What is quantum-safe encryption, and why do candidates keep failing?

Nearly every secure connection on the internet today — banking, messaging apps, government communications — rests on the assumption that certain mathematical problems are practically impossible to solve. A sufficiently powerful quantum computer could upend that assumption. That's why cryptographers worldwide have spent a decade developing a new generation of algorithms known as quantum-resistant, or post-quantum, encryption.
This effort isn't the work of any single company or lab; it's a global, multi-year evaluation process. Candidates are submitted and scrutinized in public, with cryptographers spending months or years hunting for weaknesses, and only the survivors advance to the next round. The point of the process is to be as confident as possible that no hidden backdoor or unnoticed flaw remains.
This month's news showed just how fragile that confidence can be. HAWK, a third-round candidate, had emerged intact from years of intense scrutiny — no researcher had found a fatal weakness. But a new automated attack tool called Mythos uncovered a flaw that had gone unnoticed for years, rendering the algorithm unusable.
What makes Mythos notable is its ability to systematically scan for weaknesses in places human cryptographers search by hand. Automated cryptanalysis tools can spot subtle patterns in mathematical structures at a scale a human researcher might miss — a boon for the security community, and an unsettling warning at the same time.
This isn't the first collapse in the post-quantum encryption race, either. A few years ago, another promising candidate called SIKE was broken within hours on a single laptop running classical software — no quantum computer required at all. Episodes like that explain why the process moves so cautiously and takes so long.
These failures are actually viewed as proof the system is working, not a malfunction. The entire point of the standardization process is to make sure weak algorithms collapse in a lab setting before they're deployed in the real world — in banking systems, government communications. The earlier a candidate is eliminated, the less damage it can do.
Still, the episode carries a warning for organizations: buying a product labeled "quantum-safe" isn't a permanent guarantee. While the standardization process continues, an algorithm considered secure today can collapse tomorrow — exactly what happened to HAWK.
Security experts recommend organizations adopt the concept of "crypto-agility": designing systems so they aren't rigidly locked to a single encryption algorithm, allowing a rapid switch to another one if the current one falls. That's a far more realistic long-term strategy than hoping to find one "perfect" algorithm.
The "harvest now, decrypt later" threat — where malicious actors collect encrypted data today, betting on decrypting it once a sufficiently powerful quantum computer exists — makes news like this more consequential. For organizations holding sensitive, long-lived data, the migration process isn't a doomsday scenario, but it is a planning issue worth taking seriously.
The standardization process continues to move forward, and HAWK's collapse means the remaining candidates will face equally rigorous testing. For everyday users, the practical advice is simple: there's no need to panic, quantum computers are still years away from breaking today's encryption — but understanding why the process moves so slowly and cautiously is worth knowing for anyone preparing for the eventual transition.
Read next

Do school phone bans work? What the data shows
A new Pew Research Center survey finds 77% of US adults support banning cellphones in class, and 48% now back all-day bans — up from just 36% two years ago. Here's what's driving the shift in opinion, and what the research actually shows.

Why are AI's top startups publishing less research than ever?
The field of AI, once known for its culture of open research, is entering a more closed era in which the leading startups are sharing their findings less and less. Here's what's driving the shift, and what it means for the wider scientific community.

Why has the US banned foreign-made robots? A guide to the new import restrictions
The US government has banned new imports of foreign-made humanoid robots, robot dogs and solar inverters, citing national security risks. Here's who the ban affects, why officials say it's necessary, and what it means for consumers.

Claude Opus 5 became the most aggressive AI "capitalist" yet in a vending-machine benchmark
In Andon Labs' vending-machine simulation, Claude Opus 5 became the most successful AI "shopkeeper" yet, using aggressive strategies — including deception and collusion tactics — to maximize profit. The benchmark is part of a growing field testing how AI agents make long-horizon business decisions.

What is Kimi K3, and how its architecture differs from other large language models
Kimi K3, developed by the Chinese AI lab Moonshot AI, has drawn attention from researchers for its architectural design choices. An independent analysis examines how the model balances efficiency and scale, and where those choices diverge from the approach taken by Western labs. Here is what Kimi K3 is, and what stands out about its architecture.