Fact-Check: Did a Quantum Computer Break RSA-2048 in 2026?

Fact-Check: Did a Quantum Computer Break RSA-2048 in 2026?

Fact-Check: Did a Quantum Computer Break RSA-2048 in 2026?

Last Updated: September 2026

Short answer: no. As of 30 September 2026, no quantum computer has factored an RSA-2048 modulus, and no credible, independently reproduced result says one has. The claim resurfaces every few months in a new costume: a lab announces a qubit record, a startup publishes a resource estimate, a screenshot of a “cracked” key goes around, and within hours the headline has mutated into “quantum computer broke RSA-2048.” Each time, the question to ask is whether a quantum computer can break RSA-2048 today, and the honest answer is that the largest numbers ever factored with Shor’s algorithm on real hardware are still toy-sized.

That does not mean you can relax. The estimated cost of the attack has fallen by roughly a factor of twenty since 2019, one 2026 preprint argues for another order of magnitude, and government deadlines now assume the transition must finish within about a decade. This post separates what was actually demonstrated from what was estimated, corrects several numbers that circulate in older explainers (including the first version of this article), and ends with a migration plan you can act on.

What this covers: where the viral claims come from, what Shor’s algorithm really needs, how the 2019, 2025 and 2026 resource estimates differ, what today’s hardware can and cannot do, the NIST and NSA timelines, and what to do about harvest-now-decrypt-later risk.

What Changed for September 2026

This is a full rewrite of the April 2026 fact-check. If you read the earlier version, these are the material changes.

  • The headline paper was mis-cited. The old post attributed “20 million noisy qubits in 8 hours” to a 2025 Gidney and Ekerå paper. That figure comes from their 2019 paper. The 2025 result is a single-author Gidney paper reducing the requirement to under one million noisy qubits and under a week of runtime.
  • A newer estimate now exists. A February 2026 preprint from Iceberg Quantum argues RSA-2048 might need fewer than 100,000 physical qubits using quantum LDPC codes. It is simulation-based, assumes better connectivity than current chips offer, and has not been independently validated.
  • Elliptic curves moved. In March 2026, Google Quantum AI and collaborators published resource estimates for the secp256k1 curve, reported at roughly 1,200 logical and fewer than 500,000 physical qubits. Google also publicly committed to a 2029 internal post-quantum migration target.
  • Logical-qubit claims got louder and murkier. Quantinuum’s Helios announcements (98 physical qubits, 94 error-detected and 48 error-corrected logical qubits) are real but rely on heavy post-selection and small code distances.
  • Standards moved. FIPS 203, 204 and 205 are final. FN-DSA (FIPS 206, Falcon) remains in draft, and HQC was selected in March 2025 as a backup key-encapsulation mechanism and is still in draft standardization.
  • Several numbers in the old post were wrong (ML-KEM and ML-DSA sizes, the “Gate depth 126 billion Toffoli” figure, made-up hardware names). They are corrected below.

Context and Background: Where the Viral Claims Come From

The “RSA is broken” story is not new. It has a recognizable life cycle, and knowing the pattern is the fastest fact-check.

In 2022, a Chinese group published a paper suggesting that a hybrid quantum-classical approach based on Schnorr’s factoring method could threaten RSA with a few hundred qubits. Cryptographers, including Scott Aaronson, found the scaling argument unsupported, and the claim faded within days. In October 2024, researchers in China reported using a D-Wave quantum annealer to factor a 22-bit RSA integer, and the press again wrote “RSA cracked.” A 22-bit number is about four million, and any laptop factors it in microseconds.

The pattern is consistent. A real but modest result (a proof of concept on a tiny modulus, a resource estimate, a hardware milestone) is stripped of its qualifiers, and the qualifiers are the whole story. The 2024 survey paper “The State of Factoring on Quantum Computers” (arXiv:2410.14397) states plainly that only very small integers, N of 35 or below, have been factored with Shor’s algorithm on a digital quantum computer, and it argues that many larger claims rely on circuit simplifications that make them equivalent to coin flips. Its own analysis of annealing-based factoring found exponential scaling, with the best method factoring only up to a number around 3.8 million, and at a success rate of about 0.01 percent.

Three technical facts explain why RSA-2048 is not close to falling in 2026.

First, RSA-2048 uses a modulus roughly 617 decimal digits long. The best classical attack, the general number field sieve, is sub-exponential and puts the effective strength at roughly 112 bits, which is why NIST treats RSA-2048 as a 112-bit-security primitive. Classical brute force is not a threat.

Second, the only known quantum algorithm that changes this picture is Shor’s algorithm (1994), which factors in polynomial time but needs a large, fault-tolerant machine. Grover’s algorithm, the other famous quantum speedup, gives only a quadratic gain against symmetric ciphers, which is why AES-256 and SHA-256 are considered safe against quantum attack without redesign.

Third, the distance between “a quantum computer exists” and “a quantum computer can run Shor’s algorithm at cryptographic size” is measured in error correction, not qubit counts. For a deeper look at that layer, see our explainer on quantum error correction and surface codes. For the adjacent viral claim about entanglement networks, see our quantum internet entanglement fact-check.

Authoritative context is available from NIST, whose post-quantum cryptography project tracks standards and timelines, and from the primary papers cited throughout this article.

The Reference Picture: What Breaking RSA-2048 Would Actually Take

Direct answer: For a quantum computer to break RSA-2048, it must run Shor’s algorithm on roughly a thousand or more error-corrected logical qubits for days, which the best published 2025 estimate translates into fewer than one million noisy physical qubits at 0.1 percent gate error. No device today has more than a few hundred physical qubits with the connectivity and error rates needed, and none has demonstrated fault-tolerant logical arithmetic at that scale.

Shor's algorithm pipeline showing where a quantum computer breaks RSA-2048 and where the cost concentrates

Figure 1: Shor’s algorithm splits into a classical wrapper and a quantum core. Almost all of the cost sits in the modular exponentiation step, which must be run fault-tolerantly.

Figure 1 shows the structure. Shor’s algorithm turns factoring into order finding. Pick a random number a that shares no factor with N. The function f(x) = a^x mod N is periodic, and the period r is the order of a modulo N. If r is even and a^(r/2) is not congruent to minus one mod N, then gcd(a^(r/2) minus 1, N) yields a nontrivial factor of N with good probability. The quantum computer’s only job is to find r, using modular exponentiation in superposition and a quantum Fourier transform to read out the period. Everything else, including choosing a, continued-fraction post-processing and the gcd, is classical and cheap.

That decomposition matters for fact-checking, because it tells you what a real demonstration must contain: a compiled modular-exponentiation circuit whose size is set by the modulus, not by knowledge of the answer. Toy demonstrations that factor 15 or 21 often use circuits simplified using the known factors. A demonstration that means anything for RSA-2048 would need to run the same generic arithmetic circuit for a modulus of meaningful size and produce factors that were not known in advance.

Why the Circuit Is So Expensive

The quantum Fourier transform is the famous part, but it is not where the cost is. The dominant cost is reversible modular arithmetic: multiplying and reducing 2048-bit numbers, repeatedly, without ever measuring and without leaking information. In the fault-tolerant setting, these circuits are counted in Toffoli gates (three-qubit controlled-controlled-NOT gates) because Toffolis require expensive “magic states” on a surface-code machine, while Clifford gates are comparatively cheap.

The 2019 Gidney and Ekerå estimate needed on the order of billions of Toffoli gates, and their resource model gave roughly 20 million physical qubits and about eight hours. The 2025 Gidney paper reports a reduction of more than a factor of one hundred in Toffoli count using approximate residue arithmetic, and it trades runtime for space: less than a week of run time in exchange for under a million qubits. Both figures assume a physical gate error rate of 0.1 percent, a surface-code cycle time of one microsecond, and a classical control system that reacts in 10 microseconds. These are optimistic engineering assumptions, not measured facts about any one device.

Three Ways the Estimates Differ

It is worth being precise about what each headline number represents, because they measure different things.

Estimate Year Target Physical qubits Runtime Status
Gidney and Ekerå 2019 RSA-2048 about 20 million about 8 hours Peer-reviewed resource estimate
Gidney 2025 RSA-2048 under 1 million under 1 week Preprint, widely reviewed
Iceberg Quantum, Pinnacle architecture Feb 2026 RSA-2048 under 100,000 (claimed) not the headline Simulation-based, unvalidated
Google Quantum AI et al. Mar 2026 secp256k1 (ECC) under 500,000 (reported) minutes Circuits withheld, proof-based disclosure

The pattern is that algorithmic and architectural cleverness keeps cutting the requirement, while hardware progress is slower and lumpier. The key word in every row is “estimate.” Nobody has built the machine.

Physical versus Logical Qubits, in One Paragraph

A physical qubit is a real device (a transmon, a trapped ion, a neutral atom) that suffers noise at some error rate per gate, typically around 10^-3 for the best superconducting and neutral-atom systems and better for trapped ions. A logical qubit is an encoded qubit whose error rate is suppressed by spreading the information over many physical ones with an error-correcting code. The surface code achieves this by running repeated syndrome measurements; if the physical error rate is below a threshold of roughly 1 percent, adding more physical qubits per logical qubit (increasing the code distance) exponentially suppresses the logical error rate. The overhead is severe: hundreds to over a thousand physical qubits per logical qubit at the distances that cryptographic circuits need. This is why raw qubit counts in press releases are almost meaningless for cryptographic risk.

Qubit hierarchy for quantum computer break RSA-2048 estimates showing physical to logical to algorithm layers

Figure 2: The hierarchy that turns noisy physical qubits into a Shor run. Every layer multiplies overhead, which is why estimates are quoted at the physical-qubit level.

The figure shows why an estimate of “a thousand-plus logical qubits” becomes “under a million physical qubits”: the code, the magic-state factories and the routing space multiply the logical count by hundreds. The 2025 paper’s yoked surface codes and magic state cultivation are specifically techniques for shaving that multiplier.

Deeper Analysis: The Hardware Gap in Numbers

Now compare the requirement to what has been built. The table below lists representative systems, deliberately using only well-documented figures and flagging what each number means.

System Organization Physical qubits What is actually demonstrated
Condor IBM 1,121 (2023) Large chip, not error-corrected, IBM shifted focus to modular, lower-error chips afterwards
Willow Google Quantum AI 105 (Dec 2024) Below-threshold surface code memory up to distance 7
Neutral-atom arrays Atom Computing and others around 1,000 atoms Large arrays, limited fidelity and gate depth
Helios Quantinuum 98 (Nov 2025) Trapped-ion system with very high gate fidelity, plus error-detected logical qubit demonstrations

The point is not the ranking. It is that the best public demonstrations are on the order of hundreds to a thousand-plus physical qubits, while the 2025 estimate needs under a million with error rates and connectivity that no single device yet delivers at scale. The gap in raw count is roughly a factor of one thousand against the 2025 estimate, or a factor of about a hundred against the most aggressive 2026 claim. Neither gap is small, and neither is measured with the same error rates.

What Willow Really Showed

Google’s Willow result, published in Nature in December 2024, is the cleanest evidence that quantum error correction works as theory predicts. The team ran surface codes at distance 3, 5 and 7 and observed the logical error rate falling by about a factor of two each time the distance increased, which is the definition of operating below threshold. The distance-7 logical memory had a per-cycle error of roughly 0.14 percent, and it outlived its best constituent physical qubit.

That is a milestone about quantum memory, not computation. Storing a logical qubit reliably is much easier than performing thousands of logical gates on thousands of logical qubits, with magic states, for days. Willow does not run Shor’s algorithm, and Google does not claim it does. For the mechanics, see our surface code explainer.

The Logical-Qubit Record Race

The phrase “logical qubits” has become a marketing battleground. Quantinuum’s Helios announcement is a good case study. The company reported 94 error-detected logical qubits and 48 error-corrected logical qubits on 98 physical qubits, using families of iceberg codes. These are genuine experiments, and the physical-to-logical ratios are very low.

The caveats are what matter. Distance-2 iceberg codes only detect errors, so any detected error means the shot is discarded. Analyses of the results note that for deeper circuits more than 96 percent of shots were thrown away, with acceptance rates falling from about 62 percent to about 3 percent as depth increased. Post-selection does not scale to a computation that must run for days. The codes also lean on all-to-all connectivity that trapped ions have and superconducting chips do not.

A useful rule: a logical-qubit claim is only relevant to cryptography if it names the code distance, the logical error rate per gate, whether errors are corrected in real time or merely post-selected, and whether it supports universal logical gates. Most press coverage names none of these.

Why “1,000 Qubits” Headlines Mislead

The number that was widely shared in 2026 headlines is a raw physical qubit count. Reading it as logical capacity is off by two to three orders of magnitude. The old version of this post said a thousand physical qubits are needed per logical qubit and then computed “2 billion physical qubits” for a million logical qubits. That arithmetic mixed two different regimes. The million-logical-qubit figure was a rough public-conversation shorthand and not what the 2025 paper computes; the paper’s own architecture is far more economical because most logical qubits sit idle in dense storage.

The correct way to say it: the required logical-qubit count is in the low thousands, the physical overhead per logical qubit is in the hundreds, and the estimate therefore lands under a million physical qubits, not billions.

Reading the Iceberg Quantum Claim Carefully

The February 2026 Iceberg Quantum preprint deserves neither hype nor dismissal. It proposes a “Pinnacle” architecture built on quantum low-density parity-check (QLDPC) codes, which encode many logical qubits per code block with far less overhead than surface codes. Under its assumptions, RSA-2048 requires fewer than 100,000 physical qubits.

Three caveats apply. QLDPC codes need long-range qubit connections that are natural for neutral atoms and trapped ions but hard on fixed 2D superconducting chips. The decoder must keep up in real time with a very large code, and that has not been shown at scale. And the result comes from a startup, based on simulation and resource estimation, and has not been independently validated. The right response is “a plausible reduction to track,” not “the timeline just moved by a decade.”

Google’s March 2026 Elliptic-Curve Estimate

The most consequential 2026 development is not about RSA. In late March 2026, a Google Quantum AI paper with collaborators from Stanford, Berkeley and the Ethereum Foundation reported resource estimates for attacking the secp256k1 curve, used by Bitcoin and Ethereum, at roughly 1,200 logical qubits and fewer than 500,000 physical qubits, with runtimes of order ten minutes on a fast-clock superconducting machine. Reporting says the authors withheld the actual circuits and published a zero-knowledge proof of their claim instead.

Elliptic-curve keys are smaller than RSA keys, so the quantum circuit is smaller. This is well known: ECC-256 falls before RSA-2048 in most estimates. Our analysis of the quantum threat to elliptic curve cryptography covers the mechanism. The practical takeaway is that TLS key exchange based on X25519 and ECDSA signatures are on the same clock as RSA, or slightly ahead of it.

How Shor’s Algorithm Scales, and Why Toy Demos Prove Little

Consider the two extremes of “factoring on a quantum computer”.

A textbook demonstration factors 15 into 3 times 5. The compiled circuit for a=7 or a=11 uses only a handful of gates and is known to be simplifiable. Published analyses show that with knowledge of the factors, one can hard-code the circuit and get the right answer with almost no genuine quantum period finding. Factoring 21 and 35 has been done with similar shortcuts, and honest attempts at 35 on early IBM hardware failed.

A cryptographic demonstration would require the general circuit. The gate count for n-bit modular exponentiation grows roughly as n cubed with schoolbook multiplication, and the memory and error correction overhead multiplies it. Going from a 4-bit number to a 2048-bit number multiplies circuit size by a factor on the order of 10^8 to 10^9 before error correction. The gap between a working 4-bit demo and a working 2048-bit run is therefore not a matter of adding a few qubits.

The largest number factored “with Shor’s algorithm” in the largest simulations is a 39-bit integer, reported in the 2024 survey, run on a classical supercomputer with thousands of GPUs. That is a useful benchmark for readers: classical simulation of Shor’s algorithm is already ahead of every quantum hardware demonstration.

A Checklist for Judging the Next Headline

When a new viral claim appears, run it through these questions. Most claims fail the first or second.

  1. What is the modulus size in bits? RSA-2048 means 2,048 bits. Anything under about 100 bits is classically trivial.
  2. Was the circuit generic, or compiled with knowledge of the factors?
  3. Which algorithm was used? Annealing, Schnorr-style lattice hybrids and variational methods do not scale like Shor’s algorithm.
  4. Was there error correction, or just post-selection?
  5. Who reproduced it? A press release and one preprint are not verification.
  6. Was a real RSA-2048 public key used? A published challenge modulus with independently verifiable factors is the minimum.

A real break of RSA-2048 would be followed within hours by verifiable factors of a well-known modulus, an obvious shift in government behavior, and coordinated emergency advisories from NIST, NSA, ENISA and NCSC. None of that has happened.

Post-Quantum Cryptography: The Real 2026 Story

While no machine has broken RSA-2048, the standards and deployment story is moving fast, and that is where the actionable news lives.

Where the NIST Standards Stand

In August 2024, NIST published the first three post-quantum standards:

  • FIPS 203, ML-KEM (derived from CRYSTALS-Kyber), a lattice-based key-encapsulation mechanism that replaces RSA and elliptic-curve key exchange.
  • FIPS 204, ML-DSA (derived from CRYSTALS-Dilithium), a lattice-based digital signature scheme.
  • FIPS 205, SLH-DSA (derived from SPHINCS+), a stateless hash-based signature scheme whose security rests only on hash function properties.

Two more items are in flight. FIPS 206, FN-DSA (based on Falcon) is still a draft, with final publication widely expected around late 2026 or early 2027. HQC, a code-based key-encapsulation mechanism, was selected in March 2025 as a backup to ML-KEM so that the ecosystem does not rest on lattices alone; it is in draft standardization. Check NIST’s standardization page for the current state before you cite a date in a compliance document.

Corrected Size Numbers

The first version of this post quoted sizes that were wrong, and they matter for protocol engineering. The correct figures from the standards are:

Algorithm Public key Ciphertext or signature Note
ML-KEM-768 1,184 bytes 1,088 byte ciphertext Security category 3, used in hybrid TLS
ML-DSA-44 1,312 bytes 2,420 byte signature Category 2
ML-DSA-65 1,952 bytes 3,309 byte signature Category 3
SLH-DSA-128s 32 bytes 7,856 byte signature Small variant, slow to sign
SLH-DSA-128f 32 bytes 17,088 byte signature Fast variant
RSA-2048 (for reference) 256 byte modulus 256 byte signature Classical

Signatures are the pain point. A TLS handshake typically carries a certificate chain with several signatures and public keys, so replacing RSA-2048 or ECDSA P-256 with ML-DSA-65 adds many kilobytes to the handshake. That is manageable on broadband, but it matters on constrained links, in DTLS over UDP, and in firmware signing where images and manifests are size-sensitive. For OT and embedded contexts, see our guide to secure OTA firmware update architecture.

Deployment Has Outrun the Headlines

Hybrid post-quantum key exchange is already mainstream on the public web. Chrome and other Chromium browsers enabled a hybrid of X25519 and ML-KEM-768 by default, Cloudflare and other CDNs support it at the edge, OpenSSL 3.5 (April 2025) added ML-KEM, ML-DSA and SLH-DSA, and OpenSSH 10.0 made a hybrid ML-KEM plus X25519 exchange the default. Apple’s iMessage PQ3 protocol added post-quantum protection in 2024. Google and Cloudflare have both talked about 2029 as a target for broad post-quantum migration; treat those as public statements of intent and verify specifics against their current blogs.

The old post’s claims that “Apple rolled out PQ TLS for iCloud+ in Q1 2026” and that Chrome was “experimenting” were unsourced and out of date; they are removed.

The Hybrid Key Exchange in Practice

Hybrid means running a classical and a post-quantum key exchange in parallel and combining both outputs into the session secret, so the session stays safe unless both are broken.

Hybrid X25519 plus ML-KEM-768 TLS 1.3 handshake, a practical defense after fact-checking whether a quantum computer can break RSA-2048

Figure 3: In a hybrid TLS 1.3 handshake both key shares travel in the same ClientHello and ServerHello, and the shared secret is derived from the concatenated outputs.

Figure 3 shows the flow. The client sends both an X25519 share and an ML-KEM-768 encapsulation key in one message. The server encapsulates to the ML-KEM key, completes X25519, and returns both. Each side then feeds the concatenation of the two shared secrets into the TLS 1.3 key schedule (HKDF). The cost is about 1,184 bytes extra in the client message and 1,088 in the server response, which fits in a couple of extra packets.

This structure defends against both failure modes. If a quantum computer arrives, the ML-KEM half still protects the session. If someone finds a classical break of the newer lattice scheme, the X25519 half still protects it. The old post’s formula, HKDF(X25519 || ML-KEM), is correct in spirit, though real protocols also bind transcript context into the derivation.

Timeline Reality: Government Deadlines and Expert Estimates

Nobody can date the arrival of a cryptographically relevant quantum computer (CRQC) with confidence, and any specific year you read in an article is somebody’s estimate. What you can date is the policy response.

Deadlines You Can Actually Cite

  • NIST IR 8547 (initial public draft, November 2024). It proposes deprecating quantum-vulnerable algorithms providing about 112 bits of security (including RSA-2048 and ECC P-256) after 2030, and disallowing all quantum-vulnerable public-key algorithms after 2035. It is a draft, so check whether a final version has been issued before quoting dates in a policy.
  • NSA CNSA 2.0. New national security system acquisitions are expected to be CNSA 2.0 compliant from January 2027, with full transitions for different system classes through the early-to-mid 2030s.
  • Vendors. Google has publicly committed to migrating its own infrastructure by 2029, and Cloudflare has described a similar 2029 goal.

Note the reasoning. The deadlines are not “the date the quantum computer arrives.” They are the date a careful bureaucracy thinks it needs to have finished migrating, given that migrations of this kind typically take 10 to 15 years.

What the Experts Actually Say

The old post claimed that “70 percent of cryptography experts estimate the CRQC window as 2030 to 2035” and quoted a NIST 2022 statement about breaking RSA “by 2030 to 2060.” Neither could be verified and both are removed. What can be said with support:

  • The Global Risk Institute’s annual expert survey has for years reported that a meaningful fraction of respondents assign a significant probability to a CRQC within 10 to 15 years, with wide spread. Consult the latest edition directly rather than trusting a summary.
  • Public estimates of resource requirements have fallen roughly twentyfold between 2019 and 2025, and reports in 2026 argue for a possible further reduction. Resource estimates are not arrival dates.
  • Even proponents of near-term dates acknowledge that hardware would need to jump from hundreds of high-quality physical qubits to hundreds of thousands, with real-time decoding, in a handful of years.

A defensible summary: a CRQC before 2030 is unlikely but not impossible, the early-to-mid 2030s is a plausible window that is uncomfortable for planners, and later is possible. Because migration takes a decade, the right planning date is “as soon as you can.”

Why the Timeline Is Genuinely Uncertain

The uncertainty comes from three moving parts, and each can surprise in either direction.

  1. Algorithms. Between 2019 and 2025 the software side cut the qubit requirement by about a factor of twenty without any hardware change. Further reductions from better arithmetic, codes and layouts are plausible.
  2. Error correction. Willow showed below-threshold scaling on a small memory. Scaling it to thousands of logical qubits with universal gates is an engineering problem no one has yet solved, and it involves cryogenic wiring, fabrication yield, decoders and leakage errors.
  3. Manufacturing and cost. Even if the physics works, building and running a machine with hundreds of thousands of physical qubits is a national-scale project. That constrains who could build one first.

There is also a disclosure problem. The March 2026 ECC paper’s authors withheld circuits, a sign that the research community itself now treats the topic as dual-use. If a state-level actor achieved a CRQC first, there might be no public announcement at all, which is precisely why planning cannot wait for one.

Harvest Now, Decrypt Later: The Threat That Is Real Today

RSA-2048 is not broken today, but confidentiality is a time-shifted property. Data encrypted now can be recorded now and decrypted later.

Harvest now decrypt later threat model and the secrecy lifetime rule that determines migration urgency

Figure 4: The harvest-now-decrypt-later attack, and the simple inequality that tells you whether your data is exposed.

The attack in Figure 4 has three stages. An adversary captures encrypted traffic today, whether TLS sessions, VPN tunnels, or archived messages. They store it cheaply. When a CRQC exists, they run Shor’s algorithm against the recorded key exchanges and recover session keys.

Mosca’s Inequality

Michele Mosca formalized the decision. Let X be how long your data must stay secret, Y how long your migration will take, and Z the time until a CRQC. If X plus Y exceeds Z, you have a problem today. If your data has a 15-year secrecy requirement (medical records, industrial designs, long-lived credentials, government secrets), and your migration will take 8 years, then you are exposed unless a CRQC is more than 23 years away. Nobody can promise that.

This is why key exchange is the first priority. It is also why the risk is asymmetric:

  • Confidentiality of recorded traffic is exposed retroactively. A hybrid key exchange deployed today protects sessions recorded from today onward, and nothing can protect traffic already captured under RSA or classical ECDH key exchange.
  • Authentication and signatures are only exposed at the moment the attacker can forge them. A signature checked and discarded today cannot be forged retroactively. The urgent exceptions are long-lived signatures (firmware, root certificates, legal documents) that will still be trusted in 2035.

The old post claimed specific agencies were assumed to run harvesting campaigns. That is plausible policy reasoning, and official guidance from several governments treats it as a working assumption, but naming specific agencies as fact was unsupported and is removed.

What HNDL Does Not Mean

Not everything is at risk. Symmetric encryption with 256-bit keys (AES-256), hash functions such as SHA-256 and SHA-3, and password storage using argon2 or bcrypt are not broken by Shor’s algorithm. Grover’s algorithm gives a quadratic speedup, so 128-bit symmetric keys drop to roughly 64-bit-equivalent quantum search cost, which is why AES-256 is the conservative choice. Password guessing does not become meaningfully easier. If your traffic uses a pre-shared symmetric key that is never sent over a public-key exchange, HNDL does not apply to that link.

Trade-offs, Gotchas, and What Goes Wrong

Migration is not free, and rushed migration has its own failure modes.

Handshake bloat and fragmentation. ML-KEM-768 adds a little over a kilobyte in each direction. Larger client messages can exceed one packet and trip on middleboxes that mishandle fragmented ClientHello messages. Early deployments hit exactly this problem with a small percentage of enterprise networks. Test through your real proxies, firewalls and load balancers.

Certificate chain size. ML-DSA-65 signatures are about 3.3 KB each and public keys about 2 KB. A chain of three certificates can grow from a few hundred bytes of signature material to over 10 KB. That affects latency on high-loss links and memory on constrained devices. Certificate compression, session resumption and reduced chain depth help, and the Web PKI’s post-quantum authentication story is intentionally slower than key exchange because of these costs.

Constrained and long-lived devices. Devices that cannot be updated, such as industrial controllers, meters and implanted or embedded hardware, may run for 15 to 25 years. If they ship today with only RSA or ECC roots of trust, they need a firmware-update path that can add post-quantum verification later. Stateful hash-based signatures (LMS and XMSS, standardized in NIST SP 800-208) are already viable for firmware signing, at the cost of careful state management. For industrial environments, our guides on zero trust in industrial OT and IoT and IEC 62443 zones and conduits explain how to segment while you migrate.

Implementation risk. Lattice implementations are newer than RSA or X25519 code, and side-channel and implementation bugs are more likely to appear in early libraries. Use vetted libraries (for example OpenSSL 3.5 or later, BoringSSL, liboqs for prototypes) and track advisories.

Cryptographic risk. Lattice cryptography has held up well under years of public analysis, but it is younger than factoring. The 2022 break of the SIKE candidate by a classical attack on a laptop is the standing reminder that a promising post-quantum scheme can fail. That is exactly why hybrids exist and why HQC was selected as a non-lattice backup.

Compliance theater. Publishing a “PQC roadmap” without an inventory of where cryptography lives does nothing. Most organizations cannot yet answer where RSA is used in their estate.

For a step-by-step engineering plan, our post-quantum cryptography migration and crypto-agility guide goes deeper.

Practical Recommendations

Treat the fact-check as the opening argument for a migration project, not a reason to panic or to relax.

Start by inventorying cryptographic use: every TLS endpoint, VPN, SSH host, code-signing key, certificate authority, HSM, embedded root of trust, database encryption scheme and third-party API. Tag each with the secrecy lifetime of the data it protects and the update path of the component. Apply Mosca’s inequality to prioritize.

Then move in this order. Enable hybrid key exchange first on the edge and on internal service-to-service links, because it needs no PKI change and defends against HNDL. Next, build crypto agility, meaning algorithms are configuration and not compiled constants, so you can swap them later. Then plan the signature migration, which is slower because it touches PKI, hardware and standards still in flux.

  • [ ] Inventory all uses of RSA, ECDH, ECDSA and DH, with data lifetimes
  • [ ] Enable X25519MLKEM768 hybrid key exchange on public endpoints and test through middleboxes
  • [ ] Move long-lived secrets (archives, backups, key wrap) to ML-KEM based schemes
  • [ ] Put post-quantum verification into firmware and bootloaders for devices that ship this year
  • [ ] Adopt crypto-agile designs and record algorithm identifiers in stored data
  • [ ] Track NIST IR 8547, FIPS 206 and the HQC draft, and your sector regulator’s deadlines
  • [ ] Ask every vendor for their PQC roadmap in writing
  • [ ] Do not rely on QKD or unvetted “quantum-proof” products

For individuals, the advice is short. Keep browsers, operating systems and messaging apps updated, since most of the hybrid key exchange arrives through updates. Use a password manager with long random passwords; quantum computers do not change that math meaningfully. Ignore any product that sells “quantum-proof encryption” without naming FIPS 203, 204 or 205.

Frequently Asked Questions

Has a quantum computer ever factored RSA-2048?

No. The largest integers factored with Shor’s algorithm on real digital quantum hardware are tiny, on the order of 15, 21 and 35, and even those often used circuits simplified with prior knowledge of the answer. Annealing experiments have factored numbers of about 22 to 23 bits, which are trivial for a laptop. RSA-2048 has 2,048 bits. Any credible break would come with verifiable factors of a public modulus and independent reproduction, and none exists as of September 2026.

How many qubits would it take to break RSA-2048?

The best-known peer-reviewed estimate is under one million noisy physical qubits, at 0.1 percent gate error, running for under a week (Gidney, 2025). That improved on a 2019 estimate of about 20 million qubits for eight hours. A February 2026 preprint claims fewer than 100,000 with QLDPC codes, but it is unvalidated. Current machines have hundreds to about a thousand physical qubits, without fault-tolerant arithmetic at the required scale.

Is 20 million qubits still the right number?

No. Twenty million qubits comes from the 2019 Gidney and Ekerå paper, and it was superseded by Gidney’s May 2025 estimate of under one million. The older figure still circulates because it has a memorable headline of eight hours. Estimates depend heavily on assumed error rate, qubit connectivity, cycle time and code choice, so treat every number as an engineering model, not a measurement of any existing device.

When will a quantum computer be able to break RSA-2048?

Nobody knows. Expert opinion is spread from the end of this decade to well past 2040, and estimates have shifted earlier as algorithms improved. Planning guidance from NIST proposes deprecating RSA-2048 after 2030 and disallowing it after 2035, and Google has set a 2029 internal migration goal. Those are migration deadlines, chosen because transitions are slow, and not predictions of the arrival date.

Do I need to worry about harvest now, decrypt later?

If your data must stay confidential for 10 years or more, yes. Adversaries can record encrypted traffic today and decrypt it once a capable machine exists. The mitigation is to move key exchange to a hybrid scheme such as X25519 plus ML-KEM-768 now. Data protected by AES-256 with keys that were never exchanged via RSA or elliptic curves is not exposed in the same way, and passwords are not affected.

Are my passwords or Bitcoin safe from quantum computers?

Passwords hashed with argon2 or bcrypt are not weakened meaningfully by quantum computers. Bitcoin and Ethereum are more exposed than passwords, because they use elliptic-curve signatures, which Shor’s algorithm also breaks, and the March 2026 Google estimate targeted exactly that curve. It remains a resource estimate, not an attack, and the blockchain community is discussing post-quantum signature migration. Reused addresses with exposed public keys are the highest-risk case.

Further Reading

Internal:

External:

By Riju — about

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *