Lin Hsin Hsin Intelligence Center
Post-Quantum Cryptography
👑
The Hypocrisy of the Broken Quantum Throne
A Critique of Monolithic Worship
Post-Quantum Cryptography (PQC)
The global rush towards Post-Quantum Cryptography (PQC) is built on a foundational paradox: they are frantically reinforcing the digital sandcastle gates against a future quantum dragon, while the very drawbridge we stand on -- IBM’s Qiskit -- is already collapsing under the weight of its own negligence
The Broken Quantum study (April 2026) has exposed a devastating truth: the industry's monolithic worship of IBM’s ecosystem has created
A single point of failure that renders the
quantum future insecure before it even arrives
The Illusion of Security
Harvest Now, Decrypt Later
vs
Exploit Now, Crash Now
While governments and corporations panic over the Harvest Now, Decrypt Later threat, where adversaries store encrypted data to be broken by future quantum computer a far more immediate catastrophe is unfolding. The very tools used to design the quantum future are already broken.
📍 The PQC Delusion
The world is told to migrate to PQC algorithms, such as ML-DSA to survive the quantum era. Yet, independent researcher Lin Hsin Hsin (May 2025) asserted the risks of flawed PQC implementation, and yet the quantum computing world is rushing to implement security with untested, complex code that is failing today
📍 The Qiskit Reality
While the world is worried about 2030, CVE-2025-2000 (CVSS 9.8) allows arbitrary code execution right now via a malicious .qpy file in IBM Qiskit
The quantum scaffold is not only weak; it is actively hostile. As and when an attacker loads a circuit file that can inadvertently execute malware, compromising the entire system.
This is not a FUTURE risk; it is an EXISTING exploit
The Monopoly of Negligence
One Vendor, Global Collapse
The quantum software ecosystem has fallen into a dangerous monoculture. IBM Qiskit is not just a participant; it is the de facto standard. This dominance has created a supply chain where a single vendor’s negligence cascades globally
📍 Silent Propagation to National Security
The most damning evidence of this hypocrisy is XACC, the framework used by Oak Ridge National Laboratory and other US DOE labs. XACC vendored the entire vulnerable C++ codebase of
Qiskit Aer Consequently, 5 CRITICAL memory corruption flaws (QAI-001 to QAI-005) found in IBM's commercial code are silently present in US national security infrastructure. A vulnerability in a corporate product is now a vulnerability in the nation’s quantum defense
📍 The "Broken" Scorecard
The independent Broken Quantum study gave Qiskit Aer a security score of 0/100. It is not merely flawed it is broken. Yet, the industry continues to build upon it, treating it as a gold standard. This is not innovation; it is collective negligence
The C++ Abyss: Speed Over Safety
The root of this hypocrisy lies in the architectural choice to prioritize simulation speed over memory safety.
📍 The 32-Qubit Cliff
In the pursuit of performance, Qiskit Aer (and its clones) uses unchecked C++ array accesses and integer shifts. At 32 qubits, a shift operation overflows, causing undefined behavior. At 64 qubits, an out-of-bounds read corrupts the heap. These are not edge cases; they are fundamental limits of the current architecture
📍 The Hypocrisy of Quantum Safe
How can an industry claim to be building "quantum-safe" cryptography when the simulation tools used to test these algorithms crash or allow remote code execution at modest qubit counts? The foundation is rotting. You cannot build a secure future on a simulator that fails when asked to simulate a moderately complex system
The Verdict: A Crisis of Trust
The narrative that "Quantum is coming, so we must migrate to PQC" is a distraction & destruction from the immediate crisis: The Quantum Software Stack is already compromised.
📍 Zero Cryptographic Security
Zero Cryptographic Security in the Stack
The tools used to design quantum algorithms lack basic memory safety. If the simulator can be crashed or hijacked, the algorithm it validates is suspect.
📍 Supply Chain Contamination & Condemnation
The reliance on a single vendor (IBM) has contaminated the entire ecosystem, from startups to national labs. The "monolithic worship" of Qiskit has blinded the community to alternative, more secure architectures
📍 The PQC Irony
We are rushing to fix a future cryptographic break while ignoring a present-day software break. The irony is palpable: we are deploying complex, untested PQC code on top of a quantum stack that cannot even safely manage its own memory
Conclusion
The world says Ahhh when quantum arrives, but it should be screaming
STOP!
🛑
The emperor has no clothes. The monstrous scaffolding of Qiskit
is not a platform for the future,
it is a liability of the present
Until the industry diversifies its stack, enforces memory safety in C++ backends, and acknowledges that speed without security is suicide, the reign of quantum computing will be a reign of chaos. The hypocrisy lies in promising a secure quantum future while delivering a broken quantum present