After Deskafter q · observe
A figure in a long coat on a rooftop watches a pale padlock crack apart above a city going dark The same rooftop at dawn: the padlock is whole again, rebuilt from an amber hexagonal lattice, and the city lights are back
$AFTERQSolanaAfter Q · lattice + hash signatures

Q Day is coming.
Be ready for the day after.

Q Day is the day a quantum computer gets strong enough to open ordinary crypto wallets. After Quantum is the desk for what comes next: check an address, run the new signatures in your browser, and seal a proof that still holds afterwards.

Qubits needed to break a 256-bit curve
< 500,000

Google Quantum AI estimate, March 2026. In 2023 the same job was put at about 9 million.

Largest chip announced so far
1,121

IBM Condor, December 2023. Still noisy qubits, and about 450 times short of the estimate.

NIST retires elliptic-curve signatures in
— days

Draft NIST IR 8547 disallows them after 2035. Solana wallets sign with one today.

Six windows, all of them working

Nothing here asks for a wallet connection. Keys are made in this tab, used in this tab and gone when you close it.

Algorithm registry

Sizes are measured from the library running on this page, not copied from a brochure.

AlgorithmStandardTypePublic keySignature / ciphertextOn Q Day
Ed25519RFC 8032signature32 B64 Bprivate key recoverable
ML-DSA-65FIPS 204signature1,952 B3,309 Bholds
SLH-DSA-SHA2-128fFIPS 205signature32 B17,088 Bholds
ML-KEM-768FIPS 203key exchange1,184 B1,088 Bholds
After Quantum · $AFTERQ · Solanalibrary: @noble/post-quantum 0.7.1 · white paper · X
Q Day Clock

Nobody knows the date. The gap is measurable.

There is no honest countdown to Q Day, so this window does not invent one. It tracks two numbers instead: how many physical qubits the attack is estimated to need, and how many the biggest announced chip has.

qubits the attack needs (published estimates)largest announced chip
Since NIST finalised the replacements

FIPS 203, 204 and 205 were published on 13 August 2024. The new algorithms are finished and public. The Workbench runs them.

Until NIST disallows elliptic-curve signatures

Draft NIST IR 8547 deprecates them after 2030 and disallows them after 2035. This is the only real deadline on the page.

Sources: Gidney & Ekerå, 2019 (RSA-2048, 20 million qubits) · Litinski, 2023 (256-bit curve, about 9 million) · Gidney, 2025 (RSA-2048, under 1 million) · Google Quantum AI, “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities”, March 2026 (secp256k1, under 500,000). Chips: Google Sycamore 53 (2019), IBM Eagle 127 (2021), IBM Osprey 433 (2022), IBM Condor 1,121 (2023). A raw qubit count says nothing about error rates; the estimates assume far better qubits than these chips have. The 2026 estimate is for Bitcoin's curve; Solana's Ed25519 is a curve of the same size class.

Wallet Check

What happens to this address on Q Day?

Paste a Solana address. The check runs on the address itself, in this tab. No wallet connection, no network request, nothing stored.

The report appears here. A Solana address is not a hash of a key the way a Bitcoin address is. It is the public key itself, written in base58, which is why this check needs nothing but the address.

Workbench

Run the signatures yourself

Every run makes a fresh key pair in this tab, signs your message and verifies it. Tick the box to change one character after signing: a signature that still passed would be worthless.

ready. nothing has run yet.
Survivor Proof

Sign something that should outlive Q Day

Write a note or pick a file. The desk hashes it, signs the hash with ML-DSA-65 and hands you a small proof file. Anyone can check it in the Proof Inspector, today or in twenty years.

no file · the file never leaves this tab
signer
no key yet · one is made on first seal
the proof will appear here.
Proof Inspector

Verify a proof without trusting this desk

Paste a proof or load the file. The inspector recomputes the hash, rebuilds the signed statement and checks the ML-DSA-65 signature against the public key inside the proof.

no proof loaded.
White Paper · v0.1 · October 2026

After Quantum

Summary

After Quantum is a browser desk for one question: what happens to crypto the day a quantum computer can break today's signatures, and what do you use the day after. It shows the gap in numbers, checks a Solana address against it, and lets you run the replacement algorithms yourself.

Everything cryptographic on this site executes locally with an open library. There is no account, no wallet connection and no server that signs for you.

What Q Day is

Q Day is shorthand for the first day a quantum computer runs Shor's algorithm at a scale that recovers a private key from a public key. For a 256-bit elliptic curve, a March 2026 estimate from Google Quantum AI puts that scale under 500,000 physical qubits and the runtime in minutes. The largest chip announced so far has 1,121.

Nobody can date it. What can be said is that the estimate fell about twentyfold between 2023 and 2026, and hardware grew about twentyfold between 2019 and 2023.

What breaks

Solana wallets sign with Ed25519. A Solana address is the Ed25519 public key itself, so every funded wallet address is already a published public key. On Q Day, a published public key is enough to derive the private key and sign as the owner.

Program-derived addresses are different. They are deliberately off the curve, have no private key, and are moved only by their program. Wallet Check tells the two apart.

What replaces it

In August 2024 NIST published three finished standards. ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) are signature schemes built on lattices and on hash functions; ML-KEM (FIPS 203) is for agreeing on a shared secret. None of them relies on the maths Shor's algorithm attacks.

The cost is size. An Ed25519 signature is 64 bytes. An ML-DSA-65 signature is 3,309 and an SLH-DSA-128f signature is 17,088. That is the engineering problem every chain has to solve before Q Day rather than after.

The desk

Wallet Check decodes an address and reports whether it is a key or a program address. Workbench runs key generation, signing and verification for all four algorithms with a tamper test. Survivor Proof signs a note or a file hash with ML-DSA-65. Proof Inspector verifies any such proof. The Before Q and After Q switch changes which side of the day the desk is showing.

Proof format

A proof is a JSON file with the version tag afterq-proof/1, the SHA-256 of the content, a creation time, the signer's ML-DSA-65 public key and the signature. The signed statement is the three lines version, hash, time joined by newlines. Nothing else is needed to verify it, including this website.

A proof shows that the holder of one key signed one hash. It does not show who that holder is or when the signing really happened; the time is written by the signer.

$AFTERQ

$AFTERQ is the coin of this desk and lives on Solana. Its contract address is the one shown on the After Desk. Treat any other address as someone else's token.

Where this stops

Running ML-DSA in a browser does not make a Solana wallet quantum-safe. Accounts on Solana are still authorised with Ed25519, and that only changes when the network changes. Keys made here live in tab memory and are for trying things out, not for guarding money.

Event Log

Everything this session did

The log lives in memory and resets when the tab closes. Export it if you want to keep it.

Consolesession monitor