QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
737
DAYS
10
HRS
9
MIN
56
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,815,496,300
ECDSA signatures committed onchain (BTC + ETH)
BTC #968704 · ETH #26,062,583
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · IL
FILTERS · TAP TO TOGGLE LAYERS
NEWS_BITCOINMAGGrant Cardone: Real Estate “Armageddon” Is Here – Why BITCOIN is the HedgeNEWS_DECRYPTAI Agents Are Racing to Make Quantum-Safe Bitcoin Cheap—And WinningNEWS_THEDEFIANTSolana’s Alpenglow Goes Live on Devnet Ahead of Mainnet MigrationNEWS_COINDESKKraken’s parent Payward is betting billions on becoming financial infrastructure, not just a crypto exchangeNEWS_COINTELEGRAPHKalshi loses appeal, setting up potential Supreme Court caseNEWS_DECRYPTGoogle Just Made Free 1080p AI Video Generation Available to AnyoneNEWS_COINDESKBinance deal gives Circle a boost in stablecoin race with Tether, analysts sayNEWS_COINDESKBitget hacker moves $83 million in stolen XRP that Ripple cannot freezeNEWS_COINTELEGRAPHHere’s what happened in crypto todayNEWS_COINDESKBitcoin could soon get Zcash-style 'shielded' privacy without changing its rulesNEWS_SECURITYWEEKNew x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingNEWS_COINTELEGRAPHFed requests comment on two proposals for stablecoin issuers under GENIUS ActNEWS_THEHACKERNEWSAttackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web ShellsNEWS_THEHACKERNEWSZero Trust for AI Agents Starts With Fixing Zero VisibilityNEWS_SECURITYWEEKOpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior DisclosureNEWS_THEHACKERNEWSElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
19
kev
344
cve
1272
news
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
CVE 68 · GHSA 0
68
ibm
CVE 60 · GHSA 0
60
wordpress
KEV 1 · CVE 41 · GHSA 0
42
java
KEV 1 · CVE 20 · GHSA 0
21
microsoft
KEV 6 · CVE 9 · GHSA 0
15
redhat
CVE 12 · GHSA 0
12
google
KEV 1 · CVE 10 · GHSA 0
11
cisco
KEV 4 · CVE 6 · GHSA 0
10
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
617d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
269d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
88d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
461d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1557d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2653d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_BITCOINMAG · INFO
Grant Cardone: Real Estate “Armageddon” Is Here – Why BITCOIN is the Hedge
Bitcoin Magazine Grant Cardone: Real Estate “Armageddon” Is Here – Why BITCOIN is the Hedge Grant Cardone explains how a massive shift in commercial real estate created the perfect opportunity to aggressively accumulate and store wealth in Bitcoin. This post Grant Cardone: Real Estate &#
NEWS_DECRYPT · INFO
AI Agents Are Racing to Make Quantum-Safe Bitcoin Cheap—And Winning
An open competition run by StarkWare, Yukon Research, and Eigen Labs drove the estimated cost of building a quantum-safe Bitcoin transaction from about $320 to roughly $67, with AI models topping the leaderboards.
NEWS_THEDEFIANT · INFO
Solana’s Alpenglow Goes Live on Devnet Ahead of Mainnet Migration
Anza is asking app developers to test programs and integrations as the upgrade moves validator voting off-chain. Mainnet activation remains pending.
NEWS_COINDESK · INFO
Kraken’s parent Payward is betting billions on becoming financial infrastructure, not just a crypto exchange
Kraken parent Payward is unifying trading, payments, asset management and institutional services on common rails, co-CEO Arjun Sethi said.
NEWS_COINTELEGRAPH · INFO
Kalshi loses appeal, setting up potential Supreme Court case
The 6th US Circuit Court of Appeals ruled against prediction market Kalshi, siding with Ohio and Tennessee on regulating sports-event contracts under state laws.
NEWS_DECRYPT · INFO
Google Just Made Free 1080p AI Video Generation Available to Anyone
Google Vids now lets any Google account holder generate free HD AI video using Gemini Omni 1.1 Flash, with new scene, timing, and watermark controls.
NEWS_COINDESK · INFO
Binance deal gives Circle a boost in stablecoin race with Tether, analysts say
The five-year deal could strengthen USDC’s reach in emerging markets, though Tether’s liquidity advantage remains hard to dislodge, analysts told CoinDesk.
NEWS_COINDESK · INFO
Bitget hacker moves $83 million in stolen XRP that Ripple cannot freeze
Two wallets have been almost emptied and a third is being drained, with about $75 million remaining across the five original holding accounts.
NEWS_COINTELEGRAPH · INFO
Here’s what happened in crypto today
Need to know what happened in crypto today? Here is the latest news on daily trends and events impacting Bitcoin price, blockchain, DeFi, Web3 and crypto regulation.
NEWS_COINDESK · INFO
Bitcoin could soon get Zcash-style 'shielded' privacy without changing its rules
Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
NEWS_SECURITYWEEK · INFO
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek .
NEWS_COINTELEGRAPH · INFO
Fed requests comment on two proposals for stablecoin issuers under GENIUS Act
US regulatory agencies missed a rule-making deadline under the GENIUS Act, a year after the law was signed.
NEWS_THEHACKERNEWS · INFO
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result
NEWS_THEHACKERNEWS · INFO
Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discus
NEWS_SECURITYWEEK · INFO
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure appeared first on SecurityWeek .
NEWS_THEHACKERNEWS · INFO
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to b
NEWS_COINTELEGRAPH · INFO
SEC Commissioner Hester Peirce to leave post on Oct. 2
Peirce, known as “Crypto Mom,” served on the SEC for about eight years, including as director of the Crypto Task Force.
NEWS_THEHACKERNEWS · INFO
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-
NEWS_THEHACKERNEWS · INFO
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indica
NEWS_COINTELEGRAPH · INFO
CFTC sues Cash FX, alleges $950M crypto-linked forex scheme
The CFTC claimed that Cash FX engaged in minimal forex trading and misappropriated most of the participant funds.
NEWS_COINDESK · INFO
Solana’s 150-millisecond settlement upgrade reaches second public test network
Alpenglow is running on both public test networks, giving application teams a place to check their software before the live blockchain switches.
NEWS_COINDESK · INFO
XRP Ledger’s Batch upgrade slips to Oct. 9 after validator support resets
The feature would let users bundle up to eight transactions, including asset-and-payment transfers, but a brief drop below the network’s 80% support threshold restarted its two-week activation clock.
NEWS_COINDESK · INFO
Bitcoin could soon get Zcash-style 'shielded' privacy without changing its rules
Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
NVD · HIGH
CVE-2026-100543 · CVSS 7.5
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as of
NVD · HIGH
CVE-2026-100541 · CVSS 7.5
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Ma
NVD · HIGH
CVE-2026-100535 · CVSS 7.5
OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted provenance when session-derived text is persisted to session memory. In deployments where session-memory capture and dreaming are enabled, a restricted external sende
NVD · HIGH
CVE-2026-100532 · CVSS 8.1
@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and
NVD · HIGH
CVE-2026-100530 · CVSS 7.3
OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or repositories with materially d
NVD · HIGH
CVE-2026-100520 · CVSS 8.8
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into
NVD · HIGH
CVE-2026-100504 · CVSS 7.0
Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific instruction sequences that trigger the overflow when decompiled, c

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing
GET STARTED IN 60s
Need to scope a PQC audit, scan a wallet, or pick a tier? I'll walk you through it in under a minute — with sources.