RSA-2048 vs Quantum: The Estimates From 2019 to 2026

Updated | 4 min read | QUANTUM (QNT) community

Why RSA-2048 is the yardstick

RSA with a 2048-bit key is one of the most common public key setups on the internet, so it became the benchmark for "how big a quantum computer do we need?" The standard attack is Shor's algorithm. The question is never whether the math works on paper. It is how many error-corrected qubits and how much time it takes. For how to read those numbers, see our resource estimate guide.

Before 2019: very large numbers

Earlier estimates were far larger than 2019 ones (the 2019 abstract reports a hundredfold lower spacetime volume than comparable earlier work). I did not verify specific pre-2019 figures for this page. The key point is the direction of travel, which was down.

2019: Gidney and Ekera, 20 million qubits

In May 2019, Craig Gidney (Google) and Martin Ekera published "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits." The abstract reports a spacetime volume a hundredfold below comparable earlier work. It assumed superconducting-style hardware: a planar grid with nearest-neighbor links, a characteristic gate error rate of 10 to the minus 3, a surface code cycle of 1 microsecond and a 10 microsecond reaction time. The title numbers are about 20 million noisy physical qubits and about 8 hours.

2024: a different route

Chevignard, Fouque and Schrottenloher proposed approximate residue arithmetic. According to a PostQuantum.com summary, the CRYPTO 2025 version cut the logical qubit count to 1,730, though at the price of a much higher gate count. This work became one ingredient of the 2025 result.

2025: Gidney, under one million qubits

On 21 May 2025, Gidney posted "How to factor 2048 bit RSA integers with less than a million noisy qubits." Same hardware assumptions as 2019, new software ideas. Per the arXiv paper and a secondary summary, the savings came from three places:

The headline: fewer than a million noisy qubits, in less than a week. That is roughly a twentyfold drop in qubits against 2019, traded for a longer run. A secondary source reports about 6.5 billion Toffoli gates in the new design. It is a preprint, a theoretical projection and not a demonstration.

2026: more movement, with caveats

PostQuantum.com and The Quantum Insider report two 2026 preprints:

PostQuantum.com cautions that these are theoretical preprints on architectures nobody has built, and that they change the code, connectivity or runtime, so they cannot be compared directly with Gidney's surface-code baseline. I read these only through those secondary summaries, not the papers themselves.

The trend, honestly read

YearHeadline (reported)Status
2019About 20 million noisy qubits, about 8 hoursPaper estimate
2025Under 1 million noisy qubits, under a weekPreprint estimate
2026 (Iceberg)Under 100,000 physical qubitsPreprint, simulated, other architecture
2026 (Cain et al.)As few as 10,000 neutral atoms, longer runtimePreprint, other architecture

The arrow points down, and quickly. But two cautions apply. A falling estimate does not make the machine exist. Today's systems are still far from hundreds of thousands of error-corrected-grade qubits running for days. And estimates cannot fall forever: a secondary source says Gidney himself does not see another tenfold cut inside the same hardware model. Further drops probably need new architectures, which carry their own engineering risk.

What this means

For planning, the sensible lesson is that "it needs hundreds of millions of qubits" is an outdated comfort. The cost of the attack is lower than it looked in 2019, and the field is still moving. That does not tell you a date. See the Q-Day overview and what experts say. Education only, not financial advice, no price view on any asset. The QNT memecoin is independent of Quantinuum Ltd.

Sources and further reading

Reported as of 2026-10-09. Resource estimates are theoretical preprints or whitepapers, surveys are opinion, and government dates are planning targets, so check the primary documents. Nothing here is financial advice or a prediction of any asset price. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, chain and government named on this page.

Frequently asked questions

How many qubits would it take to break RSA-2048?

Gidney's May 2025 preprint estimated under one million noisy qubits in under a week, down from about 20 million qubits and 8 hours in 2019. These are theoretical estimates under stated assumptions.

Has anyone factored an RSA-2048 key with a quantum computer?

No. The estimates describe machines that have not been built. They are paper designs.

Do the 2026 papers lower the number again?

Reportedly yes: one preprint claims under 100,000 physical qubits and another as few as 10,000 neutral atoms, but both use different architectures and longer runtimes, and neither has been built.

Share on X

Keep reading

All Quantum computing guides | Back to top | Search the site

Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.