Updated October 11, 2026
How close are quantum computers to breaking encryption?
Closer than a few years ago, and still well short. The leanest published plan for breaking RSA-2048 on a chip needs about 94,000 qubits and a month of running time. The largest quantum computer that runs full computations has 1,121 qubits.
- ●Estimate: RSA-2048
- ■Estimate: 256-bit elliptic curve
- ○Machine built
- ◌Atoms trapped, not yet computing
Tap a point, or step through them in date order.
Two lines heading toward each other
The dots along the top are estimates of how many physical qubits it would take to run Shor's algorithm against the encryption most of the internet uses. In 2012 the answer was about a billion. By 2026 it was under 100,000, a ten-thousandfold drop in fourteen years. Almost none of that came from better hardware. It came from better methods: cheaper arithmetic, and error correction that wastes fewer qubits.
The rings along the bottom are machines that were actually built. Gate-based machines grew from 53 qubits in 2019 to 1,121 in 2023, and none larger has been announced since. Companies have instead built smaller chips with fewer errors, because a large machine full of errors can't run long programs.
Why the qubit count isn't the whole story
Error rate. Nearly every estimate assumes qubits that fail about once in a thousand operations (0.1%). The best machines now reach that: about 0.08% for Quantinuum's trapped ions and 0.14% to 0.33% for Google's Willow. They do it with around a hundred qubits, not a hundred thousand.
Time. Fewer qubits usually means a longer run. Iceberg Quantum's 94,000-qubit plan takes about a month per key. Finishing in a day takes about 381,000.
Wiring. The lowest estimates use error-correcting codes that need links between qubits far apart on the chip. Today's superconducting chips only link neighbours. Neutral atoms can be physically moved next to each other, which is why the Caltech-led estimate gets down to about 10,000 of them, at the cost of running for months or longer.
Atom arrays. The dashed rings, at 6,100 and 11,000, are atoms held in place by lasers. None of those arrays has yet run a computation across all its atoms. They show that holding that many atoms is possible, which is one step of several.
The real factoring record is 15
The largest number factored by Shor's algorithm on real hardware, without shortcuts, is 15, in 2001. Results for 21 and larger numbers used simplified circuits that only work if you already know the answer. Factoring 21 properly needs about 2,400 two-qubit operations, against 21 for factoring 15, according to Google's Craig Gidney. The jump from there to a 617-digit RSA key is why every estimate above assumes full error correction.
Elliptic curves and Bitcoin
Elliptic-curve keys are shorter than RSA keys, so they fall to a smaller machine. In March 2026, Google researchers estimated that under 500,000 qubits could break a Bitcoin key in 18 to 23 minutes. Half that work can be done in advance, leaving about 9 minutes once a key becomes public in a transaction. A Bitcoin block takes about 10 minutes on average, so in principle a payment could be redirected before it is confirmed. Google withheld the circuits and published a cryptographic proof that they exist instead.
What to make of it
The date is uncertain and the direction isn't. Estimates have fallen about tenfold every three and a half years, and machines keep getting more reliable. Neither trend has to continue, but nobody should plan on both stopping.
That makes the real deadline earlier than Q-Day. Anything encrypted today with RSA or elliptic curves can be recorded now and decrypted later (harvest now, decrypt later), so data that must stay secret into the 2030s is already exposed. The fix exists. Post-quantum cryptography runs on ordinary computers, and Chrome, Signal and OpenSSH already use it to agree on keys by default. The slower work is in signatures, certificates and systems like Bitcoin that can only change when most of their users agree to.
All data
| When | What | Qubits |
|---|---|---|
| 2012 | Fowler, Mariantoni, Martinis and ClelandEstimate: RSA-2048, about a day | about 1 billion |
| 2019 | Gidney and EkeråEstimate: RSA-2048, 8 hours | 20 million |
| 2019 | Google SycamoreMachine built | 53 |
| 2021 | IBM EagleMachine built | 127 |
| 2022 | Webber, Elfving, Weidt and HensingerEstimate: 256-bit elliptic curve, a day | 13 million |
| 2022 | IBM OspreyMachine built | 433 |
| Oct 2023 | Atom ComputingAtoms trapped, not yet computing | 1,180 |
| Dec 2023 | IBM CondorMachine built | 1,121 |
| Dec 2024 | Google WillowMachine built | 105 |
| May 2025 | GidneyEstimate: RSA-2048, under a week | under 1 million |
| Sep 2025 | CaltechAtoms trapped, not yet computing | 6,100 |
| Nov 2025 | Quantinuum HeliosMachine built | 98 |
| Feb 2026 | Iceberg QuantumEstimate: RSA-2048, about a month | about 94,000 |
| Mar 2026 | Cain, Preskill, Bluvstein and othersEstimate: RSA-2048, months or longer | as few as 10,000 |
| Mar 2026 | Google Quantum AI, with Drake and BonehEstimate: 256-bit elliptic curve, 18 to 23 minutes | under 500,000 |
| Mar 2026 | Cain, Preskill, Bluvstein and othersEstimate: 256-bit elliptic curve, a few days | about 26,000 |
| Jun 2026 | Tsinghua UniversityAtoms trapped, not yet computing | about 11,000 |
Left off the chart: O'Gorman and Campbell (2017) counted only part of the machine, and Gouzien and Sangouard (2021) needed 13,436 qubits plus a quantum memory far beyond anything built. The 2026 Iceberg Quantum and Caltech-led estimates had not been peer-reviewed when added.