🔭 Futures

Quantum computer uses Shor's algorithm to factor a 2,048-bit RSA integer

draft conf: low
Trigger
A quantum computer uses Shor's algorithm (or a direct descendant exploiting quantum period-finding) to factor a 2,048-bit RSA integer, with the factorization independently verified. The integer need not be an RSA challenge number — any 2,048-bit semiprime counts.
Timeline
2027
2030
2033
2036
2040
2045
2050
P10 2033
P50 2039
P90 → 2055
38 sources last updated: 2026-05-27 View raw .md ↗
Prediction history
1 entry · latest first
  1. 2026-05-27
    P10 2033 · P50 2039 · P90 2055
    Initial estimate from initial research.
Key dependencies — watch these
  • Logical qubit count reaching 1,000 accelerates
    Gidney 2025 requires ~1,399 logical qubits; current best is 96 (QuEra), so crossing 1,000 is the binding hardware threshold that unlocks the gate.
  • Sustained fault-tolerant operation one week delays
    Longest demonstrated coherent computation is minutes; scaling to the required 5+ continuous days is potentially the hardest remaining sub-gate (P50 2035) and could push Q-Day well into the 2040s.
  • QLDPC / non-surface-code error correction accelerates
    Iceberg Quantum's QLDPC architecture claims 10x qubit reduction to ~100k physical qubits, potentially cutting years off the timeline if non-nearest-neighbor connectivity proves buildable.
  • Topological qubit hardware breakthrough both
    Microsoft Majorana-1 could eliminate massive error-correction overhead and dramatically compress the timeline, but the physics remains contested and Microsoft's 20-year development history signals deep difficulty.
  • §
    NIST post-quantum migration completion both
    If PQC migration completes before Q-Day (NIST target 2035), economic disruption is averted and the gate's impact is positive; if migration lags, a premature Q-Day puts $2-3.3T GDP at risk from a single attack.
  • Classified state-level quantum programs accelerates
    China and US national-security programs are opaque; a classified breakthrough could mean Q-Day arrives years before public disclosure, with 'harvest now, decrypt later' attacks already underway.
  • AI/ML applied to error correction (AlphaQubit), circuit optimization, and algorithm research modestly accelerates progress, though the binding constraint is hardware engineering rather than software.

TL;DR

I put the P50 at 2039 for a quantum computer to factor a 2,048-bit RSA integer using Shor’s algorithm. The P10 is 2033 (aggressive vendor roadmaps hold, QLDPC or topological breakthroughs compress the timeline, and the Gidney/Iceberg resource reductions translate directly to hardware) and the P90 is 2055 (error correction hits a scaling wall, decoherence remains intractable at >100k qubits, or sustained week-long fault-tolerant operation proves far harder than projected). The key insight driving this estimate: three papers published between May 2025 and March 2026 dropped the estimated physical qubit requirement from ~20 million to under 100,000 — a 200x reduction in seven years of algorithmic progress. But the gap between “theoretical qubit count” and “engineered system that actually runs for five days straight” is where most of the remaining uncertainty lives. As of May 2026, the largest number reliably factored by Shor’s algorithm is 21 (done in 2012), and the largest quantum-assisted factorization of any kind is a 48-bit number using a hybrid approach on 10 qubits. The chasm between 48 bits and 2,048 bits remains enormous — roughly 2,000 bits of scaling that requires not just more qubits, but fundamentally new engineering for error correction, sustained operation, and classical control at unprecedented scale.

Current state (as of 2026-05-27)

Hardware qubit counts and fidelity:

  • Google Willow: 105 qubits (superconducting), first to demonstrate below-threshold surface code error correction (distance-7, 0.143% error per cycle), logical qubit lifetime 2.4x best physical qubit [1][2]
  • China’s Zuchongzhi 3.0: 105 qubits (superconducting), 99.90% single-qubit / 99.62% two-qubit gate fidelity, claims 10^6x speedup over Google Sycamore on random circuit sampling [3]
  • China’s Tianyan-504: 504 qubits (superconducting), China’s largest as of Dec 2024 [4]
  • Quantinuum Helios: 48 logical qubits (trapped ion), highest gate fidelity in industry [5]
  • QuEra: 96 verified logical qubits (neutral atom), 1000+ atom arrays demonstrated [6]
  • IBM Condor: 1,121 physical qubits (superconducting), Heron at 156 qubits with improved error rates [7]
  • Microsoft Majorana-1: First topological qubit QPU (Feb 2025), claims million-qubit-on-chip scaling potential, but scientific reception mixed [8]
  • IonQ: trapped-ion approach, converging on 99.99% two-qubit fidelity [9]

Factoring records:

  • Largest number factored by Shor’s algorithm specifically: 21 (2012) [10]
  • Largest quantum-assisted factorization: 48-bit integer (261,980,999,226,229) using hybrid SQIF method on 10 superconducting qubits (Chinese team, Dec 2022) [11]
  • Largest Shor simulation on classical GPU: 549,755,813,701 (~40 bits) [12]
  • Shanghai University quantum-annealing factorization: 90-bit RSA number, largest to date via quantum annealing [13]

Resource estimates for RSA-2048 (theoretical):

  • Gidney & Ekera 2019: ~20 million noisy qubits, 8 hours [14]
  • Gidney May 2025: <1 million noisy qubits, <1 week — 20x reduction via approximate residue arithmetic, yoked surface codes, magic state cultivation [15]
  • Iceberg Quantum Feb 2026: <100,000 physical qubits using QLDPC codes (Pinnacle Architecture) — another 10x reduction, but requires non-nearest-neighbor connectivity, validated by simulation only [16]
  • Preskill et al. March 2026 (arXiv:2603.28627): ~10,000 reconfigurable atomic (neutral-atom) qubits theoretically sufficient, though runtime is 1-2 orders of magnitude longer than ECC-256 [17]
  • All estimates require gate error rates no higher than 0.1% and sustained multi-day operation [15]

Investment and industry scale:

  • Total quantum computing investment in 2025: $12.6 billion (6.3x YoY increase per McKinsey) [18]
  • Global quantum computing revenue exceeded $1 billion in 2025, projected $4.4 billion by 2028 [18]
  • BCG projects $90-170B provider market and $450-850B economic value by 2040 [19]
  • Israel’s quantum ecosystem: $500M+ raised in 2025, ranked 5th globally in investment; Classiq raised $200M+ total [20]

Key uncertainties

  1. Algorithmic vs. engineering progress mismatch. The qubit requirement has dropped from 20M to potentially 10K on paper in seven years, but hardware has gone from ~50 to ~1,100 physical qubits and from 0 to ~96 logical qubits in the same period. The algorithmic gains are stunning; the engineering gains are incremental. Whether the remaining gap closes by optimistic roadmaps (IBM 100k by 2033, IonQ 2M by 2030) or stalls is the single biggest uncertainty.

  2. Sustained fault-tolerant operation at scale. All current estimates require 5+ days of continuous fault-tolerant quantum computation. The longest demonstrated coherent computation is on the order of minutes. Scaling from minutes to days with millions of physical qubits maintaining below-threshold error rates is an unprecedented engineering challenge involving cryogenic stability, real-time classical decoding at microsecond latency, and thermal management at 10-20 millikelvin.

  3. Energy and infrastructure constraints. RAND estimates ~125 MW continuous power for a 20M-qubit system (8-hour run) at ~$64,000 per key in electricity alone. Even at 100k qubits, cooling to 10-20 millikelvin requires substantial cryogenic infrastructure. Whether a 10,000-qubit neutral-atom system at room temperature (per Preskill) changes this equation is unclear.

  4. Topological qubit wildcard. Microsoft’s Majorana-1 claims inherent error protection at the hardware level, potentially eliminating the massive qubit overhead for error correction. If topological qubits work as advertised, the timeline compresses dramatically. But the physics is contested — critics question whether Majorana zero modes have truly been demonstrated, and Microsoft’s 20-year development timeline suggests this is harder than superconducting/trapped-ion approaches.

  5. QLDPC codes and non-surface-code approaches. Iceberg Quantum’s Pinnacle Architecture claims 10x further reduction using quantum LDPC codes, but requires qubit connectivity beyond nearest-neighbor grids. If this architecture proves buildable, the 100k-qubit threshold could be sufficient. If not, surface codes remain the baseline and ~1M qubits is needed.

  6. National security race dynamics. Quantum cryptanalysis has obvious intelligence applications. State-level programs (US, China, potentially others) may achieve classified breakthroughs years before public disclosure. China’s quantum program is the least transparent; “harvest now, decrypt later” operations by state actors are assumed ongoing.

  7. Post-quantum migration pace. Even if Q-Day arrives in the 2030s, the practical impact depends on whether PQC migration is complete. NIST targets 2035 for full deprecation; enterprise migration takes 5-15 years. Organizations starting now may be safe; those delaying are exposed. The Federal Reserve estimates PQC migration will cost >$15B across the economy.

  8. Alternative factoring approaches. Hybrid quantum-classical methods (like the Chinese SQIF approach that factored 48 bits on 10 qubits) could potentially complement Shor’s algorithm. The 372-qubit claim for RSA-2048 via SQIF is widely disputed, but iterative improvement of hybrid methods adds another dimension of uncertainty.

Sub-gate deep dives

Logical qubit count reaches 1,000 (P50: 2032)

The binding constraint for RSA-2048 factoring. Gidney 2025 requires ~1,399 logical qubits running for approximately one week. Current state: Quantinuum at 48 logical qubits, QuEra at 96 verified. IBM’s roadmap: 200 (Starling, 2029), 500 (Super Starling, 2030), 1,000 (Maximum Starling, 2031), 1,500 (Blue Jay, 2032). Infleqtion targets 1,000 by 2030 on neutral atoms. IonQ projects 40,000-80,000 logical qubits by 2030 from 2M physical qubits — an aggressive claim. Microsoft/Atom Computing target 50 logical qubits (Magne) by early 2027. The trend from 0 to 96 logical qubits in ~2 years suggests exponential-ish growth, but the overhead ratio (physical:logical) currently ranges from 7:1 (QuEra) to 25:1 (Microsoft/Atom target) and needs to hold or improve at scale. P50 2032 assumes IBM-like timelines hold within ~1 year of plan, with at least one platform crossing 1,000 logical qubits.

Physical qubit count reaches 1 million (P50: 2034)

The fallback requirement if surface codes remain the dominant error correction scheme. Gidney 2025 needs <1M noisy qubits with surface codes. IBM targets 100k by 2033. PsiQuantum ($1B Series E from NVIDIA) is building a photonic system targeting fault-tolerant scale via CMOS-compatible silicon photonics — if photonic qubits work, manufacturing-style scaling could reach millions faster. China Telecom planned a 1,200+ qubit cluster by end-2025. The trajectory from 1,100 (IBM Condor, 2023) to target 100k (2033) implies ~10x/3-4 years scaling, reaching 1M around 2037 if sustained. More optimistic neutral-atom and photonic approaches could compress this. P50 2034 assumes one technology reaches the 1M threshold with adequate fidelity.

Error rate sustained below threshold at scale (P50: 2030)

Google Willow proved that adding more physical qubits to a logical qubit actually reduces the logical error rate (the “below threshold” result) on a 101-qubit distance-7 code. This is the single most important proof-of-principle result in quantum computing history. But maintaining this below-threshold performance at 10,000+ physical qubits — with the exponentially growing classical decoding overhead, increased crosstalk, and thermal management challenges — is a separate engineering question. Google DeepMind’s AlphaQubit uses ML for real-time decoding, which could help. Quantinuum’s trapped-ion approach has inherently lower error rates but slower gate speeds. P50 2030 assumes the trend continues from 100-qubit demonstrations to 1,000+ qubit systems with sustained below-threshold performance.

Sustained computation for one week (P50: 2035)

This is potentially the hardest sub-gate. No quantum computer has ever maintained coherent, error-corrected computation for more than minutes. A week of continuous surface-code operation requires: (a) cryogenic system stability at 10-20 millikelvin for 120+ hours without interruption; (b) real-time classical decoding at microsecond latency processing terabytes of syndrome data; (c) no catastrophic correlated errors across the entire system. Neutral-atom and photonic systems operating at higher temperatures could ease the cryogenic challenge. Room-temperature topological qubits (if realized) would eliminate it. P50 2035 reflects the view that this is a “last mile” engineering problem that gets solved ~3-5 years after the qubit count and error rate milestones are met.

NIST PQC migration complete (P50: 2035)

NIST published FIPS 203/204/205 in August 2024 (ML-KEM, ML-DSA, SLH-DSA). HQC selected as backup KEM in March 2025. CNSA 2.0 requires: new NSS systems quantum-safe by Jan 2027, full application migration by 2030, full infrastructure by 2035. UK NCSC issued PQC migration timelines in 2025. Browsers (Chrome, Firefox) already support hybrid PQC key exchange. Enterprise migration takes 5-15 years — discovery alone is 12-24 months. The $15B migration market is growing but most enterprises haven’t started. P50 2035 aligns with NIST’s own deprecation deadline and reflects both mandate-driven urgency and the sheer difficulty of crypto-agility at enterprise scale.

Cross-gate interactions

AI agents (ai-agent-30pct-knowledge-work, P50 2029): The connection is indirect but real. AI/ML is already being applied to quantum error correction (Google’s AlphaQubit), quantum circuit optimization (Classiq’s platform), and materials simulation. If AI agents reach 30% knowledge-work autonomy by 2029, they could accelerate quantum algorithm research and hardware control software development. However, the binding constraint for this gate is physical hardware engineering, not software — so the relationship is weak/correlates.

Metals BOM (metals-bom-30pct, P50 2031): Quantum simulation of molecular and materials properties is one of the most-cited near-term applications (BCG projects this as the first major value domain). Quantum advantage for chemistry simulation is expected in the early-to-mid 2030s — roughly contemporaneous with the metals BOM gate. If quantum simulation accelerates discovery of novel battery cathode materials, rare-earth alternatives, or magnet-free motor designs, it could modestly accelerate the metals BOM gate. Strength: weak, because classical simulation and experimental methods remain dominant for materials R&D through this timeframe.

SMR deployment (smr-first-oecd-deployment, P50 2032): Quantum simulation of nuclear materials and reactor physics is an active research area, but SMR deployment timelines are driven by regulatory approval, construction logistics, and financing — not simulation capability. Quantum computing is unlikely to materially affect the SMR gate timeline. Strength: weak/correlates.

Global explosive growth (global-economy-explosive-growth, P50 2049): This gate has a complex bidirectional relationship with quantum computing. A premature Q-Day (before PQC migration is complete) could cause catastrophic economic disruption — Citi models $2-3.3 trillion GDP at risk from a single targeted attack on US interbank payments. Conversely, a well-managed quantum transition contributes to the $450-850B economic value BCG projects by 2040, and quantum computing breakthroughs in materials science, drug discovery, and optimization would be one of many contributors to explosive growth. If Q-Day arrives after PQC migration (the P50 scenario), the net effect is strongly positive for global growth.

Sources

  1. Google Research, Quantum error correction below the surface code threshold, Nature, December 2024
  2. Google Research Blog, Dynamic surface codes open new avenues for quantum error correction, 2025
  3. Chinese Academy of Sciences / USTC, Zuchongzhi 3.0: 105-qubit processor, arXiv:2412.11924, March 2025
  4. The Quantum Insider, Chinese Team Officially Report on Zuchongzhi 3.0, March 2025
  5. Quantinuum, Helios: 48 logical qubits, November 2025
  6. Quantum Zeitgeist, Top Quantum Hardware Companies 2026
  7. IBM Quantum Roadmap
  8. Microsoft Azure Quantum Blog, Microsoft unveils Majorana 1, February 2025
  9. IonQ Roadmap
  10. PostQuantum, The State of Factoring on Quantum Computers
  11. PostQuantum, Quantum Computer Factors Record 48-Bit Number
  12. arXiv:2410.14397, The State of Factoring on Quantum Computers
  13. SpinQuanta, How Shor’s Algorithm Breaks RSA
  14. Gidney & Ekera, How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits, arXiv:1905.09749, 2019/2021
  15. Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits, arXiv:2505.15917, May 2025
  16. The Quantum Insider, New Architecture Could Cut Quantum Hardware Needed to Break RSA-2048 by Tenfold, February 2026
  17. Preskill et al., Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits, arXiv:2603.28627, March 2026
  18. McKinsey Quantum Technology Monitor 2026
  19. BCG, Quantum Computing On Track to Create Up to $850 Billion of Economic Value By 2040, July 2024
  20. Calcalist, Israel’s quantum boom: Startups hit $500 million in funding in 2025
  21. Global Risk Institute, Quantum Threat Timeline Report 2025
  22. PostQuantum, Quantum Threat Timeline Report 2025: Record Predictions
  23. IT Pro, Google just revised its Q-Day timeline: within three years, March 2026
  24. Citi Institute, Quantum Threat: The Trillion-Dollar Security Race Is On, January 2026
  25. American Banker, Citi: Banks face $3 trillion risk from quantum cyberattacks
  26. Manifold Markets, Will quantum computing break RSA encryption before 2030?
  27. Metaculus, Date of RSA-2048 quantum factorization?
  28. Metaculus, Date Quantum Algorithm Factors RSA Number
  29. NIST, Post-Quantum Cryptography Standardization
  30. NIST, Transition to Post-Quantum Cryptography Standards (NISTIR 8547 draft)
  31. UK NCSC, Timelines for migration to post-quantum cryptography
  32. PostQuantum, The Enormous Energy Cost of Breaking RSA-2048 with Quantum Computers
  33. The Quantum Insider, Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline, March 2026
  34. CNN, ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K, May 2026
  35. PR Newswire, The $15 Billion Post-Quantum Migration
  36. Infleqtion, New Architecture to Achieve 1000 Logical Qubits by 2030
  37. Riverlane, Quantum Error Correction: Our 2025 trends and 2026 predictions
  38. PostQuantum, Q-Day Revisited — RSA-2048 Broken by 2030: Detailed Analysis
Full markdown source (frontmatter + body) ▾
---
title: Quantum computer uses Shor's algorithm to factor a 2,048-bit RSA integer
status: draft
dimensions: ["technology","security","finance"]
horizon: long
trigger: A quantum computer uses Shor's algorithm (or a direct descendant exploiting quantum period-finding) to factor a 2,048-bit RSA integer, with the factorization independently verified. The integer need not be an RSA challenge number — any 2,048-bit semiprime counts.
timeline: {"p10":2033,"p50":2039,"p90":2055}
confidence: low
sub_gates: [{"slug":"logical-qubit-count-1000","p50":2032,"why":"IBM targets 1,000 logical qubits by 2031 (Maximum Starling), Infleqtion targets 1,000 by 2030 (neutral atom). Gidney 2025 needs ~1,399 logical qubits for RSA-2048. IonQ projects 40,000-80,000 logical qubits from 2M physical by 2030, but these roadmaps have historically slipped. P50 2032 balances optimistic vendor roadmaps against engineering reality."},{"slug":"physical-qubit-count-1m","p50":2034,"why":"Gidney's May 2025 paper shows <1M noisy physical qubits suffice for RSA-2048 factoring. IBM targets 100k qubits by 2033. Microsoft's Majorana-1 topological chip claims million-qubit-on-chip scalability but remains unproven. P50 2034 assumes one platform reaches 1M physical qubits with adequate fidelity."},{"slug":"error-rate-below-threshold-at-scale","p50":2030,"why":"Google Willow crossed the surface-code breakeven threshold in 2024 (distance-7 code, 0.143% error/cycle). Quantinuum delivered 48 logical qubits in late 2025. The trend is clear but scaling from 100 to 10,000+ physical qubits while maintaining below-threshold error rates is a distinct engineering challenge. P50 2030."},{"slug":"sustained-computation-1-week","p50":2035,"why":"Gidney 2025 requires ~5 days continuous fault-tolerant operation with 1-microsecond surface code cycles. Current longest coherent computations are minutes, not days. Sustained week-long fault-tolerant operation is an extreme engineering milestone requiring cryogenic stability, real-time decoding, and zero-downtime error correction at scale."},{"slug":"nist-pqc-migration-complete","p50":2035,"why":"NIST mandates full deprecation of quantum-vulnerable algorithms by 2035, with high-risk systems by 2030. NSA CNSA 2.0 requires full infrastructure migration by 2035. Enterprise migration takes 5-15 years per Citi/NIST estimates. The $15B migration is underway but nowhere near complete."}]
history: [{"date":"2026-05-27T00:00:00.000Z","p10":2033,"p50":2039,"p90":2055,"why":"Initial estimate from initial research."}]
cross_gate: [{"other":"ai-agent-30pct-knowledge-work","relation":"correlates","strength":"weak","note":"AI agents may accelerate quantum algorithm design and error-correction code optimization, but the binding constraint is hardware engineering, not software. Google's AlphaQubit uses ML for quantum error decoding, a modest but real connection."},{"other":"metals-bom-30pct","relation":"correlates","strength":"weak","note":"Quantum simulation of novel materials (battery cathodes, rare-earth alternatives) could accelerate materials discovery, but practical quantum advantage for chemistry simulation is expected in the 2030-2035 window — helpful but unlikely to be the binding constraint for metals BOM."},{"other":"smr-first-oecd-deployment","relation":"correlates","strength":"weak","note":"Quantum simulation of nuclear materials and reactor physics is an active research area but decades from practical deployment advantage. SMR timelines are driven by regulatory and construction challenges, not simulation capability."},{"other":"global-economy-explosive-growth","relation":"correlates","strength":"medium","note":"A cryptographically-relevant quantum computer would trigger massive economic disruption (Citi estimates $2-3.3T GDP at risk from a single attack) unless PQC migration is complete. If migration succeeds in time, quantum computing becomes a $90-170B market by 2040 (BCG) contributing to economic growth. The relationship is bidirectional: explosive growth funds quantum R&D, but premature Q-Day could derail it."}]
key_dependencies: [{"factor":"Logical qubit count reaching 1,000","kind":"capability","direction":"accelerates","linked_gate":null,"impact":"Gidney 2025 requires ~1,399 logical qubits; current best is 96 (QuEra), so crossing 1,000 is the binding hardware threshold that unlocks the gate."},{"factor":"Sustained fault-tolerant operation one week","kind":"capability","direction":"delays","linked_gate":null,"impact":"Longest demonstrated coherent computation is minutes; scaling to the required 5+ continuous days is potentially the hardest remaining sub-gate (P50 2035) and could push Q-Day well into the 2040s."},{"factor":"QLDPC / non-surface-code error correction","kind":"capability","direction":"accelerates","linked_gate":null,"impact":"Iceberg Quantum's QLDPC architecture claims 10x qubit reduction to ~100k physical qubits, potentially cutting years off the timeline if non-nearest-neighbor connectivity proves buildable."},{"factor":"Topological qubit hardware breakthrough","kind":"capability","direction":"both","linked_gate":null,"impact":"Microsoft Majorana-1 could eliminate massive error-correction overhead and dramatically compress the timeline, but the physics remains contested and Microsoft's 20-year development history signals deep difficulty."},{"factor":"NIST post-quantum migration completion","kind":"regulation","direction":"both","linked_gate":null,"impact":"If PQC migration completes before Q-Day (NIST target 2035), economic disruption is averted and the gate's impact is positive; if migration lags, a premature Q-Day puts $2-3.3T GDP at risk from a single attack."},{"factor":"Classified state-level quantum programs","kind":"event","direction":"accelerates","linked_gate":null,"impact":"China and US national-security programs are opaque; a classified breakthrough could mean Q-Day arrives years before public disclosure, with 'harvest now, decrypt later' attacks already underway."},{"factor":"AI agents accelerating quantum R&D","kind":"gate","direction":"accelerates","linked_gate":"ai-agent-30pct-knowledge-work","impact":"AI/ML applied to error correction (AlphaQubit), circuit optimization, and algorithm research modestly accelerates progress, though the binding constraint is hardware engineering rather than software."}]
external_calibration: {"metaculus":"https://www.metaculus.com/questions/30596/date-of-rsa-2048-quantum-factorization/","manifold":"https://manifold.markets/Dig/will-quantum-computing-break-rsa-en","expert_consensus":"GRI 2025 survey (26 experts): CRQC 28-49% likely within 10 years, 51-70% within 15 years — highest 10-year probability in the survey's 7-year history. Google revised Q-Day estimate to 'as early as 2029' (March 2026). Citi (Jan 2026): 19-34% probability by 2034, up to 82% by 2044. Manifold: 19% chance of RSA-2048 broken by 2030. Consensus median clusters around mid-to-late 2030s."}
last_updated: "2026-05-27T00:00:00.000Z"
sources_count: 38
---

## TL;DR

I put the **P50 at 2039** for a quantum computer to factor a 2,048-bit RSA integer using Shor's algorithm. The **P10 is 2033** (aggressive vendor roadmaps hold, QLDPC or topological breakthroughs compress the timeline, and the Gidney/Iceberg resource reductions translate directly to hardware) and the **P90 is 2055** (error correction hits a scaling wall, decoherence remains intractable at >100k qubits, or sustained week-long fault-tolerant operation proves far harder than projected). The key insight driving this estimate: three papers published between May 2025 and March 2026 dropped the estimated physical qubit requirement from ~20 million to under 100,000 — a 200x reduction in seven years of algorithmic progress. But the gap between "theoretical qubit count" and "engineered system that actually runs for five days straight" is where most of the remaining uncertainty lives. As of May 2026, the largest number reliably factored by Shor's algorithm is **21** (done in 2012), and the largest quantum-assisted factorization of any kind is a 48-bit number using a hybrid approach on 10 qubits. The chasm between 48 bits and 2,048 bits remains enormous — roughly 2,000 bits of scaling that requires not just more qubits, but fundamentally new engineering for error correction, sustained operation, and classical control at unprecedented scale.

## Current state (as of 2026-05-27)

**Hardware qubit counts and fidelity:**
- Google Willow: 105 qubits (superconducting), first to demonstrate below-threshold surface code error correction (distance-7, 0.143% error per cycle), logical qubit lifetime 2.4x best physical qubit [1][2]
- China's Zuchongzhi 3.0: 105 qubits (superconducting), 99.90% single-qubit / 99.62% two-qubit gate fidelity, claims 10^6x speedup over Google Sycamore on random circuit sampling [3]
- China's Tianyan-504: 504 qubits (superconducting), China's largest as of Dec 2024 [4]
- Quantinuum Helios: 48 logical qubits (trapped ion), highest gate fidelity in industry [5]
- QuEra: 96 verified logical qubits (neutral atom), 1000+ atom arrays demonstrated [6]
- IBM Condor: 1,121 physical qubits (superconducting), Heron at 156 qubits with improved error rates [7]
- Microsoft Majorana-1: First topological qubit QPU (Feb 2025), claims million-qubit-on-chip scaling potential, but scientific reception mixed [8]
- IonQ: trapped-ion approach, converging on 99.99% two-qubit fidelity [9]

**Factoring records:**
- Largest number factored by Shor's algorithm specifically: **21** (2012) [10]
- Largest quantum-assisted factorization: 48-bit integer (261,980,999,226,229) using hybrid SQIF method on 10 superconducting qubits (Chinese team, Dec 2022) [11]
- Largest Shor simulation on classical GPU: 549,755,813,701 (~40 bits) [12]
- Shanghai University quantum-annealing factorization: 90-bit RSA number, largest to date via quantum annealing [13]

**Resource estimates for RSA-2048 (theoretical):**
- Gidney & Ekera 2019: ~20 million noisy qubits, 8 hours [14]
- Gidney May 2025: <1 million noisy qubits, <1 week — 20x reduction via approximate residue arithmetic, yoked surface codes, magic state cultivation [15]
- Iceberg Quantum Feb 2026: <100,000 physical qubits using QLDPC codes (Pinnacle Architecture) — another 10x reduction, but requires non-nearest-neighbor connectivity, validated by simulation only [16]
- Preskill et al. March 2026 (arXiv:2603.28627): ~10,000 reconfigurable atomic (neutral-atom) qubits theoretically sufficient, though runtime is 1-2 orders of magnitude longer than ECC-256 [17]
- All estimates require gate error rates no higher than 0.1% and sustained multi-day operation [15]

**Investment and industry scale:**
- Total quantum computing investment in 2025: $12.6 billion (6.3x YoY increase per McKinsey) [18]
- Global quantum computing revenue exceeded $1 billion in 2025, projected $4.4 billion by 2028 [18]
- BCG projects $90-170B provider market and $450-850B economic value by 2040 [19]
- Israel's quantum ecosystem: $500M+ raised in 2025, ranked 5th globally in investment; Classiq raised $200M+ total [20]

## Key uncertainties

1. **Algorithmic vs. engineering progress mismatch.** The qubit requirement has dropped from 20M to potentially 10K on paper in seven years, but hardware has gone from ~50 to ~1,100 physical qubits and from 0 to ~96 logical qubits in the same period. The algorithmic gains are stunning; the engineering gains are incremental. Whether the remaining gap closes by optimistic roadmaps (IBM 100k by 2033, IonQ 2M by 2030) or stalls is the single biggest uncertainty.

2. **Sustained fault-tolerant operation at scale.** All current estimates require 5+ days of continuous fault-tolerant quantum computation. The longest demonstrated coherent computation is on the order of minutes. Scaling from minutes to days with millions of physical qubits maintaining below-threshold error rates is an unprecedented engineering challenge involving cryogenic stability, real-time classical decoding at microsecond latency, and thermal management at 10-20 millikelvin.

3. **Energy and infrastructure constraints.** RAND estimates ~125 MW continuous power for a 20M-qubit system (8-hour run) at ~$64,000 per key in electricity alone. Even at 100k qubits, cooling to 10-20 millikelvin requires substantial cryogenic infrastructure. Whether a 10,000-qubit neutral-atom system at room temperature (per Preskill) changes this equation is unclear.

4. **Topological qubit wildcard.** Microsoft's Majorana-1 claims inherent error protection at the hardware level, potentially eliminating the massive qubit overhead for error correction. If topological qubits work as advertised, the timeline compresses dramatically. But the physics is contested — critics question whether Majorana zero modes have truly been demonstrated, and Microsoft's 20-year development timeline suggests this is harder than superconducting/trapped-ion approaches.

5. **QLDPC codes and non-surface-code approaches.** Iceberg Quantum's Pinnacle Architecture claims 10x further reduction using quantum LDPC codes, but requires qubit connectivity beyond nearest-neighbor grids. If this architecture proves buildable, the 100k-qubit threshold could be sufficient. If not, surface codes remain the baseline and ~1M qubits is needed.

6. **National security race dynamics.** Quantum cryptanalysis has obvious intelligence applications. State-level programs (US, China, potentially others) may achieve classified breakthroughs years before public disclosure. China's quantum program is the least transparent; "harvest now, decrypt later" operations by state actors are assumed ongoing.

7. **Post-quantum migration pace.** Even if Q-Day arrives in the 2030s, the practical impact depends on whether PQC migration is complete. NIST targets 2035 for full deprecation; enterprise migration takes 5-15 years. Organizations starting now may be safe; those delaying are exposed. The Federal Reserve estimates PQC migration will cost >$15B across the economy.

8. **Alternative factoring approaches.** Hybrid quantum-classical methods (like the Chinese SQIF approach that factored 48 bits on 10 qubits) could potentially complement Shor's algorithm. The 372-qubit claim for RSA-2048 via SQIF is widely disputed, but iterative improvement of hybrid methods adds another dimension of uncertainty.

## Sub-gate deep dives

### Logical qubit count reaches 1,000 (P50: 2032)

The binding constraint for RSA-2048 factoring. Gidney 2025 requires ~1,399 logical qubits running for approximately one week. Current state: Quantinuum at 48 logical qubits, QuEra at 96 verified. IBM's roadmap: 200 (Starling, 2029), 500 (Super Starling, 2030), 1,000 (Maximum Starling, 2031), 1,500 (Blue Jay, 2032). Infleqtion targets 1,000 by 2030 on neutral atoms. IonQ projects 40,000-80,000 logical qubits by 2030 from 2M physical qubits — an aggressive claim. Microsoft/Atom Computing target 50 logical qubits (Magne) by early 2027. The trend from 0 to 96 logical qubits in ~2 years suggests exponential-ish growth, but the overhead ratio (physical:logical) currently ranges from 7:1 (QuEra) to 25:1 (Microsoft/Atom target) and needs to hold or improve at scale. P50 2032 assumes IBM-like timelines hold within ~1 year of plan, with at least one platform crossing 1,000 logical qubits.

### Physical qubit count reaches 1 million (P50: 2034)

The fallback requirement if surface codes remain the dominant error correction scheme. Gidney 2025 needs <1M noisy qubits with surface codes. IBM targets 100k by 2033. PsiQuantum ($1B Series E from NVIDIA) is building a photonic system targeting fault-tolerant scale via CMOS-compatible silicon photonics — if photonic qubits work, manufacturing-style scaling could reach millions faster. China Telecom planned a 1,200+ qubit cluster by end-2025. The trajectory from 1,100 (IBM Condor, 2023) to target 100k (2033) implies ~10x/3-4 years scaling, reaching 1M around 2037 if sustained. More optimistic neutral-atom and photonic approaches could compress this. P50 2034 assumes one technology reaches the 1M threshold with adequate fidelity.

### Error rate sustained below threshold at scale (P50: 2030)

Google Willow proved that adding more physical qubits to a logical qubit actually reduces the logical error rate (the "below threshold" result) on a 101-qubit distance-7 code. This is the single most important proof-of-principle result in quantum computing history. But maintaining this below-threshold performance at 10,000+ physical qubits — with the exponentially growing classical decoding overhead, increased crosstalk, and thermal management challenges — is a separate engineering question. Google DeepMind's AlphaQubit uses ML for real-time decoding, which could help. Quantinuum's trapped-ion approach has inherently lower error rates but slower gate speeds. P50 2030 assumes the trend continues from 100-qubit demonstrations to 1,000+ qubit systems with sustained below-threshold performance.

### Sustained computation for one week (P50: 2035)

This is potentially the hardest sub-gate. No quantum computer has ever maintained coherent, error-corrected computation for more than minutes. A week of continuous surface-code operation requires: (a) cryogenic system stability at 10-20 millikelvin for 120+ hours without interruption; (b) real-time classical decoding at microsecond latency processing terabytes of syndrome data; (c) no catastrophic correlated errors across the entire system. Neutral-atom and photonic systems operating at higher temperatures could ease the cryogenic challenge. Room-temperature topological qubits (if realized) would eliminate it. P50 2035 reflects the view that this is a "last mile" engineering problem that gets solved ~3-5 years after the qubit count and error rate milestones are met.

### NIST PQC migration complete (P50: 2035)

NIST published FIPS 203/204/205 in August 2024 (ML-KEM, ML-DSA, SLH-DSA). HQC selected as backup KEM in March 2025. CNSA 2.0 requires: new NSS systems quantum-safe by Jan 2027, full application migration by 2030, full infrastructure by 2035. UK NCSC issued PQC migration timelines in 2025. Browsers (Chrome, Firefox) already support hybrid PQC key exchange. Enterprise migration takes 5-15 years — discovery alone is 12-24 months. The $15B migration market is growing but most enterprises haven't started. P50 2035 aligns with NIST's own deprecation deadline and reflects both mandate-driven urgency and the sheer difficulty of crypto-agility at enterprise scale.

## Cross-gate interactions

**AI agents (ai-agent-30pct-knowledge-work, P50 2029):** The connection is indirect but real. AI/ML is already being applied to quantum error correction (Google's AlphaQubit), quantum circuit optimization (Classiq's platform), and materials simulation. If AI agents reach 30% knowledge-work autonomy by 2029, they could accelerate quantum algorithm research and hardware control software development. However, the binding constraint for this gate is physical hardware engineering, not software — so the relationship is weak/correlates.

**Metals BOM (metals-bom-30pct, P50 2031):** Quantum simulation of molecular and materials properties is one of the most-cited near-term applications (BCG projects this as the first major value domain). Quantum advantage for chemistry simulation is expected in the early-to-mid 2030s — roughly contemporaneous with the metals BOM gate. If quantum simulation accelerates discovery of novel battery cathode materials, rare-earth alternatives, or magnet-free motor designs, it could modestly accelerate the metals BOM gate. Strength: weak, because classical simulation and experimental methods remain dominant for materials R&D through this timeframe.

**SMR deployment (smr-first-oecd-deployment, P50 2032):** Quantum simulation of nuclear materials and reactor physics is an active research area, but SMR deployment timelines are driven by regulatory approval, construction logistics, and financing — not simulation capability. Quantum computing is unlikely to materially affect the SMR gate timeline. Strength: weak/correlates.

**Global explosive growth (global-economy-explosive-growth, P50 2049):** This gate has a complex bidirectional relationship with quantum computing. A premature Q-Day (before PQC migration is complete) could cause catastrophic economic disruption — Citi models $2-3.3 trillion GDP at risk from a single targeted attack on US interbank payments. Conversely, a well-managed quantum transition contributes to the $450-850B economic value BCG projects by 2040, and quantum computing breakthroughs in materials science, drug discovery, and optimization would be one of many contributors to explosive growth. If Q-Day arrives after PQC migration (the P50 scenario), the net effect is strongly positive for global growth.

## Sources

1. [Google Research, *Quantum error correction below the surface code threshold*, Nature, December 2024](https://www.nature.com/articles/s41586-024-08449-y)
2. [Google Research Blog, *Dynamic surface codes open new avenues for quantum error correction*, 2025](https://research.google/blog/dynamic-surface-codes-open-new-avenues-for-quantum-error-correction/)
3. [Chinese Academy of Sciences / USTC, *Zuchongzhi 3.0: 105-qubit processor*, arXiv:2412.11924, March 2025](https://arxiv.org/pdf/2412.11924)
4. [The Quantum Insider, *Chinese Team Officially Report on Zuchongzhi 3.0*, March 2025](https://thequantuminsider.com/2025/03/04/chinese-team-officially-report-on-zuchongzhi-3-0-claims-million-times-speedup-over-googles-willow/)
5. [Quantinuum, *Helios: 48 logical qubits*, November 2025](https://www.quantinuum.com/blog/unlocking-scalable-chemistry-simulations-for-quantum-supercomputing)
6. [Quantum Zeitgeist, *Top Quantum Hardware Companies 2026*](https://quantumzeitgeist.com/top-quantum-hardware-companies/)
7. [IBM Quantum Roadmap](https://www.ibm.com/roadmaps/quantum/)
8. [Microsoft Azure Quantum Blog, *Microsoft unveils Majorana 1*, February 2025](https://azure.microsoft.com/en-us/blog/quantum/2025/02/19/microsoft-unveils-majorana-1-the-worlds-first-quantum-processor-powered-by-topological-qubits/)
9. [IonQ Roadmap](https://www.ionq.com/roadmap)
10. [PostQuantum, *The State of Factoring on Quantum Computers*](https://postquantum.com/post-quantum/4099-qubits-rsa/)
11. [PostQuantum, *Quantum Computer Factors Record 48-Bit Number*](https://postquantum.com/post-quantum/quantum-48-bit-rsa-2048/)
12. [arXiv:2410.14397, *The State of Factoring on Quantum Computers*](https://arxiv.org/html/2410.14397v1)
13. [SpinQuanta, *How Shor's Algorithm Breaks RSA*](https://www.spinquanta.com/news-detail/shors-algorithm)
14. [Gidney & Ekera, *How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits*, arXiv:1905.09749, 2019/2021](https://arxiv.org/abs/1905.09749)
15. [Gidney, *How to factor 2048 bit RSA integers with less than a million noisy qubits*, arXiv:2505.15917, May 2025](https://arxiv.org/html/2505.15917v1)
16. [The Quantum Insider, *New Architecture Could Cut Quantum Hardware Needed to Break RSA-2048 by Tenfold*, February 2026](https://thequantuminsider.com/2026/02/13/new-architecture-could-cut-quantum-hardware-needed-to-break-rsa-2048-by-tenfold-study-finds/)
17. [Preskill et al., *Shor's algorithm is possible with as few as 10,000 reconfigurable atomic qubits*, arXiv:2603.28627, March 2026](https://arxiv.org/abs/2603.28627)
18. [McKinsey Quantum Technology Monitor 2026](https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/mckinsey-quantum-technology-monitor-2026-a-commercial-tipping-point)
19. [BCG, *Quantum Computing On Track to Create Up to $850 Billion of Economic Value By 2040*, July 2024](https://www.bcg.com/press/18july2024-quantum-computing-create-up-to-850-billion-of-economic-value-2040)
20. [Calcalist, *Israel's quantum boom: Startups hit $500 million in funding in 2025*](https://www.calcalistech.com/ctechnews/article/bk15be00mbg)
21. [Global Risk Institute, *Quantum Threat Timeline Report 2025*](https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/)
22. [PostQuantum, *Quantum Threat Timeline Report 2025: Record Predictions*](https://postquantum.com/security-pqc/quantum-threat-timeline-report-2025/)
23. [IT Pro, *Google just revised its Q-Day timeline: within three years*, March 2026](https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready)
24. [Citi Institute, *Quantum Threat: The Trillion-Dollar Security Race Is On*, January 2026](https://www.citigroup.com/rcs/citigpa/storage/public/Citi_Institute_Quantum_Threat.pdf)
25. [American Banker, *Citi: Banks face $3 trillion risk from quantum cyberattacks*](https://www.americanbanker.com/news/citi-banks-face-3-trillion-risk-from-quantum-cyberattacks)
26. [Manifold Markets, *Will quantum computing break RSA encryption before 2030?*](https://manifold.markets/Dig/will-quantum-computing-break-rsa-en)
27. [Metaculus, *Date of RSA-2048 quantum factorization?*](https://www.metaculus.com/questions/30596/date-of-rsa-2048-quantum-factorization/)
28. [Metaculus, *Date Quantum Algorithm Factors RSA Number*](https://www.metaculus.com/questions/3684/date-quantum-algorithm-factors-rsa-number/)
29. [NIST, *Post-Quantum Cryptography Standardization*](https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization)
30. [NIST, *Transition to Post-Quantum Cryptography Standards (NISTIR 8547 draft)*](https://csrc.nist.gov/pubs/ir/8547/ipd)
31. [UK NCSC, *Timelines for migration to post-quantum cryptography*](https://www.ncsc.gov.uk/guidance/pqc-migration-timelines)
32. [PostQuantum, *The Enormous Energy Cost of Breaking RSA-2048 with Quantum Computers*](https://postquantum.com/post-quantum/energy-cost-rsa-2048-quantum/)
33. [The Quantum Insider, *Q-Day Just Got Closer: Three Papers in Three Months Are Rewriting the Quantum Threat Timeline*, March 2026](https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/)
34. [CNN, *'Q-Day' is almost here. It could unleash a cybersecurity crisis far worse than Y2K*, May 2026](https://www.cnn.com/2026/05/17/science/quantum-computing-cybersecurity-q-day)
35. [PR Newswire, *The $15 Billion Post-Quantum Migration*](https://www.prnewswire.com/news-releases/the-15-billion-post-quantum-migration-nist-standards-are-final-nsa-deadlines-are-set-and-enterprise-cybersecurity-is-about-to-be-rebuilt-from-the-ground-up-302730679.html)
36. [Infleqtion, *New Architecture to Achieve 1000 Logical Qubits by 2030*](https://infleqtion.com/infleqtion-unveils-new-architecture-to-accelerate-its-quantum-computing-roadmap-to-achieve-1000-logical-qubits-by-2030/)
37. [Riverlane, *Quantum Error Correction: Our 2025 trends and 2026 predictions*](https://www.riverlane.com/blog/quantum-error-correction-our-2025-trends-and-2026-predictions)
38. [PostQuantum, *Q-Day Revisited — RSA-2048 Broken by 2030: Detailed Analysis*](https://postquantum.com/post-quantum/q-day-y2q-rsa-broken-2030/)