QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
797
DAYS
14
HRS
36
MIN
44
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
3,844,642,200
ECDSA signatures committed onchain (BTC + ETH)
BTC #— · ETH #25,630,949
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · US
FILTERS · TAP TO TOGGLE LAYERS
NEWS_THEDEFIANTeToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-UpNEWS_THEDEFIANTBitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of SupplyNEWS_THEDEFIANTNEAR Governance Votes to Scrap Developer Gas RebateNEWS_THEDEFIANTEDX Markets Closes $76M Series C Led by SBI HoldingsNEWS_THEDEFIANTSummerFi to Wind Down After Seven Years, Citing ExploitNEWS_INFOSECURITYCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachNEWS_SECURITYWEEKHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerNEWS_SECURITYWEEKHush Security Raises $30 Million for AI Agent GovernanceNVDCVE-2026-14785 · CVSS 7.5NVDCVE-2026-14328 · CVSS 8.8NVDCVE-2026-10207 · CVSS 7.5NEWS_COINTELEGRAPHIMF warns Brazil’s stablecoin activity outpaces traditional capital flowsNEWS_DECRYPT'Running Away Balloon' Artist Sues AI Meme Generator Over Ad TemplatesNEWS_COINDESKPerpetuals tied to SK Hynix hit by flash crash to $900 on HyperliquidNEWS_INFOSECURITYNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesNEWS_COINDESKBitMEX and BitMart may be first casualties of crypto trading slump
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
21
kev
417
cve
1155
news
609
vendor
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
KEV 2 · CVE 205 · GHSA 3
210
github
CVE 0 · GHSA 152
152
microsoft
KEV 7 · CVE 27 · GHSA 26
60
wordpress
KEV 4 · CVE 38 · GHSA 0
42
java
CVE 12 · GHSA 16
28
python
CVE 11 · GHSA 12
23
apache
CVE 14 · GHSA 0
14
linux
CVE 5 · GHSA 7
12
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
557d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
209d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
28d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
521d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1617d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2713d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_THEDEFIANT · INFO
eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up
eToro has become a strategic investor in Extended, an onchain perpetual futures exchange, and said the round begins a partnership with Zengo, the self-custody wallet eToro acquired earlier this year. Neither company disclosed the investment size.
NEWS_THEDEFIANT · INFO
BitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of Supply
BitMine Immersion Technologies (NYSE: BMNR), the Ethereum treasury company chaired by Fundstrat's Tom Lee, bought 42,197 ETH worth roughly $73 million over the past week, according to the company's own holdings update posted Monday. The purchase lifts BitMine's total to 5,742,237 ETH, about 4.8% of…
NEWS_THEDEFIANT · INFO
NEAR Governance Votes to Scrap Developer Gas Rebate
NEAR's on-chain governance body, House of Stake, passed proposal HSP-027 to eliminate the protocol's developer gas rebate, a change that will send all network gas fees to be burned rather than partly rebated to smart-contract owners. NEAR co-founder Illia Polosukhin confirmed the outcome Monday,…
NEWS_THEDEFIANT · INFO
EDX Markets Closes $76M Series C Led by SBI Holdings
EDX Markets, an institutional-only crypto trading venue with its own central clearinghouse, closed a $76 million Series C funding round led by SBI Holdings, the firm said in a press release. The Tokyo-listed financial group becomes a strategic investor in the U.S. exchange. The capital will fund…
NEWS_THEDEFIANT · INFO
SummerFi to Wind Down After Seven Years, Citing Exploit
Aave founder Stani Kulechov called the DeFi access point 'an OG' as its team said it would sunset the UI.
NEWS_INFOSECURITY · INFO
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
NEWS_SECURITYWEEK · INFO
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek .
NEWS_SECURITYWEEK · INFO
Hush Security Raises $30 Million for AI Agent Governance
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek .
NVD · HIGH
CVE-2026-14785 · CVSS 7.5
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible
NVD · HIGH
CVE-2026-14328 · CVSS 8.8
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that
NVD · HIGH
CVE-2026-10207 · CVSS 7.5
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes Word
NEWS_COINTELEGRAPH · INFO
IMF warns Brazil’s stablecoin activity outpaces traditional capital flows
The IMF said Brazil’s stablecoin market has expanded rapidly since 2017, with cross-border crypto flows growing faster than traditional capital flows.
NEWS_DECRYPT · INFO
'Running Away Balloon' Artist Sues AI Meme Generator Over Ad Templates
The suit sidesteps the fight over AI training data, alleging the comic sits in a paywalled template catalogue, searchable by name.
NEWS_COINDESK · INFO
Perpetuals tied to SK Hynix hit by flash crash to $900 on Hyperliquid
Perpetual futures on the South Korean chipmaker's American depositary receipts plunged 20% in one minute before quickly rebounding above $1,000.
NEWS_INFOSECURITY · INFO
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
NEWS_COINDESK · INFO
BitMEX and BitMart may be first casualties of crypto trading slump
Trading volumes across major centralized platforms fell down to $1.05 trillion, marking the quietest stretch of activity for the digital asset market in over two years.
NVD · HIGH
CVE-2026-14516 · CVSS 7.5
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the
NVD · HIGH
CVE-2026-14169 · CVSS 8.1
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.
NVD · HIGH
CVE-2026-14168 · CVSS 8.8
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
NVD · HIGH
CVE-2026-14167 · CVSS 8.8
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.
NVD · HIGH
CVE-2026-13161 · CVSS 7.5
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio
NVD · HIGH
CVE-2026-12800 · CVSS 7.5
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied parameter
NEWS_COINTELEGRAPH · INFO
Lido upgrade aims to slash Ethereum’s validator count by one-third
Lido launched Curated Module v2, an upgrade that could reduce Ethereum’s validator count by one-third by consolidating validators and introducing new operator rules.
NEWS_COINTELEGRAPH · INFO
Ondo shifts from layer-1 blockchain plan to offchain execution network
The new system marks an apparent departure from the institution-focused layer-1 blockchain Ondo announced in 2025.
NEWS_DECRYPT · INFO
Kalshi, Polymarket Score Win as Judge Blocks Minnesota Prediction Market Ban—For Now
The order turns on whether each contract counts as a swap under federal law, and the judge found that not every one does.
NEWS_INFOSECURITY · INFO
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
NEWS_SECURITYWEEK · INFO
Google Adopts New Threat Actor Naming System
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek .
NVD · HIGH
CVE-2026-12741 · CVSS 7.5
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi
NEWS_THEHACKERNEWS · INFO
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions
NEWS_THEHACKERNEWS · INFO
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificia

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing