Lin Hsin Hsin Intelligence Center
Post-Quantum Cryptography
👑







The Hypocrisy of the Broken Quantum Throne
A Critique of Monolithic Worship







Post-Quantum Cryptography (PQC)


The global rush towards Post-Quantum Cryptography (PQC) is built on a foundational paradox: they are frantically reinforcing the digital sandcastle gates against a future quantum dragon, while the very drawbridge we stand on -- IBM’s Qiskit -- is already collapsing under the weight of its own negligence

The Broken Quantum study (April 2026) has exposed a devastating truth: the industry's monolithic worship of IBM’s ecosystem has created


A single point of failure that renders the
quantum future insecure before it even arrives




The Illusion of Security


Harvest Now, Decrypt Later
vs
Exploit Now, Crash Now



While governments and corporations panic over the Harvest Now, Decrypt Later threat, where adversaries store encrypted data to be broken by future quantum computer a far more immediate catastrophe is unfolding. The very tools used to design the quantum future are already broken.


📍 The PQC Delusion

The world is told to migrate to PQC algorithms, such as ML-DSA to survive the quantum era. Yet, independent researcher Lin Hsin Hsin (May 2025) asserted the risks of flawed PQC implementation, and yet the quantum computing world is rushing to implement security with untested, complex code that is failing today


📍 The Qiskit Reality

While the world is worried about 2030, CVE-2025-2000 (CVSS 9.8) allows arbitrary code execution right now via a malicious .qpy file in IBM Qiskit The quantum scaffold is not only weak; it is actively hostile. As and when an attacker loads a circuit file that can inadvertently execute malware, compromising the entire system.


This is not a FUTURE risk; it is an EXISTING exploit




The Monopoly of Negligence



One Vendor, Global Collapse


The quantum software ecosystem has fallen into a dangerous monoculture. IBM Qiskit is not just a participant; it is the de facto standard. This dominance has created a supply chain where a single vendor’s negligence cascades globally


📍 Silent Propagation to National Security


The most damning evidence of this hypocrisy is XACC, the framework used by Oak Ridge National Laboratory and other US DOE labs. XACC vendored the entire vulnerable C++ codebase of Qiskit Aer Consequently, 5 CRITICAL memory corruption flaws (QAI-001 to QAI-005) found in IBM's commercial code are silently present in US national security infrastructure. A vulnerability in a corporate product is now a vulnerability in the nation’s quantum defense


📍 The "Broken" Scorecard


The independent Broken Quantum study gave Qiskit Aer a security score of 0/100. It is not merely flawed it is broken. Yet, the industry continues to build upon it, treating it as a gold standard. This is not innovation; it is collective negligence



The C++ Abyss: Speed Over Safety


The root of this hypocrisy lies in the architectural choice to prioritize simulation speed over memory safety.



📍 The 32-Qubit Cliff


In the pursuit of performance, Qiskit Aer (and its clones) uses unchecked C++ array accesses and integer shifts. At 32 qubits, a shift operation overflows, causing undefined behavior. At 64 qubits, an out-of-bounds read corrupts the heap. These are not edge cases; they are fundamental limits of the current architecture


📍 The Hypocrisy of Quantum Safe


How can an industry claim to be building "quantum-safe" cryptography when the simulation tools used to test these algorithms crash or allow remote code execution at modest qubit counts? The foundation is rotting. You cannot build a secure future on a simulator that fails when asked to simulate a moderately complex system


The Verdict: A Crisis of Trust


The narrative that "Quantum is coming, so we must migrate to PQC" is a distraction & destruction from the immediate crisis: The Quantum Software Stack is already compromised.


📍 Zero Cryptographic Security


Zero Cryptographic Security in the Stack



The tools used to design quantum algorithms lack basic memory safety. If the simulator can be crashed or hijacked, the algorithm it validates is suspect.


📍 Supply Chain Contamination & Condemnation


The reliance on a single vendor (IBM) has contaminated the entire ecosystem, from startups to national labs. The "monolithic worship" of Qiskit has blinded the community to alternative, more secure architectures


📍 The PQC Irony


We are rushing to fix a future cryptographic break while ignoring a present-day software break. The irony is palpable: we are deploying complex, untested PQC code on top of a quantum stack that cannot even safely manage its own memory


Conclusion


The world says Ahhh when quantum arrives, but it should be screaming

STOP! 🛑


The emperor has no clothes. The monstrous scaffolding of Qiskit


is not a platform for the future,
it is a liability of the present


Until the industry diversifies its stack, enforces memory safety in C++ backends, and acknowledges that speed without security is suicide, the reign of quantum computing will be a reign of chaos. The hypocrisy lies in promising a secure quantum future while delivering a broken quantum present