QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
797
DAYS
17
HRS
43
MIN
58
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,724,330,500
ECDSA signatures committed onchain (BTC + ETH)
BTC #959944 · ETH #25,630,011
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · KR
FILTERS · TAP TO TOGGLE LAYERS
NEWS_THEDEFIANTeToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-UpNEWS_THEDEFIANTBitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of SupplyNEWS_THEDEFIANTNEAR Governance Votes to Scrap Developer Gas RebateNEWS_THEDEFIANTEDX Markets Closes $76M Series C Led by SBI HoldingsNEWS_THEDEFIANTSummerFi to Wind Down After Seven Years, Citing ExploitNEWS_COINDESKHong Kong’s central bank puts a number on lenders' quantum preparedness. It's very low.NEWS_COINDESKBitcoin recovers from Asian session lows; Nasdaq futures remain under pressureNEWS_COINTELEGRAPHApple faces lawsuit over alleged $1.8M Bitcoin wallet app lossesNEWS_SECURITYWEEKUnpatched Fastjson Vulnerability Exploited in AttacksNVDCVE-2026-16585 · CVSS 7.2NVDCVE-2026-14490 · CVSS 7.5NEWS_SECURITYWEEKCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayNEWS_THEHACKERNEWSMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostNEWS_COINTELEGRAPHBinance co-founder CZ backs crypto license passporting across ASEANNEWS_SECURITYWEEKOrigin Energy Data Breach Affects 900,000 AustraliansNEWS_THEHACKERNEWSAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
21
kev
410
cve
1155
news
609
vendor
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
KEV 2 · CVE 205 · GHSA 3
210
github
CVE 1 · GHSA 152
153
microsoft
KEV 7 · CVE 27 · GHSA 26
60
wordpress
KEV 4 · CVE 31 · GHSA 0
35
java
CVE 12 · GHSA 16
28
python
CVE 11 · GHSA 12
23
apache
CVE 14 · GHSA 0
14
linux
CVE 5 · GHSA 7
12
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
557d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
209d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
28d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
521d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1617d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2713d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_THEDEFIANT · INFO
eToro Takes Strategic Stake in Onchain Derivatives Exchange Extended, Plans Zengo Tie-Up
eToro has become a strategic investor in Extended, an onchain perpetual futures exchange, and said the round begins a partnership with Zengo, the self-custody wallet eToro acquired earlier this year. Neither company disclosed the investment size.
NEWS_THEDEFIANT · INFO
BitMine Adds $73 Million in ETH, Pushing Holdings to 4.8% of Supply
BitMine Immersion Technologies (NYSE: BMNR), the Ethereum treasury company chaired by Fundstrat's Tom Lee, bought 42,197 ETH worth roughly $73 million over the past week, according to the company's own holdings update posted Monday. The purchase lifts BitMine's total to 5,742,237 ETH, about 4.8% of…
NEWS_THEDEFIANT · INFO
NEAR Governance Votes to Scrap Developer Gas Rebate
NEAR's on-chain governance body, House of Stake, passed proposal HSP-027 to eliminate the protocol's developer gas rebate, a change that will send all network gas fees to be burned rather than partly rebated to smart-contract owners. NEAR co-founder Illia Polosukhin confirmed the outcome Monday,…
NEWS_THEDEFIANT · INFO
EDX Markets Closes $76M Series C Led by SBI Holdings
EDX Markets, an institutional-only crypto trading venue with its own central clearinghouse, closed a $76 million Series C funding round led by SBI Holdings, the firm said in a press release. The Tokyo-listed financial group becomes a strategic investor in the U.S. exchange. The capital will fund…
NEWS_THEDEFIANT · INFO
SummerFi to Wind Down After Seven Years, Citing Exploit
Aave founder Stani Kulechov called the DeFi access point 'an OG' as its team said it would sunset the UI.
NEWS_COINDESK · INFO
Hong Kong’s central bank puts a number on lenders' quantum preparedness. It's very low.
The Hong Kong Monetary Authority published a whitepaper on the quantum preparedness of Hong Kong’s banking industry and its first Quantum Preparedness Index.
NEWS_COINDESK · INFO
Bitcoin recovers from Asian session lows; Nasdaq futures remain under pressure
It's a risk-off day. Still, bitcoin is holding better than Nasdaq and Asian equity markets.
NEWS_COINTELEGRAPH · INFO
Apple faces lawsuit over alleged $1.8M Bitcoin wallet app losses
Three users allege a fake Sparrow Wallet app on Apple’s App Store drained their Bitcoin holdings, with losses totaling more than $1.8 million.
NEWS_SECURITYWEEK · INFO
Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .
NVD · HIGH
CVE-2026-16585 · CVSS 7.2
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated
NVD · HIGH
CVE-2026-14490 · CVSS 7.5
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicl
NEWS_SECURITYWEEK · INFO
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .
NEWS_THEHACKERNEWS · INFO
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current b
NEWS_COINTELEGRAPH · INFO
Binance co-founder CZ backs crypto license passporting across ASEAN
Binance co-founder CZ backed crypto license passporting across ASEAN to simplify approvals, reduce compliance costs and encourage competition.
NEWS_SECURITYWEEK · INFO
Origin Energy Data Breach Affects 900,000 Australians
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .
NEWS_THEHACKERNEWS · INFO
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrar
NEWS_COINDESK · INFO
Bitcoin slides 2% after U.S. close while Korea’s Kospi plunges 10%
NEWS_COINTELEGRAPH · INFO
US judge temporarily blocks Minnesota prediction market ban
The preliminary injunction allows Kalshi and Polymarket US to continue operating in Minnesota while the court considers their challenge to the state law.
NEWS_COINTELEGRAPH · INFO
Zimbabwe admits 7 fintech projects to regulatory sandbox
Sandbox participation permits supervised testing but does not guarantee full commercial registration.
NEWS_SECURITYWEEK · INFO
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
Decades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own. The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup appeared first on
NEWS_COINTELEGRAPH · INFO
Hong Kong prepares banks for quantum threats amid tokenization push
The HKMA aims to make Hong Kong’s banking sector fully prepared for quantum-related security risks by 2030 as the city expands tokenized finance.
NEWS_COINTELEGRAPH · INFO
Binance phishes its own staff monthly, India censors BitChat code: Asia Express
Binance has been phishing its own staff to get ahead of potential attacks. South Korean crypto volumes tank 89% — plus all of the week’s other crypto news from Asia.
NEWS_DARKREADING · INFO
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
NEWS_COINDESK · INFO
U.S. Senate puts off crypto Clarity Act for now as it focuses limited bandwidth elsewhere
The majority leader is pursuing floor time for unrelated bills as the crypto industry waits for its policy effort to get its chance for votes.
NEWS_COINDESK · INFO
Kalshi, Polymarket win pause against Minnesota's prediction market ban
A federal judge ruled that Minnesota's law criminalizing prediction markets would probably violate the federal Commodity Exchange Act.
NEWS_DECRYPT · INFO
Elon Musk: Humans Will Lose Control of AI Within a Decade
The SpaceX founder says artificial intelligence is advancing too quickly to stop and is urging leading AI companies to coordinate on safety before releasing their most powerful models.
NEWS_COINTELEGRAPH · INFO
New York AG warns CLARITY Act could weaken state crypto enforcement
New York Attorney General Letitia James said the federal crypto market structure bill could restrict state regulators and urged Congress to impose stronger consumer protections on digital asset platforms.
NEWS_CYBERSCOOP_ME · INFO
Microsoft debuts AI cybersecurity offerings as competition heats up
It includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop .
NEWS_CYBERSCOOP_ME · INFO
Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms
In a Monday filing, the Justice Department said states sued before agencies even decided how the order would work. The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop .
NEWS_DECRYPT · INFO
OpenAI’s GPT-6 Will Arrive by September, Markets Predict
Money is moving on a September bet for OpenAI’s next major model on both Polymarket and Myriad prediction markets.

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing