A 2025 estimate says a hypothetical quantum computer with fewer than one million noisy qubits could factor a 2048-bit RSA integer in less than a week. That is more than a 20-fold reduction in estimated qubit requirements compared with a 2019 estimate—not a faster attack, a demonstrated RSA break, or evidence that such a machine exists today.
Can quantum computers break RSA-2048?
In principle, a sufficiently capable quantum computer could use a factoring algorithm to attack RSA. Craig Gidney’s preprint, submitted to arXiv on May 21, 2025, estimates the resources for factoring a 2048-bit RSA integer on a hypothetical machine. It does not report that a real quantum computer has completed the calculation.
The distinction matters: a resource estimate models what a machine would need under specified assumptions. It does not establish that the required hardware can be built, or when it might be available. NIST has reported that some experts predict a capable device could arrive within a decade, but that is a prediction, not a confirmed delivery date.
What does the 20x reduction mean?
The comparison is about estimated qubit count. Gidney’s 2025 preprint contrasts its estimate with the 2019 estimate by Gidney and Ekerå:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
| Estimate | Estimated noisy qubits | Estimated runtime |
|---|---|---|
| 2019, by Gidney and Ekerå (as reported in Gidney’s 2025 preprint) | 20 million | Eight hours |
| 2025, by Craig Gidney | Fewer than one million | Less than a week |
Because the newer estimate is below one million versus 20 million before, its modeled qubit requirement is more than 20 times lower. The projected runtime is not correspondingly shorter: the newer estimate is less than a week, compared with eight hours in the earlier estimate. “Easier” in the headline therefore describes the qubit count, not elapsed time or a completed attack.
What assumptions does the 2025 estimate rely on?
The result is conditional on a particular hardware and error-correction model, not a hardware-independent forecast. Gidney specifies a square grid of qubits with nearest-neighbor connections, a uniform gate error rate of 0.1%, a one-microsecond surface-code cycle, and a ten-microsecond control-system reaction time.
Rank #2
Changing hardware capabilities or these modeled conditions could change the resources and runtime. The estimate should be read as a calculation for a machine meeting the paper’s assumptions, not as a measurement of current quantum-computer performance.
Why did the estimated qubit count fall?
Gidney attributes much of the reduction to changes in the proposed computation and error-correction approach: approximate residue arithmetic, yoked surface codes for storing idle logical qubits, and magic state cultivation. The preprint also reports reducing the Toffoli count by more than 100 times compared with the 2024 approach it discusses.
Free tools Windows power users keep installed
One-click scans. No signup required.
These are technical improvements in a resource estimate. They do not by themselves demonstrate that the full calculation has been run or that the physical hardware needed to execute it is available.
Does this mean RSA is broken now?
No. The paper is a modeled estimate for a hypothetical quantum computer; it is not an observed factoring result or proof of an imminent attack. Nor does the estimate set a reliable date for when a machine capable of factoring RSA-2048 will exist.
Rank #4
What should organizations do about post-quantum cryptography?
The estimate is not a new migration deadline, but organizations with data that must remain confidential for a long time have reason to plan. NIST finalized three post-quantum cryptography standards on August 13, 2024, described them as ready for use, and encouraged administrators to begin integrating them. NIST mathematician Dustin Moody, who leads its standardization project, said: “We encourage system administrators to start integrating them into their systems immediately, because full integration will take time.”
Match the standard to the use
| Standard | Algorithm | NIST’s stated role |
|---|---|---|
| FIPS 203 | ML-KEM | Primary standard for general encryption |
| FIPS 204 | ML-DSA | Primary standard for digital signatures |
| FIPS 205 | SLH-DSA | Another digital-signature standard, based on a different mathematical approach |
NIST says the standards are designed around mathematical problems intended to resist attacks from both conventional and quantum computers. For a practical starting point, an organization can:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
- Inventory where cryptography is used, including systems, vendors, protocols, and data flows.
- Identify information that needs confidentiality over a long period and the systems protecting it.
- Plan how affected systems could adopt the relevant NIST standard, coordinating with vendors and internal system owners.
The inventory and transition planning are useful because integration takes time; the 2025 estimate does not establish that an attack is imminent.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

