Logical vs Physical Qubits: How Quantum Resource Estimates Work
Why the numbers look inconsistent
Read about breaking RSA or Bitcoin's curve and you will see figures like 1,450 qubits, under 500,000 qubits, 19,397 qubits and under a million qubits. They are not mistakes. They describe different layers of the same calculation, under different assumptions. Once you can tell the layers apart, headlines become much easier to judge.
Layer 1: the algorithm
Start with the math. Shor's algorithm for a given key size can be written as a circuit. Researchers count two things: how many logical qubits it needs (ideal, error-free qubits as the program sees them), and how many gates it uses. For these problems the expensive gate is the Toffoli gate (a controlled-controlled-NOT), so papers quote Toffoli counts. For example, Google Quantum AI's March 2026 whitepaper reported circuits for the 256-bit secp256k1 curve using up to 1,200 logical qubits and up to 90 million Toffoli gates, or up to 1,450 logical qubits and up to 70 million. An IonQ-authored preprint in September 2026 reported about 1,450 logical qubits and 40 million Toffoli gates for the same curve. Trading qubits for gates, and the reverse, is a common knob.
Layer 2: error correction
Real qubits are noisy. To get a reliable logical qubit, error correction spreads one logical qubit across many physical qubits and keeps checking them. In the common surface code, the overhead can be hundreds to thousands of physical qubits per logical qubit, depending on how noisy the hardware is and how long the program runs. Better physical error rates mean less overhead. Different codes (for example quantum LDPC codes) can cut overhead further but may need more connectivity between qubits. There is also extra space for "magic state" factories, which produce the special resources Toffoli gates need.
This is why a few thousand logical qubits can become hundreds of thousands of physical ones. It is also why a headline using physical qubits and one using logical qubits can differ by a factor of hundreds while describing the same attack.
Layer 3: runtime and clock speed
Finally, how long does it take? Superconducting and photonic designs have fast clocks: the 2019 and 2025 RSA estimates assume a 1 microsecond error correction cycle. Trapped ions and neutral atoms tend to run slower cycles but may need fewer physical qubits. Google's whitepaper draws exactly this line, calling the first group "fast-clock" and the second "slow-clock." The IonQ-authored preprint reported about 25.7 days on 19,397 physical qubits for its trapped-ion design, with a 63% estimated success probability. Fewer qubits, much more time. Neither number is wrong. They are different points on a trade-off curve.
The assumptions that move everything
| Assumption | Example in the RSA-2048 papers | Why it matters |
|---|---|---|
| Physical error rate | 0.1% per gate (10 to the minus 3) | Lower error means less overhead |
| Cycle time | 1 microsecond | Sets total runtime |
| Connectivity | 2D grid, nearest neighbor | Other layouts change the code you can use |
| Reaction time | 10 microseconds | Classical decoding must keep up |
| Success probability | Single run vs repeated attempts | Failed runs cost more time |
Those hardware settings are quoted in the Gidney and Ekera 2019 abstract and carried into later work. Real machines have to actually reach them. Today's best systems are impressive but remain far from the scale and runtime these designs imagine (see the error correction state of play).
What estimates do not tell you
- They are not a build plan. Nobody has shown these machines can be built on any schedule.
- They are lower bounds on difficulty under stated assumptions. Real engineering often adds overhead the paper does not model.
- They can fall. Smarter algorithms and codes have repeatedly cut counts (see the RSA history).
A quick checklist for any headline
- Is the number logical or physical qubits?
- What runtime does it assume: minutes, hours, days, weeks?
- What error rate and clock speed?
- Is it a peer-reviewed paper, a preprint or a company blog?
- Does it reflect hardware that exists?
Using that checklist you can read Q-Day stories calmly. For the bigger picture, see the Q-Day overview. This is education, not financial advice, and says nothing about the price of any token. The QNT memecoin is independent of Quantinuum Ltd.
Sources and further reading
- Gidney and Ekera (2019): How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, arXiv
- Gidney (May 2025): How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv
- Babbush et al., Google Quantum AI (30 March 2026): Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, whitepaper
- IonQ authors (September 2026): Computing 256-bit elliptic curve discrete logarithms in 26 days on a fault-tolerant trapped-ion quantum computer, IACR ePrint 2026/1916
- PostQuantum.com: RSA-2048 resource estimates and the 2026 follow-ups
Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
What is the difference between a logical and a physical qubit?
A logical qubit is an error-protected qubit built from many physical qubits. In the surface code the overhead can be hundreds to thousands of physical qubits per logical one, depending on noise.
Why do some papers say 1,450 qubits and others say under 500,000?
The first is a logical qubit count for the algorithm. The second is a physical qubit count after error correction, under stated hardware assumptions such as a 10 to the minus 3 error rate.
Does a lower qubit count mean an easier attack?
Not always. Designs can trade qubits for time. One IonQ-authored preprint reported about 19,397 physical qubits but about 25.7 days of runtime.
Keep reading
- The Surface Code Explained for Beginners
What is the surface code? A clear guide to a leading quantum error correction scheme: stabilizer checks, code distance, thresholds, overhead and open issues. - Quantum Error Correction Explained
Qubits are fragile, so quantum computers need error correction. Learn how logical qubits are built and why this is the key challenge. - Shor's Algorithm Explained Step by Step
How does Shor's algorithm work? A plain English walk through period finding, why it breaks RSA and elliptic curves in theory, and what hardware it would need.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary