RSA-2048 vs Quantum: The Estimates From 2019 to 2026
Why RSA-2048 is the yardstick
RSA with a 2048-bit key is one of the most common public key setups on the internet, so it became the benchmark for "how big a quantum computer do we need?" The standard attack is Shor's algorithm. The question is never whether the math works on paper. It is how many error-corrected qubits and how much time it takes. For how to read those numbers, see our resource estimate guide.
Before 2019: very large numbers
Earlier estimates were far larger than 2019 ones (the 2019 abstract reports a hundredfold lower spacetime volume than comparable earlier work). I did not verify specific pre-2019 figures for this page. The key point is the direction of travel, which was down.
2019: Gidney and Ekera, 20 million qubits
In May 2019, Craig Gidney (Google) and Martin Ekera published "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits." The abstract reports a spacetime volume a hundredfold below comparable earlier work. It assumed superconducting-style hardware: a planar grid with nearest-neighbor links, a characteristic gate error rate of 10 to the minus 3, a surface code cycle of 1 microsecond and a 10 microsecond reaction time. The title numbers are about 20 million noisy physical qubits and about 8 hours.
2024: a different route
Chevignard, Fouque and Schrottenloher proposed approximate residue arithmetic. According to a PostQuantum.com summary, the CRYPTO 2025 version cut the logical qubit count to 1,730, though at the price of a much higher gate count. This work became one ingredient of the 2025 result.
2025: Gidney, under one million qubits
On 21 May 2025, Gidney posted "How to factor 2048 bit RSA integers with less than a million noisy qubits." Same hardware assumptions as 2019, new software ideas. Per the arXiv paper and a secondary summary, the savings came from three places:
- Approximate residue arithmetic, using fewer logical qubits.
- Yoked surface codes, storing idle logical qubits more densely.
- Magic state cultivation, shrinking the space spent making Toffoli resources.
The headline: fewer than a million noisy qubits, in less than a week. That is roughly a twentyfold drop in qubits against 2019, traded for a longer run. A secondary source reports about 6.5 billion Toffoli gates in the new design. It is a preprint, a theoretical projection and not a demonstration.
2026: more movement, with caveats
PostQuantum.com and The Quantum Insider report two 2026 preprints:
- Iceberg Quantum, Pinnacle architecture (February 2026): reported to replace surface codes with quantum LDPC codes and to claim RSA-2048 with fewer than 100,000 physical qubits, under the same headline error and timing assumptions. The Quantum Insider says it was validated by simulation, not hardware.
- Cain et al. (March 2026): reported to propose cryptographically relevant Shor computations with as few as 10,000 reconfigurable neutral atoms, accepting much longer runtimes.
PostQuantum.com cautions that these are theoretical preprints on architectures nobody has built, and that they change the code, connectivity or runtime, so they cannot be compared directly with Gidney's surface-code baseline. I read these only through those secondary summaries, not the papers themselves.
The trend, honestly read
| Year | Headline (reported) | Status |
|---|---|---|
| 2019 | About 20 million noisy qubits, about 8 hours | Paper estimate |
| 2025 | Under 1 million noisy qubits, under a week | Preprint estimate |
| 2026 (Iceberg) | Under 100,000 physical qubits | Preprint, simulated, other architecture |
| 2026 (Cain et al.) | As few as 10,000 neutral atoms, longer runtime | Preprint, other architecture |
The arrow points down, and quickly. But two cautions apply. A falling estimate does not make the machine exist. Today's systems are still far from hundreds of thousands of error-corrected-grade qubits running for days. And estimates cannot fall forever: a secondary source says Gidney himself does not see another tenfold cut inside the same hardware model. Further drops probably need new architectures, which carry their own engineering risk.
What this means
For planning, the sensible lesson is that "it needs hundreds of millions of qubits" is an outdated comfort. The cost of the attack is lower than it looked in 2019, and the field is still moving. That does not tell you a date. See the Q-Day overview and what experts say. Education only, not financial advice, no price view on any asset. The QNT memecoin is independent of Quantinuum Ltd.
Sources and further reading
- Gidney and Ekera (2019): How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, arXiv
- Gidney (May 2025): How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv
- PostQuantum.com: RSA-2048 resource estimates and the 2026 follow-ups
- The Quantum Insider (31 March 2026): three papers rewriting the quantum threat timeline
Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.
Frequently asked questions
How many qubits would it take to break RSA-2048?
Gidney's May 2025 preprint estimated under one million noisy qubits in under a week, down from about 20 million qubits and 8 hours in 2019. These are theoretical estimates under stated assumptions.
Has anyone factored an RSA-2048 key with a quantum computer?
No. The estimates describe machines that have not been built. They are paper designs.
Do the 2026 papers lower the number again?
Reportedly yes: one preprint claims under 100,000 physical qubits and another as few as 10,000 neutral atoms, but both use different architectures and longer runtimes, and neither has been built.
Keep reading
- What Is RSA and Why Can Quantum Computers Break It?
RSA encryption relies on the difficulty of factoring big numbers. Learn how RSA works in plain English and why a large quantum computer could break it. - Shor's Algorithm Explained Step by Step
How does Shor's algorithm work? A plain English walk through period finding, why it breaks RSA and elliptic curves in theory, and what hardware it would need. - Logical vs Physical Qubits: How Quantum Resource Estimates Work
Why one paper says 1,450 qubits and another says under 500,000? Logical and physical qubits, gate counts, runtime and assumptions, explained plainly.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary