Breaking RSA-2048: Why the Estimate Fell From 20 Million to 10,000 Qubits
In 2019 the reference estimate for breaking RSA-2048 was 20 million noisy qubits running for eight hours. In March 2026 a Caltech and Oratomic team put the figure at 10,000. That is a factor of two thousand in seven years, and not one step of it came from new hardware.
The estimate everyone still anchors to
Shor’s algorithm, published in 1994, is why cryptographers watch quantum hardware. RSA security rests on the difficulty of factoring the product of two large primes. RSA-2048 is a 617-digit number, and no classical method factors it in useful time. Shor recasts that problem as period-finding, which a quantum computer solves efficiently. This is the same threat that closes our survey of what changed in quantum computing, examined here on its own terms. The practical worry is not tomorrow’s traffic. It is harvest now, decrypt later: an adversary records encrypted data today and waits for a machine that can open it.
The 2019 baseline. Craig Gidney and Martin Ekerå published the calculation that became the field’s yardstick: 20 million noisy physical qubits, running roughly eight hours. They stated their assumptions plainly. A square grid of qubits with nearest-neighbour connections. A uniform gate error rate of 0.1 percent. A surface-code cycle time of one microsecond. A control-system reaction time of ten microseconds. Those four numbers matter, because every later estimate answers to them.
What it established
A fixed hardware model for later work to answer to. Without it, “fewer qubits” would be a claim about assumptions rather than about algorithms.
One million qubits, but a week instead of eight hours
In May 2025 Gidney revised his own figure. Fewer than one million noisy qubits, running for less than a week, on exactly the same hardware assumptions as 2019. The qubit count fell roughly twentyfold.
Where the saving came from. Three changes, all algorithmic. Approximate residue arithmetic replaced exact modular exponentiation, following work by Chevignard, Fouque and Schrottenloher. Idle logical qubits moved into yoked surface codes, which store them at roughly triple the density. And less space went to magic-state distillation, the expensive process that supplies the non-Clifford gates Shor’s algorithm needs. Gidney reports cutting the Toffoli-gate count by more than a hundredfold.
The trade is explicit. Twenty times fewer qubits, roughly twenty times longer runtime. This is a space-for-time exchange, not a free saving. A headline that reports only the qubit count reports half the result.
One hundred thousand qubits, with a different code
On 12 February 2026, Paul Webster and colleagues posted the Pinnacle Architecture. Their claim: RSA-2048 factored with fewer than one hundred thousand physical qubits, at a physical error rate of one in a thousand, a one-microsecond code cycle and a ten-microsecond reaction time. The hardware assumptions are essentially Gidney’s. The code is not.
Why the code choice moves the number. The surface code stores one logical qubit per two-dimensional patch, and the patch grows with the protection you want. Quantum low-density parity-check codes pack many logical qubits into a single block that shares its parity checks. The encoding rate rises, and the physical-qubit bill for a fixed amount of protected information falls. That ratio is doing more work in these estimates than the qubit count is, and it is not measured the same way by every group. Pinnacle applies that idea to a full factoring circuit rather than to a memory.
The cost is connectivity. These codes require parity checks between qubits that are not neighbours, which superconducting grids do not natively provide. That constraint is the reason the same idea reappears immediately on a different platform.
Ten thousand atoms, and a much longer clock
On 30 March 2026, Madelyn Cain, Qian Xu, Robbie King, Lewis Picard, Harry Levine, Manuel Endres, John Preskill, Hsin-Yuan Huang and Dolev Bluvstein posted the lowest estimate yet. Shor’s algorithm at cryptographically relevant scale with as few as 10,000 reconfigurable atomic qubits. Optical tweezers hold neutral atoms in place and can move them physically during a computation, which supplies the long-range connectivity that high-rate codes demand.
Read the runtime clause. The paper’s own figure for speed is a different problem. With 26,000 physical qubits, a discrete logarithm on the P-256 elliptic curve could take a few days. Factoring RSA-2048 runs one to two orders of magnitude longer than that. At the 10,000-qubit end of the range, the calculation is not a matter of days.
One number for scale. The authors note that neutral-atom groups have already trapped arrays of more than 6,000 highly coherent qubits. The estimate is now within a factor of two of an array size that exists. Trapping 6,000 atoms and running fault-tolerant logic on 10,000 are not the same achievement.
What it promises, conditionally
If neutral-atom hardware scales as its recent results suggest, the machine that breaks RSA is smaller than the field assumed a year ago. The result is a theoretical analysis, it has not been peer-reviewed, and all nine authors hold shares in Oratomic, the company whose architecture it favours. Anyone can check the physics. The incentive still deserves a mention.
Figure 1
The estimate fell 2,000-fold. The hardware did not move.
Published resource estimates for factoring RSA-2048, on a logarithmic scale. Every reduction came from codes and circuits, not from a larger machine.
What the chart does not show. All four estimates assume a gate error rate of 0.1 percent, held uniform across the device for the whole computation. None of them describes a machine that has been built, and no quantum computer has factored a number of cryptographic size.
Sources: Gidney & Ekerå, Quantum 5, 433 (2021); Gidney, arXiv:2505.15917; Webster et al., arXiv:2602.11457; Cain et al., arXiv:2603.28627.
Estimates of the physical qubits needed to factor RSA-2048 have fallen from 20 million to 10,000 in seven years, entirely through better error-correcting codes and circuits. The dashed lines mark hardware that exists: roughly 120 qubits in the largest general-purpose machines, and just over 6,000 atoms in the largest coherent trapping array. Trapping atoms and running fault-tolerant logic on them are different achievements. Sources: Quantum 5, 433 (2021) · arXiv:2505.15917 · arXiv:2602.11457 · arXiv:2603.28627
What none of these numbers are
They are resource estimates. They are not measurements, and they are not schedules.
No quantum computer has factored a number of cryptographic size. The largest general-purpose commercial machines in service hold on the order of 100 to 130 physical qubits: Quantinuum’s Helios has 98, Google’s Willow 105, IBM’s Nighthawk 120. Every estimate above assumes a physical error rate near 0.1 percent, held uniform across the whole device and sustained for the entire computation. None of those machines runs error correction at the distance a factoring circuit needs. None of them assumes a machine that exists.
What the trend does show is that the target keeps moving in one direction. Four independent efforts, using four different code families, have each cut the estimate. That is a statement about how much slack remained in the algorithms, and it says nothing about when the hardware arrives.
The policy clock moved anyway
On 22 June 2026 the White House issued Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks.” It converts a set of advisory timelines into dated requirements for federal systems.
- Within 30 days, every agency names a post-quantum migration lead.
- Within 90 days, the Office of Management and Budget issues implementation guidance. OMB published memorandum M-26-15 the same day the order was signed.
- By 31 December 2030, all high-value assets and high-impact systems must use post-quantum cryptography for key establishment.
- By 31 December 2031, the same systems must use it for digital signatures.
- Within 180 days, the Federal Acquisition Regulatory Council must propose a rule requiring covered contractors to comply with post-quantum standards by 31 December 2030.
National Security Systems are excluded and sit on a separate track managed by the NSA. Cloudflare’s cryptography team reads the 2031 signature deadline as an implicit forecast. Authentication only fails once a cryptographically relevant machine exists. Setting a date for it therefore says something about what the government thinks is possible by then. That is their inference, not a statement in the order.
The defence shipped before the threat did
NIST finalised three post-quantum standards in August 2024: FIPS 203 for key encapsulation (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. On 11 March 2025 it selected HQC as a fifth algorithm, a code-based backup for ML-KEM built on different mathematics, with a draft standard expected in 2026 and a final version in 2027.
Deployment is lopsided. Encryption has moved fast. More than two-thirds of browser traffic reaching Cloudflare’s network now uses post-quantum key agreement, up from under a third in January 2025, almost all of it the X25519MLKEM768 hybrid. Origin-side support sits near 10 percent. Post-quantum authentication has barely started, because ML-DSA signatures are larger than classical ones and the upgrade chain runs through certificate authorities, transparency logs, root stores and browsers.
NIST’s own transition roadmap, IR 8547, proposes deprecating RSA-2048 and ECC P-256 after 2030 and disallowing them after 2035. It was released as an initial public draft in November 2024 and had not been finalised as of mid-2026, though organisations plan against its dates regardless.
What it promises, or threatens
Less a capability than a countdown, and a countdown driven by mathematics rather than by machines. The encryption half of the migration is largely a software update and is already most of the way done on the public web. The authentication half is a coordination problem across the whole certificate ecosystem, and it has one year less to run.
What is actually unresolved
Whether any of these architectures can be built. Pinnacle and the neutral-atom analysis both assume error rates and connectivity that no device has demonstrated at scale. The estimates are internally consistent. They are not engineering plans.
Whether the numbers keep falling. Four reductions in seven years is a trend, not a law. Each one exploited a specific inefficiency. There is no argument that the remaining slack is large.
Whether 2031 is reachable for signatures. The federal deadline assumes the certificate ecosystem can move in five years. It took the web years to turn off SSLv3 after a known attack. This is a larger dependency chain.
The honest summary is that the threat and the defence are advancing on separate tracks. The threat is a set of calculations that keep improving. The defence is a set of standards that are already deployed on most of the public web. Neither track is waiting for the other, and only one of them has a working implementation.
Note on sourcing
Every resource estimate above is a theoretical calculation on hardware that has not been built. Three of the four are preprints and are labelled as such. The 2019 baseline is peer-reviewed. The executive order, the OMB memorandum and the NIST standards are primary government documents and are linked directly. Deployment percentages come from Cloudflare’s own network telemetry and describe traffic reaching Cloudflare, not the whole internet.
References
- C. Gidney and M. Ekera, How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, Quantum 5, 433 (2021) doi:10.22331/q-2021-04-15-433
- C. Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits (May 2025). Preprint, not peer-reviewed
- P. Webster et al., The Pinnacle Architecture: reducing the cost of breaking RSA-2048 to 100,000 physical qubits using quantum LDPC codes (February 2026). Preprint, not peer-reviewed
- M. Cain, Q. Xu, R. King, L. R. B. Picard, H. Levine, M. Endres, J. Preskill, H.-Y. Huang and D. Bluvstein, Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits (March 2026). Preprint, not peer-reviewed
- Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, 22 June 2026, 91 FR 38483
- Office of Management and Budget, M-26-15: Execution of the Migration to Post-Quantum Cryptography, June 2026
- NIST, Post-Quantum Cryptography Standardization: FIPS 203, 204 and 205 (August 2024); HQC selected 11 March 2025, NIST IR 8545
- D. Moody, R. Perlner, A. Regenscheid, A. Robinson and D. Cooper, Transition to Post-Quantum Cryptography Standards, NIST IR 8547, initial public draft (November 2024)
- S. Goldberg and V. Voci, The White House's post-quantum executive order is an important milestone, Cloudflare, 23 June 2026
- Cloudflare Radar, post-quantum adoption telemetry
Common questions
Can a quantum computer break RSA today?
No. No quantum computer has factored a number of cryptographic size. The largest general-purpose machines in service hold 98 to 120 physical qubits, and every estimate above assumes hundreds of thousands or more.
Why did the estimate fall if the hardware did not improve?
All four reductions are algorithmic. Better modular arithmetic, denser storage for idle logical qubits, cheaper magic-state distillation, and error-correcting codes that pack more logical qubits into the same physical hardware.
Does 10,000 qubits mean the attack takes 10,000 qubits and a few days?
No. The few-day figure in that paper is for a discrete logarithm on the P-256 curve at 26,000 qubits. Factoring RSA-2048 runs one to two orders of magnitude longer.
Is my data at risk right now?
Not from a quantum computer. The relevant concern is harvest now, decrypt later, where an adversary records encrypted traffic today and opens it once a capable machine exists.
What replaces RSA?
NIST finalised ML-KEM for key establishment and ML-DSA and SLH-DSA for signatures in August 2024, with HQC added in March 2025 as a code-based backup built on different mathematics.
Has the migration started?
Yes, unevenly. More than two-thirds of browser traffic reaching Cloudflare now uses post-quantum key agreement. Post-quantum authentication has barely begun, because the upgrade chain runs through certificate authorities, transparency logs, root stores and browsers.
1 response