Megatrend · Quantum Computing
The secret that "instantly knows" someone is listening in
Almost every security system in the world relies on math that's too hard to crack. But there's another idea that sidesteps the math entirely — you send the secret key on a "single photon," and if anyone tries to read it in transit, the particle gets disturbed and you can detect it instantly. The security comes from the laws of physics, not from a hard-to-guess code. This is Quantum Key Distribution (QKD) and quantum networking — real, but still expensive, distance-limited, and for now more of a battlefield for states than a mass market.
01What it is
Picture mailing your house key to a friend. The classic problem: somewhere along the way, someone could secretly open the envelope, copy the key, then seal it back up and send it on — and neither you nor your friend would ever know it had been copied. Today we solve this with very hard math (codes that would take millions of years of computation to crack). But "hard" isn't the same as "impossible."
Quantum Networking & QKD offers a completely different answer: instead of hoping the thief can't crack the code, you send the key in the form of a single photon, where the laws of quantum mechanics guarantee that anyone who secretly measures it changes its state and always leaves a trace. The result: if there's an eavesdropper, the sender and receiver can detect it and throw that batch of key away before ever using it.
"QKD" stands for Quantum Key Distribution. It doesn't encrypt the message itself — its job is to "hand off the secret key" to two parties so securely that you can be sure no one snooped. After that, you just encrypt your data with that key as usual. "Quantum Networking" is the bigger picture — laying down the infrastructure (fiber, satellites, repeaters) to send quantum states across long distances, with the ultimate destination being the dream called the "quantum internet."
A fundamental quantum rule that says you cannot make a perfect copy of an unknown quantum state. This is why QKD is secure — a thief can't "quietly copy the key and pass it on," because secretly measuring it changes the particle, and a perfect copy is something physics forbids from the start.
On the megatrend map, this node sits under Quantum Computing. Its definition is straightforward: "quantum key distribution, repeaters, quantum-internet infrastructure — still early, mostly private." Let's stress that phrase "still early" from the outset, because it's the core of this whole chapter's story.
02Why it matters — two answers to "Q-Day"
The reason people are talking about QKD now comes from a threat called "Q-Day" — the day a quantum computer is powerful enough to crack the codes protecting the entire internet (the RSA/ECC-style codes that underpin banks, email, digital signatures). The scarier threat is "harvest now, decrypt later" — an adversary intercepts encrypted data today, stockpiles it, and waits for the day quantum is ready to decrypt it. So secrets that must stay hidden for 10–20 years (state secrets, medical records) are "already unsafe right now," even though Q-Day hasn't arrived.
The world has two answers to this threat, and they're competing:
- The "software/math" answer — PQC: switch to new mathematical formulas that even a quantum computer can't crack. It's a software update, fits on any device, and is cheap — this is Quantum-Safe / Post-Quantum Cryptography (PQC), and in the broader cybersecurity frame, Post-Quantum & Cryptographic Trust
- The "physics/hardware" answer — QKD: relies on no math at all, but on laws of physics where you can't eavesdrop without getting caught — this is the node we're in
Here's the point to state plainly: for most of the world's use cases, PQC will probably win — because it's cheap, deploys instantly as software, and can do digital signatures (which QKD can't). World-class security agencies like the U.S. NSA and the U.K. NCSC both advise against relying on QKD for national-security systems, reasoning that PQC is "more cost-effective and easier to maintain." QKD, by contrast, requires dedicated hardware, special cabling, and is distance-limited.
The market size reflects this reality clearly — the entire global QKD market in 2025 is worth only about $0.5–0.6 billion, tiny next to the hundreds-of-billions cybersecurity market. Even though it's expected to grow fast (CAGR ~33%) to ~$2.5 billion by 2030, it's still a "tiny island" in the ocean of encryption.
03How it works (the QKD mechanism)
The heart of QKD is a protocol called BB84 (devised in 1984 by Bennett & Brassard). Let's walk through it step by step — you don't need deep physics, just grab the main idea.
The sender (called Alice by convention) fires single photons, one at a time, toward the receiver (Bob). Each one is randomly "rotated" (polarized) at different angles to represent a 0 or a 1. The key point: to read the particle's value correctly, you have to measure it with the "right angle." Measure at the wrong angle and the value you get is random — and the particle has already had its state changed.
This is exactly the trap for the thief (Eve) — if Eve secretly measures the particles in transit, she has to guess the angle, and she guesses wrong about half the time. Every time she guesses wrong, she unintentionally disturbs that particle. In the end, when Alice and Bob compare a sample of the key, they find an abnormally high "error rate" = a signal someone is eavesdropping → throw that batch of key out and start over. The security comes not from a "hard code," but from the act of eavesdropping itself, which always leaves a trace.
All of this sounds beautiful, but there's a big engineering catch: a single photon can't travel far. The farther it goes, the higher the chance it "vanishes" in the fiber. And because of no-cloning, you can't "amplify the signal" like an ordinary repeater (amplifying = copying = against the rules). In practice, QKD over fiber reaches about 100–200 km per segment before the signal gets too weak.
Today's fix for distance is to set up a "relay station" every ~100 km that extracts the key and passes it on — but these points have to be "trusted", because there, for a moment, the key exists in plain form. If someone controls the station, they can see the key. This is the big weakness of today's QKD networks, and the reason everyone is waiting for the next technology, the "quantum repeater," which can relay without extracting the key (still in the lab).
04Where it sits in the quantum world
This node is one of the sub-branches of Quantum Computing, but it has a clearly different personality from its siblings — while the other branches try to "build a quantum computer that can compute," this node is mainly interested in "sending quantum information across places." So it's both a tool to defend against quantum threats and an infrastructure that may one day link multiple quantum computers together.
The most important link is with the security side:
- Rival/partner with PQC: QKD and Quantum-Safe / PQC are two answers to the same threat — the physics camp vs the math camp. Some jobs pick one or the other, some use them layered together
- Feeds into Cybersecurity & Digital Trust: both QKD and PQC are pieces of a bigger story — "digital trust" in an era when quantum shakes the foundations of encryption. The crypto-specific dimension sits at Post-Quantum & Cryptographic Trust
- Underpins AI and data centers: over the long run, the most secure link between critical data centers is one of the places QKD makes the most business sense
Another dimension you can't overlook is space — because distance on the ground is limited, firing photons through the "vacuum of space" (where the signal is lost less than in fiber) becomes a shortcut across continents. This part overlaps with the space trend, and is the source of the field's most famous feat — which we'll tell in the next chapter.
05Where things stand now + who's playing
The story of QKD today is dominated by one country: China. In 2017, China built a ~2,000 km Beijing–Shanghai quantum-communication backbone over fiber, with 30+ "trusted nodes" lined up every ~100 km. That same year it launched the world's first quantum satellite, Micius (墨子), to fire photons down and link ground stations on opposite sides of the country.
The numbers tell the ambition clearly: in 2021, China combined the fiber backbone with the Micius satellite link into the world's first ground-to-space network, covering ~4,600 km, and used Micius as a relay to send keys between points up to ~7,600 km apart. Today the networks linking cities across China are talked about at the scale of ~12,000 km. No other country comes close to this scale.
Outside China, progress on the private/Western side comes from a handful of specialists. The standout is Toshiba, which has set record after record for QKD over standard telecom fiber (reaching ~254 km in a 2025 experiment in Germany, using room-temperature equipment that needs no cooling), and has begun trials on real commercial fiber networks in the U.S. The commercial pioneer ID Quantique of Switzerland (which IonQ took a major stake in during 2025, alongside a partnership with SK Telecom) is another pillar.
But let's keep the big picture straight: most of the real players are still states and private companies that aren't on the stock market — universities, national labs, and startups still raising private capital. So pure-play listed companies on QKD are genuinely hard to find. Below are the main players who tell this story best:
06The future: toward a "quantum internet"
The first direction is a real "quantum internet" — a dream far bigger than QKD. Not just sending keys, but sending full "quantum states" to link multiple quantum computers together and connect quantum sensors to make them more precise. Its heart is a phenomenon called "entanglement" and a technique for relaying it across distance called entanglement swapping. Teams like QuTech (Netherlands) demonstrated three-node entanglement across separate labs back in 2021, and Harvard/MIT have experimented with quantum memory in diamond — but all of it is still lab-level research, not a product.
The second direction is the quantum repeater — the key that would unlock distance without relying on the weak "trusted node." If it succeeds commercially, it would turn QKD from a "network you have to trust the relay stations of" into a "truly end-to-end secure network." But it's still a fair way from real-world use.
The third direction is state- and satellite-level infrastructure. The EU is building EuroQCI — a quantum-communication network across 27 countries, both terrestrial fiber and space, with a prototype satellite, Eagle-1, set to launch in late 2026. It's a sign that Western governments haven't abandoned QKD, but are investing to "lay the groundwork for the future" rather than rushing it to mass use.
07Challenges & risks
This is the node where you have to tell the risks most plainly, because its appeal as physics comes with constraints just as heavy.
The first risk is that "PQC may win for most use cases." As long as post-quantum math deploys as software on any device, cheaply, and can do digital signatures (something QKD can't), the mass market has almost no reason to invest in expensive QKD hardware — and when the NSA and NCSC say "not recommended yet," that's a strong market signal.
The second risk is the stubborn physical constraints — the ~100–200 km per-segment distance, the need to lay dedicated fiber or launch satellites, the "trusted node" that's still a security weakness, and the quantum repeater that would fix these but is still in the lab. So progress is tied to research that's hard to predict.
The third risk is being "niche + state-led." The whole global market is still <$1 billion, and the big investment comes from states (China, EuroQCI) doing it for reasons of security and technological sovereignty rather than commercial returns. Pure-play listed QKD companies are few and small (the case of Arqit, with ~$0.5 million in revenue and forced to pivot, is a blunt reflection of this) — for investors, this is a "long-term/speculative-possibility" theme, not a business making money today.