← Observatory › The Record › FR-QE-0005
PROG-QE
FR-QE-0005

Cryptographically Relevant Quantum Computing — RSA Factorisation

A quantum computer can factor commercially relevant RSA cryptographic keys faster than any classical computer.

EscalatingVS-02·since 2026-09-15
Assessment trajectory
Escalatingstate held · last assessed 2026-09-15
Verification Matrix

Verification position derived from the record’s assessments; dates show when Faultline first recorded each stage.

VS-01
Assertion
—
VS-02
Published evidence
Current from 2024-01-15 — present
VS-03
Audit
First recorded 2026-06-29
VS-04
Replication
—
VS-05
Operation
—
Stage first recorded Current verification position Not yet recorded
State Warrant
Current stateEscalatingVS-02
Why this state?IN-007 and IN-008 admitted through normal Record Review after LPR-001-D17. Architecture-dependent estimates are kept distinct from experimental capability and from like-for-like surface-code resource reductions.
Assessment summaryNormal Record Review admits two independent 2026 RSA-2048 resource analyses. Webster et al.'s Pinnacle Architecture estimates fewer than 100,000 physical qubits under explicit QLDPC and hardware assumptions, while Mundada et al. estimate approximately 381,000 physical qubits and 9.2 days using an experimentally demonstrated grid-coupling topology, with lower or faster alternatives under changed architectural assumptions. Together they strengthen the evidence that theoretical resource requirements can compress substantially through architecture and compilation choices. They do not demonstrate the required fault-tolerant machine, an RSA-2048 factorisation, or a uniform like-for-like trend across architectures. ESCALATING / VS-02 therefore remains appropriate: the modelled engineering boundary has moved materially, but the tracked claim remains experimentally unrealised.
State entered2024-01-15
Last reaffirmed2026-09-15
Mechanisms

Causal mechanisms recorded for this claim. The State Warrant above remains the authoritative current assessment.

Resistance MechanismRM-001

The engineering gap remains large even as theoretical resource estimates compress. Gidney 2025 places one surface-code route below one million noisy physical qubits; 2026 architecture studies model lower counts, including below 100,000 under Pinnacle QLDPC assumptions and approximately 381,000 using Mundada et al.'s experimentally demonstrated grid-coupling topology. None corresponds to an existing fault-tolerant machine capable of the computation. Error rates, connectivity, decoding, sustained operation, control overhead and fault-tolerance resources must all be delivered simultaneously. The resistance mechanism is therefore the absence of experimentally demonstrated cryptographic-scale fault-tolerant hardware, not adherence to any single qubit estimate.

Resistance MechanismRM-002

Classical algorithm improvement. The claim requires factoring RSA keys faster than any classical computer. Classical factorisation algorithms continue to improve. The general number field sieve has been optimised continuously since 1990. If classical algorithms improve substantially — through better mathematical insights, specialised hardware, or distributed computing advances — the bar for quantum advantage in this specific application rises. The claim is a race; the classical side of the race is not standing still. The resistance mechanism is therefore not just about quantum hardware but about the relative improvement rate of both sides.

BottleneckBN-001

Sequential substrate dependency. This claim cannot be satisfied until the scaling and below-threshold behaviour tracked in FR-QE-0003 and FR-QE-0004 extend to a fault-tolerant machine capable of executing an RSA-scale factoring circuit. Resource estimates now span materially different architectures and assumptions rather than defining one fixed qubit threshold: approximately 20 million noisy qubits in Gidney–Ekerå, below one million in Gidney 2025, below 100,000 in the Pinnacle QLDPC model, and approximately 381,000 in Mundada et al.'s grid-connectivity case. The bottleneck is demonstrated end-to-end fault-tolerant scale under realizable architecture assumptions, not attainment of any single modelled qubit count.

AttractorAT-001

Demonstration of increasing fault-tolerant logical scale toward a cryptographically relevant factoring workload. Intermediate milestones at hundreds and then thousands of useful logical qubits would materially narrow the engineering gap, but the decisive attractor is an end-to-end fault-tolerant factorisation experiment at a key size that is commercially cryptographically relevant, with a transparent classical comparator and resource accounting. Resource-estimate reductions alone do not satisfy this attractor.

Assessment History
2024-01-15
Initial assessment — Escalating
The claim has not been satisfied. No quantum computer has factored a commercially relevant RSA key. The most credible direct attempt (INST-005) failed. The engineering gap between current capability and the Gidney-Ekerå resource estimate remains approximately three to four orders of magnitude in physical qubit count, with additional requirements for error rates, connectivity, and operational duration not yet demonstrated at any scale approaching relevance. The pressure state is ESCALATING rather than EMERGING because the substrate advances documented in FR-QE-0003 and FR-QE-0004 (INST-003) show the underlying error-correction engineering progressing on a credible trajectory, even though the gap to the resource requirement remains enormous. Institutional behaviour — NIST's finalisation of post-quantum cryptography standards (INST-004) — reflects institutional acceptance that the risk is credible enough to justify migration, adding pressure to the claim's trajectory independent of any direct technical progress toward satisfaction.
Verification Stage: VS-02 preserved — historically unverified.
2026-06-29
Reassessed, no change — Escalating
No threshold has been crossed since AS-001 — no factorisation of a commercially relevant key has occurred, and none is closer to occurring in any demonstrated sense. What has moved is the resource-estimate trajectory underlying OQ-001. Gidney (Google, May 2025) reduced the estimated physical-qubit requirement for RSA-2048 factorisation from the Gidney-Ekerå (2021) figure of ~20 million to under 1 million, under comparable fault-tolerance assumptions — roughly a 20-fold reduction achieved through improved algorithmic and error-correction engineering rather than any experimental demonstration. A 2026 proposal using QLDPC codes (an architecture distinct from the surface codes assumed in both prior estimates) suggests a further reduction toward ~100,000 physical qubits, though this is unvalidated at scale. A March 2026 Google/Stanford/Ethereum Foundation whitepaper applies the same style of resource-reduction analysis to elliptic-curve cryptography, estimating under 500,000 physical qubits for widely used curves. All three results are theoretical resource estimates — the same evidence category as INST-002's original figure — not experimental progress toward the claim. The pressure state remains ESCALATING; no reclassification is warranted by an estimate revision alone. What is new is the rate: three independent downward revisions within roughly eighteen months is faster compression of the engineering-gap estimate than the original record anticipated, and OQ-001 now has materially fresher input than it did at AS-001.
Sourced from: Gidney, "How to factor 2048-bit RSA with less than a million noisy qubits" (May 2025, arXiv); Iceberg Quantum QLDPC architecture proposal (early 2026, unvalidated at scale per secondary reporting); Google Quantum AI / Stanford / Ethereum Foundation whitepaper on elliptic-curve cryptography resource estimates (March 2026). All three accessed via secondary technical reporting (The Quantum Insider, postquantum.com) rather than primary papers in full; primary sourcing should be substituted before this assessment is treated as fully verified.
Verification Stage: VS-03 after ratified review (stored code VS-02 preserved).
2026-09-15
Reassessed, no change — Escalating
LPR-001-D17 corrected the provenance and representation of all six legacy evidence instances. Shor's 1994 result establishes the algorithmic basis but not an RSA-2048 engineering estimate; Gidney–Ekerå provides the 20-million-qubit resource estimate; the 2022 Yan et al. experiment factored only small integers and proposed, rather than demonstrated, RSA-2048 scaling; and Gidney 2025 reduces the RSA-2048 estimate to fewer than one million noisy qubits without an experimental factorisation. The earlier AS-001/AS-002 wording remains historical and is not silently rewritten. The corrected evidence still supports ESCALATING / VS-02: substrate capability and theoretical resource estimates are advancing, but no commercially relevant RSA key has been factored by a quantum computer. The 2026 QLDPC Pinnacle estimate and other genuinely new resource analyses require normal Record Review before they can affect the canonical evidence state.
Corrective assessment issued after LPR-001-D17. It supersedes provenance-dependent historical characterisations in AS-001/AS-002 without altering their append-only text.
2026-09-15
Reassessed, no change — Escalating
Normal Record Review admits two independent 2026 RSA-2048 resource analyses. Webster et al.'s Pinnacle Architecture estimates fewer than 100,000 physical qubits under explicit QLDPC and hardware assumptions, while Mundada et al. estimate approximately 381,000 physical qubits and 9.2 days using an experimentally demonstrated grid-coupling topology, with lower or faster alternatives under changed architectural assumptions. Together they strengthen the evidence that theoretical resource requirements can compress substantially through architecture and compilation choices. They do not demonstrate the required fault-tolerant machine, an RSA-2048 factorisation, or a uniform like-for-like trend across architectures. ESCALATING / VS-02 therefore remains appropriate: the modelled engineering boundary has moved materially, but the tracked claim remains experimentally unrealised.
IN-007 and IN-008 admitted through normal Record Review after LPR-001-D17. Architecture-dependent estimates are kept distinct from experimental capability and from like-for-like surface-code resource reductions.
Claim Lineage

Historical narrative recorded for this claim. It does not override the current State Warrant.

1994
Shor publishes polynomial-time quantum algorithms for factoring and discrete logarithms, establishing the theoretical basis for quantum attacks on RSA.
2019–21
Gidney–Ekerå quantify one fault-tolerant RSA-2048 path at approximately 20 million noisy physical qubits and eight hours under stated assumptions.
2022–23
Yan et al. demonstrate hybrid factorisation only at small integer sizes and estimate a 372-qubit path to challenge RSA-2048; an independent implementation contests the claimed scaling beyond small inputs.
2024
Error-correction substrate evidence strengthens and NIST finalises ML-KEM, ML-DSA and SLH-DSA, while no cryptographically relevant quantum factorisation is demonstrated.
2025
Gidney reduces the theoretical RSA-2048 estimate to fewer than one million noisy qubits and less than one week under the same headline hardware assumptions as the earlier estimate. The change is theoretical resource compression, not experimental RSA progress.
2026
Independent architecture studies widen the feasible resource-estimate envelope: Pinnacle models RSA-2048 below 100,000 physical qubits using QLDPC codes, while Mundada et al. estimate approximately 381,000 physical qubits and 9.2 days with experimentally demonstrated grid connectivity. Neither is an experimental RSA factorisation; architecture assumptions now materially determine the headline resource count.
Open Questions

Questions retained in this record. The current State Warrant may have narrowed or reframed earlier questions.

OQ-001

How quickly can experimentally demonstrated fault-tolerant hardware close the gap to architecture-dependent RSA-2048 resource estimates? Primary-source estimates now range from below one million noisy qubits for Gidney's 2025 surface-code analysis to below 100,000 under Pinnacle's QLDPC assumptions and approximately 381,000 under Mundada et al.'s experimentally demonstrated grid-connectivity case. None is an experimental roadmap or evidence that the required machine exists.

Raised 2024-01-15
OQ-002

IN-004 (NIST PQC standards) is the second occurrence of anticipatory institutional evidence as an evidence object type (the first was FR-AM-0004 INST-003, the Helion/Microsoft contract). The corpus now has two instances. Whether anticipatory institutional acts constitute evidence for a claim — and at what weight — is a recurring question that may warrant attention before a third occurrence.

Raised 2024-01-15
OQ-003

This claim sits at the top of the PROG-QE capability stack and depends on all substrate claims being satisfied first. If FR-QE-0003 or FR-QE-0004 encounter unexpected obstacles at larger scales, this claim's trajectory changes without any direct evidence bearing on it. How should a record respond when its substrate records encounter setbacks? No governed procedure exists.

Raised 2024-01-15
OQ-004

How much evidentiary weight should repeated downward revisions in theoretical RSA resource estimates receive when architectural assumptions change? The 2026 admissions confirm that lower resource counts are not one uniform trend line: Pinnacle obtains below 100,000 through QLDPC architecture assumptions, while Mundada et al. obtain approximately 381,000 with demonstrated grid connectivity and approximately 190,000 only under hypothetical long-range coupling. Future reviews should distinguish like-for-like algorithmic improvement from resource reductions purchased by new architectural assumptions.

Raised 2026-06-29
Mutation Log
MutationDateFieldPrior valueCurrent value
M-0152026-09-15instances_loggedIN-006IN-008
M-0142026-09-15provenance_correctedLPR-001-D17 discrepanciesPASS-AFTER-CORRECTION
M-0132026-09-06description_restoredLegacy ingestion cutoffs: mechanisms:RM-001, mechanisms:RM-002, mechanisms:BN-001, mechanisms:AT-001Source-restored complete descriptions
M-0122026-07-09description_reordered—DESCRIPTION-REORDERED
M-0112026-07-08reference_corrected—REFERENCE-CORRECTED
M-0102026-07-08realization_note_added—REN-001
M-0092026-06-29open_question_raised—OQ-RAISED
M-0082026-06-29assessment_issuedAS-001AS-002
M-0072026-06-29instances_logged—INSTANCES-LOGGED
M-0062024-01-15programme_panel_added—PROGRAMME-PANEL-ADDED
M-0052024-01-15null_condition_met—NULL-CONDITION-MET
M-0042024-01-15mechanisms_recorded—MECHANISMS-RECORDED
M-0032024-01-15assessment_issued—ASSESSMENT-ISSUED
M-0022024-01-15instances_logged—INSTANCES-LOGGED
M-0012024-01-15record_created—RECORD-CREATED
Evidence Sources
8 instances on recordShow sources ↓Hide ↑
IN-001Shor's algorithm — theoretical foundation established1. Shor, P. W. Algorithms for quantum computation: discrete logarithms and factoring. Proceedings of the 35th Annual Symposium on Foundations of Computer Science (1994). DOI 10.1109/SFCS.1994.365700 · Algorithm and complexity resultneutral
IN-002Gidney–Ekerå — RSA-2048 physical-resource estimate1. Gidney, C. & Ekerå, M. How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits. Quantum 5, 433 (2021). DOI 10.22331/q-2021-04-15-433 · Abstract and resource estimateneutral
IN-003FR-QE-0003 and FR-QE-0004 substrate progress — engineering prerequisites advance1. Google Quantum AI and Collaborators. Quantum error correction below the surface code threshold. Nature 638, 920–926 (2025). DOI 10.1038/s41586-024-08449-y · Published online 9 December 2024; d=3, 5 and 7 scaling2. Quantinuum and Microsoft. Breakthrough demonstration of reliable logical qubits. 3 April 2024. · Company announcement; four logical qubits and reported logical-error suppressionsupportive
IN-004NIST finalises first post-quantum cryptography standards1. NIST. Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography. 13 August 2024. · FIPS 203, 204 and 205 approval and algorithm namespartial
IN-005Yan et al. hybrid factorisation proposal — small-device demonstration and scaling challenge1. Yan, B. et al. Factoring integers with sublinear resources on a superconducting quantum processor. arXiv:2212.12372 (2022). · Abstract; submitted 23 December 20222. Khattar, T. & Yosri, N. A comment on ‘Factoring integers with sublinear resources on a superconducting quantum processor’. arXiv:2307.09651 (2023). · Abstract and implementation resultcontesting
IN-006Gidney — RSA-2048 estimate falls below one million noisy qubits1. Gidney, C. How to factor 2048 bit RSA integers with less than a million noisy qubits. arXiv:2505.15917 (2025). · Abstract; submitted 21 May 2025neutral
IN-007Pinnacle Architecture — QLDPC RSA-2048 estimate below 100,000 physical qubits1. Webster, P. et al. The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes. arXiv:2602.11457 (2026). · Abstract and RSA-2048 resource estimate; v2 May 2026supportive
IN-008Heterogeneous architecture — RSA-2048 estimate with experimentally demonstrated grid connectivity1. Mundada, P. S. et al. Heterogeneous architectures enable a 138x reduction in physical qubit requirements for fault-tolerant quantum computing under detailed accounting. arXiv:2604.06319 (2026). · Abstract; RSA-2048 resource estimatessupportive