· Michal Pietrus · 3 min read
Czy obecne algorytmy postkwantowe rozsypią się tego lata, czy to tylko szum?
Druga połowa lata przynosi wyjątkowo dużo aktywności kryptanalitycznej. Choć jest w niej sporo szumu, pojawia się też pytanie praktyczne: co dalej i jak organizacje powinny się dalej pozycjonować (oraz swoje budżety) względem migracji postkwantowej?

Despite still being in the middle of the summer slowdown, this is actually the hottest time during this year so far.
- Weakening HAWK leads to its withdrawal from the NIST competition.
- Literally several days later, Simon publishes a quantum algorithm potentially affecting the security foundations of lattice-based schemes, specifically the Learning-With-Errors (LWE) family, with potential implications for schemes such as FrodoKEM, ML-KEM, and ML-DSA. Not much time passes before another paper appears arguing that Simon’s algorithm doesn’t work, at least the current variant, effectively putting the discussion on hold for now.
- Meanwhile, the recently ISO-standardized Classic McEliece is under heavy scrutiny, with recent work demonstrating real cryptanalytic progress[1][2], it still remains strong, but what’s the next step?
Noise, signal, and uncertainty
While observing this might be fun, it also demonstrates the uncertainty surrounding cryptosystems and the potential impact on businesses that depend on them in their daily digital operations.
Inherently, several questions appear:
- Is this the right time now to start the migration?
- Could migrating too aggressively lead to immature choices?
- Could the “PQC migration” itself create another form of cryptographic lock-in?
The limits of crypto-agility
Approaches such as crypto-agility may soften the technical part and even potentially impact the governance part, but it heavily depends on the organization’s posture.
Crypto-agility isn’t sufficient for everyone, especially in the cases that rely on trust distribution that encompasses heterogeneous / multi-domain trust ecosystems. Such distributed systems have high inertia to change to a new state, and therefore, crypto-agility becomes part of the toolset rather than an ultimate solution.
Finding the balance
Thus, rather than asking more questions, it may be more useful to look at the problem through a risk-management lens. Namely, uncertainty itself isn’t the risk. Inability to react to uncertainty is.
Reducing that inability, however, has a cost, and here, the easy part is over.
Spending today on inventories and dependency discovery does not reduce cryptosystem threats themselves. What it buys, however, is reaction capability for tomorrow.
For some systems, waiting is perfectly rational, but for others, waiting may simply accumulate transition debt.
Post-quantum migration, while being one of a kind, requires organizations to take a tailored approach, seeking the right balance between business impact, threat horizon, and transition time.
Although this summer’s cryptanalytic activity is heavily focused on post-quantum schemes, as we’ve discussed in Will Quantum Computing Threats Fit into the Cybersecurity Transformation?, another emerging threat coming from the “AI” angle may become much more tangible sooner, with an impact perhaps not on cryptographic standards themselves, but on the remaining parts of cryptosystems.


