QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
737
DAYS
15
HRS
47
MIN
16
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,815,139,750
ECDSA signatures committed onchain (BTC + ETH)
BTC #968669 · ETH #26,060,906
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · US
FILTERS · TAP TO TOGGLE LAYERS
NEWS_COINTELEGRAPHSEC Commissioner Hester Peirce to leave post on Oct. 2NEWS_COINTELEGRAPHCFTC sues Cash FX, alleges $950M crypto-linked forex schemeNEWS_COINDESKSolana’s 150-millisecond settlement upgrade reaches second public test networkNEWS_COINDESKXRP Ledger’s Batch upgrade slips to Oct. 9 after validator support resetsNEWS_COINDESKBitcoin could soon get Zcash-style 'shielded' privacy without changing its rulesNEWS_COINDESKBitcoin could soon get Zcash-style 'shielded' privacy without changing its rulesNVDCVE-2026-100543 · CVSS 7.5NVDCVE-2026-100541 · CVSS 7.5NVDCVE-2026-100535 · CVSS 7.5NVDCVE-2026-100532 · CVSS 8.1NVDCVE-2026-100530 · CVSS 7.3NVDCVE-2026-100520 · CVSS 8.8NVDCVE-2026-100504 · CVSS 7.0NEWS_THEDEFIANTAlphaFi Winds Down After Oracle Error, With Sui Foundation SupportNEWS_COINDESKU.S. SEC's steadiest crypto advocate, Hester Peirce, to depart next weekNVDCVE-2026-100419 · CVSS 7.0
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
19
kev
345
cve
1263
news
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
CVE 68 · GHSA 0
68
ibm
CVE 60 · GHSA 0
60
wordpress
KEV 1 · CVE 41 · GHSA 0
42
java
KEV 1 · CVE 20 · GHSA 0
21
microsoft
KEV 6 · CVE 9 · GHSA 0
15
redhat
CVE 12 · GHSA 0
12
google
KEV 1 · CVE 10 · GHSA 0
11
cisco
KEV 4 · CVE 6 · GHSA 0
10
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
617d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
269d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
88d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
461d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1557d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2653d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_COINTELEGRAPH · INFO
SEC Commissioner Hester Peirce to leave post on Oct. 2
Peirce, known as “Crypto Mom,” served on the SEC for about eight years, including as director of the Crypto Task Force.
NEWS_COINTELEGRAPH · INFO
CFTC sues Cash FX, alleges $950M crypto-linked forex scheme
The CFTC claimed that Cash FX engaged in minimal forex trading and misappropriated most of the participant funds.
NEWS_COINDESK · INFO
Solana’s 150-millisecond settlement upgrade reaches second public test network
Alpenglow is running on both public test networks, giving application teams a place to check their software before the live blockchain switches.
NEWS_COINDESK · INFO
XRP Ledger’s Batch upgrade slips to Oct. 9 after validator support resets
The feature would let users bundle up to eight transactions, including asset-and-payment transfers, but a brief drop below the network’s 80% support threshold restarted its two-week activation clock.
NEWS_COINDESK · INFO
Bitcoin could soon get Zcash-style 'shielded' privacy without changing its rules
Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
NEWS_COINDESK · INFO
Bitcoin could soon get Zcash-style 'shielded' privacy without changing its rules
Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
NVD · HIGH
CVE-2026-100543 · CVSS 7.5
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as of
NVD · HIGH
CVE-2026-100541 · CVSS 7.5
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Ma
NVD · HIGH
CVE-2026-100535 · CVSS 7.5
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sende
NVD · HIGH
CVE-2026-100532 · CVSS 8.1
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and
NVD · HIGH
CVE-2026-100530 · CVSS 7.3
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially d
NVD · HIGH
CVE-2026-100520 · CVSS 8.8
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into
NVD · HIGH
CVE-2026-100504 · CVSS 7.0
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, c
NEWS_THEDEFIANT · INFO
AlphaFi Winds Down After Oracle Error, With Sui Foundation Support
New deposits and loans are disabled, while Slush users are told to exit four strategies with immediate withdrawals.
NEWS_COINDESK · INFO
U.S. SEC's steadiest crypto advocate, Hester Peirce, to depart next week
The long-anticipated exit of the commissioner sometimes known as Crypto Mom is Oct. 2, announced as the agency was sending out its latest crypto work.
NVD · HIGH
CVE-2026-100419 · CVSS 7.0
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees whe
NEWS_KREBSONSECURITY · INFO
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&#038;T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victim
NEWS_CYBERSCOOP_ME · INFO
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companies
Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty. The post Army soldier sentenced for spree of attacks on AT&amp;T, Snowflake and other major companies appeared first on CyberScoop .
NEWS_DECRYPT · INFO
US Prosecutors Want $84.2 Million From a Bank Tied to Tether
Federal prosecutors are targeting a Montana payments firm and a Caribbean bank accused of moving money without a license.
NEWS_COINDESK · INFO
Another appeals court rules against prediction market provider Kalshi, says sports contracts are subject to state regulations
A Sixth Circuit Court of Appeals panel ruled that prediction markets' sports-related events contracts are not swaps, and therefore aren't subject to federal regulatory oversight.
NVD · HIGH
CVE-2026-10758 · CVSS 7.5
Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlle
NVD · HIGH
CVE-2026-100391 · CVSS 8.2
MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full resp
NVD · HIGH
CVE-2026-100390 · CVSS 7.4
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access cont
NVD · HIGH
CVE-2026-100389 · CVSS 8.1
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible up
NVD · HIGH
CVE-2026-100387 · CVSS 8.1
pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored
NEWS_THEDEFIANT · INFO
EBA Floats Stablecoin Lending Restrictions for EU Crypto Firms
The regulator wants the EU to examine rules for DeFi gateways, with leverage caps and certification of lending protocols among the options.
NEWS_COINTELEGRAPH · INFO
OG.com seeks CFTC approval for single-stock perpetual futures
OG.com, recently spun out of Crypto.com, joins Coinbase, Kalshi and Kraken parent Payward in seeking approval to bring perpetual futures to individual US stocks.
NEWS_COINTELEGRAPH · INFO
Ex-CFTC leader to leave Blockchain Association after CLARITY vote fails
Former CFTC Commissioner Summer Mersinger joined the Blockchain Association in 2025 after resigning during her second term at the federal commodities regulator.
NEWS_THEDEFIANT · INFO
Duelbits Co-Founder Reports $7 Million Hack as Casino Stays Offline
The platform says customer balances are unchanged and withdrawals will resume when it reopens, while onchain records show funds consolidated into ETH.
NEWS_THERECORD · INFO
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing