Blog

Harvest Now, Decrypt Later: The Silent Attack Already Targeting Defense Infrastructure

Somewhere right now, an adversary could be recording your encrypted network traffic. Not to read it today. But to store it, waiting for the moment quantum computing makes today’s encryption obsolete. When that moment comes, the data they captured years ago becomes an open book. This is a “harvest now, decrypt later” (HNDL) attack — and it’s not a theoretical future threat. It’s happening now, targeting defense infrastructure, government communications, and critical systems around the world.

The uncomfortable truth is that most organizations are already compromised in this sense. They just don’t know it yet. Understanding what HNDL attacks are, why defense networks are prime targets, and what post-quantum encryption actually demands from your infrastructure is the first step toward closing that exposure window before it’s too late.

What is a harvest now, decrypt later attack?

A harvest now, decrypt later attack is exactly what it sounds like. An adversary intercepts and stores encrypted data today with no intention of decrypting it immediately. They wait until they have access to a quantum computer powerful enough to break the encryption protecting that data. At that point, everything they collected becomes readable.

The attack exploits a fundamental asymmetry in time. Data captured right now may still be sensitive in five, ten, or twenty years. Intelligence reports, weapons specifications, diplomatic communications, personnel records — none of these expire quickly. Current encryption standards like RSA and elliptic curve cryptography (ECC) hold up fine against classical computers, but they’re mathematically vulnerable to sufficiently powerful quantum computers running Shor’s algorithm. Adversaries with long-term strategic interests don’t need to break encryption today. They just need to collect the ciphertext and wait.

Why defense infrastructure is already in the crosshairs

Defense and government networks are the highest-value targets for HNDL attacks precisely because their data has the longest shelf life. A classified communication intercepted today may still carry operational or strategic value a decade from now. Nation-state adversaries with the resources to build quantum computing programs also have the patience and infrastructure to run large-scale collection operations.

This isn’t speculation. Intelligence agencies and cybersecurity researchers have documented sustained, systematic efforts by state-sponsored actors to intercept and archive encrypted government and military traffic. The January 2027 deadline under CNSA 2.0 (Commercial National Security Algorithm Suite 2.0) — which requires post-quantum cryptography (PQC) for all US national security systems — exists because policymakers already know the collection is underway. NIST finalized its PQC standards in August 2024. Procurement has started. The window to act is narrowing fast.

How legacy VPNs and network tools make the problem worse

Traditional VPNs and legacy network infrastructure were never designed with quantum threats in mind. They rely on classical key exchange protocols — typically RSA or Diffie-Hellman — that a sufficiently powerful quantum computer can solve mathematically. Every session key negotiated over these protocols is a potential future liability if the handshake was recorded.

The problem compounds with complexity. Legacy environments often layer multiple tools together: hardware firewalls, software VPN concentrators, separate management planes, fragmented monitoring systems. Each layer adds more attack surface and more encrypted traffic for adversaries to harvest. Worse, many of these systems are difficult to update or replace. They were built for a threat model that assumed classical computing would remain the ceiling. That assumption no longer holds. Patching a VPN client doesn’t fix the underlying cryptographic architecture. You need to replace the foundation, not the wallpaper.

What post-quantum cryptography actually requires from your network

Post-quantum cryptography isn’t a single algorithm you swap in. It’s a new cryptographic baseline that demands changes at the transport layer, the key exchange layer, and the identity layer of your network architecture. NIST’s finalized PQC standards center on algorithms like ML-KEM (Module Lattice Key Encapsulation Mechanism), designed to resist attacks from both classical and quantum computers.

Implementing PQC correctly requires hybrid cryptography during the transition period. Running both a classical algorithm and a PQC algorithm simultaneously means security holds even if one is later found to have weaknesses. This isn’t optional belt-and-suspenders thinking — it’s the approach mandated by CNSA 2.0 and recommended by NIST for any system handling sensitive data. Beyond the algorithms themselves, PQC requires cryptographic identity at every node, not just at the perimeter. Every endpoint, every controller, every packet needs to carry a verifiable, quantum-resistant identity. That’s a fundamentally different architecture from what most legacy networks provide.

How software-defined networking closes the HNDL exposure window

Software-defined networking (SDN) separates the control plane — the logic that decides how traffic flows — from the data plane, which handles the actual movement of packets. This separation makes it possible to update cryptographic policies, rotate keys, and enforce new identity requirements across an entire network without touching physical hardware.

For HNDL defense, that matters enormously. A software-defined overlay network — a private network built on top of the public internet using encrypted tunnels — can embed post-quantum cryptography directly into the transport layer, applying it to every packet in transit rather than just at entry and exit points. It can enforce cryptographic identity per node, making it impossible for an intercepted packet to be attributed to a legitimate session without the corresponding private key. And because the control plane is software, it can be updated as PQC standards evolve, without ripping out hardware or redeploying physical infrastructure. The architecture anticipates change rather than reacting to it.

Steps to harden your network against quantum-era threats today

Hardening against HNDL attacks isn’t a single project. It’s a phased transition that starts with visibility and ends with a fully post-quantum cryptographic architecture. Here’s where to begin.

First, inventory your cryptographic exposure. Identify every system transmitting sensitive data over encrypted channels and document the algorithms in use. This is sometimes called a CBOM (Cryptographic Bill of Materials). You can’t fix what you can’t see.

Second, prioritize your highest-value data flows. Not everything needs to migrate at once. Start with communications carrying the longest-lived sensitive data: classified traffic, personnel records, infrastructure control signals, anything touching national security systems.

Third, move toward hybrid cryptography on those priority paths. Running classical and PQC encryption together protects data in transit today while building toward full PQC compliance. Fourth, replace perimeter-based security models with zero trust — a model that verifies every device and user continuously rather than assuming anything inside the network boundary is safe — and cryptographic identity at every node. Perimeter security assumes the inside is clean. It isn’t. Fifth, plan for agility. The PQC landscape will keep evolving through the late 2020s and into the 2030s. Your network architecture needs to update cryptographic primitives without full redeployment.

How ZeroTier Quantum addresses HNDL threats

ZeroTier Quantum is the only software-defined, end-to-end quantum-secure networking platform on the market. It was built specifically to address the challenges described above, including direct protection against harvest now, decrypt later attacks. Here’s what that looks like in practice:

  • Hybrid post-quantum cryptography at the transport layer: ZeroTier Quantum introduces the ZeroTier Transport Protocol (ZTP), which embeds hybrid FIPS-140-compliant PQC directly into every packet, meeting NIST and NSA CNSA 2.0 standards with ML-KEM 1024-bit key encryption.
  • Cryptographic identity per node: Every endpoint, controller, and device carries a globally unique cryptographic identity with mutual authentication. There’s no implicit trust anywhere in the network.
  • Zero trust enforcement without perimeter dependency: Local policy enforcement removes reliance on a central chokepoint. Security is enforced at every node, not just at the edge.
  • Flexible deployment for sensitive environments: ZeroTier Quantum runs in SaaS cloud, sovereign-gapped, or fully air-gapped configurations, making it viable for defense, government, and regulated industries that can’t route traffic through third-party infrastructure.
  • Built in memory-safe Rust with an API-first design: The platform integrates into existing infrastructure without requiring hardware replacement or a full network redesign.

The CNSA 2.0 deadline is January 2027. EU NIS2 and NIST’s Cybersecurity Framework (CSF) 2.0 are already applying auditor pressure across critical sectors. The time to start is now — not when the quantum computer arrives. If your network is still running classical cryptography on sensitive traffic, the harvest is already underway. Talk to the ZeroTier team about how ZeroTier Quantum can close your HNDL exposure window before the decryption era begins.

Related Articles

Sign up for our newsletter

Don’t miss an update. Sign up to receive occasional networking content and news.

By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it’s awesome!

Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.