
My illustration entitled: “The Quantum Siege” – A colossal quantum computer unleashes luminous waves against the cryptographic walls of a digital civilization. I stand on the battlements, replacing shattered locks with post-quantum shields built from lattice patterns.
For decades, modern cryptography has protected the digital world by placing certain mathematical problems beyond the practical reach of conventional computers. Encryption protects private communications. Digital signatures authenticate identities and authorize transactions. Public-key systems allow strangers to establish secure connections across hostile networks without first exchanging a secret in person.
Much of digital civilization now depends upon these protections. Banking, electronic commerce, software distribution, government communications, medical records, corporate infrastructure, digital identity and cryptocurrencies all rely upon cryptographic assumptions that most users never see.
Quantum computing challenges some of those assumptions.
A sufficiently powerful quantum computer could threaten several public-key algorithms upon which contemporary digital security depends. Such a machine does not yet exist at the scale necessary to break widely deployed modern encryption. Nevertheless, the danger cannot be postponed until the machine arrives. Confidential information intercepted today may be stored and decrypted years later. Digital identities, long-lived credentials and self-custodied assets may remain exposed long enough for a future breakthrough to become relevant.
The question for Cypherpunkism is therefore not whether quantum computing should be feared or prohibited. The question is whether individuals and societies can cross into a new cryptographic era without surrendering the privacy, ownership and digital sovereignty that cryptography was created to protect.
The Cryptographic Foundation of Digital Sovereignty
Cypherpunkism treats cryptography as more than a technical security mechanism. As explained in Cryptography Is Applied Freedom, encryption gives individuals the practical ability to establish informational boundaries even when the networks carrying their communications cannot be trusted.
Public-key cryptography was revolutionary because it reduced the need for prior trust. Two people could communicate securely without first meeting to exchange a secret key. A person could publish a public key for the world to see while retaining a private key that enabled decryption or the creation of digital signatures.
This architecture made secure websites, encrypted messaging, digital certificates, software authentication and decentralized digital assets possible. It allowed mathematical verification to replace some of the trust previously placed in institutions.
Yet every cryptographic system rests upon assumptions. An algorithm is secure because a particular problem is believed to require an impractical amount of time or computation to solve. If a new type of machine changes the difficulty of that problem, the surrounding architecture of trust changes with it.
Quantum computing represents such a possibility.
What Quantum Computing Threatens
Quantum computers process information through quantum states rather than operating solely through the binary logic of conventional computers. They are not simply faster versions of existing machines. Their significance comes from their ability, under appropriate conditions, to approach certain problems in fundamentally different ways.
In 1994, mathematician Peter Shor described a quantum algorithm capable of efficiently factoring large integers and calculating discrete logarithms. These are precisely the kinds of mathematical problems that support widely used public-key systems, including RSA, conventional Diffie–Hellman and elliptic-curve cryptography.
If a cryptographically relevant quantum computer can eventually implement Shor’s algorithm at sufficient scale, public keys protected by these mathematical assumptions could be used to derive their corresponding private keys. An attacker could then decrypt protected information, impersonate legitimate users or generate fraudulent digital signatures.
Symmetric encryption and cryptographic hashing face a different problem. Grover’s algorithm can theoretically accelerate searches across a key space, but it does not destroy symmetric cryptography in the same manner that Shor’s algorithm threatens RSA and elliptic-curve systems. Larger symmetric keys and appropriately selected hash functions can provide stronger margins against quantum search.
The post-quantum challenge is therefore not the disappearance of cryptography. It is the need to replace vulnerable assumptions before an adversary becomes capable of exploiting them.
The Quantum Computer Does Not Need to Exist Yet
It is tempting to dismiss the threat because no known quantum computer can presently break the public-key encryption protecting the modern internet. That response misunderstands the lifespan of information.
An adversary can intercept encrypted communications today and preserve them until more powerful computation becomes available. This strategy is commonly described as “harvest now, decrypt later.” Its importance depends upon how long the captured information must remain confidential.
A temporary delivery notification may have little value after several years. Medical histories, intelligence records, trade secrets, genetic information, political communications and evidence identifying dissidents may remain sensitive for decades. The fact that such information is secure at the time of interception does not mean it will remain secure throughout its useful life.
The threat also extends beyond message confidentiality. A digital signature created today may be relied upon for years. A software-update system may remain embedded in critical infrastructure long after its original deployment. A cryptographic identity may be connected to permanent public records. A dormant digital asset may remain secured by the same key for an indefinite period.
Post-quantum security is therefore a problem of time. The relevant calculation is not merely when a powerful quantum computer might appear. It is whether the time required to identify vulnerable systems, establish new standards, update software, replace hardware and migrate users will exceed the remaining life of the existing protection.
The First Post-Quantum Standards
On 13 August 2024, the United States National Institute of Standards and Technology published its first three finalized standards for post-quantum cryptography. NIST stated that the standards were ready for immediate use and encouraged system administrators to begin transitioning as soon as possible.
The first standard, FIPS 203, specifies the Module-Lattice-Based Key-Encapsulation Mechanism, or ML-KEM. A key-encapsulation mechanism allows parties communicating across a public channel to establish a shared secret that can subsequently be used with symmetric encryption. ML-KEM is derived from the algorithm previously known as CRYSTALS-Kyber.
The second standard, FIPS 204, specifies the Module-Lattice-Based Digital Signature Algorithm, or ML-DSA. Derived from CRYSTALS-Dilithium, it is designed to authenticate signatories and detect unauthorized modifications to signed information.
The third standard, FIPS 205, specifies the Stateless Hash-Based Digital Signature Algorithm, or SLH-DSA. It is based on SPHINCS+ and provides a signature approach grounded in hash-based cryptography rather than the lattice assumptions supporting ML-DSA.
These standards do not prove that every uncertainty has been eliminated. Cryptographic confidence develops through continuing public examination, implementation experience and attempted attack. NIST has also continued evaluating additional algorithms to provide alternatives should weaknesses be discovered in a principal family.
Their publication nevertheless marks a significant transition. Post-quantum cryptography has moved from an area of specialist preparation into a set of deployable public standards.
Post-Quantum Does Not Mean Quantum Encryption
Post-quantum cryptography is sometimes confused with quantum cryptography. They are not the same.
Quantum cryptography uses quantum-mechanical properties as part of a communication system. Quantum key distribution is one example. Such systems may require specialized physical infrastructure and are not direct replacements for all the cryptographic functions used throughout ordinary digital networks.
Post-quantum cryptography consists of algorithms designed to run on conventional computers while resisting attacks from both conventional and quantum computers. This makes it possible to incorporate quantum-resistant protection into existing software, protocols and devices without requiring every user to possess quantum hardware.
That distinction matters politically. A defensive technology available only to governments, military institutions or the largest corporations would deepen the concentration of technological power. Post-quantum security must become available through ordinary devices, open implementations and interoperable protocols if it is to protect individual sovereignty.
Migration Is a Question of Sovereignty
A cryptographic transition is not merely an upgrade from one algorithm to another. It redistributes authority throughout an existing system.
Who selects the replacement algorithms? Who implements them? Who can inspect the implementations? Who controls the update process? Can users move their keys and identities to another provider? What happens to people using devices that no longer receive security updates? Can a government or company use the migration to require new identity systems, impose surveillance mechanisms or exclude independent software?
These are questions of technological power.
A migration can strengthen individual security while simultaneously increasing institutional dependency. A provider might offer post-quantum protection only through a closed platform in which it controls the user’s keys. A financial service might require assets to be transferred into institutional custody in the name of quantum safety. A government could connect upgraded credentials to a centralized identity system capable of monitoring every authenticated action.
The replacement of vulnerable cryptography must not become an excuse to replace self-custody with custodial control.
Post-Quantum Cypherpunkism therefore asks not only whether the new algorithm resists quantum attack, but whether the migration preserves the individual’s authority over keys, identity, communications and digital property.
Cryptographic Agility and the Right to Migrate
No algorithm should be treated as permanent. Even a system believed to be quantum-resistant may later reveal mathematical weaknesses, implementation errors or dangerous side channels. Security requires the ability to change cryptographic components without destroying the larger system.
This capacity is known as cryptographic agility.
A cryptographically agile system can identify which algorithms it uses, replace vulnerable components, update parameters and support controlled transitions between old and new protection. It does not embed one assumption so deeply that migration becomes practically impossible.
From a Cypherpunkist perspective, cryptographic agility should include a right to migrate. Users should be able to transfer their identities, credentials, messages and assets to stronger protection without surrendering ownership to an intermediary.
This principle extends the argument made in The Right to Exit in Digital Civilization. A person does not possess meaningful digital sovereignty if leaving a vulnerable system requires abandoning identity, property, reputation or access to essential services.
Secure migration should be understandable, accessible and reversible until the transition has been verified. Recovery procedures must exist for users who lose credentials or fail to upgrade within the preferred period. At the same time, recovery must not create a universal master key capable of defeating everyone’s security.
The Role of Hybrid Cryptography
During a transition, systems may combine established cryptographic algorithms with post-quantum algorithms. The purpose of a hybrid approach is to avoid placing complete trust in either the old system or the new one.
If the conventional algorithm remains secure, it continues contributing protection. If the post-quantum algorithm performs as intended, it provides security against future quantum attacks. A carefully designed combination can remain secure so long as at least one of its components remains unbroken.
Hybrid deployment is not automatic safety. Combining algorithms increases complexity, and complexity can create implementation errors. Protocols must define precisely how keys and signatures are combined, how failures are handled and whether an attacker can force participants to downgrade to weaker protection.
Nevertheless, hybrid systems embody a valuable principle: important transitions should not require immediate and unconditional trust in a single untested replacement. Diversity can function as a check on cryptographic dependence.
Blockchains and Self-Custodied Assets
Blockchain systems deserve particular attention because digital signatures are central to their concept of ownership. In a self-custodied system, control of a private key enables the user to authorize transactions. The ledger recognizes the valid signature rather than the legal identity or physical possession of the person creating it.
Many blockchain networks use elliptic-curve signatures that could be threatened by a sufficiently capable quantum computer. Where a public key has been exposed, a quantum attacker might eventually be able to derive the corresponding private key and create a fraudulent signature.
Some address structures conceal a public key behind a cryptographic hash until funds are spent, providing a degree of additional protection while the public key remains unrevealed. This protection should not be mistaken for a complete post-quantum solution. Reused addresses, already exposed public keys, vulnerable signature schemes and the time required to confirm transactions all affect the risk.
The challenge is not solved by telling every user to transfer assets on the day a threat becomes undeniable. A rushed global migration would invite fraud, congestion, confusion and coercive custody. Networks must develop and test quantum-resistant signature options before an emergency arises.
Decentralized systems face a special governance difficulty. A bank can direct customers into a centrally managed upgrade. A decentralized network must achieve sufficient agreement among developers, node operators, miners or validators, custodians, hardware manufacturers and users. The absence of a central authority protects the network from unilateral control, but it can also make urgent migration slower.
This does not mean decentralization has failed. It means that decentralized sovereignty carries a corresponding responsibility to prepare, coordinate openly and preserve credible options before a crisis removes the luxury of deliberation.
As argued in Bitcoin and Cypherpunkism: Money Without Permission, cryptographic self-custody is one of the most important practical experiments in digital sovereignty. Post-quantum preparation is necessary if that sovereignty is to survive changes in computation.
Digital Identity and the Future of Signatures
The quantum threat extends far beyond money. Digital signatures establish the authenticity of software, legal documents, identity credentials, medical records and administrative instructions. They allow a recipient to verify that information came from the claimed sender and was not altered after signing.
If a signature system becomes vulnerable, an attacker may be able to impersonate people, publish malicious software updates or fabricate apparently authentic records.
The migration of digital identity therefore requires more than issuing new keys. Systems must determine how old credentials will be replaced, how compromised signatures will be distinguished from legitimate historical signatures and how authority will be transferred without permitting an institution to seize control of the identity itself.
A sovereign identity system should allow individuals to create new quantum-resistant credentials, prove continuity from an earlier identity and revoke vulnerable keys. It should minimize the personal information revealed during the transition and avoid forcing every credential into a universal centralized database.
Long-term documents may also require renewed signatures or trusted timestamps demonstrating that a signature was valid before its underlying algorithm became vulnerable. Otherwise, quantum capability could create uncertainty not only about future actions, but about the authenticity of historical records.
The Danger of Cryptographic Inequality
The transition to post-quantum security may not occur evenly.
Governments, intelligence agencies, banks and major technology companies possess the expertise and resources to identify vulnerable systems and begin migration. Individuals, small organizations, independent developers and poorer societies may remain dependent upon obsolete devices and unsupported software.
This could create a period in which the strongest institutions protect their own information while retaining the ability to collect information encrypted by weaker actors. Quantum preparedness would then reinforce the existing hierarchy of surveillance rather than protect society as a whole.
Post-quantum cryptography must therefore be treated as public security infrastructure. Standards should be publicly accessible. Implementations should be open to examination. Secure libraries should be available to independent developers. Hardware and software vendors should provide clear migration paths rather than using security as a pretext for unnecessary replacement or permanent subscription.
Open knowledge is essential because individuals cannot meaningfully protect themselves with tools they are forbidden or unable to understand. Freedom to build is equally important because society should not depend exclusively upon a handful of approved vendors for quantum-resistant communication.
The State Must Not Monopolize the Quantum Shield
Quantum-resistant cryptography will be important to national security. Governments have legitimate reasons to protect military systems, critical infrastructure and confidential public records. But national security cannot justify reserving strong cryptography for the state while leaving citizens with weakened alternatives.
The history of the Crypto Wars demonstrates the danger of dividing encryption into privileged and civilian forms. A cryptographic weakness created to provide exceptional access for one authority can become a vulnerability exploitable by hostile states, criminals and unauthorized insiders.
Post-quantum standards should not contain secret access mechanisms or deliberate weaknesses. The algorithms and their implementations should be subject to sustained international analysis. Security claims must rest upon evidence and open examination rather than institutional reputation alone.
This position is not anti-state. Governments can make valuable contributions by funding research, publishing standards, coordinating migration and protecting critical infrastructure. Their authority is legitimate when it is necessary, limited, transparent, proportionate and contestable.
What Cypherpunkism rejects is the idea that protection against a new technological threat requires granting any institution unrestricted authority over everyone else’s keys.

My illustration “The Quantum Siege” work-in-progress. The art represents: Upgrading digital defences before quantum computers render existing cryptography vulnerable.
Post-Quantum Cypherpunkism: Twelve Requirements
- Begin before the emergency: Migration must start while systems can still be tested deliberately rather than under conditions of panic.
- Protect long-lived information first: Data that must remain confidential for many years requires early post-quantum protection.
- Preserve self-custody: Quantum safety must not become a pretext for transferring private keys or digital assets to centralized custodians.
- Build cryptographic agility: Systems must be capable of replacing algorithms and parameters when weaknesses emerge.
- Support user-controlled migration: Individuals should be able to move identities, credentials and assets into stronger cryptographic systems.
- Use open standards: Important algorithms and protocols should be publicly documented and available for independent examination.
- Permit independent implementation: No single government or corporation should monopolize access to quantum-resistant security.
- Maintain algorithmic diversity: Alternative cryptographic families should remain available in case a principal approach is later weakened.
- Prevent downgrade attacks: Systems must not allow an adversary to force users back into vulnerable cryptography.
- Protect metadata as well as content: Stronger encryption does not eliminate surveillance created by exposed identities, locations and communication patterns.
- Provide recoverability without master access: Migration and recovery mechanisms must assist users without creating universal backdoors.
- Keep power answerable to the individual: Every transition should be judged by whether it strengthens the user’s security or merely expands institutional control.
Applying the Cypherpunkist Test
The Cypherpunkist Test asks who a technology ultimately empowers. Applied to post-quantum migration, it produces several immediate questions:
- Who chooses the cryptographic algorithm?
- Can independent researchers examine its design and implementation?
- Who controls the upgraded private keys?
- Can the user migrate without entering institutional custody?
- Can a provider force a downgrade to vulnerable protection?
- Can an old identity be transferred without disclosing unnecessary personal information?
- Are obsolete users protected, assisted or simply excluded?
- Does the transition create a new centralized point of surveillance?
- Can another algorithm be adopted if the first choice fails?
- Does the new architecture strengthen individual sovereignty or merely change the institution upon which the individual depends?
An algorithm may be mathematically resistant to quantum attack while the system surrounding it remains politically vulnerable. If the provider owns the keys, the user is not sovereign. If the implementation contains a backdoor, the mathematics cannot protect the individual. If migration requires universal identification, confidentiality may be purchased at the price of anonymity.
Post-quantum security must therefore be evaluated as an architecture of power, not merely a collection of equations.
Quantum Computing Is Not the Enemy
Cypherpunkism is not a philosophy against technological progress. Quantum computers may contribute to advances in science, medicine, materials, simulation and other fields that remain difficult for conventional computation. Their development should not be reduced to the threat they pose to encryption.
The problem is not that a new machine changes what is computationally possible. The problem arises when society continues depending upon vulnerable systems after their assumptions have begun to expire.
Cryptography has never been static. Algorithms are developed, examined, attacked, strengthened and eventually replaced. The ability to adapt is part of security itself.
Post-Quantum Cypherpunkism therefore rejects both complacency and panic. Complacency leaves present information exposed to future attack. Panic encourages rushed centralization, opaque standards and the unnecessary surrender of private keys.
The correct response is disciplined preparation: open research, tested standards, diverse implementations, cryptographic agility and migration designed around the rights of the individual.
Sovereignty Across Technological Eras
Digital sovereignty cannot depend upon one algorithm surviving forever. It depends upon the individual’s ability to retain meaningful authority as technology changes.
A person whose privacy disappears when computation advances never possessed a durable private sphere. A person whose assets must be surrendered to a custodian in order to survive a cryptographic transition possesses only conditional ownership. A person whose identity cannot move beyond an obsolete provider does not control that identity.
The post-quantum transition is therefore a test of whether the digital world can evolve without recentralizing the powers that cryptography once distributed.
The purpose of post-quantum cryptography is not merely to preserve old systems. It is to carry privacy, authentication, self-custody and individual control into a new computational era.
Cryptographic sovereignty is not loyalty to a particular algorithm. It is the capacity to preserve freedom when an algorithm must change.
Privacy is sovereignty. Cryptography is applied freedom. Decentralization is a check on power. Code is political architecture. Digital sovereignty belongs to the individual—even when the mathematics changes.
References
- Herbert R. Sim, Cypherpunkism.
- Herbert R. Sim, Cryptography Is Applied Freedom.
- Herbert R. Sim, Privacy as a Human Right: Why Cryptography Is Essential for Freedom.
- Herbert R. Sim, The Architecture of Power: A Cypherpunkist Theory of Technology.
- Herbert R. Sim, The Right to Exit in Digital Civilization.
- Herbert R. Sim, Bitcoin and Cypherpunkism: Money Without Permission.
- Peter W. Shor, Algorithms for Quantum Computation: Discrete Logarithms and Factoring, 1994.
- Lov K. Grover, A Fast Quantum Mechanical Algorithm for Database Search, 1996.
- National Institute of Standards and Technology, NIST Releases First 3 Finalized Post-Quantum Encryption Standards, 13 August 2024.
- National Institute of Standards and Technology, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard, 2024.
- National Institute of Standards and Technology, FIPS 204: Module-Lattice-Based Digital Signature Standard, 2024.
- National Institute of Standards and Technology, FIPS 205: Stateless Hash-Based Digital Signature Standard, 2024.