◉ NEAR YOU
5 active threats in your region (US)
QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
800
DAYS
19
HRS
49
MIN
9
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,719,717,400
ECDSA signatures committed onchain (BTC + ETH)
BTC #959514 · ETH #25,607,857
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · US
FILTERS · TAP TO TOGGLE LAYERS
NEWS_THEDEFIANTeToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-UpNEWS_THEDEFIANTBitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of SupplyNEWS_THEDEFIANTNEAR Governance Votes to Scrap Developer Gas RebateNEWS_THEDEFIANTEDX Markets Closes $76M Series C Led by SBI HoldingsNEWS_THEDEFIANTSummerFi to Wind Down After Seven Years, Citing ExploitGHSAGHSA · go/go.etcd.io/etcd/v3 · GHSA-6vch-q96h-7gc3GHSAGHSA · npm/@frontmcp/adapters · GHSA-8q49-2h5h-434xGHSAGHSA · go/github.com/getkin/kin-openapi · GHSA-jpcw-4wr7-c3vqGHSAGHSA · pip/bedrock-agentcore · CVE-2026-16796GHSAGHSA · go/go.etcd.io/etcd/v3 · GHSA-xg4h-6gfc-h4m8GHSAGHSA · rust/aws-smithy-http-server · CVE-2026-16756GHSAGHSA · pip/libp2p · GHSA-hmj8-5xmh-5573GHSAGHSA · npm/quasar · GHSA-3r53-75j5-3g7jGHSAGHSA · go/github.com/jandedobbeleer/oh-my-posh · GHSA-6xj8-qv9j-xcjqGHSAGHSA · go/github.com/jandedobbeleer/oh-my-posh · GHSA-fwjx-9p69-h25hGHSAGHSA · maven/org.omnifaces:omnifaces · GHSA-fp43-vj7g-pg92
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
644
vendor
359
cve
1140
news
27
kev
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
KEV 2 · CVE 191 · GHSA 3
196
github
CVE 2 · GHSA 188
190
microsoft
KEV 7 · CVE 25 · GHSA 27
59
wordpress
KEV 4 · CVE 29 · GHSA 0
33
java
CVE 12 · GHSA 18
30
python
CVE 10 · GHSA 15
25
linux
CVE 5 · GHSA 8
13
aws
CVE 1 · GHSA 9
10
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
554d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
206d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
25d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
524d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1620d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2716d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_THEDEFIANT · INFO
eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up
eToro has become a strategic investor in Extended, an onchain perpetual futures exchange, and said the round begins a partnership with Zengo, the self-custody wallet eToro acquired earlier this year. Neither company disclosed the investment size.
NEWS_THEDEFIANT · INFO
BitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of Supply
BitMine Immersion Technologies (NYSE: BMNR), the Ethereum treasury company chaired by Fundstrat's Tom Lee, bought 42,197 ETH worth roughly $73 million over the past week, according to the company's own holdings update posted Monday. The purchase lifts BitMine's total to 5,742,237 ETH, about 4.8% of…
NEWS_THEDEFIANT · INFO
NEAR Governance Votes to Scrap Developer Gas Rebate
NEAR's on-chain governance body, House of Stake, passed proposal HSP-027 to eliminate the protocol's developer gas rebate, a change that will send all network gas fees to be burned rather than partly rebated to smart-contract owners. NEAR co-founder Illia Polosukhin confirmed the outcome Monday,…
NEWS_THEDEFIANT · INFO
EDX Markets Closes $76M Series C Led by SBI Holdings
EDX Markets, an institutional-only crypto trading venue with its own central clearinghouse, closed a $76 million Series C funding round led by SBI Holdings, the firm said in a press release. The Tokyo-listed financial group becomes a strategic investor in the U.S. exchange. The capital will fund…
NEWS_THEDEFIANT · INFO
SummerFi to Wind Down After Seven Years, Citing Exploit
Aave founder Stani Kulechov called the DeFi access point 'an OG' as its team said it would sunset the UI.
GHSA · HIGH
GHSA · go/go.etcd.io/etcd/v3 · GHSA-6vch-q96h-7gc3
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA · MEDIUM
GHSA · npm/@frontmcp/adapters · GHSA-8q49-2h5h-434x
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA · MEDIUM
GHSA · go/github.com/getkin/kin-openapi · GHSA-jpcw-4wr7-c3vq
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA · HIGH
GHSA · pip/bedrock-agentcore · CVE-2026-16796
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA · HIGH
GHSA · go/go.etcd.io/etcd/v3 · GHSA-xg4h-6gfc-h4m8
etcd: Watch API authorization bypass via open-ended range requests
GHSA · HIGH
GHSA · rust/aws-smithy-http-server · CVE-2026-16756
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA · HIGH
GHSA · pip/libp2p · GHSA-hmj8-5xmh-5573
libp2p: yamux connection DoS via oversized data frame
GHSA · MEDIUM
GHSA · npm/quasar · GHSA-3r53-75j5-3g7j
Quasar: Prototype pollution in the extend() utility
GHSA · HIGH
GHSA · go/github.com/jandedobbeleer/oh-my-posh · GHSA-6xj8-qv9j-xcjq
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA · MEDIUM
GHSA · go/github.com/jandedobbeleer/oh-my-posh · GHSA-fwjx-9p69-h25h
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA · HIGH
GHSA · maven/org.omnifaces:omnifaces · GHSA-fp43-vj7g-pg92
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA · HIGH
GHSA · npm/shescape · GHSA-gm3r-q2wp-hw87
Shescape: Quadratic-time denial of service in the flag-protection
GHSA · MEDIUM
GHSA · npm/shescape · GHSA-q53c-4prm-w95q
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA · CRITICAL
GHSA · npm/shescape · GHSA-w4hw-qcx7-56pr
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA · MEDIUM
GHSA · npm/shescape · GHSA-6v4m-fw66-8r4x
Shescape: Path disclosure on Unix with Zsh
GHSA · HIGH
GHSA · pip/awslabs.aws-api-mcp-server · CVE-2026-16584
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA · MEDIUM
GHSA · go/github.com/OpenListTeam/OpenList/v4 · GHSA-86cx-wwf4-phq4
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA · MEDIUM
GHSA · go/github.com/OpenListTeam/OpenList/v4 · GHSA-p6ph-3jx2-3337
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA · HIGH
GHSA · go/github.com/OpenListTeam/OpenList/v4 · GHSA-95cv-r8x4-vh75
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA · HIGH
GHSA · maven/org.http4s:http4s-blaze-server_2.13 · GHSA-7ppr-r889-mcf2
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA · HIGH
GHSA · maven/org.http4s:blaze-http_2.13 · GHSA-46q4-43ph-c6fr
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA · HIGH
GHSA · maven/org.http4s:http4s-blaze-server_2.13 · GHSA-mhvj-jhpq-885v
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
NEWS_BITCOINMAG · INFO
Morgan Stanley Bitcoin ETF Nearly Notches $400M in Assets
Bitcoin Magazine Morgan Stanley Bitcoin ETF Nearly Notches $400M in Assets Investors were cashing out of Bitcoin ETFs this week — but Morgan Stanley's product received fresh cash. This post Morgan Stanley Bitcoin ETF Nearly Notches $400M in Assets first appeared on Bitcoin Magazine and is written by
NEWS_DECRYPT · INFO
Stocks Just Topped Crypto on Hyperliquid. ARK Says That Changes Everything
For the first time, real-world assets—stocks, commodities, and market indices—outpaced crypto on the world's biggest decentralized derivatives exchange.
GHSA · HIGH
GHSA · composer/poweradmin/poweradmin · GHSA-cmwh-g2h8-c222
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing
GET STARTED IN 60s
Need to scope a PQC audit, scan a wallet, or pick a tier? I'll walk you through it in under a minute — with sources.