← ObservatoryThe RecordFR-QE-0005
PROG-QE
FR-QE-0005

Cryptographically Relevant Quantum Computing — RSA Factorisation

A quantum computer can factor commercially relevant RSA cryptographic keys faster than any classical computer.

EscalatingVS-03·since 2026-06-29
Verification Matrix
VS-01
Assertion
VS-02
Published
2024-01-15
VS-03
Audit
2026-06-29 — present
VS-04
Replication
VS-05
Operation
State reached Current state Not yet reached
State Warrant
Current stateEscalatingVS-03
Why this state?Sourced from: Gidney, "How to factor 2048-bit RSA with less than a million noisy qubits" (May 2025, arXiv); Iceberg Quantum QLDPC architecture proposal (early 2026, unvalidated at scale per secondary reporting); Google Quantum AI / Stanford / Ethereum Foundation whitepaper on elliptic-curve cryptography resource estimates (March 2026). All three accessed via secondary technical reporting (The Quantum Insider, postquantum.com) rather than primary papers in full; primary sourcing should be substituted before this assessment is treated as fully verified.
Assessment summaryNo threshold has been crossed since AS-001 — no factorisation of a commercially relevant key has occurred, and none is closer to occurring in any demonstrated sense. What has moved is the resource-estimate trajectory underlying OQ-001. Gidney (Google, May 2025) reduced the estimated physical-qubit requirement for RSA-2048 factorisation from the Gidney-Ekerå (2021) figure of ~20 million to under 1 million, under comparable fault-tolerance assumptions — roughly a 20-fold reduction achieved through improved algorithmic and error-correction engineering rather than any experimental demonstration. A 2026 proposal using QLDPC codes (an architecture distinct from the surface codes assumed in both prior estimates) suggests a further reduction toward ~100,000 physical qubits, though this is unvalidated at scale. A March 2026 Google/Stanford/Ethereum Foundation whitepaper applies the same style of resource-reduction analysis to elliptic-curve cryptography, estimating under 500,000 physical qubits for widely used curves. All three results are theoretical resource estimates — the same evidence category as INST-002's original figure — not experimental progress toward the claim. The pressure state remains ESCALATING; no reclassification is warranted by an estimate revision alone. What is new is the rate: three independent downward revisions within roughly eighteen months is faster compression of the engineering-gap estimate than the original record anticipated, and OQ-001 now has materially fresher input than it did at AS-001.
State entered2024-01-15
Last reaffirmed2026-06-29
Stage provenanceRatified VS-03; stored historical code VS-02 preserved.
Record Lineage — Chronological
2024-01-15
Record opened — Escalating
The claim has not been satisfied. No quantum computer has factored a commercially relevant RSA key. The most credible direct attempt (INST-005) failed. The engineering gap between current capability and the Gidney-Ekerå resource estimate remains approximately three to four orders of magnitude in physical qubit count, with additional requirements for error rates, connectivity, and operational duration not yet demonstrated at any scale approaching relevance. The pressure state is ESCALATING rather than EMERGING because the substrate advances documented in FR-QE-0003 and FR-QE-0004 (INST-003) show the underlying error-correction engineering progressing on a credible trajectory, even though the gap to the resource requirement remains enormous. Institutional behaviour — NIST's finalisation of post-quantum cryptography standards (INST-004) — reflects institutional acceptance that the risk is credible enough to justify migration, adding pressure to the claim's trajectory independent of any direct technical progress toward satisfaction.
Verification Stage: VS-02 preserved — historically unverified.
2026-06-29
Reassessed, no change — Escalating
No threshold has been crossed since AS-001 — no factorisation of a commercially relevant key has occurred, and none is closer to occurring in any demonstrated sense. What has moved is the resource-estimate trajectory underlying OQ-001. Gidney (Google, May 2025) reduced the estimated physical-qubit requirement for RSA-2048 factorisation from the Gidney-Ekerå (2021) figure of ~20 million to under 1 million, under comparable fault-tolerance assumptions — roughly a 20-fold reduction achieved through improved algorithmic and error-correction engineering rather than any experimental demonstration. A 2026 proposal using QLDPC codes (an architecture distinct from the surface codes assumed in both prior estimates) suggests a further reduction toward ~100,000 physical qubits, though this is unvalidated at scale. A March 2026 Google/Stanford/Ethereum Foundation whitepaper applies the same style of resource-reduction analysis to elliptic-curve cryptography, estimating under 500,000 physical qubits for widely used curves. All three results are theoretical resource estimates — the same evidence category as INST-002's original figure — not experimental progress toward the claim. The pressure state remains ESCALATING; no reclassification is warranted by an estimate revision alone. What is new is the rate: three independent downward revisions within roughly eighteen months is faster compression of the engineering-gap estimate than the original record anticipated, and OQ-001 now has materially fresher input than it did at AS-001.
Sourced from: Gidney, "How to factor 2048-bit RSA with less than a million noisy qubits" (May 2025, arXiv); Iceberg Quantum QLDPC architecture proposal (early 2026, unvalidated at scale per secondary reporting); Google Quantum AI / Stanford / Ethereum Foundation whitepaper on elliptic-curve cryptography resource estimates (March 2026). All three accessed via secondary technical reporting (The Quantum Insider, postquantum.com) rather than primary papers in full; primary sourcing should be substituted before this assessment is treated as fully verified.
Verification Stage: VS-03 after ratified review (stored code VS-02 preserved).
Mutation Log
MutationDateFieldPrior valueCurrent value
M-0122026-07-09description_reorderedDESCRIPTION-REORDERED
M-0112026-07-08reference_correctedREFERENCE-CORRECTED
M-0102026-07-08realization_note_addedREN-001
M-0092026-06-29open_question_raisedOQ-RAISED
M-0082026-06-29assessment_issuedAS-001AS-002
M-0072026-06-29instances_loggedINSTANCES-LOGGED
M-0062024-01-15programme_panel_addedPROGRAMME-PANEL-ADDED
M-0052024-01-15null_condition_metNULL-CONDITION-MET
M-0042024-01-15mechanisms_recordedMECHANISMS-RECORDED
M-0032024-01-15assessment_issuedASSESSMENT-ISSUED
M-0022024-01-15instances_loggedINSTANCES-LOGGED
M-0012024-01-15record_createdRECORD-CREATED
Evidence Sources
6 instances on recordShow sources ↓Hide ↑
IN-001Shor's algorithm — theoretical foundation establishedneutral
IN-002Small-scale Shor demonstrations and resource estimate refinementsneutral
IN-003FR-QE-0003 and FR-QE-0004 substrate progress — engineering gap begins closingsupportive
IN-004NIST post-quantum cryptography standards — world prepares for the claim being satisfiedpartial
IN-005Chinese research group factorisation claim — and rapid refutationcontesting
IN-006Gidney (2025) and successive resource-estimate reductions — RSA and elliptic-curveneutral