Resource Estimation: T Gates, Logical Qubits and What an Algorithm Really Costs
Why a bill of materials matters
An algorithm on paper says "polynomial time." A builder needs to know: how many qubits, how many operations, how long, at what error rate. Resource estimation is the discipline of answering that, and it is the closest thing quantum computing has to engineering cost accounting. It also keeps the field honest, because it replaces "someday" with a number that can be challenged and improved.
The vocabulary
- Physical qubit. A real, noisy device element: a superconducting circuit, a trapped ion, an atom.
- Logical qubit. A protected qubit made from many physical ones using error correction, such as the surface code. For where labs stand, see Helios and logical qubits.
- Clifford gates. A family of gates that error-correcting codes can apply cheaply and relatively directly.
- T gates and Toffoli gates. Non-Clifford gates that complete the toolkit. They are the expensive ones: each requires a prepared "magic state," made in dedicated factories that consume many physical qubits and time. This is why papers headline T counts or Toffoli counts rather than total gates. Toffoli is a three-qubit gate that costs a small fixed number of T gates, so the two are related currencies.
- Code distance. How large a code patch is. Bigger distance suppresses errors more but costs more qubits.
From algorithm to machine: the pipeline
- Write the algorithm in terms of logical qubits and a count of Toffoli or T gates.
- Choose an error-correcting code and a distance so the total chance of any failure stays small over all those gates.
- Add magic-state factories sized to feed the gate rate.
- Convert to physical qubits and wall-clock time using assumptions about error rate, cycle time and decoder speed.
Every number is conditional on step 4's assumptions, which is why you should always read them. A rule of thumb: the gap between logical and physical qubit counts is often two to three orders of magnitude.
Case study 1: factoring RSA-2048
Craig Gidney's May 2025 paper reported that 2048-bit RSA could be factored in under a week using fewer than one million noisy qubits, down from about 20 million qubits and about eight hours in the 2019 Gidney and Ekera estimate. Assumptions: a square grid with nearest-neighbor connections, uniform gate error rate 0.1 percent, 1 microsecond surface-code cycle and 10 microsecond control reaction time. The paper attributes the qubit saving mainly to approximate residue arithmetic, yoked surface codes for idle logical qubits and magic state cultivation, and says the longer runtime comes from more Toffoli gates and fewer magic state factories. The Toffoli count was reported reduced by over 100 times relative to a 2024 estimate. Note the lesson: the estimate fell by 20 times in six years from software ideas alone, with no new hardware. See Shor's algorithm and will quantum break Bitcoin and Solana.
Case study 2: chemistry
For the nitrogenase cofactor FeMoco, Lee and coauthors (2020 preprint, PRX Quantum 2021) reported about four million physical qubits and under four days using qubitization with tensor hypercontraction, at 1 microsecond cycles and 0.1 percent gate errors. Their abstract gives the cost of block-encoding the Hamiltonian as order N Toffoli gates in N orbitals, and phase estimation repetitions of order lambda over epsilon, where lambda is a norm of the Hamiltonian. This ties phase estimation and qubitization to a concrete bill.
What the hardware has shown
Estimates assume error correction works as the code distance grows. Google's Nature 2025 paper (arXiv August 2024) reported a distance-7 surface code memory where each step up in distance of two cut the logical error rate by about a factor of 2.14, the largest code using 101 qubits and 0.143 percent error per cycle, with real-time decoding at 63 microseconds average latency. It also found rare correlated errors, about one per hour, as a limit. That is below-threshold behavior, a prerequisite, but a logical memory is far from the thousands of logical qubits and billions of gates in these estimates (state of play).
How to read an estimate
- Which error rate and cycle time were assumed?
- Does it include magic-state factories and decoding?
- Is the connectivity realistic for the hardware type? Neutral atoms and ions differ from grids (compared here).
- Is the date recent? Estimates fall quickly, so a 2019 figure is stale.
Estimates are not forecasts of when machines arrive. They say what must be built, not whether or when it will be. This page is education, not financial advice, and the QNT memecoin is independent of Quantinuum Ltd.
Sources and further reading
- Gidney: How to factor 2048 bit RSA integers with less than a million noisy qubits (arXiv, May 2025)
- Lee et al.: Even more efficient quantum computations of chemistry through tensor hypercontraction (arXiv)
- Google Quantum AI: Quantum error correction below the surface code threshold (arXiv, Nature 2025)
- Reiher et al.: Elucidating Reaction Mechanisms on Quantum Computers (arXiv)
Reported as of 2026-10-09. Theory results are proven only under the stated assumptions, and experimental claims and classical rebuttals keep changing, so check the primary papers. Nothing here is financial advice and nothing here predicts the price of any asset. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab and researcher named on this page.
Frequently asked questions
What is a T gate and why is it costly?
A non-Clifford gate that completes the universal gate set. In error-corrected machines it needs magic states made in dedicated factories, which use many physical qubits and time.
How many qubits to break RSA-2048?
Gidney reported in May 2025 under one million noisy qubits and under a week, under assumptions of 0.1 percent gate error and 1 microsecond cycles. No such machine exists.
Why do resource estimates keep falling?
Better algorithms and error-correction tricks. Gidney's RSA-2048 estimate fell from about 20 million qubits in 2019 to under one million in 2025.
Keep reading
- Quantum Error Correction Explained
Qubits are fragile, so quantum computers need error correction. Learn how logical qubits are built and why this is the key challenge. - Shor's Algorithm Explained Step by Step
How does Shor's algorithm work? A plain English walk through period finding, why it breaks RSA and elliptic curves in theory, and what hardware it would need. - Quantum Chemistry Timelines: An Honest, Optimistic Guide
When might quantum computers do useful chemistry? A grounded look at published projections from the early 2030s to the 2040s and what could change them.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary