lattice
Y2Q warning — quantum computers will break RSA & ECDSAtime to quantum 2029 · migrate to lattice
threat: high 48,210 keys get a key

the cold wallet that died in 2040

war story

the cold wallet that died in 2040

by Amar Jafari · Apr 10, 2026

Imagine a hardware wallet, generated in 2024, holding a life's savings on a secp256k1 key. Then imagine the year 2040, when a fault-tolerant quantum computer exists.

Here's what happens: the wallet's public key was broadcast years ago, in every transaction. Shor's algorithm factors it back into the private key in hours. The funds don't get "hacked" — the math just stops protecting them.

harvest now, decrypt later

The scary part is that the attack already started. An adversary recording ciphertext today can crack it the moment a quantum computer exists — which is why long-lived secrets are the first to migrate. Your cold wallet's keys aren't data. They're a countdown.

the fix is already here

Lattice keys are lattice-based, and lattices have no known quantum attack. The migration exists, the standards are final, and the only question left is whether you do it before the era or after it. Before is cheaper.

— Amar JafariFounder, Lattice