Updated October 11, 2026

How close are quantum computers to breaking encryption?

Closer than a few years ago, and still well short. The leanest published plan for breaking RSA-2048 on a chip needs about 94,000 qubits and a month of running time. The largest quantum computer that runs full computations has 1,121 qubits.

  • ●Estimate: RSA-2048
  • ■Estimate: 256-bit elliptic curve
  • ○Machine built
  • ◌Atoms trapped, not yet computing

Tap a point, or step through them in date order.

Embed

Paste this into any web page to show this simulation there.

Two lines heading toward each other

The dots along the top are estimates of how many physical qubits it would take to run Shor's algorithm against the encryption most of the internet uses. In 2012 the answer was about a billion. By 2026 it was under 100,000, a ten-thousandfold drop in fourteen years. Almost none of that came from better hardware. It came from better methods: cheaper arithmetic, and error correction that wastes fewer qubits.

The rings along the bottom are machines that were actually built. Gate-based machines grew from 53 qubits in 2019 to 1,121 in 2023, and none larger has been announced since. Companies have instead built smaller chips with fewer errors, because a large machine full of errors can't run long programs.

Why the qubit count isn't the whole story

Error rate. Nearly every estimate assumes qubits that fail about once in a thousand operations (0.1%). The best machines now reach that: about 0.08% for Quantinuum's trapped ions and 0.14% to 0.33% for Google's Willow. They do it with around a hundred qubits, not a hundred thousand.

Time. Fewer qubits usually means a longer run. Iceberg Quantum's 94,000-qubit plan takes about a month per key. Finishing in a day takes about 381,000.

Wiring. The lowest estimates use error-correcting codes that need links between qubits far apart on the chip. Today's superconducting chips only link neighbours. Neutral atoms can be physically moved next to each other, which is why the Caltech-led estimate gets down to about 10,000 of them, at the cost of running for months or longer.

Atom arrays. The dashed rings, at 6,100 and 11,000, are atoms held in place by lasers. None of those arrays has yet run a computation across all its atoms. They show that holding that many atoms is possible, which is one step of several.

The real factoring record is 15

The largest number factored by Shor's algorithm on real hardware, without shortcuts, is 15, in 2001. Results for 21 and larger numbers used simplified circuits that only work if you already know the answer. Factoring 21 properly needs about 2,400 two-qubit operations, against 21 for factoring 15, according to Google's Craig Gidney. The jump from there to a 617-digit RSA key is why every estimate above assumes full error correction.

Elliptic curves and Bitcoin

Elliptic-curve keys are shorter than RSA keys, so they fall to a smaller machine. In March 2026, Google researchers estimated that under 500,000 qubits could break a Bitcoin key in 18 to 23 minutes. Half that work can be done in advance, leaving about 9 minutes once a key becomes public in a transaction. A Bitcoin block takes about 10 minutes on average, so in principle a payment could be redirected before it is confirmed. Google withheld the circuits and published a cryptographic proof that they exist instead.

What to make of it

The date is uncertain and the direction isn't. Estimates have fallen about tenfold every three and a half years, and machines keep getting more reliable. Neither trend has to continue, but nobody should plan on both stopping.

That makes the real deadline earlier than Q-Day. Anything encrypted today with RSA or elliptic curves can be recorded now and decrypted later (harvest now, decrypt later), so data that must stay secret into the 2030s is already exposed. The fix exists. Post-quantum cryptography runs on ordinary computers, and Chrome, Signal and OpenSSH already use it to agree on keys by default. The slower work is in signatures, certificates and systems like Bitcoin that can only change when most of their users agree to.

All data

WhenWhatQubits
2012Fowler, Mariantoni, Martinis and ClelandEstimate: RSA-2048, about a dayabout 1 billion
2019Gidney and EkeråEstimate: RSA-2048, 8 hours20 million
2019Google SycamoreMachine built53
2021IBM EagleMachine built127
2022Webber, Elfving, Weidt and HensingerEstimate: 256-bit elliptic curve, a day13 million
2022IBM OspreyMachine built433
Oct 2023Atom ComputingAtoms trapped, not yet computing1,180
Dec 2023IBM CondorMachine built1,121
Dec 2024Google WillowMachine built105
May 2025GidneyEstimate: RSA-2048, under a weekunder 1 million
Sep 2025CaltechAtoms trapped, not yet computing6,100
Nov 2025Quantinuum HeliosMachine built98
Feb 2026Iceberg QuantumEstimate: RSA-2048, about a monthabout 94,000
Mar 2026Cain, Preskill, Bluvstein and othersEstimate: RSA-2048, months or longeras few as 10,000
Mar 2026Google Quantum AI, with Drake and BonehEstimate: 256-bit elliptic curve, 18 to 23 minutesunder 500,000
Mar 2026Cain, Preskill, Bluvstein and othersEstimate: 256-bit elliptic curve, a few daysabout 26,000
Jun 2026Tsinghua UniversityAtoms trapped, not yet computingabout 11,000

Left off the chart: O'Gorman and Campbell (2017) counted only part of the machine, and Gouzien and Sangouard (2021) needed 13,436 qubits plus a quantum memory far beyond anything built. The 2026 Iceberg Quantum and Caltech-led estimates had not been peer-reviewed when added.