ETSI published Technical Report TR 104 171 on September 24, 2026, capturing a growing engineering paradox: quantum random number generators (QRNGs), promoted as a bulwark of post-quantum security, can produce statistically valid output that is operationally compromisable. The stakes are the integrity of the entire cryptographic chain that rests on this entropy: if the quantum source is indeterminate, the pipeline that turns it into cryptographic keys is not.
The report, led by Mark Pecen in his role as Chair of the ETSI Technical Committee Quantum, introduces the Entropy Zero Trust (EZT) framework. The guidance treats every stage of the entropy pipeline as untrusted without continuous verification, from physical generation to the consuming application.
- QRNGs can pass statistical randomness tests while delivering predictable patterns exploitable by an attacker with access to side-channel information.
- Artificial intelligence can accelerate the discovery of patterns caused by sensors, power supplies, or signal processors in the quantum device.
- ETSI defines three trust levels (TL-0, TL-2, TL-3) and five throughput classes in the EZT framework, with continuous monitoring requirements at a minimum frequency of 1 Hz.
- The July 2026 Coldcard case, with 594 BTC stolen due to a hardware RNG failure, demonstrates the concrete impact of compromised entropy on real cryptographic systems.
The Gap Between Quantum Indeterminacy and Classical Implementation
The promise of QRNGs rests on a solid physical principle: quantum mechanics generates intrinsically non-deterministic events. ETSI does not contest this foundation. What TR 104 171 documents is the gap between that foundation and its engineering realization. Sensors, analog-to-digital converters, power supplies, communication buses, and conditioning signal processors are all classical components, subject to correlations, systematic noise, and electromagnetic interference.
As Help Net Security's technical analysis of the report notes, "the numbers can appear random in statistical tests while providing clues to an attacker about future output." This is the central vulnerability: a NIST SP 800-90B or Dieharder test evaluates statistical distribution, not resistance to an adversary with side-channel observation capabilities. The output can be uniformly distributed and perfectly predictable at the same time, if physical correlations remain hidden from the test battery.
The ETSI report, cited by Quantum Computing Report, adds that "while the output may appear statistically random, an adversary with access to relevant side-channel information adds a layer of predictability." The threat is not theoretical: variations in power consumption and electromagnetic signals emitted by the device constitute concrete leak vectors, documented in the report as "RF electromagnetic interference, and power-analysis probing."
The AI Accelerant and Invisible Pattern Recognition
A distinctive element of the ETSI report is the explicit mention of artificial intelligence as a threat multiplier. According to Help Net Security, which expands on the technical mechanism of the leak, "AI can help an attacker identify patterns caused by the sensors, power supplies, or signal processors of a QRNG." Machine learning excels at finding weak correlations in high-dimensional signals, exactly the type of pattern that traditional statistical analysis may miss.
This shift is significant: until a few years ago, side-channel attacks on RNGs required highly specialized signal analysis expertise. AI lowers the barrier to entry, making automation of the pattern-discovery phase plausible. The report does not quantify the actual time or effort required for AI-assisted exploits on commercial QRNGs — this remains a documented limit of the dossier — but the principle of vulnerability is established.
Entropy Zero Trust: Verifying Every Stage of the Pipeline
The architectural response proposed by ETSI is the Entropy Zero Trust framework, which Quantum Computing Report describes as a system in which "every stage of the entropy pipeline is treated as untrusted and subject to continuous hardware verification, runtime attestation, and cryptographic signing." The name is intentional: it replicates the Zero Trust paradigm of network security, applying it to the entropy generation chain.
The framework defines granular classifications. Three trust levels: TL-0 for unverified raw sources, TL-2 for EZT-compliant platforms, TL-3 for critical and military grade. Five throughput classes, from Class I (up to 100,000 bits/s) to Class V (over 1 Gbit/s). Four power levels, from Class A (up to 100 mW) to Class D (2-10 W). This taxonomy allows mapping shielding, monitoring, and attestation requirements to the device's actual capabilities and criticality.
Specified side-channel defenses include optical isolators against blinding attacks, EMI shielding against electromagnetic interference, active power and voltage monitoring, and continuous statistical sampling at a minimum frequency of 1 Hz. For randomness extraction, the report recommends seeded Toeplitz hashing or multi-source extractors, techniques that distill entropy from multiple sources, reducing dependence on single points of failure.
"While quantum physics is adept at providing genuine unpredictability, secure randomness rests on the integrity of the entire implementation" — Mark Pecen, Chair ETSI TC Quantum
From the Coldcard Case to the Stakes for the PQC Transition
The ETSI report does not cite product-specific vulnerabilities in QRNGs, but the real-world impact context exists. In July 2026, a failure of the Coldcard wallet's hardware random number generator allowed the theft of 594 BTC, approximately $38 million at the exchange rate of the time. The bug, present in production for roughly 5.5 years, made the seed predictable from the serial number and system clock. Coldcard is not a QRNG: it is a classical hardware RNG. But the incident concretely demonstrates how compromised entropy invalidates the entire cryptographic security chain, regardless of the overlying algorithmic sophistication.
For PKI infrastructures and the post-quantum transition, this is the critical node. New cryptographic standards — ML-KEM for key exchange, ML-DSA for signatures — assume verifiable-quality entropy. A QRNG that passes statistical tests but leaks predictive information renders ML-KEM vulnerable to key recovery, just like a defective classical RNG. Post-quantum security, in other words, is only as robust as its entropy source.
Why It Matters
The ETSI dossier does not specify whether TL-3 certified QRNGs already exist, nor whether the EZT framework is implemented by commercial vendors or only proposed as a recommendation. TR 104 171 is a guidance technical report, not a binding normative standard: its adoption status remains unknown. The report also does not quantify the actual effort for AI-assisted exploits on real devices, nor document infrastructure overlaps between threat actors and specific QRNG vulnerabilities.
What the dossier establishes is an evaluation criterion: for QRNG buyers, comparison cannot be limited to throughput or price. Trust level, documented physical shielding, firmware and conditioning pipeline auditability, alignment with Common Criteria or FIPS 140-3 are necessary parameters. The future priorities indicated by ETSI — standardized APIs, logging protocols, regulatory alignment, explicit integration with PQC — suggest the ecosystem is still in a structuring phase.
The paradox remains: investing in QRNGs to resist quantum computing, without verifying the physical implementation, is like installing a blast door on a drywall partition. Quantum physics guarantees indeterminacy; electronic engineering determines whether that indeterminacy reaches the consumer intact.
Frequently Asked Questions
Are QRNGs insecure by definition?
No. The ETSI report recommends their use with rigorous implementation controls, not dismissal. The vulnerability concerns the gap between physical principle and engineering realization, not the principle itself.
Does AI "crack" quantum mechanics?
No. AI identifies classical patterns in implementation components — sensors, power supplies, signal processors — it does not violate quantum principles of indeterminacy.
Is the EZT framework already mandatory?
The dossier does not establish whether the framework is implemented by commercial vendors or only recommended. TR 104 171 has guidance status, not binding normative standard status.
Sources
- https://www.helpnetsecurity.com/2026/09/28/quantum-random-number-generator-qrng-guidance/
- https://quantumcomputingreport.com/etsi-identifies-technical-limitations-and-implementation-vulnerabilities-in-quantum-random-number-generators-etsi-tr-104-171/
- https://www.etsi.org/newsroom/press-releases/etsis-identifies-limitations-of-quantum-random-number-generators/
- https://thequantuminsider.com/2026/09/24/etsi-guidance-secure-quantum-random-number-generators/
- https://cryptoticker.io/en/coldcard-594-btc-drained-firmware-flaw/
- https://www.helpnetsecurity.com/2026/09/25/ariel-assaraf-coralogix-ai-agent-guardrails/
- https://www.etsi.org/