◉ NEAR YOU
22 active threats in your region (NL)
QorTrace
QORTRACE THREAT RADAR · LIVE

The clock is
already ticking.

A live map of post-quantum and Web3 threats. Every signature you commit today is harvest-now-decrypt-later candy when fault-tolerant quantum arrives. Watch the threat surface — and the countdown — in real time.

Schedule Consult
ESTIMATED Q-DAY · 2028-10-03
764
DAYS
8
HRS
54
MIN
56
SEC
STATE OF THE ART
1,180
physical qubits
Atom Computing · Phoenix
Best logical: 24 q (Microsoft + Quantinuum)
HARVEST · NOW · DECRYPT · LATER
6,774,683,850
ECDSA signatures committed onchain (BTC + ETH)
BTC #964758 · ETH #25,869,420
SEE EXPOSED WALLETS →
WEEKLY THREAT BRIEFING · FREE
Tweet this view · NL
FILTERS · TAP TO TOGGLE LAYERS
NEWS_THEDEFIANTRevolut Starts EURR Rollout With Bridge as Regulated IssuerNEWS_THEDEFIANTSEC Crypto Custody Rewrite Enters White House ReviewNEWS_COINDESKMichael Saylor hints at first bitcoin purchase in two months as bitcoin nears $79,000NEWS_COINDESKFrom Hawala to Swift: Inside the 1,000-year battle to move money safelyNEWS_DECRYPTAfter Their AI Models Hacked Real Companies, AI Labs Call for Stronger Cyber DefensesNEWS_COINTELEGRAPHHere’s what happened in crypto todayNEWS_COINDESKCrypto market makers are cashing in on bitcoin's rally - without betting on directionNEWS_COINTELEGRAPHRussia’s Sber eyes USDT loans, questions digital ruble demandNEWS_COINTELEGRAPHReal Trump Coins denies launching GOLD token, blames ‘bad actors’NEWS_THEHACKERNEWSTerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel BackdoorNVDCVE-2026-82478 · CVSS 7.3NEWS_COINDESKA $1.1 million crypto card hack crashed a neobank's token 49%NEWS_COINTELEGRAPHPolygon discloses security flaws fixed in recent hard forksNEWS_COINTELEGRAPHStellar tokenized RWA market more than quadruples to nearly $4BNVDCVE-2026-75807 · CVSS 7.5NEWS_DECRYPTBernie Sanders Vows Legislation to 'Stop Flock and AI Mass Surveillance'
FREE PQC SCAN · 1 PER DAY

Paste a wallet or contract address and we'll score its cryptographic exposure on a 0-100 scale. Free, no card, instant.

REGIONAL HOTSPOTS · 14d
NIST PQC STANDARDS
ML-KEM (Kyber)
FIPS 203 · Key Encapsulation
STANDARDISED
2024
ML-DSA (Dilithium)
FIPS 204 · Digital Signature
STANDARDISED
2024
SLH-DSA (SPHINCS+)
FIPS 205 · Hash-based Signature
STANDARDISED
2024
FN-DSA (Falcon)
FIPS 206 · Digital Signature
DRAFT (DIS)
2025
HQC
— · Backup KEM
SELECTED (2025)
2025
THREAT FEED · LAST 14 DAYS
1153
news
349
cve
24
kev
Sources: CISA Known Exploited Vulnerabilities catalog, NIST NVD CVE feed, GitHub Advisory Database, and curated cybersecurity + Web3 RSS feeds. Refreshed hourly.
MOST-TARGETED VENDORS · 30d
oracle
KEV 1 · CVE 132 · GHSA 2
135
ibm
KEV 1 · CVE 118 · GHSA 0
119
wordpress
CVE 56 · GHSA 0
56
github
CVE 4 · GHSA 31
35
microsoft
KEV 6 · CVE 23 · GHSA 0
29
splunk
CVE 16 · GHSA 0
16
java
CVE 10 · GHSA 6
16
python
CVE 9 · GHSA 6
15
QUANTUM RACE · LEADERBOARD
IBM
Condor
1,121q
Atom Computing◉ SOTA
Phoenix
1,180q
USTC
Zuchongzhi 3.0
504q
Quantinuum
H2
56q
Google
Willow
105q
Microsoft + Quantinuum
Topological + ion-trap
56q
IonQ
Forte
64q
Rigetti
Ankaa-3
84q
PQC COMPLIANCE COUNTDOWN
DORA · Digital Operational Resilience Act
590d ago
2025-01-17 · EU
EU financial-sector firms must demonstrate operational resilience (incl. ICT third-party risk) — including cryptographic posture.
CNSA 2.0 · Software/Firmware
242d ago
2025-12-31 · US-NSA
NSA target for new National Security Systems software & firmware to start adopting CNSA 2.0 (Kyber, Dilithium, SHA-2) algorithms.
BSI TR-02102-1 · Crypto Recommendation Refresh
61d ago
2026-06-30 · DE-BSI
Annual BSI cryptographic-recommendation refresh — flagged deadline for hybrid (classical + PQC) roll-out in regulated DE.
CNSA 2.0 · Networking & VPN
488d
2027-12-31 · US-NSA
Networking, VPN, and key-management products on NSS networks should fully support CNSA 2.0 algorithms.
NIST SP 800-131A · Disallow RSA-2048 / ECDSA P-256
1584d
2030-12-31 · US-NIST
NIST recommended sunset for classical public-key crypto in federal systems — full PQC migration target.
CNSA 2.0 · Full PQC Adoption
2680d
2033-12-31 · US-NSA
All NSS systems must be using CNSA 2.0 PQC algorithms exclusively.
COMMUNITY PULSE · CURATED
@CISAgov
Reminder: NSA's CNSA 2.0 timeline is in effect. New software for NSS should now be adopting Kyber, Dilithium, and SHA-2.
@NIST
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are now the standards. Migration windows are short for high-value targets.
@matthew_d_green
Harvest-now-decrypt-later isn't a scenario, it's an active intelligence program. The ECDSA signatures you commit today are tomorrow's plaintext.
@hashedout
Bitcoin's quantum exposure isn't a 2040 problem. ~25% of circulating supply sits in P2PKH addresses with exposed pubkeys. Q-Day day-one targets.
@SchneierBlog
If your security architecture cannot survive the public release of CRYSTALS-Kyber breaks, you needed PQC yesterday.
@a16zcrypto
Wallet providers shipping PQC migration paths in 2026 will own the institutional custody narrative for the next decade.
LATEST ADVISORIES
NEWS_THEDEFIANT · INFO
Revolut Starts EURR Rollout With Bridge as Regulated Issuer
Revolut opens EURR to selected customers in three countries; Bridge reported €374 outstanding, compared with €394.5 million of Circle’s EURC.
NEWS_THEDEFIANT · INFO
SEC Crypto Custody Rewrite Enters White House Review
The planned rule would cover advisers and investment companies and clarify digital-asset custody, following the withdrawal of a separate 2023 proposal.
NEWS_COINDESK · INFO
Michael Saylor hints at first bitcoin purchase in two months as bitcoin nears $79,000
Bitcoin rebounds from Friday’s low as Strategy’s valuation expands and bitcoin dominance climbs above 60%.
NEWS_COINDESK · INFO
From Hawala to Swift: Inside the 1,000-year battle to move money safely
Finance has spent centuries decoupling wealth from physical transport, but constantly erasing friction creates vectors for increasingly high-tech exploits.
NEWS_DECRYPT · INFO
After Their AI Models Hacked Real Companies, AI Labs Call for Stronger Cyber Defenses
More than 100 AI, security, finance, and technology organizations want governments and industry to prepare for attacks powered by increasingly capable models.
NEWS_COINTELEGRAPH · INFO
Here’s what happened in crypto today
Need to know what happened in crypto today? Here is the latest news on daily trends and events impacting Bitcoin price, blockchain, DeFi, Web3 and crypto regulation.
NEWS_COINDESK · INFO
Crypto market makers are cashing in on bitcoin's rally - without betting on direction
As bitcoin surges back above $80,000, sophisticated trading firms are quietly collecting yield rather than making directional bet.
NEWS_COINTELEGRAPH · INFO
Russia’s Sber eyes USDT loans, questions digital ruble demand
Russia’s largest bank, Sber, plans to accept USDT and Ether alongside Bitcoin as loan collateral as the country introduces regulated crypto trading under a new law.
NEWS_COINTELEGRAPH · INFO
Real Trump Coins denies launching GOLD token, blames ‘bad actors’
Trump-linked Real Trump Coins said it never authorized GOLD or any digital token as questions persisted over its X account, associated domains and the concentrated token supply.
NEWS_THEHACKERNEWS · INFO
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique b
NVD · HIGH
CVE-2026-82478 · CVSS 7.3
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-based buffer overflow
NEWS_COINDESK · INFO
A $1.1 million crypto card hack crashed a neobank's token 49%
The exploit caused the neobank's AVICI token to drop 49% from a 24-hour high, hitting a record low before paring some of the losses.
NEWS_COINTELEGRAPH · INFO
Polygon discloses security flaws fixed in recent hard forks
The vulnerabilities posed denial-of-service and validator resource risks but were patched before Polygon publicly disclosed them.
NEWS_COINTELEGRAPH · INFO
Stellar tokenized RWA market more than quadruples to nearly $4B
Stellar’s real-world asset market has expanded rapidly this year as institutional adoption and tokenization activity grow across the network.
NVD · HIGH
CVE-2026-75807 · CVSS 7.5
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certific
NEWS_DECRYPT · INFO
Bernie Sanders Vows Legislation to 'Stop Flock and AI Mass Surveillance'
The Vermont senator warned that the surveillance company's 120,000-plus AI cameras are pushing the US toward a "surveillance state," adding a prominent voice to a growing bipartisan backlash.
NVD · HIGH
CVE-2026-82475 · CVSS 8.1
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.
NVD · HIGH
CVE-2026-82474 · CVSS 7.8
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.
NVD · HIGH
CVE-2026-82473 · CVSS 8.2
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade sche
NVD · HIGH
CVE-2026-82472 · CVSS 7.5
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document
NVD · HIGH
CVE-2026-82466 · CVSS 8.7
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credent
NVD · HIGH
CVE-2026-82463 · CVSS 8.1
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.
NVD · HIGH
CVE-2026-82461 · CVSS 8.1
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role
NEWS_COINTELEGRAPH · INFO
Tokenized stock transfer volume jumps 415% in 30 days to $29.5B
Tokenized equities saw a sharp rise in onchain activity as active addresses and holders more than doubled over the past month.
NEWS_THEHACKERNEWS · INFO
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patch
NEWS_DECRYPT · INFO
Bitcoin's Oldest Coins Are Waking Up in 2026 at a Pace Rarely Seen
Galaxy Research shows coins untouched for 10-plus years moving at an unusual pace in 2026, with six ancient wallets shifting $40 million in a single 10-day stretch this month.
NEWS_COINDESK · INFO
Inside the high-stakes battle between digital dollars and Swift's massive money engine
Crypto executives say new blockchain payment infrastructure could make Swift obsolete. Bankers say its 11,500-institution network gives it the power to absorb the technology instead.
NEWS_COINDESK · INFO
The next trillion-dollar currency may not be a stablecoin — it might not even have a name yet
AI agents are coming. They will need to pay each other. Crypto executives agree on the problem but disagree sharply on the solution, and one thinks the answer has not been invented yet.
NEWS_COINDESK · INFO
Ditching 'digital gold': BPI study suggests everyday Americans prefer control and micro-investing
A new survey suggests some of bitcoin's most familiar sales pitches of changing the world may be poorly suited to a majority of prospective buyers.
NVD · HIGH
CVE-2026-82457 · CVSS 7.8
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target pr

Don't wait for Q-Day.

QorTrace audits smart contracts, scans wallets for cryptographic exposure, and certifies post-quantum readiness. The strongest hands move first.

Get auditedSee pricing
GET STARTED IN 60s
Need to scope a PQC audit, scan a wallet, or pick a tier? I'll walk you through it in under a minute — with sources.