
Wed Jun 10 2026
Most organisations are waiting for quantum computers to become real before they act on quantum risk — and the people who study this threat for a living have a simple equation explaining why that’s a mistake.
The 2025 Quantum Threat Timeline Report, published by evolutionQ Inc. and the Global Risk Institute, surveys 26 of the world’s leading quantum computing experts each year. Buried in its risk framework is a deceptively simple piece of arithmetic that should reframe how every security leader thinks about timing. It’s called the Mosca Inequality, and once you understand it, “we’ll deal with quantum when it arrives” stops being a defensible position.
The Mosca Inequality weighs three numbers against each other:
(The framework comes from Dr. Michele Mosca, a pioneering quantum cryptography researcher and co-author of the report itself — which makes its conclusion all the harder to wave away as vendor hype.)
The logic is unforgiving: if your shelf-life plus your migration time is greater than the threat time, your assets are already exposed. You do not get to wait until the threat arrives, because the clock you actually have to beat is the threat clock minus however long your migration takes — and your data may need to stay protected long after that.
In other words, the relevant deadline isn’t the day a quantum computer breaks encryption. It’s that day, pulled backward by years of migration work you haven’t started yet.
The inequality only matters because of a strategy the report places at the centre of quantum risk: “harvest now, decrypt later.” Adversaries don’t need a working quantum computer today. They need only to intercept and store encrypted data now, then decrypt it once the capability exists.
For anything with a long shelf-life, this is already an active threat. Financial records, intellectual property, identity data, confidential models, and digital asset transactions that expose public keys are all being captured today against a future payday. The report stresses that the risk isn’t just exposed secrets — once the threat arrives before migration is complete, the integrity, availability, and operational control of connected systems are all at stake in real time.
What makes the Mosca Inequality urgent in 2025 is that the threat-time number has shrunk. This year’s surveyed experts are the most optimistic they have ever been about a cryptographically relevant quantum computer arriving within a decade — half of them put the likelihood at around 50% or higher within ten years. Even the report’s deliberately pessimistic reading lands at roughly 28% over the same period.
That’s compounded by a recent breakthrough showing that breaking RSA-2048 may require fewer than one million physical qubits — a roughly twenty-fold reduction from earlier estimates — and by governments treating the matter as settled: Canada requires every federal department to draft a post-quantum migration plan by April 2026, and the EU requires member states to begin deploying post-quantum encryption this year, with critical infrastructure complete by the end of 2030.
When the threat-time number drops while your migration-time number stays fixed, the inequality tips against you — often without anyone noticing.
A rushed, last-minute migration is its own hazard. The report warns that forcing a hurried transition can introduce fresh vulnerabilities — design flaws and implementation errors that even conventional attackers can exploit. The orderly path requires starting early, while there’s still time to test, validate, and deploy properly.
That is exactly the window most of the digital asset and enterprise world is letting close. The gap between how fast the threat is moving and how slowly the response is moving is the precise exposure the Mosca Inequality is designed to expose.
01 Quantum’s work is aimed squarely at shrinking the migration-time side of the equation — making quantum-safe protection something organisations can adopt now rather than rebuild from scratch later.
On the AI side, 01 Quantum’s Quantum AI Wrapper (QAW) uses fully homomorphic encryption (FHE) to bring artificial intelligence workloads into a quantum-safe operating environment — protecting models and the sensitive data they process without forcing organisations to abandon the AI infrastructure they already depend on. As AI systems ingest ever-larger volumes of long-shelf-life data, they sit squarely in the harvest-now-decrypt-later crosshairs, and they represent by far the largest body of data now exposed to the inequality.
On the digital assets side, the Quantum Crypto Wrapper (QCW) and Quantum DeFi Wrapper (QDW) extend the same quantum-safe protection to existing assets and decentralised applications across Bitcoin, Ethereum, Solana, and Hyperliquid — preserving the chains in use while closing the quantum vulnerability.
All of this is built on IronCAP™, engineered to align with the finalised NIST standards (FIPS 203, 204, and 205) that now define the quantum-safe benchmark, and powered by patent-pending technology (US #63/832787). It is reinforced by strategic advisor Dr. Edoardo Persichetti, a NIST post-quantum standardisation contributor and co-author of the HQC algorithm. These are working demonstrations of readiness — available today, while much of the industry is still calculating whether it has time to wait.
The experts behind the report are measured scientists who freely admit the future is uncertain. But the Mosca Inequality doesn’t require certainty about the threat date — it requires only that you account for how long your own migration will take. Once you do that honestly, the conclusion is hard to avoid.
The threat clock has already started, your migration clock hasn’t, and the quantum-safe tools to protect both your AI workloads and your digital assets exist today.