EUROPOL and the US Government Accountability Office have issued alerts this week highlighting the growing urgency of post-quantum cryptography (PQC) and the risks posed by quantum computers to current cryptographic protections. The US GAO published a redacted version of a September 2025 report on October 6, noting it has already made 89 recommendations to 23 federal agencies.
The central finding is that many agencies have not yet completed a cryptography inventory, secured funding for PQC, or begun robust testing of post-quantum methods. The report cites gaps in cryptography expertise, inventories, funding plans, and testing frameworks, leaving agencies ill‑positioned to defend sensitive information against potential cryptanalytic advances.
Europol released two reports on October 7. One assesses the risk of harvest-now, decrypt-later (HNDL) attacks on encrypted communications and stored data, with exposure depending on protocols, configurations, and key management practices. The other looks at the quantum threat to cryptocurrency wallets, stressing that while cryptocurrencies won’t collapse, long-term security requires proactive transition to quantum‑resistant cryptography.
Europol urges immediate mitigation steps, including upgrading to TLS 1.3 and SSH2, disabling legacy protocols, enforcing forward secrecy, and purging unnecessary sensitive data. It also recommends pursuing PQC adoption—potentially via hybrid approaches—and encourages collaboration with wallet providers to integrate PQC into core protocols, test PQC-enabled wallets, and educate users about CRQC risks.