Harvest Now, Decrypt Later: Why Messages Need Post-Quantum Security
Adversaries store encrypted traffic today to read it once quantum computers arrive. How long your secrets must last, and how VOIDEX protects them now.
There is a quiet assumption behind almost every private conversation you have ever had online: that the lock on it will still hold on the day someone tries to open it. For decades that assumption was safe. The mathematics protecting your messages would take longer than the age of the universe to break by brute force, so it hardly mattered when an attacker tried.
Quantum computing changes the question. It no longer matters only whether your messages can be read today. It matters whether they can be read in 2032, or 2040, by someone who copied them in 2026. That is the threat known as harvest now, decrypt later, and it is the reason VOIDEX Messenger was built with post-quantum encryption from its first day rather than waiting for the threat to arrive.
The patient adversary
Harvest now, decrypt later (sometimes written "store now, decrypt later") describes a simple strategy. An attacker who cannot read encrypted traffic today records it anyway, stores it cheaply, and waits. When a sufficiently powerful quantum computer exists, the attacker runs the old recordings through it and reads everything that was protected by quantum-vulnerable cryptography.
Nothing about this requires exotic access. Encrypted traffic crosses undersea cables, exchange points, mobile carriers and cloud providers. The attacker does not need to break in at the moment of sending. They only need a copy, and storage is cheap.
This is not a hypothetical capability for well-resourced states. In 2024 it emerged that the group known as Salt Typhoon, attributed to Chinese state actors, had been operating inside major US telecommunications networks. In December 2024, officials at CISA and the FBI publicly urged people to move their communications to end-to-end encrypted messaging, and CISA later published mobile communications guidance recommending exactly that. End-to-end encryption defeats a network intruder today. The harder question is whether that encryption will still defeat them in ten years.
Why quantum computers change the math
Most encrypted messengers today agree on a shared secret using elliptic-curve cryptography, commonly the X25519 function. The security of these schemes rests on the difficulty of problems like the discrete logarithm on an elliptic curve. A classical computer cannot solve them at useful sizes.
In 1994, Peter Shor showed that a large, error-corrected quantum computer could solve both integer factoring and discrete logarithms efficiently. That single result threatens RSA and every widely deployed elliptic-curve scheme. It does not threaten everything: symmetric ciphers such as AES-256 and hash functions such as SHA-256 remain strong, because the best known quantum attack against them (Grover's algorithm) only offers a square-root speedup that longer keys absorb.
So the weak point is specific. It is the moment two devices agree on a key using public-key cryptography. If a recorded session's key exchange can be broken later, every message protected by that key can be read later.
How long must a secret stay secret?
The Canadian cryptographer Michele Mosca framed the problem in a way that security teams still use. Call it Mosca's inequality. Let:
- X be how long your information needs to remain confidential.
- Y be how long it takes you to migrate to quantum-safe cryptography.
- Z be how long until a cryptographically relevant quantum computer exists.
If X plus Y is greater than Z, you already have a problem. Data you are sending now will still need protection at a time when it can be broken. Mosca set this out in a 2015 paper, and the logic has only become more pressing since.
Think about what X really is for a private conversation. A business negotiation may matter for five years. A medical conversation matters for a lifetime. A message that reveals a source, a relationship, a location or a financial position can matter for decades. Personal secrets rarely expire on a schedule.
Now look at Z. Estimates of the hardware needed to break RSA-2048 have fallen sharply. In 2019, Craig Gidney and Martin Ekerå estimated about 20 million noisy qubits. In May 2025, Gidney revised that to fewer than one million noisy qubits running for under a week. Research published in early 2026 pushed further, including work targeting the elliptic curves used by Bitcoin and Ethereum, summarised here by The Quantum Insider. We examine those papers, and their caveats, in Q-Day in 2026.
Nobody can give an honest date for Z. What has changed is that the uncertainty now points in one direction. When your X is measured in decades, you cannot afford to bet on Z being long.
What governments are already doing
The institutions responsible for the most sensitive data have stopped debating whether to act and started setting deadlines.
- On 13 August 2024, NIST finalised its first post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).
- NIST's draft transition report, IR 8547, published in November 2024, proposes deprecating quantum-vulnerable RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035.
- The US National Security Agency's CNSA 2.0 guidance expects new national security systems to be quantum-safe by January 2027.
Those deadlines exist precisely because of harvest now, decrypt later. If governments were worried only about live attacks, they could wait until a quantum computer appeared. They are not waiting because traffic captured today is already exposed to a future machine. We track these dates in detail in The PQC deadlines: 2030 and 2035.
The only defence: protect the key exchange now
There is no way to retroactively protect a message that was already sent with vulnerable key exchange. Re-encrypting stored data helps with archives you control, but it does nothing for the copy an adversary made while it crossed the network. The protection has to be in place at the moment of sending.
That is the core design principle behind post-quantum messaging. The key agreement must include an algorithm that a quantum computer cannot break, so that a recorded session remains opaque even to a future attacker with a working quantum machine.
The leading choice is ML-KEM, standardised in FIPS 203 and derived from the CRYSTALS-Kyber submission. ML-KEM is a key encapsulation mechanism built on lattice problems, a family of mathematics for which no efficient quantum algorithm is known. We explain how it works in plain language in ML-KEM-768 explained.
Serious messaging platforms are moving. Signal introduced PQXDH in 2023 and, in October 2025, added ML-KEM-768 to its ratchet. Apple introduced PQ3 for iMessage in February 2024. These are good, serious designs, and their adoption confirms that the industry now treats the threat as real.
How VOIDEX Messenger protects against harvesting
VOIDEX was designed on the assumption that everything crossing the network may be recorded. VOIDEX Messenger therefore protects every direct conversation in three layers.
Hybrid key agreement from the first message. When two members start a conversation, their devices perform a PQXDH-style handshake that combines classical X25519 with post-quantum ML-KEM-768. The resulting key depends on both. An attacker who records the handshake and later breaks X25519 with a quantum computer still faces ML-KEM-768. If a flaw were ever found in ML-KEM, X25519 still stands. We explain why that combination matters in Why hybrid post-quantum encryption wins.
A ratchet that keeps re-keying. After the handshake, VOIDEX runs a double ratchet with post-quantum re-keying, so each message is encrypted with its own key. That gives forward secrecy (a key stolen today does not unlock yesterday's messages) and post-compromise security (a conversation heals after a device compromise once new key material flows). For a harvesting adversary, it means there is no single key whose theft unlocks a whole conversation.
Identity that is also quantum-aware. Device identities are signed with hybrid Ed25519 plus ML-DSA-65, so the signatures that prove who you are talking to are not solely dependent on elliptic curves.
Groups and private VOIDEX Channels use MLS, the IETF standard RFC 9420. Keys are created on members' own devices, and VOIDEX servers store only public keys and ciphertext. The cryptographic core is open source, and the full design is laid out in the public VOIDEX security report.
One honest note, because it matters for long-lived secrets. Each member has a VOIDEX recovery code that can open their message history on a new device. That encrypted history copy is deliberately not forward-secret, because that is what allows the code to open the past. VOIDEX never holds the code, and members who prefer not to keep a history copy can switch it off. We believe a security design should say out loud where its trade-offs are.
What you can do today
You cannot control when quantum computers arrive. You can control what your conversations are exposed to from here on.
- Move sensitive conversations to a post-quantum messenger now. Every month on a classical-only channel adds to what a patient adversary can one day read.
- Think in decades, not days. Ask how long a message needs to stay private, then choose a channel that plausibly protects it for that long.
- Prefer verifiable claims. Open-source cryptography and published designs let independent experts check what a company says.
- Remember that what you post publicly is public. Public posts on VOIDEX Space and Public channels are meant to be seen and are labelled as not end-to-end encrypted. Keep secrets in VOIDEX Messenger and private channels.
The long view
Harvest now, decrypt later is unsettling because it turns time into an attack vector. The messages you send today are only as private as the weakest encryption that will exist over their lifetime. The good news is that the defence is mature, standardised and running in production. The only mistake left is waiting.
VOIDEX is invite-only. Request access to join, or see exactly how VOIDEX encryption works.
Sources
- Mosca, M. "Cybersecurity in an era with quantum computers: will we be ready?" (2015): https://eprint.iacr.org/2015/1075
- Gidney, C. and Ekerå, M. "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits" (2019): https://arxiv.org/abs/1905.09749
- Gidney, C. "How to factor 2048 bit RSA integers with less than a million noisy qubits" (2025): https://arxiv.org/abs/2505.15917
- The Quantum Insider, "Q-Day just got closer" (31 March 2026): https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
- NIST Post-Quantum Cryptography Standardization: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
- NIST IR 8547 (initial public draft, November 2024): https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- CISA, Mobile Communications Best Practice Guidance: https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance
- Signal, "SPQR: Signal's post-quantum ratchet" (October 2025): https://signal.org/blog/spqr/
- Apple Security Research, "iMessage with PQ3" (February 2024): https://security.apple.com/blog/imessage-pq3/
- RFC 9420, The Messaging Layer Security Protocol: https://www.rfc-editor.org/rfc/rfc9420
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



