Q-Day Countdown

Explainer

How Many Qubits Does It Take to Break RSA-2048?

September 25, 2026  ·  qdayiscoming.com

Log-scale chart comparing estimates of the qubits needed to break RSA-2048 with what exists: physical-qubit estimates falling from 20 million in 2019 to under one million in 2025 and 10,000 to 100,000 in 2026 papers, against a 6,100-atom array and the 98-qubit Helios-1; about 1,399 logical qubits needed, 100 to 200 targeted by the US Department of Energy, and 8 measured

The estimate has fallen from 20 million physical qubits (2019) to under a million (2025), and 2026 papers go lower still. What has been built and measured sits far below every line.

By the most widely cited estimate, breaking RSA-2048 takes about 1,400 error-corrected “logical” qubits, built from just under one million physical qubits and running for less than a week. That is the 2025 estimate by Google researcher Craig Gidney. In an independent benchmark published by Sandia National Laboratories this month, Quantinuum’s Helios-1 ran fully error-corrected programs on eight logical qubits.

So the honest answer has two parts: what is needed, and what exists. Both are moving. Below, every serious estimate since 2019 sits next to what has actually been built, with a link to each source.

Physical qubits and logical qubits are not the same thing

A qubit is the basic unit of a quantum computer. A physical qubit is one piece of hardware: a trapped ion, a single atom or a tiny superconducting circuit. Physical qubits make mistakes. Heat, stray light and vibration knock them off course.

A logical qubit is a group of physical qubits that works as one reliable qubit. The group checks itself all the time and repairs errors before they spread. This is called quantum error correction.

Think of a choir holding one note. Single singers drift off key, but because they listen to each other, the choir keeps the note. The singers are the physical qubits. The note is the logical qubit.

That reliability is expensive. In Gidney’s design, each logical qubit in active use takes 1,352 physical qubits; logical qubits in storage are packed more tightly, at 430 each (section 3.2). That is why one number is about 1,400 and the other about a million. For the basics, see how a quantum computer works; for the attack itself, see Shor’s algorithm explained.

How the estimate fell, 2019 to 2026

YearResearchersPhysical qubitsLogical qubitsRun time
2019Gidney & Ekerå20 millionabout 6,200*8 hours
2025Gidneyunder 1 million1,399under a week
2026Webster, Cohen et al. (Iceberg Quantum)under 100,000—about a month
2026Cain et al. (Caltech, UC Berkeley, Oratomic)from 10,000 atoms—longer still**

* The 2019 paper gives a formula, not one number: three logical qubits per bit of the key, plus a little. For a 2048-bit key that comes to about 6,200.
** The paper says RSA-2048 takes 10 to 100 times longer than the “few days” it gives for breaking a common elliptic-curve key (P-256) on 26,000 qubits.

Two things stand out. First, the drop is steep: from 20 million to under a million in six years, a factor of twenty, and the 2026 papers claim another factor of ten or more. Second, fewer qubits usually means a slower attack. Gidney’s 2025 design needs twenty times fewer qubits than his 2019 design, but runs for days instead of hours.

Every estimate also rests on hardware that does not exist yet. The Gidney papers and the Iceberg Quantum paper all assume that only one operation in a thousand goes wrong, and that one round of error correction takes a millionth of a second. The 100,000 figure holds only under those conditions. Both 2026 papers are preprints on arXiv. We covered the first wave of these papers in three papers in three months.

What exists today

The largest collection of physical qubits is an array of 6,100 atoms, built at Caltech in 2025. It keeps them in a delicate quantum state for about 13 seconds. It does not compute with them yet: linking the atoms together, the step from storing information to calculating with it, is the team’s next goal.

The best independent measurement of real computing power comes from Sandia National Laboratories. In September 2026, a team from Sandia, Quantinuum and NVIDIA tested machines from Quantinuum, Google and IBM with a single benchmark. On Quantinuum’s Helios-1, which has 98 physical qubits, they ran fully error-corrected programs on up to 8 logical qubits.

The same paper translates RSA-2048 into its own benchmark scale, called QUOPS. RSA-2048 needs 250 million. The best score measured was 1,504. The authors put the gap at “roughly five orders of magnitude”: a factor of about 100,000.

Companies have announced higher logical-qubit counts. We leave those out of this comparison until we have checked them against a primary source.

The US government’s target: 100 logical qubits

On 17 September 2026, the US Department of Energy opened a competition worth up to $215 million for a quantum computer with at least 100 logical qubits, able to run hundreds of millions of error-corrected operations. Bonus prizes go to machines with 150 and 200. Only $2.5 million of it is money for fiscal year 2026; the rest depends on future funding decisions by Congress. Applications close on 19 October 2026.

DOE names chemistry, materials, physics and applied mathematics as the goals. Encryption is not mentioned. The comparison is ours: the top prize, 200 logical qubits, is about one seventh of the 1,399 in Gidney’s estimate.

What we do not know

Whether the assumptions hold. No machine has run error correction at anything close to a million qubits. Each estimate is only as good as the error rate it assumes.

Whether the number keeps falling. It fell twentyfold between 2019 and 2025 under the same hardware assumptions, through better methods alone. The next paper could move it again.

When. A qubit count measures distance, not a date. The NSA’s own guidance says “NSA does not know when there will be a CRQC”, a cryptographically relevant quantum computer. For what experts expect, see the Q-Day countdown and when RSA-2048 will be broken.

Why the number matters now

Data protected by RSA today can be copied now and decrypted later, once a large enough machine exists. That is the harvest now, decrypt later risk. If information has to stay secret for many years, the question is not only when such a machine arrives, but whether it arrives before that secret expires.

Sources