The CRQC Reality Check: The Count Is Zero. The Clock Is Not.
Here's a question every security architect should be able to answer precisely: how many quantum computers capable of breaking RSA-2048 exist today?
Zero. Not "probably zero." Not "zero that we know of, but who can say." Zero, with high confidence, for reasons that come down to physics and engineering rather than intelligence assessments.
And yet: NIST deprecates RSA and ECC after 2030. NSA's timeline for national security software signing already prefers post-quantum today and turns exclusive in 2030. The estimated hardware needed to break RSA-2048 fell twentyfold in six years without a single qubit being built. Both things are true at once. The machines don't exist, and the migration deadlines are already here.
This post is the reality check: what actually exists, what the honest records are, why the resource estimates keep collapsing, and why the deadline that matters is set by your data's lifetime, not by Q-Day.
The Honest Factoring Records
A cryptographically relevant quantum computer (CRQC) is a machine that can run Shor's algorithm against real key sizes: RSA-2048, P-256, secp256k1. Measured against that bar, the public record is almost comically short.
The largest number ever factored by a genuine Shor's algorithm implementation on real hardware is 21. A 5-bit number. And even that used a "compiled" circuit that baked in prior knowledge of the answer. Craig Gidney of Google once illustrated how meaningless the "largest number factored" metric is by satirically "factoring" a 6,021-digit number with 2 qubits via extreme classical precompilation.
The largest number factored on any quantum device by any method is a 48-bit integer, via a hybrid classical-quantum approach that does not scale. For comparison, the largest hard semiprime ever factored classically is RSA-250: 829 bits, February 2020, roughly 2,700 CPU core-years of the number field sieve. The classical record is 17 times longer in bits than the quantum one.
The widely circulated claims to the contrary have all collapsed under scrutiny:
- The 372-qubit RSA-2048 claim. A December 2022 paper (Yan, Tian et al., arXiv:2212.12372) claimed 372 physical qubits could challenge RSA-2048 using Schnorr's lattice algorithm plus quantum optimization. Scott Aaronson called it "one of the most actively misleading quantum computing papers I've seen in 25 years." Independent replications by IonQ (August 2023) and Google researchers (arXiv:2307.09651) showed the method fails above roughly 70–80 bits and exhibits no quantum speedup. The underlying classical algorithm doesn't scale; adding qubits doesn't fix it.
- Quantum annealing "RSA-2048" claims. These factored trivially structured numbers with special form, not hard semiprimes. Structure is the whole game in factoring; remove it and the method dies.
No genuine, un-cheated Shor factorization of a nontrivial number has ever run on hardware. That's the baseline.
Physical, Logical, Cryptographically Relevant
Three different bars, routinely conflated in coverage:
Physical qubits are the noisy hardware units. Logical qubits are error-corrected units built out of many physical qubits, capable of surviving deep circuits. A CRQC needs on the order of 1,400 logical qubits running fault-tolerant for days, executing circuits with billions of gate operations.
Here's where the leading platforms actually stand:
| Platform | System | Physical qubits | Notable |
|---|---|---|---|
| IBM (superconducting) | Nighthawk (Q4 2025) | 120 | Current flagship; 2,477 qubits total across 17 QPUs. Condor hit 1,121 in 2023 as a scaling demo before IBM pivoted to quality |
| Atom Computing (neutral atom) | 1,225-site array (2023) | 1,180 | First universal platform above 1,000 |
| Google (superconducting) | Willow (Dec 2024) | 105 | First below-threshold error correction |
| USTC, China (superconducting) | Zuchongzhi 3.0 (Mar 2025) | 105 | Comparable to Willow; commercially deployed on the Tianyan cloud |
| Quantinuum (trapped ion) | Helios (Nov 2025) | 98 | Highest commercial fidelity: 99.921% two-qubit |
| IonQ (trapped ion) | Tempo (2025) | ~100 | Competes on quality, not count |
| Caltech (research) | Cesium tweezer array (Sep 2025) | 6,100 atoms | Largest qubit array ever; not yet an entangled computing system |
The metric that actually matters is logical qubits, and the state of the art in 2026 is roughly 48 to 96:
- Google Willow demonstrated below-threshold error correction: a distance-7 surface code whose logical error rate drops by a factor of 2.14 for every two units of code distance, with a logical qubit living 2.4 times longer than its best physical qubit. Published in Nature. This was the field's long-standing existence proof: error correction now makes things better, not worse.
- Quantinuum Helios generated 48 fully error-corrected logical qubits at a two-to-one encoding ratio, and entangled 94 logical qubits in one of the largest GHZ states ever recorded.
- QuEra, Harvard, and MIT produced 96 logical qubits from 448 physical neutral atoms using [[16,6,4]] qLDPC codes, published in Nature, alongside continuous operation of a 3,000-atom array and logical magic-state distillation.
- Microsoft's Majorana 1 claimed the first topological qubit in February 2025. The claim remains heavily disputed by outside physicists, and the Nature paper's own reviewers noted the results did not constitute evidence for Majorana zero modes. Don't count it.
So: the best machines on Earth hold 48–96 logical qubits capable of shallow demonstration circuits. A CRQC needs ~1,400 logical qubits sustaining error-free operation for a week. That gap spans two to three orders of magnitude in physical qubit count, at error rates that must hold or improve while everything scales. Nobody is close.
The Number That Keeps Falling
If the hardware is that far away, why act now? Because the requirement itself keeps collapsing, and it collapses from mathematics, which nobody controls.
| Estimate | Physical qubits | Logical qubits | Runtime |
|---|---|---|---|
| Gidney & Ekerå, 2019 | ~20 million | ~4,000+ | ~8 hours |
| Gidney, May 2025 (arXiv:2505.15917) | under 1 million | ~1,400 | under a week |
| Iceberg Quantum "Pinnacle," Feb 2026 (theoretical) | under 100,000 | qLDPC architecture, unbuilt | longer |
| Cain et al., Mar 2026 (theoretical) | ~10,000 | reconfigurable neutral atoms, unbuilt | much longer |
Read the first two rows carefully. Between 2019 and 2025, the estimated cost of breaking RSA-2048 dropped twentyfold with identical hardware assumptions: same 0.1% gate error, same surface-code cycle time. The entire reduction came from algorithmic and error-correction advances (approximate residue arithmetic, yoked surface codes, magic-state cultivation). Zero hardware progress required.
The 2026 sub-100,000 estimates are preprints on architectures nobody has built, and they change the error-correcting code and connectivity assumptions, so they aren't like-for-like. The defensible surface-code figure remains "under 1 million physical qubits." But the trend line is the point: the bar moves by orders of magnitude from math alone, and math ships silently, instantly, to everyone.
One more asymmetry worth knowing: Google's March 2026 whitepaper estimates that breaking 256-bit elliptic curves (the secp256k1 that signs every Bitcoin transaction, the P-256 in most TLS handshakes) needs fewer resources than RSA-2048: at most 1,200–1,450 logical qubits, under 500,000 physical qubits, minutes-scale runtime. ECC likely falls first.
Gidney himself was explicit that the 2025 result doesn't mean a CRQC arrives by 2030. His actual argument is sharper: security should not depend on quantum progress being slow.
What the Experts Actually Say
The Global Risk Institute's Quantum Threat Timeline Report 2025 (published March 2026, authored by Michele Mosca and Marco Piani, surveying 26 experts) puts a CRQC at "quite possible (28–49%) within the next 10 years, and likely (51–70%) in the next 15." That is the highest 10-year estimate in the report's seven-year history, up sharply from the 2024 edition's 19–34%.
Individual estimates cluster around 2030–2035, with wide error bars in both directions. IBM's roadmap targets Starling, its first fault-tolerant machine with 200 logical qubits, by 2029: a real milestone if it ships, and still an order of magnitude short of a CRQC.
Take the survey with its caveats attached: 26 respondents, weighted toward North America and Europe, zero based in China. That last gap matters given China's quantum investment and shrinking transparency. The physics makes a secret CRQC in 2026 extraordinarily unlikely (you cannot hide a machine that requires millions of components operating fault-tolerant for days when the public state of the art is 96 logical qubits), but prudent threat modeling puts a well-resourced nation-state at the optimistic edge of the public timeline, not the median.
Meanwhile the milestones that matter keep landing. Google's "Quantum Echoes" result (October 2025, published in Nature) ran a verifiable algorithm on Willow roughly 13,000 times faster than the best classical method: about 2 hours versus an estimated 3.2 years on the Frontier supercomputer. It's a physics benchmark, not a cryptographic one. But together with below-threshold error correction demonstrated across superconducting, trapped-ion, and neutral-atom platforms, the signal is consistent: fault tolerance has moved from open scientific question to engineering execution.
The Deadline Isn't Q-Day
Here's the part that changes what you do on Monday. The migration deadlines don't depend on when a CRQC arrives, because the threat model doesn't wait for one.
Harvest now, decrypt later. An adversary who records your encrypted traffic today decrypts it the day a CRQC exists. Every ECDHE session key negotiated this morning is exactly what that adversary is storing. The attack is already running; only the decryption step is deferred.
Mosca's inequality makes the arithmetic explicit: if the time your data must stay secret, plus the time it takes you to migrate, exceeds the time until a CRQC exists, you are already exposed. A secret that must hold until 2035, in an organization that needs three years to migrate, was breached in effect years ago if a CRQC arrives on the survey median.
The regulators did this math already:
- NIST IR 8547 deprecates RSA, ECDSA, ECDH, DSA, and finite-field DH after 2030 and disallows them after 2035.
- NSA CNSA 2.0 is most aggressive on software and firmware signing: post-quantum preferred by 2025, exclusive by 2030, with networking equipment around 2030 and remaining categories by roughly 2033.
- The replacements are finalized and have been since August 2024: ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures.
The practical sequence follows directly. Inventory where RSA and ECC protect long-lived data. Deploy ML-KEM in hybrid mode with a classical exchange for transit encryption now (hybrid modes are explicitly exempt from the 2035 disallowance and hedge against both HNDL and any premature PQC weakness). Migrate signatures to ML-DSA on a schedule that treats 2030 as a hard certificate re-issuance wall, which means planning the transition in 2028–2029 to absorb CA lead times.
The Benchmarks That Should Change Your Posture
The honest position holds two things simultaneously: zero CRQCs exist, and the trend lines all point one direction. So instead of re-litigating the timeline every time a press release lands, watch for the signals that actually move it:
- A genuine, uncompiled Shor factorization of a number above ~100 bits on real hardware
- A demonstration of over 1,000 high-fidelity logical qubits under sustained error-corrected operation
- Any credible peer-reviewed factoring of an RSA-sized number by any method
- IBM Starling (or an equivalent) shipping on schedule in 2029 with 200 logical qubits, confirming the logical-qubit scaling curve is real
- A GRI-class survey putting the 5-year CRQC probability above ~30%
If any of these land, accelerate. Until then, the vendor roadmaps promising 80,000 logical qubits by 2030 are upper bounds on optimism, not forecasts. Roadmaps slip. Math doesn't.
Why We Didn't Wait
We've written before about why every credential the Aethyr Registry issues is signed with ML-DSA-65 and published the benchmarks showing post-quantum signing costs microseconds, four orders of magnitude less than the AI inference calls it protects.
The reasoning was never "a CRQC is imminent." The count is zero and we say so plainly. The reasoning is that agent credentials are long-lived, HNDL means captured signatures become forgeable retroactively, and the cost of breaking RSA-2048 fell 20x in six years from mathematics alone. A defender cannot control when the next paper lands. What a defender controls is whether anything issued today needs emergency re-issuance when it does.
The machines don't exist. The deadline does. Build accordingly.
All figures in this post reflect the public record as of August 2026 and are attributed to their primary sources: peer-reviewed results where available, vendor announcements where noted. Vendor roadmap dates are aspirations, not commitments, and the theoretical sub-100,000-qubit resource estimates describe architectures not yet built at scale.
Aethyr Research, Salt Lake City, UT