QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
727
DAYS
17
HRS
12
MIN
34
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,830,278,650
ECDSA signatures committed onchain (BTC + ETH)
BTC #970151 · ETH #26,132,192
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · RU
FILTERS · TAP TO TOGGLE LAYERS
NEWS_INFOSECURITYRansomware Affiliate Double-Crosses RaaS Operator to Steal Victim FundsNEWS_COINDESKWhy bitcoin is down 'just' 32% a year after its record high of $126,000NEWS_THEDEFIANTOndo Unveils Private-Market Notes Ahead of First AI OfferingNEWS_COINTELEGRAPHBitcoin ETFs shed $90M as BTC sits 32% below year-old ATHNEWS_COINTELEGRAPHEEZ tests atomic L1-to-L2 transaction in push to unify EthereumNEWS_BITCOINMAGBringin Opens Euro Business Accounts for Bitcoin Companies Across 30 European CountriesNEWS_THEHACKERNEWSCritical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsNEWS_THEHACKERNEWSFBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters BreachNEWS_THEHACKERNEWSDenmark Says Attackers Accessed CPR Data for 8.8 Million People via Company AccountNEWS_COINTELEGRAPHHere’s what happened in crypto todayNEWS_COINTELEGRAPHBetter Markets says CFTC is ‘wrong agency’ to regulate retail cryptoNEWS_THEHACKERNEWSClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run LimitsNVDCVE-2026-105704 · CVSS 7.3NEWS_COINDESKU.S. scraps proposed $10,000 reporting rule for for crypto sent to private walletsNEWS_COINDESKEthereum’s Glamsterdam test gets last-minute fix before major capacity jumpNEWS_COINDESKBitcoin keeps getting rejected at $87,000 as stocks hover near records
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
14
kev
1318
news
340
cve
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
CVE 67 · GHSA 0
67
ibm
CVE 41 · GHSA 0
41
wordpress
KEV 1 · CVE 37 · GHSA 0
38
java
CVE 22 · GHSA 0
22
python
CVE 14 · GHSA 0
14
redhat
CVE 12 · GHSA 0
12
google
KEV 1 · CVE 10 · GHSA 0
11
mysql
CVE 10 · GHSA 0
10
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
627d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
279d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
98d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
451d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1547d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2643d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_INFOSECURITY · INFO
Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims
NEWS_COINDESK · INFO
Why bitcoin is down 'just' 32% a year after its record high of $126,000
This shallower decline isn’t limited to the one-year anniversary. The bear market itself has been milder with past downturns seeing prices plummet 77% to 85%.
NEWS_THEDEFIANT · INFO
Ondo Unveils Private-Market Notes Ahead of First AI Offering
The notes offer exposure without shareholder rights. Secondary-market prices can diverge sharply from the eventual payout tied to a liquidity event.
NEWS_COINTELEGRAPH · INFO
Bitcoin ETFs shed $90M as BTC sits 32% below year-old ATH
US spot Bitcoin ETFs reversed two days of inflows as Bitcoin slipped below $86,000, trading roughly 32% below its October 2025 all-time high.
NEWS_COINTELEGRAPH · INFO
EEZ tests atomic L1-to-L2 transaction in push to unify Ethereum
An EEZ contributor shared a 0.001 ETH cross-chain test as the project develops a framework to connect Ethereum mainnet and its rollups.
NEWS_BITCOINMAG · INFO
Bringin Opens Euro Business Accounts for Bitcoin Companies Across 30 European Countries
Bitcoin Magazine Bringin Opens Euro Business Accounts for Bitcoin Companies Across 30 European Countries The accounts run on MiCA-authorized infrastructure from Lightspark Payments Europe AS. Keys sit in a hardware security module, and only designated owners can move funds. This post Bringin Opens E
NEWS_THEHACKERNEWS · INFO
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds.
NEWS_THEHACKERNEWS · INFO
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To d
NEWS_THEHACKERNEWS · INFO
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful righ
NEWS_COINTELEGRAPH · INFO
Here’s what happened in crypto today
Need to know what happened in crypto today? Here is the latest news on daily trends and events impacting Bitcoin price, blockchain, DeFi, Web3 and crypto regulation.
NEWS_COINTELEGRAPH · INFO
Better Markets says CFTC is ‘wrong agency’ to regulate retail crypto
Better Markets said the CFTC’s proposed framework to bring certain cryptocurrency transactions and exchanges under its oversight will leave investors less protected than under the SEC.
NEWS_THEHACKERNEWS · INFO
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the brows
NVD · HIGH
CVE-2026-105704 · CVSS 7.3
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might
NEWS_COINDESK · INFO
U.S. scraps proposed $10,000 reporting rule for for crypto sent to private wallets
FinCEN withdrew two proposals that had hung over self-custody and crypto mixers for years without ever taking effect.
NEWS_COINDESK · INFO
Ethereum’s Glamsterdam test gets last-minute fix before major capacity jump
One of Ethereum’s main validator clients updated its software hours before a Sepolia test that will raise the amount of work each block can hold to 200 million gas.
NEWS_COINDESK · INFO
Bitcoin keeps getting rejected at $87,000 as stocks hover near records
BTC fell back to about $85,600 after sellers turned it away from $87,000 for the third time since Sept. 23, while Nasdaq closed at a record and Treasury yields kept climbing.
NEWS_COINDESK · INFO
Solana Foundation unveils a program to settle institutional trades in seconds. JPMorgan gave input
Solana Foundation launched an open-source program that lets institutions settle trades in seconds, not days. JPMorgan provided key inputs.
NEWS_COINTELEGRAPH · INFO
Rain seeks US trust bank charter days after OCC sued over crypto charters
Rain joins a growing queue of crypto firms seeking federal trust charters, while community banks have just asked a court to overturn the OCC rules underpinning them.
NEWS_COINTELEGRAPH · INFO
OKX eyes emerging markets with yield-offering stablecoin savings and payments app
OKX Money lets users hold, send and spend dollar-backed stablecoins, with qualifying USDG balances earning up to 10% APY.
NVD · HIGH
CVE-2026-105571 · CVSS 7.3
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely.
NVD · HIGH
CVE-2026-105486 · CVSS 7.3
A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and ma
NEWS_DECRYPT · INFO
Solana Debuts Institutional Settlement Standard With J.P. Morgan Input
Built with input from J.P. Morgan, the open-source "DvP" program lets institutions settle trades atomically on Solana with finality in seconds instead of days.
NEWS_COINTELEGRAPH · INFO
Chinese crime network laundered over $1B for Lazarus: ZachXBT
ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.
NVD · HIGH
CVE-2026-105471 · CVSS 7.3
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The atta
NVD · HIGH
CVE-2026-105470 · CVSS 7.3
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql inje
NVD · HIGH
CVE-2026-105469 · CVSS 7.3
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval
NEWS_CYBERSCOOP_ME · INFO
Citrix discloses third actively exploited NetScaler zero-day in less than a week
The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days. The post Citrix discloses third actively exploited NetScaler zero-day in less than a week appeared first on CyberScoop .
NEWS_DECRYPT · INFO
Strive Adds $169M Bitcoin in Its Biggest Buy in Four Months
The Nasdaq-listed bitcoin treasury company, co-founded by Vivek Ramaswamy, paid roughly $169 million for 2,000 coins last week and now holds 29,462 BTC.
NVD · HIGH
CVE-2026-105468 · CVSS 7.3
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection
NEWS_DECRYPT · INFO
DeFi Development Corp Adds $3 Million in Solana as SOL Buys Slow
Nasdaq-listed DeFi Development Corp's latest SEC filing shows its Solana stash grew 1%, to about 2.56 million SOL and SOL equivalents—roughly half the prior week's gain and well below mid-September's pace.

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing
GET STARTED IN 60s
Need to scope a PQC audit, scan a wallet, or pick a tier? I'll walk you through it in under a minute — with sources.