Summary
After Quantum is a browser desk for one question: what happens to crypto the day a quantum computer can break today's signatures, and what do you use the day after. It shows the gap in numbers, checks a Solana address against it, and lets you run the replacement algorithms yourself.
Everything cryptographic on this site executes locally with an open library. There is no account, no wallet connection and no server that signs for you.
What Q Day is
Q Day is shorthand for the first day a quantum computer runs Shor's algorithm at a scale that recovers a private key from a public key. For a 256-bit elliptic curve, a March 2026 estimate from Google Quantum AI puts that scale under 500,000 physical qubits and the runtime in minutes. The largest chip announced so far has 1,121.
Nobody can date it. What can be said is that the estimate fell about twentyfold between 2023 and 2026, and hardware grew about twentyfold between 2019 and 2023.
What breaks
Solana wallets sign with Ed25519. A Solana address is the Ed25519 public key itself, so every funded wallet address is already a published public key. On Q Day, a published public key is enough to derive the private key and sign as the owner.
Program-derived addresses are different. They are deliberately off the curve, have no private key, and are moved only by their program. Wallet Check tells the two apart.
What replaces it
In August 2024 NIST published three finished standards. ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) are signature schemes built on lattices and on hash functions; ML-KEM (FIPS 203) is for agreeing on a shared secret. None of them relies on the maths Shor's algorithm attacks.
The cost is size. An Ed25519 signature is 64 bytes. An ML-DSA-65 signature is 3,309 and an SLH-DSA-128f signature is 17,088. That is the engineering problem every chain has to solve before Q Day rather than after.
The desk
Wallet Check decodes an address and reports whether it is a key or a program address. Workbench runs key generation, signing and verification for all four algorithms with a tamper test. Survivor Proof signs a note or a file hash with ML-DSA-65. Proof Inspector verifies any such proof. The Before Q and After Q switch changes which side of the day the desk is showing.
Proof format
A proof is a JSON file with the version tag afterq-proof/1, the SHA-256 of the content, a creation time, the signer's ML-DSA-65 public key and the signature. The signed statement is the three lines version, hash, time joined by newlines. Nothing else is needed to verify it, including this website.
A proof shows that the holder of one key signed one hash. It does not show who that holder is or when the signing really happened; the time is written by the signer.
$AFTERQ
$AFTERQ is the coin of this desk and lives on Solana. Its contract address is the one shown on the After Desk. Treat any other address as someone else's token.
Where this stops
Running ML-DSA in a browser does not make a Solana wallet quantum-safe. Accounts on Solana are still authorised with Ed25519, and that only changes when the network changes. Keys made here live in tab memory and are for trying things out, not for guarding money.