Quantum Advantage Is Not Q-Day: Two Very Different Milestones
Headlines say quantum computers beat supercomputers. That is not the same as breaking encryption. Here is the gap between the two milestones.
Every few months a headline announces that a quantum computer has done something no classical computer can. In October 2025 it was Google's Willow chip. In July 2026 it was IBM, three times in one day. Each time, a reasonable person asks the same follow-up question: does this mean encryption is broken?
It does not. "Quantum advantage" and "Q-Day", the day a quantum computer can break the public-key cryptography the internet runs on, are two different milestones. They are measured in different units, they need different machines, and today they are separated by several orders of magnitude.
This is the second post in our Quantum, Plainly series. The first one explained why recorded traffic makes quantum a problem today. This one is about reading the news without either panicking or shrugging.
Two milestones, two questions
The two terms answer different questions.
- Quantum advantage asks: is there any task, however narrow, where a quantum computer beats the best classical method? The task is usually chosen by the researchers because it suits quantum hardware and is hard to simulate classically.
- Q-Day asks: can a quantum computer run one specific algorithm, Shor's algorithm, on real 2048-bit RSA keys or 256-bit elliptic curve keys, correctly, to the end?
The first is a race you can win with a clever choice of problem. The second is a fixed target that does not move to suit the machine. Winning the first says very little about how close you are to the second.
What the advantage experiments actually did
It helps to look at the recent results in detail, because the details are where the difference lives.
Google Quantum Echoes (October 2025). Google ran an algorithm on its Willow processor that measures how information spreads and scrambles inside a quantum system, a quantity physicists call an out-of-time-order correlator. Google reported it ran about 13,000 times faster than the best known classical method on a top supercomputer, and that the result is verifiable: another quantum computer can repeat it, and for some molecules it can be compared with laboratory measurements. It is a genuine scientific result and a step toward useful physics simulation.
IBM, three claims in one day (July 2026). IBM announced three results on July 30, 2026, based on preprints posted a few days earlier. As an independent fact-check points out, they do not carry equal weight:
- The strongest, with the University of Chicago, sampled from a specially constructed circuit on 97 physical qubits of an IBM Heron processor and came with a mathematical argument that the task is hard for classical computers, plus a certificate for how accurate the hardware was.
- The other two, with Qedma (74 qubits) and Algorithmiq (56 qubits), simulated physics models and showed that the classical methods the teams tried became unreliable. That is useful evidence, but a weaker claim than "no classical computer can do this".
All three are real engineering achievements. All three are also simulations of model systems that were picked because they are hard classically, not because anyone needed the answer.
The classical side keeps answering
Advantage claims have a habit of shrinking after publication, because classical researchers treat them as a challenge.
Google's 2019 "quantum supremacy" experiment on its 53-qubit Sycamore chip estimated that a supercomputer would need about 10,000 years to match it. IBM immediately argued it would take days, not millennia. By 2022, improved classical simulation methods did it in hours on a GPU cluster, and a 2024 study reported running it faster than Sycamore itself, on 1,432 GPUs.
IBM's 2026 result is getting the same treatment, in a more constructive form. On August 13, a team posted a paper that computed the exact ideal probabilities of all 2,051 outputs IBM published for its largest run, in 37.3 minutes on 256 NVIDIA H100 GPUs. That is not a refutation: computing the probability of outputs you are handed is easier than producing the samples in the first place, and the authors say their numbers are consistent with IBM's accuracy claim. But it shows how quickly "beyond the reach of classical computers" turns into a moving line, measured in months.
This back-and-forth is healthy science. It is also the clearest sign that advantage lives at the edge of what classical computers can do, while Q-Day is nowhere near that edge.
What Q-Day actually requires
Shor's algorithm is not a sampling trick. It is a long, exact calculation: billions of logical operations in sequence, every one of which has to be right. Today's physical qubits make an error roughly once every thousand operations. A calculation that long on raw hardware would be noise long before it finished.
The answer is error correction: bundling many physical qubits into one reliable logical qubit, and correcting errors continuously while the program runs. The best current estimates for what that costs:
- Breaking 256-bit elliptic curve keys: about 1,200 logical qubits, built from fewer than 500,000 physical qubits, per Google Quantum AI in March 2026.
- Breaking RSA-2048: fewer than one million physical qubits running for under a week, per Craig Gidney in 2025.
Put next to the advantage experiments, the gap is easy to see.

On a log scale, where every step is ten times the one before, today's advantage runs sit about four steps away from a code-breaking machine. And qubit count is only one of the gaps. The machine also has to run error correction in real time, for days, without falling over.
The milestone worth watching: logical qubits
If advantage headlines are the wrong signal, what is the right one? Watch for progress on logical qubits: how many, how reliable, and for how long.
That field is moving. On September 24, 2026, Infleqtion announced 30 entangled logical qubits on its neutral-atom machine, encoded in 80 physical atoms. The caveats are instructive, and an independent analysis spells them out: the code used can detect errors but not correct them, and runs where an error was detected were thrown away. Throwing runs away works for short experiments, but the share you keep shrinks as circuits grow, so it cannot carry a days-long Shor calculation.
That is not a criticism of the work, which is a real step. It is a reminder of what the finish line looks like: not "logical qubits exist" but "enough logical qubits, corrected in real time, for long enough".
How to read the next headline
A short checklist for the next "quantum computer beats supercomputer" story:
- What was the task? If it is sampling or simulating a model system chosen for the experiment, it is an advantage result, not a cryptography result.
- Physical or logical qubits? A headline qubit count is almost always physical. Code-breaking is counted in logical qubits.
- Was error correction running, or were bad runs discarded? Detection plus throwing runs away does not scale to long programs.
- How long did the program run? Shor needs hours to days of continuous, corrected computation. Today's demonstrations are short circuits, repeated many times.
- Has the classical side answered yet? Give it a few months.
None of this means the threat is imaginary. The estimates for a code-breaking machine have fallen by more than an order of magnitude in six years, and that trend, not any single demo, is why migration timelines keep tightening. Next week's post looks at that trend directly: what Q-Day is, where the estimates come from, and why they keep dropping.
In the meantime, the practical advice has not changed: the fix for cryptography is new cryptography, and it is already rolling out. You do not have to wait for the headlines to settle to benefit from it.
If you like plain-language explanations of technical news, subscribe below. We publish them alongside updates on what we are building at FirstPoint.