Carr Digital

Analysis · July 31, 2026

The load-bearing word

Two claims made the rounds this month: 'post-quantum cracked' and 'qubits can be cloned.' Both anchor to real papers by serious people. Both are false as stated, and in each case the distance between true and false is exactly one word.

Two claims crossed my feeds this month. “AI cracks post-quantum cryptography.” “Qubits can be cloned.” Each one anchors to a real paper by serious people. Each one is false as stated. And in both cases, the distance between true and false is exactly one word.

This is a short field guide to finding that word before it costs you a bad decision, or an afternoon calming down a steering committee.

Exhibit one: qubits were not cloned

The no-cloning theorem says you cannot make an independent copy of an unknown quantum state. It is not an engineering limitation waiting on better hardware. It is a theorem, a short linearity argument, and it is load-bearing for most of quantum information science: it is the reason quantum key distribution can promise eavesdropper detection, and the reason backing up a quantum computer’s state is famously impossible.

So a headline announcing that qubits can be cloned is announcing that a theorem failed. Theorems don’t do that.

Here is what actually happened. Koji Yamaguchi and Achim Kempf at the University of Waterloo published a result in Physical Review Letters this January, and the paper’s own title carries the entire story: Encrypted Qubits Can Be Cloned. If you encrypt a qubit, you can make as many copies of the ciphertext as you like. The catch, and the reason the theorem survives, is in the decryption: using the key on any one copy permanently expires it for all the others. The abstract states it plainly: “only one decryption is possible, in agreement with the no-cloning theorem.”

Count what is actually recoverable and it is still exactly one qubit. Always was. What the construction buys you is resilience against loss: you can park encrypted copies of a quantum state in several places, lose some of them, and still recover the state from a survivor. It is backup in the sense of RAID, if reading one disk shredded the rest of the array. For future quantum memories and quantum networks, that is genuinely new and genuinely useful. Storage redundancy for quantum information was thought to be off the table entirely.

What it does not do: violate the theorem (the authors say so in the abstract), break quantum key distribution (the construction plays by quantum mechanics’ rules, it doesn’t bend them), or touch post-quantum cryptography in any way. PQC is classical math running on classical computers to resist a future quantum attacker. Nothing in ML-KEM, ML-DSA, or SLH-DSA cares how qubits are stored.

Here’s the part I find instructive. The Quantum Insider’s headline actually keeps the word: “Encrypted Qubits Can Be Cloned: Scientists Discover First Method to Safely Back Up Quantum Information.” The journalist did the job. But look at the article’s URL: qubits-can-be-cloned-scientists-discover-first-method.... The slug dropped it. And a link’s slug is what survives in a chat message, a feed preview, a forwarded email. By the time the claim reached me it was “qubits can be cloned,” no qualifier attached. The word made it through the journalism and died in transit.

Exhibit two: post-quantum was not cracked

I wrote up the HAWK story in detail yesterday, so the short version: an AI model found a real, structural attack on a signature scheme called HAWK, and the scheme’s designers withdrew it from NIST’s ongoing competition the next day. The headlines said post-quantum cryptography was cracked. HAWK was a candidate. It was competing for future standardization; it was not deployed anywhere, and the finalized standards rest on different math the attack does not touch, which the researchers who found the attack said themselves in the disclosure.

One word again. “AI breaks post-quantum candidate” is true and important. “AI breaks post-quantum cryptography” is false and viral. The entire difference fits in nine letters.

That same disclosure carried a third example as a bonus: an improved attack on AES-128 reduced to 7 of its 10 rounds. “Reduced-round” is how cryptanalysts measure a cipher’s safety margin, like picking a lock after agreeing to remove three of its ten pins. Strip the qualifier and you get “AI attacks AES,” which spent a news cycle scaring people about the algorithm that encrypts approximately everything.

Why the word falls off

Mostly it isn’t malice. It’s compression. A claim passes from paper title to headline to URL slug to social card to someone’s two-line paraphrase in a group chat, and every hop shortens it. The qualifier is the first thing to go, because the qualifier is the boring part. It is also the part that states what the result actually covers: a candidate scheme, an encrypted state, a reduced-round cipher, a lab prototype at forty millikelvin. The limiting word and the exciting word are never the same word, and the funnel selects for excitement.

Both papers this month were sober, careful work. Both teams stated the limits of their own results in the first place you’d look, the title or the opening of the abstract. The gap didn’t open between the scientists and the truth. It opened between the paper and the paraphrase.

The sixty-second check

When a scary crypto headline lands in your feed, before it lands in your incident channel:

  1. Find the primary source and read its title. Not the coverage, the paper. In both cases this month, the dropped word was sitting in the paper’s own title. This step alone resolves most of them.
  2. Find the population. What does the result actually cover? A standard, or a candidate? Deployed systems, or a lab setup? The full cipher, or a weakened variant built specifically for margin-testing?
  3. Ask what changes on Monday. If the honest answer is “nothing I operate is affected,” you have read entertainment, not intelligence. That’s allowed, but file it accordingly.
  4. Check the authors’ own caveats. Serious work states its limits plainly. If the paper says “in agreement with the no-cloning theorem” and the retelling says the theorem fell, you know exactly where the signal was lost.

None of this requires being a cryptographer. It requires one click past the headline and sixty seconds of reading the least exciting sentence on the page. In my own writing I make that sentence mandatory: every claim gets labeled as measured by me, cited to a primary source, or explicitly speculative. The labels are dull. Dull is the point. The load-bearing word is always the dull one.

Provenance

Every claim above about the two results is Reported: it comes from the linked primary sources, read on 2026-07-31, not from headlines or memory. The HAWK numbers and sourcing are in the previous article, which links the original disclosure and the NIST forum thread. If I got something wrong, email the studio and I’ll correct it here, with a note saying what changed.

Sources