Back to News

An Indian Government Body Just Co-Led a ₹200 Crore Funding Round — for a Cyberattack That Doesn't Fully Exist Yet

T
Author
Tarun Punde
Published
September 15, 2026
Reading Time
6 MIN READ
Spread the Word
An Indian Government Body Just Co-Led a ₹200 Crore Funding Round — for a Cyberattack That Doesn't Fully Exist Yet
QNu Labs raised ₹200 Cr, co-led by India's National Quantum Mission, to defend against quantum computers powerful enough to break encryption. Bengaluru-based QNu Labs just raised ₹200 crore to protect against an attack that quantum computers capable of actually pulling off don't fully exist yet. Half the people writing that check work for the Indian government.

What actually happened

QNu Labs, a deep-tech cybersecurity company incubated at IIT Madras in 2016, raised ₹200 crore in a Series A1 round co-led by India's National Quantum Mission and Speciale Invest, with Sony Innovation Fund, Gaja Capital, and Artha Ventures also participating. The round takes QNu Labs' total capital raised to ₹375 crore. Roughly 80% of this round came from investors new to the company, which its CEO pointed to as a signal that global conviction in quantum-safe security is building rather than staying a niche, government-only concern. The company builds quantum key distribution and other quantum-resistant cryptography products, already deployed across Indian government agencies, critical infrastructure, and banking and financial services clients, with a team of roughly 160 engineers, physicists, and mathematicians. Part of the new capital will go toward QNu's contribution to a government-funded project building the technology backbone for India's Quantum Secure and Sensing Networks. EntrackrBusiness Standard 

Why a threat that doesn't fully exist yet is getting funded now

The urgency here isn't about quantum computers that can break encryption today — those don't exist at usable scale yet. It's about a specific, already-active attack pattern known as "harvest now, decrypt later": adversaries intercept and store encrypted data today, betting that a sufficiently powerful quantum computer will exist within the data's useful lifetime to decrypt it retroactively. For data that needs to stay confidential for years — government records, financial histories, critical infrastructure controls — that bet is worth defending against well before the quantum computer actually arrives, not after.India's National Quantum Mission has set an aggressive 2029 timeline for the country's transition to quantum-safe infrastructure — meaning the funding push isn't speculative long-term R&D betting, it's tied to an actual government deadline that's roughly three years out.India isn't setting that pace in isolation, either. The US National Institute of Standards and Technology has set its own official deadline: RSA, ECDSA, EdDSA, DH, and ECDH — the encryption algorithms underpinning most of today's internet security — are to be deprecated by 2030 and completely disallowed by 2035, with some analysts estimating state actors could possess working quantum-decryption capability as early as 2028. Seen against that backdrop, QNu Labs' funding isn't a company getting ahead of a distant, hypothetical timeline — it's a race that multiple governments have already put a hard date on, and India's 2029 target sits inside the same narrow window the rest of the world is racing toward. YourStory  The Quantum Insider 

Who else is racing in the same space

QNu Labs isn't the only quantum-safe cybersecurity company pulling in fresh capital right now — Canberra-based QuintessenceLabs, which builds quantum random number generators and data access control software, raised $25 million in a Series B round led by Main Sequence and TELUS Ventures around the same period, with backing from Mizuho-linked investors.
That parallel raise matters for how QNu's round should be read: this isn't one Indian company getting ahead of a distant, theoretical risk on its own — it's part of a wider pattern of capital moving into quantum-safe infrastructure across multiple countries at roughly the same time, each backed by domestic strategic interest rather than a single company's sales pitch. What sets QNu's round apart within that pattern is the direct government co-investment, rather than purely  private-market backing. 
TechCrunch

Post image

Why it matters

What makes this round unusual isn't the cybersecurity pitch — it's who's writing part of the check. Most government involvement in critical-infrastructure security shows up as regulation, procurement contracts, or grants; here, the National Quantum Mission is directly co-leading a private equity round alongside venture investors, treating quantum-safe migration as a strategic capability worth owning a stake in rather than just mandating. That's a meaningfully different posture than most countries have taken toward quantum-security preparedness so far, and it puts India in a position to export sovereign quantum-safe technology rather than import it once global demand catches up to the threat. With the same AI systems now accelerating cryptographic research on both the offense and defense side, the pressure to move early on "harvest now, decrypt later" risk is compounding faster than most enterprises are currently planning for. Business Standard

If a government is already co-investing in quantum-safe defenses for a threat that's still years from being technically real, how many enterprises holding decades-sensitive data are still treating quantum migration as someone else's problem?


FAQ

What does QNu Labs actually build? Quantum-safe cybersecurity products, including quantum key distribution (QKD) and other cryptographic technologies designed to protect data against both current threats and future quantum-computing-capable attacks.

How much did QNu Labs raise, and from whom? ₹200 crore in a Series A1 round, co-led by India's National Quantum Mission and Speciale Invest, with Sony Innovation Fund, Gaja Capital, and Artha Ventures also participating. Total capital raised to date is ₹375 crore.

What is "harvest now, decrypt later"? An attack pattern where adversaries collect and store encrypted data today, betting they'll be able to decrypt it once quantum computers become powerful enough — making long-lived sensitive data vulnerable even before quantum-breaking computers exist.

Why is an Indian government body co-leading a startup funding round? India's National Quantum Mission has set a 2029 target for national quantum-safe infrastructure migration, and is treating investment in domestic quantum-security capability as a strategic priority rather than only a regulatory one.

Is India's 2029 deadline unusual globally? No — it lines up with a broader global push. The US NIST has set 2030 as the deadline to deprecate current encryption algorithms (RSA, ECDSA, and others) and 2035 for full disallowance, with some analysts estimating state actors could have working quantum-decryption capability as early as 2028.

Tarun Punde

Tarun Punde

B.Tech AIADS@ Shri Balaji Institute of Technology & Management

I write at Metaplugs — breaking down the latest in tech, economics, and business into simple, impactful stories for everyday readers. Passionate about software testing and global finance.