128-bit is still absolutely impractical to brute force now or in the foreseeable future. Even 96-bit is questionable, though likely achievable after some time by someone with a lot of money who is able to create a huge farm full of ASICs for the task.
A QC large and stable enough to run Grover's Algorithm would be a problem for symmetric keys and hashes smaller than about 192 bits. Most cryptographers recommend 256-bit or larger for a good margin of safety.
Asymmetric crypto is more complex story.