Standards sold as quantum-proof derive their credibility from the physics and their real attack surface from the ordinary software that wraps the physics. The arXiv paper Beyond the Quantum Promise makes the pattern concrete in the most-cited specifications in the field, the ETSI and ITU-T standards that everyone building or buying quantum key distribution references.
The audit lands where the marketing doesn't: the classical control plane, the routine software plumbing that ties quantum bits to the rest of the protocol. Three specification-level vulnerabilities sit in the procedural plumbing the standards leave under-specified, each a kind of attack the quantum side was supposed to make impossible: malicious quantum states slipped past authentication, measurement steps deferred in ways the security proof assumed away, and protocol messages reflected back at their own sender. None exploits the physics. All exploit the gap between what the specification text says about classical operations and what an adversary can actually do with them.
Beyond the Quantum Promise proposes two countermeasures, a measurement commitment and identity-bound message authentication, and confirms in the same Tamarin framework that they close the gaps, with results already communicated to the standards bodies. The lesson travels. In any cryptographic protocol whose brand is the math or the physics, the classical wrapper is where the audit should look first, and the standards body is where the fix should land.