THE QUANTUM THREAT / ADVANCED

How Many Qubits To Break RSA-2048? A Dated History Of Estimates

Published estimates of the quantum computer needed to break RSA-2048 have fallen from about a billion physical qubits in 2012 to under 100,000 in 2026. Here is each step and the assumptions behind it.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The size of the quantum computer needed to break RSA has been estimated very differently over the past fourteen years. Each answer is a resource estimate: a detailed blueprint for running Shor’s algorithm on a hypothetical machine with stated error rates and speeds. None describes hardware that exists. Together they show a clear downward trend.

This article lists the main published estimates for RSA-2048 in date order, with the assumptions that make each one comparable or not. It is current as of October 2026; the field moves quickly, so check the dates. Background on logical and physical qubits is in Inside Shor’s Algorithm.

The Estimates In Order

  1. About A Billion Physical Qubits, About A Day

    Fowler and colleagues, surface code, 0.1 percent physical error rate. Estimated for a 2000-bit number.

  2. 20 Million Noisy Qubits, About 8 Hours

    Gidney and Ekerå, surface code on a planar grid, 0.1 percent gate error, 1 microsecond cycle.

  3. Under One Million Noisy Qubits, Under A Week

    Gidney, same assumptions as 2019. 1,399 logical qubits and about 6.5 billion Toffoli gates.

  4. Under 100,000 Physical Qubits, About A Month

    Webster and colleagues, quantum LDPC codes, same error, cycle and reaction time assumptions as 2025.

  5. Neutral Atom Architecture

    Cain and colleagues: Shor at cryptographically relevant scale with as few as 10,000 atoms; RSA-2048 slower than elliptic curves.

Published resource estimates for breaking RSA-2048 with Shor’s algorithm, as of October 2026. All describe machines that do not yet exist.

2012. In an introduction to surface code quantum computing, Fowler, Mariantoni, Martinis and Cleland estimated that factoring a 2000-bit number would take about a billion physical qubits running for about a day, at a physical error rate of 0.1 percent. Most of those qubits were needed to prepare the special states that power the expensive gates.1

2019. Gidney and Ekerå estimated that RSA-2048 could be factored in about eight hours with 20 million noisy qubits. They assumed a planar grid of superconducting qubits with nearest-neighbour connections, a 0.1 percent gate error and a one microsecond surface code cycle.2

2025. Gidney cut the qubit count about twentyfold, to under one million noisy qubits, at the cost of a longer run of under a week. He kept the 2019 assumptions: 0.1 percent gate error, a one microsecond cycle and a 10 microsecond control system reaction time.3 The savings came from an approximate form of modular arithmetic, denser storage of idle qubits using yoked surface codes, and a cheaper way to prepare magic states, the special resource states that the expensive gates consume. The paper’s cost table gives 1,399 logical qubits and about 6.5 billion Toffoli gates; counting idle working patches, the physical layout holds fewer than 1,600 logical qubits.3

2026, quantum LDPC codes. Webster and colleagues’ Pinnacle architecture, first posted in February 2026 and revised in May, estimates RSA-2048 can be factored with fewer than 100,000 physical qubits in an expected runtime of about one month, under the same error, cycle and reaction time assumptions. Adding qubits shortens the run: the same paper puts a one-week factoring at about 139,000 physical qubits.4 The design uses quantum low-density parity-check (qLDPC) codes, which pack many logical qubits into one code block. The price is that qubits must interact beyond their nearest neighbours, though only over a bounded distance.4

2026, neutral atoms. Cain and colleagues, including John Preskill, estimated that an architecture based on reconfigurable neutral atoms could run Shor’s algorithm at cryptographically relevant scale with as few as 10,000 atomic qubits. With 26,000 atoms they put elliptic curve P-256 at a few days, and RSA-2048 at one to two orders of magnitude longer. The authors state that substantial engineering challenges remain.5

Physical qubits in published RSA-2048 estimates, on a logarithmic scale where each grid line is a factor of 100. The bottom bar is a real chip for comparison: Google’s Willow, announced in December 2024 with 105 qubits.

Reading Estimates Carefully

Estimates are only comparable when their assumptions match, and several numbers trade against each other.

Qubits versus time. The 2025 estimate uses about twenty times fewer qubits than 2019 but runs for days instead of hours. For an attacker decrypting a stored archive, a week per key is no obstacle. For forging a signature during a live transaction it might be.

Logical qubits versus gate count. A Toffoli gate is a three-qubit operation, and it dominates the cost of these circuits, so papers report how many are needed. The 2019 method used roughly 3 billion of them with a little over three logical qubits for every bit of the modulus. A 2024 method by Chevignard, Fouque and Schrottenloher brought the logical qubits down to about half a qubit per bit, but its gate count climbed to around 2 trillion, as Gidney’s 2025 paper points out before landing between the two.3 When a headline quotes a small logical qubit count, check the gate count too, because the gates decide how long the attack runs.

Error rate, speed and connectivity. All the superconducting estimates assume a 0.1 percent physical error rate across a very large device. The qLDPC estimate also assumes interactions between qubits that are not direct neighbours. Neutral atom machines can physically rearrange their qubits, and their estimates come out at fewer qubits but longer runtimes.5 Google researchers group neutral atoms and trapped ions as slow-clock architectures, in contrast with fast-clock superconducting and photonic designs.6

What The Trend Means For Planning

Two lessons follow. First, the target keeps moving closer through better algorithms and error correction, independent of how fast hardware grows. A plan that assumed the 2019 figure of 20 million qubits already looks optimistic. Second, every estimate depends on stated assumptions about hardware that has not been built, so a single number should never be quoted without its date and conditions.

For key exchange, the trend strengthens the case for acting on harvest now, decrypt later exposure. For elliptic curve cryptography the picture is starker, because recent estimates suggest it is cheaper to break than RSA. That is covered in Elliptic Curves Fall First.

Footnotes

  1. A. G. Fowler, M. Mariantoni, J. M. Martinis and A. N. Cleland, “Surface codes: Towards practical large-scale quantum computation”, arXiv 1208.0928, August 2012, revised October 2012, appendix M. arxiv.org ↩

  2. C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits”, arXiv 1905.09749, May 2019. arxiv.org ↩

  3. C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, arXiv 2505.15917, 21 May 2025. arxiv.org ↩ ↩2 ↩3

  4. P. Webster and others, “The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes”, arXiv 2602.11457, 12 February 2026, revised 5 May 2026. arxiv.org ↩ ↩2

  5. M. Cain and others, “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits”, arXiv 2603.28627, 30 March 2026. arxiv.org ↩ ↩2 ↩3

  6. R. Babbush and others (Google Quantum AI and collaborators), “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, arXiv 2603.28846, 30 March 2026, revised 15 April 2026. arxiv.org ↩

  7. Google, “Meet Willow, our state-of-the-art quantum chip”, 9 December 2024. blog.google ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.