ZKSF logo, a neon quantum brainZKSF
← All applications

Cryptography and digital assets

When does a quantum computer break your keys?

This page has a different shape from the others. There is no head-to-head benchmark here, because no classical algorithm competes with Shor's: factoring is subexponential classically and polynomial quantumly, and that gap is the whole point. The question is not which is faster. It is how large a quantum computer would have to be, and how that compares to what exists.

Why this is the one with a deadline

Every other application on this site is a question of whether quantum computing will become useful. This one is a question of when it becomes dangerous, and the difference matters because encrypted data can be captured today and decrypted later. Anything with a confidentiality lifetime measured in decades, medical records, state secrets, long-dated contracts, is already exposed to a machine that does not yet exist. Digital assets have the same structure: a public key visible on-chain today is a target for hardware that arrives at any point in the future.

The calculation

Two steps, both shown so the assumptions are visible rather than asserted.

Logical qubits. Shor's algorithm against an n-bit RSA modulus needs about 2n + 3 logical qubits using the standard modular-exponentiation construction. Elliptic curve discrete logarithms over a prime field of n bits need roughly 9n, which is why a 256-bit elliptic curve key is a smaller target than a 2048-bit RSA key despite offering comparable classical security.

Physical qubits. Logical qubits are not free. Under the surface code, the logical error rate falls as roughly 0.1(p/p_th)^(d/2) for physical error rate p, threshold p_th near 1 percent, and code distance d, and each logical qubit costs about 2d^2 physical ones. Requiring a logical error rate of 1e-15, low enough that an algorithm running for hours does not fail, fixes d.

That second step is the assumption to argue with, and it is the weakest part of this page. Surface-code overhead assumes a two-dimensional nearest-neighbour layout, which suits superconducting hardware and overstates the cost for architectures that do not have that constraint. IBM's bivariate bicycle qLDPC code encodes 12 logical qubits in 144 data qubits and claims roughly a tenfold overhead reduction against the surface code, and Quantinuum's all-to-all trapped-ion connectivity permits high-rate codes that a planar layout cannot. Treat the surface-code figure as an architecture-specific upper bound rather than a universal one. Apply IBM’s claimed tenfold reduction to the table below and RSA-2048 falls from roughly 6.9 million physical qubits to roughly 690,000. Still enormous, and an order of magnitude is not a rounding error.

Error rate drives everything

Physical qubits needed per logical qubit, at a target logical error rate of 1e-15.

Physical error rateCode distancePhysical per logicalComment
1%n/anever: at or above thresholdError correction cannot help here
0.5%9518,050Marginal, overhead explodes
0.1%291,682Typical of good superconducting devices
0.01%15450Reached today by IonQ and Silicon Quantum Computing

The top row is the most important one on this page. At or above the threshold, error correction does not work at all, and no number of qubits fixes it. Below threshold the overhead falls fast: a tenfold improvement in gate fidelity cuts the physical requirement by a factor of nearly four. This is why gate fidelity, not qubit count, is the number to track, and why a headline about a thousand-qubit processor tells you far less than a fidelity figure does.

The naive surface-code arithmetic

At a 0.1% physical error rate, giving 1,682 physical qubits per logical qubit. This is the conservative column, not the optimistic one: the best two-qubit fidelity reported today is 99.99 percent, a 0.01% error rate, which drops the overhead to 450 and every figure below by a factor of 3.7. At that rate RSA-2048 needs roughly 1.8 million physical qubits rather than 6.9 million.

TargetLogical qubitsPhysical (naive surface code)vs 108 todayWhere it is used
RSA-20484,0996,894,51863,838xTLS, code signing, most PKI
RSA-40968,19513,783,990127,630xLong-lived roots of trust
ECC P-256 / secp256k12,3043,875,32835,883xTLS, Bitcoin, Ethereum
ECC P-3843,4565,812,99253,824xHigh-assurance and government

Reading these numbers honestly

The largest processor available through this platform is 108 physical qubits with no error correction, which is where the "vs 108 today" column comes from. That is our catalogue, not the state of the art. Machines with more than a thousand physical qubits exist, two-qubit fidelity has passed 99.99 percent, and QuEra has demonstrated 96 logical qubits from 448 physical ones. Measured against the field rather than against what we resell, the gap is smaller, though it remains four orders of magnitude.

Treat 6.9 million as a textbook upper bound, not a forecast, and expect the real figure to be far lower. The arithmetic above is deliberately naive: generic surface code, no algorithmic optimisation, no co-design between the algorithm and the code. Published analyses that do all three land an order of magnitude below it, and they have been falling fast.

Craig Gidney’s 2019 analysis needed roughly 20 million physical qubits. His 2025 revision put it at 897,864 physical qubits and about five days, using approximate residue arithmetic, yoked surface codes and magic-state cultivation. A February 2026 architecture replacing surface codes with quantum LDPC codes projects fewer than 100,000 physical qubits at a 0.1 percent error rate, though it assumes non-local connectivity that superconducting hardware does not currently provide and codes not yet demonstrated at scale.

So the honest trajectory is 20 million in 2019, under a million in 2025, and plausibly under 100,000 in 2026. That is a factor of 200 in seven years, driven by algorithms and error correction rather than by hardware. The table below is useful for understanding the mechanism, and it should not be read as the number to plan against. Our post-quantum primer tracks the published estimates.

Note also that elliptic curve keys fall first. P-256 and secp256k1 need roughly half the logical qubits of RSA-2048, so any migration plan that treats RSA as the urgent case and elliptic curve as comfortable has the ordering backwards. For anyone holding digital assets, the exposed quantity is the public key, so addresses whose public key has been revealed by a prior spend are the concern rather than the hashing that secures mining.

What to do with this

The gap is enormous and the timeline is genuinely unknown, which is exactly why the standard guidance is to migrate on a schedule rather than in a panic. Post-quantum algorithms are standardised and available now. The work is inventory and dependency management, not cryptography research: knowing which systems use which primitives, and which of your data has a confidentiality requirement that outlives the estimate above.

If you take one number from this page to a board, do not take the qubit count. Take the observation that the requirement moves by orders of magnitude on gate fidelity and code choice alone, which is why credible timelines disagree by decades and why a migration plan should be indexed to milestones rather than to a date.

The milestones worth watching are published. Quantinuum Sol in 2027 targets around 100 logical qubits, but through the iceberg code, which is distance 2 and therefore detects errors and discards the run rather than correcting them. Postselection cannot carry an algorithm of Shor’s depth, so Sol is not the threshold event for cryptography. IBM Starling and Quantinuum Apollo, both targeting 2029, are: hundreds of logical qubits with genuine correction and circuits of 100 million gates. Even then, RSA-2048 needs on the order of a thousand logical qubits, so hundreds is still short, though by less than the naive table above suggests.

For context: where the hardware actually is

Gaps on this page are quoted against the devices ZKSF can run, which are Amazon Braket’s public processors. That is not the frontier. Quantinuum, IBM, QuEra and Atom Computing are not resellable through us, and their machines are considerably further along. As of September 2026:

Physical qubits built

Infleqtion Sqale1,600Neutral atom
Atom Computing1,180Neutral atom, 1,225 sites
IBM Condor1,121Superconducting, 2023
IBM Heron R2156Superconducting, ~99.5% two-qubit fidelity
Rigetti Cepheus108The largest available through ZKSF

Two-qubit gate fidelity

The number that actually governs what a circuit can do.

IonQ99.99%Trapped ion, first past four nines
Silicon Quantum Computing99.99%Silicon spin
Quantinuum99.97%Trapped ion, all-to-all
IQM99.91%Superconducting, available through ZKSF

Logical qubits demonstrated

Published results, not roadmap targets.

QuEra96 logical / 448 physicalNeutral atom
Quantinuum48 logical / 98 physicalTrapped ion, iceberg code
Atom Computing24 logicalOn the 1,180-qubit system
Google1 logical / 105 physicalSurface code, below threshold

Announced roadmap

Targets. Roadmaps slip, and these are not results.

Quantinuum Sol, 2027192 physical, ~100 logicalIceberg code, distance 2. Error detection with postselection, not correction
IBM Starling, 2029~200 logicalBivariate bicycle qLDPC, 100 million gates
Quantinuum Apollo, 2029hundreds of logicalThousands of physical, logical error 1e-6 or better

Check the arithmetic yourself.

Every figure here is computed from the two formulas above rather than cited, so you can reproduce it in a few lines. The primer explains what post-quantum migration involves in practice, and the Shor walkthrough runs the algorithm at a size that fits on hardware today.