When will Quantum Computers Break Existing PKI Crypto?

Quantum crypto

We asked Hal9000 (Claude) how likely Public Key Infrastructure (PKI) crypto could be broken by existing quantum computers.

Considering the rapid evolution of quantum computing, one might wonder how much longer we will be safe. While the report seems optimistic in that it’s not currently possible to break PKI in short timespans, organizations should really be concerned about the “harvest now, analyze later” challenge.

Verdict: across every publicly documented quantum system as of mid-2026, no deployed public-key algorithm — RSA-2048, RSA-4096, ECC P-256/P-384, or Diffie-Hellman — can be broken in 7 days, or in any realistic timeframe, on existing hardware. The shortfall isn’t close. It’s measured in orders of magnitude, on both qubit count and error-correction maturity.

01 / The Gap, Measured

Required vs. demonstrated — log scale

RSA-2048 factoring via Shor’s algorithm.

1 10 100 1K 10K 100K 1M LOGICAL QUBITS best demonstrated (QuEra) 96 required — optimized circuit ~1,730 required — classic Shor bound 4,099 PHYSICAL QUBITS largest single processor (IBM) 1,121 required — optimistic 2026 est. 100,000 required — conservative est. ~1,000,000
02 / Algorithm-by-Algorithm

What’s actually on the table right now

Algorithm Attack Logical qubits needed Current best 7-day break?
RSA-2048 Shor’s (factoring) ~1,730 – 4,099 96 demonstrated No
RSA-4096 Shor’s (factoring) ~3,460 – 8,195 96 demonstrated No
ECC P-256 Shor’s (discrete log) ~1,500 – 2,300 (est.) 96 demonstrated No
Diffie–Hellman Shor’s (discrete log) Comparable to RSA at same key size 96 demonstrated No
AES-256 Grover’s (brute force) Quadratic speedup only — ~128-bit security remains not a live concern No

Note on ECC: because Shor’s algorithm scales with key size rather than classical security strength, and ECC’s stronger per-bit security let implementers use much shorter keys (256 vs. 2048 bits), elliptic curve schemes are generally expected to fall to a capable quantum computer before RSA does — once one exists.

03 / Why “7 Days” Doesn’t Work as a Frame

Even the optimistic path requires 5 days of uptime alone

  • Best 2025 estimate (Gidney, Google): RSA-2048 factoring needs under 1 million physical qubits — and 5 days of continuous, fault-tolerant runtime once that machine exists. That’s the runtime budget alone, before any machine capable of it has been built.
  • Most aggressive 2026 estimate (LDPC-code approach): ~100,000 physical qubits — still roughly 100x larger than the largest processor that exists today.
  • The lowest-qubit circuit designs trade space for time: on the order of 2³⁶ (~68 billion) Toffoli gates per run, with roughly 40 repeated runs expected before success — none of which has been executed at any meaningful scale.
  • Logical-qubit demonstrations today top out at 96 (QuEra). Getting to the ~1,730–4,099 logical qubits Shor’s algorithm needs isn’t a software update — it’s a hardware-scaling problem still measured in years on every public roadmap.
04 / The Timeline That Actually Matters

Not “if 7 days,” but “when years”

Resource estimates for breaking RSA-2048 have fallen consistently for over a decade — from roughly a billion physical qubits in 2010-era analyses to under a million today — driven by better algorithms (windowed arithmetic, discrete-log shortcuts, LDPC error correction) more than by raw hardware growth. That trend is real and worth tracking. But an expert consensus places a cryptanalytically relevant quantum computer in the 2029–2032 window, with 2030 commonly cited as a median estimate. The NSA’s own public position is that it does not know when, or even if, such a machine will be built.

The operationally relevant risk today isn’t live decryption — it’s harvest-now, decrypt-later: encrypted traffic captured today and stored for a future quantum break. That risk doesn’t care about qubit counts; it cares about how long your data needs to stay confidential and how fast your organization migrates to post-quantum algorithms (ML-KEM, ML-DSA, and friends).

Methodology: figures drawn from publicly published hardware specs (IBM, Google, QuEra, Quantinuum, Atom Computing) and peer-reviewed / preprint resource-estimation papers (Gidney & Ekerå; Chevignard et al.; 2026 LDPC-code resource estimates) current as of Jun–Jul 2026. Qubit and runtime figures are estimates from cited literature, not measured attacks — no organization has demonstrated factoring of a cryptographically relevant RSA modulus.