QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
726
DAYS
23
HRS
48
MIN
48
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,831,412,050
ECDSA signatures committed onchain (BTC + ETH)
BTC #970269 · ETH #26,137,388
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · US
FILTERS · TAP TO TOGGLE LAYERS
NEWS_COINTELEGRAPHBitcoin.de trading remains halted as German regulator rejects MiCA applicationNEWS_SECURITYWEEKPersonal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court SystemNVDCVE-2026-93449 · CVSS 8.5NVDCVE-2026-93447 · CVSS 7.5NVDCVE-2026-93445 · CVSS 8.1NVDCVE-2026-93443 · CVSS 7.5NVDCVE-2026-88962 · CVSS 8.8NVDCVE-2026-103360 · CVSS 8.1NVDCVE-2026-101331 · CVSS 7.7NVDCVE-2026-104335 · CVSS 8.8NEWS_COINTELEGRAPHPudgy Penguins-backed Abstract to shut down after ‘tens of millions’ in lossesNEWS_DECRYPTGoogle Launches Nano Banana 2.1: Better Than Its Predecessor at Half the PriceNEWS_DECRYPTCircle Welcomes DJ Khaled to 'Team USDC' and Crypto Twitter Is FuriousNEWS_DECRYPTSomeone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for FreeNEWS_THEDEFIANTKalshi Launches US 500 Perpetual Future With No ExpirationNEWS_BITCOINMAGCrypto Card Payments Hit Record $12.5 Billion as Stablecoin Adoption Surges
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
337
cve
14
kev
1326
news
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
CVE 67 · GHSA 0
67
ibm
CVE 50 · GHSA 0
50
wordpress
KEV 1 · CVE 39 · GHSA 0
40
java
CVE 22 · GHSA 0
22
python
CVE 14 · GHSA 0
14
redhat
CVE 12 · GHSA 0
12
google
KEV 1 · CVE 10 · GHSA 0
11
microsoft
KEV 4 · CVE 6 · GHSA 0
10
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
628d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
280d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
99d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
450d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1546d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2642d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_COINTELEGRAPH · INFO
Bitcoin.de trading remains halted as German regulator rejects MiCA application
Trading on the platform has largely been suspended since June as its operator awaited MiCA authorization, with the company now looking to regulated partners to restart services.
NEWS_SECURITYWEEK · INFO
Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
The Arizona Supreme Court said the information was copied for people dating back as far as 30 years. The post Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System appeared first on SecurityWeek .
NVD · HIGH
CVE-2026-93449 · CVSS 8.5
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
NVD · HIGH
CVE-2026-93447 · CVSS 7.5
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.
NVD · HIGH
CVE-2026-93445 · CVSS 8.1
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
NVD · HIGH
CVE-2026-93443 · CVSS 7.5
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code.
NVD · HIGH
CVE-2026-88962 · CVSS 8.8
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
NVD · HIGH
CVE-2026-103360 · CVSS 8.1
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
NVD · HIGH
CVE-2026-101331 · CVSS 7.7
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
NVD · HIGH
CVE-2026-104335 · CVSS 8.8
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
NEWS_COINTELEGRAPH · INFO
Pudgy Penguins-backed Abstract to shut down after ‘tens of millions’ in losses
Igloo CEO Luca Netz said the company funded Abstract for 18 months but still failed to find product-market fit despite attracting major brands and a community of millions.
NEWS_DECRYPT · INFO
Google Launches Nano Banana 2.1: Better Than Its Predecessor at Half the Price
Google's new image model, Nano Banana 2.1, is live. It costs about half as much as its predecessor, but the performance claims come from Google's own tests.
NEWS_DECRYPT · INFO
Circle Welcomes DJ Khaled to 'Team USDC' and Crypto Twitter Is Furious
Nothing in Circle's posts announces a sponsorship, but replies dug up Khaled's 2018 SEC settlement over a crypto fraud he promoted. The internet never forgets.
NEWS_DECRYPT · INFO
Someone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for Free
A developer posted metadata for about 5.6 billion public TikTok videos, scraped through the app's private API in a way TikTok's terms prohibit. The free dataset also doubles as a storefront.
NEWS_THEDEFIANT · INFO
Kalshi Launches US 500 Perpetual Future With No Expiration
The stock-index contract uses daily funding payments and futures-account collateral; Kalshi displayed maximum leverage of 15.3 times on launch day.
NEWS_BITCOINMAG · INFO
Crypto Card Payments Hit Record $12.5 Billion as Stablecoin Adoption Surges
Bitcoin Magazine Crypto Card Payments Hit Record $12.5 Billion as Stablecoin Adoption Surges More people are using crypto cards than ever before to make payments. This post Crypto Card Payments Hit Record $12.5 Billion as Stablecoin Adoption Surges first appeared on Bitcoin Magazine and is written b
NEWS_BITCOINMAG · INFO
$350M St Cloud CEO: The First Credit Union to Put Bitcoin on Core Ledger | Jed Meyer
Bitcoin Magazine $350M St Cloud CEO: The First Credit Union to Put Bitcoin on Core Ledger | Jed Meyer A 1930s postal credit union now custodies real Bitcoin. St. Cloud CEO Jed Meyer breaks down its hybrid vault model and quiet path to over 20 BTC. This post $350M St Cloud CEO: The First Credit Union
NEWS_BITCOINMAG · INFO
Housingwire’s Logan Mohtashami: Real Estate vs Bitcoin & Bond Market Outlook
Bitcoin Magazine Housingwire’s Logan Mohtashami: Real Estate vs Bitcoin & Bond Market Outlook Mortgage rates hit 3-year highs as homebuyers retreat. HousingWire’s Logan Mohtashami explains why rising bond yields and Fed hawkishness drive the surge. This post Housingwire’s Logan Mohta
NEWS_BITCOINMAG · INFO
Leon Wankum: BTC Taking on Real Estate’s $300T Monetary Premium
Bitcoin Magazine Leon Wankum: BTC Taking on Real Estate’s $300T Monetary Premium Property was once the default wealth store, but Leon Wankum argues that run is over. He explains why Bitcoin is stripping real estate of its monetary premium. This post Leon Wankum: BTC Taking on Real Estate&#8217
NVD · HIGH
CVE-2026-106062 · CVSS 7.8
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit arithmetic that overflows. The allocated buffer is too small for the amount of pixel data written throug
NVD · HIGH
CVE-2026-101258 · CVSS 7.8
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path acc
NEWS_BITCOINMAG · INFO
StoneX’s Mark Palmer: $435 MSTR Price Target Explained – DAT Consolidation Outlook
Bitcoin Magazine StoneX’s Mark Palmer: $435 MSTR Price Target Explained – DAT Consolidation Outlook Strategy bought STRC over Bitcoin. Mark Palmer explains why the preferred stock is vital to Strategy's fundraising and how reserve cash drives it to par. This post StoneX’s Mark Palm
NEWS_THEDEFIANT · INFO
Coinbase Launches 15-Minute And Hourly Crypto Price Markets
Coinbase added short-dated up-or-down contracts on bitcoin, ether and eight other tokens to its prediction markets on Tuesday. Kalshi lists the contracts and already runs the same 15-minute markets on its own exchange.
NEWS_BITCOINMAG · INFO
Bitcoin Privacy Legend Amir Taaki Deported From Singapore
Bitcoin Magazine Bitcoin Privacy Legend Amir Taaki Deported From Singapore The early Bitcoin contributor says he was questioned for hours before being deported — something which keeps happening. This post Bitcoin Privacy Legend Amir Taaki Deported From Singapore first appeared on Bitcoin Magazine an
NEWS_CYBERSCOOP_ME · INFO
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. The post Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks appeared first on CyberScoop .
NEWS_COINTELEGRAPH · INFO
Conduit sues Tether over allegedly freezing $2.8M without explanation
The lawsuit alleged that Tether froze USDt funds in a Conduit wallet tied to an investigation launched by Brazilian authorities in 2024.
NEWS_COINTELEGRAPH · INFO
Winklevoss-backed Zcash ETF files with SEC for Nasdaq listing
The proposed fund would hold ZEC directly, with Gemini Trust serving as custodian and Winklevoss Capital affiliates eyeing up to a $100 million investment.
NEWS_COINTELEGRAPH · INFO
Here’s what happened in crypto today
Need to know what happened in crypto today? Here is the latest news on daily trends and events impacting Bitcoin price, blockchain, DeFi, Web3 and crypto regulation.
NEWS_THEDEFIANT · INFO
Abstract to Shut Down Ethereum Layer 2 on Dec. 15
Users can withdraw through the Migration Hub or native bridge, while the team plans to help apps move to other chains.
NEWS_DARKREADING · INFO
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing