What Is RSA and Why Can Quantum Computers Break It?
How RSA works, simply
RSA uses two linked keys. The public key can be shared with anyone and is used to lock a message or check a signature. The private key stays secret and is used to unlock or sign. The public key is built from the product of two large secret prime numbers.
Why it is safe today
Multiplying two big primes is easy. Going backward, finding the primes from the product, is believed to be extremely slow for normal computers when the numbers are big enough. RSA security rests on that gap. RSA is widely used on the web, in email and in software signing.
Where quantum comes in
In 1994, Peter Shor described a quantum algorithm that factors large numbers in a manageable amount of time. See quantum algorithms explained. If a large enough error corrected quantum computer is built, it could recover the private key from a public key.
How far away is that
Experts generally expect that breaking real RSA keys would need a very large number of high quality qubits, far more than today's machines. Estimates vary and keep changing as methods improve, so no one can give a date with confidence. See the timeline.
What is being done
Standards bodies have published new algorithms designed to resist quantum attacks. Read post-quantum cryptography. Data can also be stolen now and decrypted later, as explained in harvest now, decrypt later.
Crypto note
Bitcoin and Solana do not use RSA. They use elliptic curves, covered in elliptic curve cryptography explained. This site is educational; QUANTUM (QNT) is a memecoin.
A tiny worked example
Pick two small primes, 3 and 11. Multiply them to get 33. The product is public, and anyone who learns the primes can rebuild the private key. With 33, finding 3 and 11 is trivial. Real RSA uses primes hundreds of digits long, so their product has 617 digits for a 2048-bit key, and nobody can factor it with known classical methods. Shor's algorithm changes the cost of that one step on a quantum machine.
How the estimates have moved
| Year | Estimate for RSA-2048 | Source |
|---|---|---|
| 2019 | About 20 million noisy qubits, about 8 hours | Gidney and Ekera |
| 2025 | Fewer than 1 million noisy qubits, under a week | Gidney |
Gidney's 2025 estimate keeps the same hardware assumptions, including a 0.1 percent gate error rate and a 1 microsecond surface code cycle, and gains from better algorithms. One later source mentions even lower claims from a 2026 proposal using different error correcting codes, but we could not verify them independently. The key point: these are estimates for a machine that does not exist. Today's largest devices are in the hundreds to low thousands of qubits, and are not error corrected at this scale.
What is changing in 2026
NIST finalized three post-quantum standards on 13 August 2024: FIPS 203 (ML-KEM) for encryption, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. NIST said there is no need to wait for further standards. In its November 2024 draft report IR 8547, NIST proposes deprecating RSA and elliptic curves after 2030 and disallowing them after 2035. We read this from secondary summaries, so check NIST's site for the final text. See the standards status guide and ML-KEM.
Common mistakes
- Thinking bigger keys are a fix. Shor's scales too well for that to help in practice.
- Thinking only the future matters. Recorded traffic can be decrypted later. See harvest now, decrypt later.
- Assuming all encryption breaks. AES and SHA are affected far less.
How to check this yourself
Look at a website's certificate in your browser to see whether it uses RSA or elliptic curves, and read how to try post-quantum TLS. For organizations, see the migration checklist. The estimate history is told in Shor's algorithm explained.
Sources and further reading
- Gidney 2025: How to factor 2048 bit RSA integers with less than a million noisy qubits (arXiv)
- NIST: first three finalized post-quantum standards, 13 August 2024
- Encryption Consulting: NIST IR 8547 plan (secondary summary of a draft)
- The Quantum Insider: Gidney's 2025 estimate
Checked 2026-10-09. Research and standards change often, so check the primary documents. Nothing here is financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company, and of every lab, company and standards body named on this page.
Frequently asked questions
What does RSA stand for?
RSA is named after its inventors, Rivest, Shamir and Adleman.
Can quantum computers break RSA today?
No. Current quantum computers are far too small and noisy to factor real RSA keys.
Does Bitcoin use RSA?
No. Bitcoin uses elliptic curve signatures, which are also exposed to Shor's algorithm in theory.
Will longer RSA keys fix the problem?
Not practically. Shor's algorithm scales well enough that new quantum resistant algorithms are the recommended answer.
How big is a 2048-bit RSA key number?
It has about 617 decimal digits.
What replaces RSA?
NIST has standardized ML-KEM for key exchange and ML-DSA and SLH-DSA for signatures, with more in progress.
Is my bank's website at risk today?
No known attack exists today. Banks and browsers are working on migration anyway, because of long term data.
When will RSA be broken?
No one can say. Estimates describe resources, not dates, and no machine of that scale exists.
Keep reading
- Elliptic Curve Cryptography Explained for Crypto Users
Elliptic curve cryptography secures Bitcoin and Solana wallets. Learn how it works in plain English and why a large quantum computer could threaten it. - Quantum Algorithms Explained for Beginners
What is a quantum algorithm? Learn how Shor's, Grover's and other quantum algorithms work in plain English, and which ones matter for cryptography and crypto. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary