JoS QUANTUM’s Post

Everyone asks how many qubits it takes to break RSA or ECC. It's the wrong question. The number that matters isn't qubit count — it's how efficiently Shor's algorithm compiles into fault-tolerant gates, and how much overhead error correction adds on top. And that overhead has been falling fast: → RSA-2048: from 20 million noisy qubits (2019) to under 1 million (2025) — same hardware assumptions. → ECC-256: from ~9 million physical qubits (2023) to under 500,000, in about nine minutes (2026). Hardware is improving steadily. But the part most people underestimate is that algorithmic and error-correction requirements can drop by orders of magnitude — which is exactly why the timeline keeps compressing even when the chips stand still. No cryptographically relevant quantum computer exists yet. What's changed is the shape of the target. We wrote up where the real bottleneck sits — the T-gate and magic-state distillation — and what the collapsing estimates mean for the post-quantum migration. Link in comments. #QuantumComputing #PostQuantum #Cryptography #QEC #QuantumSecurity

To view or add a comment, sign in

Explore content categories