Post-quantum security researchers warned that public reporting is becoming an unreliable measure of progress toward cryptographically relevant quantum computers, after high-profile disclosures on Shor-based attacks against elliptic-curve cryptography exposed tensions between openness and national-security concerns. Oratomic publicly released resource estimates and a responsible-disclosure statement for fault-tolerant quantum cryptanalysis, while Google published ECDLP-256 resource estimates only after consulting the U.S. government and withheld the underlying circuits behind a zero-knowledge proof. The disclosures were presented as evidence that publication decisions around quantum cryptanalysis are becoming sensitive in their own right, with U.S. export controls, executive actions, and other intervention mechanisms cited as tools that could further limit what becomes public.
Google’s partial-disclosure approach quickly unraveled: André Schrottenloher independently reconstructed the concealed circuits, and Trail of Bits reportedly forged a proof by exploiting bugs in Google’s prover code, undermining the attempt to reveal results without fully exposing implementation details. Commentaries tied those events to a broader warning that future breakthroughs may be selectively disclosed or kept secret altogether, echoing older intelligence-era norms around cryptanalytic advances. For defenders, the practical message was to stop using public quantum milestones as the trigger for post-quantum migration and instead treat published capability as a lower bound while accelerating cryptographic inventory, dependency mapping, and migration planning.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Within 63 days of Google’s March 31, 2026 publication, Trail of Bits forged a proof by exploiting bugs in Google’s prover code, further breaking the intended confidentiality of the hidden circuits.
Within 63 days of Google’s March 31, 2026 publication, André Schrottenloher independently reconstructed the hidden circuits, undermining Google’s partial-disclosure approach.
On March 31, 2026, Google published ECDLP-256 quantum resource estimates after consulting the U.S. government, but withheld the underlying circuits and instead used a zero-knowledge proof to support its claims.
On March 31, 2026, Oratomic publicly released Shor’s algorithm resource estimates along with a responsible disclosure statement warning that future progress toward cryptographically relevant quantum computing may become externally invisible.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
postquantum.com
Open sourcepostquantum.com
Open sourcearxiv.org
Open sourcealgassert.com
Open sourceoratomic.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.