---
title: "Harvest now, decrypt later: what it means for your crypto"
description: Why a quantum attack years away already affects your wallet today, which coins it applies to, and the two habits that reduce your exposure now.
url: "https://hardyindex.com/guides/harvest-now-decrypt-later"
section: Understand the threat
updated: 2026-08-12
methodology_version: 1.1
---

# Harvest now, decrypt later: what it means for your crypto

**Harvest now, decrypt later is the reason the quantum threat matters before Q-Day. An attacker records encrypted data or exposed public keys today, then breaks them once a quantum computer exists. For crypto, the concern is funds sitting at addresses whose public keys are already visible.**

*As of 12 August 2026. This is a security-readiness assessment, not investment advice.*

This is the reason experts say the quantum threat is already here, even though the machine that would carry it out is not. It is simpler than it sounds.

## What is harvest now, decrypt later?

Harvest now, decrypt later is an attack where someone collects encrypted information today and waits for a machine that can break it. The data is captured while it is still safe, and read years later when it is not. It is also written as store now, decrypt later, or shortened to HNDL.

NIST treats this as one of the main reasons the migration to post-quantum cryptography is urgent. Its [transition report](https://csrc.nist.gov/pubs/ir/8547/ipd) puts it plainly. The transition is starting before a cryptographically relevant quantum computer has been built, because encrypted data collected now stays valuable for years.

Citi Institute reached the same conclusion in January 2026. It called harvesting "an immediate and systemic threat of the quantum era" and noted that historical privacy loss cannot be reversed. Nothing you do in 2035 un-reads data captured in 2026.

## Why does it make the threat urgent today?

It makes the threat urgent because the attacker does not need the machine yet, only the patience. Every day between now and Q-Day is a day in which more data and more public keys get recorded. None of that can be withdrawn afterwards.

This is what separates the quantum threat from an ordinary software vulnerability. A normal bug is dangerous until it is patched. Harvest now, decrypt later runs the other way, because the exposure is created today and the harm arrives later. Patching in time means acting before anything has visibly gone wrong.

It is also why the standards deadlines look early. United States federal agencies are expected to have migrated high-risk systems by 2030 and to be fully quantum-resistant by 2035, well ahead of any expected attack. That gap is deliberate.

## Which crypto is affected?

For crypto, the harvest is already public. A blockchain publishes its own data by design, so an attacker does not need to intercept anything. Any address that has revealed its public key has effectively been harvested the moment it appeared on-chain.

On most chains, a public key becomes visible the first time an address spends, because the network has to check the signature against it. On some chains it is visible from the start. Solana and Algorand addresses are derived directly from the public key, so every account is exposed from creation.

Bitcoin is the largest measured case. Deloitte found roughly 4 million BTC at exposed addresses, about 25% of supply. Galaxy Digital estimated roughly 7 million BTC, and Glassnode 6.04 million, or 30.2%. Citi Institute noted in January 2026 that on many other blockchains the majority of coins are vulnerable.

That is why exposure is one of the six dimensions the Hardy Index scores, and why it is weighted separately from a chain's roadmap. A chain can have an excellent plan and still carry a permanent liability in its history. [The methodology](https://hardyindex.com/methodology) sets out how the two are scored apart.

## What reduces the risk?

Two habits reduce your exposure today, and both are free. Use a fresh address for each payment you receive, and move long-term holdings off addresses that have already spent. Neither makes you quantum-safe, and both shrink the surface an attacker can record.

1. **Stop reusing addresses.** Google's Quantum AI team gave this exact advice alongside its 2026 estimate, recommending that people refrain from exposing or reusing vulnerable wallet addresses. On chains where addresses are key hashes, an unspent address has not revealed its key at all.
2. **Move funds that sit at spent addresses.** Once an address has spent, its public key is public for good. Moving the remaining balance to a fresh address does not erase the old key, but it removes the funds from behind it.
3. **Take your chain's post-quantum upgrade when it ships.** This is the step that actually ends the exposure, and it is the one you cannot do yourself. Watching for it is the point of [the Hardy Index](https://hardyindex.com/).

What does not help is switching wallet brands, buying a token marketed as quantum-proof, or moving coins in a hurry. [How to protect your crypto from quantum computers](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers) goes through the steps in order, including where hardware wallets genuinely help and where they do not.



## Frequently asked questions

### What does harvest now, decrypt later mean?

Harvest now, decrypt later means recording encrypted data today so it can be decrypted years later, once a quantum computer capable of breaking the encryption exists. NIST names it as one of the main reasons the transition to post-quantum cryptography is urgent, even though no such computer has been built.

### Does harvest now, decrypt later apply to Bitcoin?

Yes, in a specific form. Bitcoin does not need to be intercepted, because the blockchain is public. Any address that has revealed its public key is permanently recorded and available to a future attacker. That happens by spending, or by being an original pay-to-public-key output. Estimates put the total at between 4 million and 7 million BTC.

### Can I undo my exposure?

You cannot un-publish a public key, but you can move the funds. Once an address has spent, its key is on the chain for good. Transferring the balance to an address that has never spent means an attacker who breaks the old key would find nothing behind it. That is the practical version of undoing exposure.

### Is my exchange account affected?

If you hold coins on an exchange, the exchange controls the keys and carries this exposure on your behalf. That does not remove the risk, it moves it to a company whose migration plan you cannot see. Chains still have to ship post-quantum signatures before any custodian can use them.

### How long do I have to act?

There is no deadline you can rely on, which is the point of harvest now, decrypt later. The habits that reduce exposure cost nothing and work immediately, so there is no reason to wait for a date. Estimates quoted by Citi Institute put the chance of Q-Day before 2034 at 19% to 34%.

## Where to go next

- [The Hardy Index ranking](https://hardyindex.com/): Exposure scored and sourced for all 23 rated chains.
- [Q-Day, and when quantum might break crypto](https://hardyindex.com/guides/q-day-when-will-quantum-break-crypto): The expert ranges, and why the forecasts keep moving.
- [Will quantum computers break Bitcoin?](https://hardyindex.com/guides/will-quantum-computers-break-bitcoin): How the attack would work, and how exposed Bitcoin already is.
- [How to protect your crypto, step by step](https://hardyindex.com/guides/how-to-protect-crypto-from-quantum-computers): The steps that reduce exposure today, in order.
- [Which crypto is quantum proof?](https://hardyindex.com/guides/which-crypto-is-quantum-proof): The chains whose signatures a quantum computer could not forge today.

## Sources

1. [NIST IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards](https://csrc.nist.gov/pubs/ir/8547/ipd): National Institute of Standards and Technology (primary, checked 12 August 2026)
2. [Quantum Threat: the trillion-dollar security race is on](https://www.citigroup.com/rcs/citigpa/storage/public/Citi_Institute_Quantum_Threat.pdf): Citi Institute (primary, checked 12 August 2026)
3. [Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly](https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/): Google Research (primary, checked 12 August 2026)
4. ['That is the end of Bitcoin': the quantum race for $470 billion](https://www.forbes.com/sites/boazsobrado/2026/08/02/that-is-the-end-of-bitcoin-the-quantum-race-for-470-billion/): Forbes (secondary, checked 12 August 2026)

---
Cite as: The Hardy Index, "Harvest now, decrypt later: what it means for your crypto", https://hardyindex.com/guides/harvest-now-decrypt-later, as of 12 August 2026.
