still respond. But trust, the invisible foundation the entire system runs on, is gone.

What about post-quantum cryptography?

Cryptographers saw this coming. NIST (the US National Institute of Standards and Technology) has been running a competition since 2016 to develop encryption algorithms that resist quantum attacks. In 2024, they published their first set of post-quantum cryptography standards: ML-KEM (formerly CRYSTALS-Kyber) for key encapsulation and ML-DSA (formerly CRYSTALS-Dilithium) for digital signatures.

These algorithms are based on mathematical problems that quantum computers can't solve efficiently (lattice-based problems rather than factoring). They work. They're being deployed. Google has been testing post-quantum key exchange in Chrome since 2023. Signal implemented the PQXDH protocol in late 2023.

But there's a gap. The gap between "standards are published" and "every system on earth has migrated to the new standard" is measured in years, possibly decades. Banks, governments, hospitals, power grids, military systems, embedded devices, IoT sensors. Millions of systems running legacy encryption that their operators haven't updated, can't update, or don't know needs updating.

When quantum computers break current encryption, every system that hasn't migrated to post-quantum algorithms is exposed. And the migration is a colossal undertaking. It's not a software update you push to a phone. It's rebuilding the cryptographic foundations of every connected system on the planet.

The scramble

Governments would declare emergencies. Financial markets would suspend trading. Military communications would revert to physical couriers carrying paper documents, a method that's unbreakable by quantum computers but somewhat slower than fibre-optic cables.

Air-gapped systems (computers never connected to the internet) become the only trusted platforms. Critical infrastructure disconnects from the network. The global internet fragments into isolated, physically secured networks that communicate through trusted human intermediaries rather than encrypted digital channels.

It would look, in many ways, like going backwards. The digital age's greatest achievement was connecting everything to everything. Quantum decryption's consequence is that you can no longer afford to have everything connected.

The deeper problem

Encryption isn't just a technical tool. It's the reason digital society functions at all. Without it, there is no online privacy, no secure communication, no digital commerce, no protection for dissidents living under authoritarian governments, no attorney-client privilege over email, no confidential medical records, no secure elections.

Privacy and encryption are so tightly coupled that destroying one effectively destroys the other. And privacy, despite being unfashionable in an age of social media oversharing, is the foundation that free societies are built on. The ability to have a private thought, a private conversation, a private transaction. Remove that and the power dynamic between individuals and institutions shifts permanently toward the institutions.

We'll get quantum-resistant encryption deployed eventually. The maths exists. The standards are written. The implementations are being tested. But the transition period, the years between "quantum computers can break everything" and "everything has been upgraded to resist quantum computers," would be the most dangerous window in the history of information security. Every stored secret from the last thirty years, readable. Every system that hasn't migrated, vulnerable.

The padlock in your browser bar is a promise. Right now, it's a promise that holds. Whether it holds for another five years or another fifty depends on a race between two groups of very smart people: the ones building quantum computers and the ones building defences against them.