RSA-2048
BPrivate-key recovery; complete break if the circuit succeeds.
≈3,000 algorithmic logical qubits
≈20 million noisy qubits
No quantum computer can break deployed public-key cryptography today. That is not a reason to wait: sensitive data can be collected now, migrations take years, and attack-cost estimates continue to move.
Plan against the lifetime of your sensitive data and the time required to replace exposed RSA and ECC—not against a speculative Q-day forecast.
RSA-2048 / P-256
noisy qubits · 2025 preprint
noisy qubits · 2021
200 logical qubits
The comparison below uses logical-qubit counts only. It does not claim that qubit count alone measures attack capability.
Logarithmic scale. Logical-qubit definitions, error rates, code performance and executable circuit depth differ. Threshold lines are research estimates, not forecasts or engineering specifications.
Public-key and symmetric cryptography face different quantum effects. Treating them as one problem creates the wrong priorities.
Private-key recovery; complete break if the circuit succeeds.
≈3,000 algorithmic logical qubits
≈20 million noisy qubits
Same complete break, with a substantially reduced theoretical hardware estimate.
Not separately headlined
<1 million noisy qubits
Private-key recovery from a public key; complete break if the circuit succeeds.
≈2,330 logical qubits
Not estimated in the cited paper
Quadratic search speedup; effective security is approximately 64 bits, not an automatic break.
≈2,953 circuit width
Not estimated in the cited paper
Quadratic search speedup; effective security remains approximately 128 bits.
≈6,681 circuit width
Not estimated in the cited paper
Estimates preserve each source’s units and assumptions. They are not directly comparable and should not be converted into a date prediction.
Observed experiments and future company targets are separated, so the sequence does not imply a smooth march toward cryptanalysis.
53 physical qubits used for random-circuit sampling
A programmable superconducting processor completed a specialized sampling experiment beyond the reported classical baseline.
Why it matters: Random-circuit sampling is not a cryptographic attack and the device did not use fault-tolerant logical qubits.
Primary source1,180 atoms populated in a 1,225-site array
The company reported the first neutral-atom system to exceed 1,000 populated qubit sites.
Why it matters: Array size does not establish circuit depth, error correction, or the ability to execute Shor's algorithm.
Primary source1,121-qubit superconducting processor
IBM presented Condor as a scale milestone while emphasizing lower-error Heron processors for useful circuits.
Why it matters: These are noisy physical qubits, not an error-corrected logical-qubit register suitable for cryptanalysis.
Primary source4 logical qubits; reported logical error rate 800× below physical error rate
A trapped-ion processor and qubit-virtualization system demonstrated repeated error correction on four logical qubits.
Why it matters: Four logical qubits are a proof of error suppression, not a cryptanalytic computer, and logical-qubit definitions vary by code and task.
Primary sourceBelow-threshold surface-code scaling through code distance 7
Increasing surface-code size suppressed logical errors, demonstrating the scaling behavior required for fault tolerance.
Why it matters: The experiment studied a logical memory, not thousands of logical qubits executing a cryptographic algorithm.
Primary sourceRoadmap target: 200 logical qubits and 100 million gates in 2029
IBM published a modular fault-tolerant architecture and a target for its Starling system.
Why it matters: This is a vendor target, not observed capability; IBM states roadmap goals may change or be withdrawn.
Primary source