What Is Q-Day? Reading the Quantum Timeline Without the Hype

Q-Day is when quantum computers break today's public-key crypto. Why the estimates fell from 20 million qubits to 10,000, and how to read them.

Share
Three quantum computer cabinets shrinking from tall to small, with the Cosmo mascot measuring the smallest one

"Q-Day" is the name people use for the day a quantum computer can break the public-key cryptography that protects most of the internet: RSA, and the elliptic curve schemes behind TLS, messaging apps and cryptocurrencies. Researchers call the machine that could do it a cryptographically relevant quantum computer.

Nobody knows when that day comes, and anyone who gives you an exact year is guessing. But the estimates have a direction, and it is worth understanding why they keep moving the way they do. That is the subject of this third post in our Quantum, Plainly series, after harvest now, decrypt later and why quantum advantage headlines are not Q-Day.

Why there is no single date

Three things have to line up before Q-Day, and each one moves on its own schedule.

  • Hardware. How many physical qubits a machine has, how often they make errors, how fast they operate, and which qubits can talk to which.
  • Error correction. How many physical qubits it takes to build one reliable logical qubit. This is the "exchange rate" of quantum computing, and it dominates the cost.
  • Algorithms. How many logical qubits and operations Shor's algorithm actually needs for a real key, once someone has optimized the circuit.

A resource estimate is a statement about all three at once: "with hardware like this, error correction like that, and this version of the algorithm, the attack needs N physical qubits for T hours." Improve any one of the three and N drops. Over the past seven years, all three improved.

The estimates, one paper at a time

Here is the path of the headline number, the count of physical qubits needed.

  • 2019: about 20 million. Craig Gidney and Martin Ekerå estimated that factoring a 2048-bit RSA key would take roughly 20 million noisy qubits running for about eight hours. This became the standard reference point.
  • May 2025: under one million. Gidney cut that by about twenty times, to fewer than a million qubits running for less than a week. The hardware assumptions did not change: a flat grid of qubits talking to their neighbors, one error per thousand operations, one error-correction cycle per microsecond. The savings came from better arithmetic and cheaper ways to produce the special "magic states" the algorithm consumes.
  • February 2026: under 100,000. Iceberg Quantum's Pinnacle architecture claimed RSA-2048 with fewer than 100,000 physical qubits, taking about a month per key in its example. The trick is a different family of error-correcting codes (quantum LDPC codes) that protect more logical qubits per physical qubit, at the price of needing long-range connections between qubits that have not been demonstrated at scale. Scott Aaronson called it serious and plausible work, while noting how much harder those codes are to engineer.
  • March 2026: under 500,000, for elliptic curves. Google Quantum AI estimated that 256-bit elliptic curve keys could be broken with about 1,200 logical qubits and fewer than 500,000 physical qubits, in a runtime measured in minutes. Unusually, Google did not publish the attack circuits, releasing a zero-knowledge proof instead so others can verify the numbers without getting a blueprint.
  • March 2026: as few as 10,000. A team from Caltech and the startup Oratomic, including John Preskill, showed that Shor's algorithm could run at cryptographically relevant sizes on as few as 10,000 reconfigurable neutral-atom qubits. The catch is time: with 26,000 atoms, a 256-bit elliptic curve key takes a few days, and RSA-2048 takes ten to a hundred times longer.
Log-scale bar chart of physical qubits needed to run Shor's algorithm: 20 million in 2019, one million in 2025, 100,000 in February 2026, 500,000 for elliptic curves in March 2026, and 10,000 in March 2026

The chart is a trend, not a like-for-like race. The targets differ (RSA or elliptic curves), the assumed hardware differs (superconducting grids or movable atoms), and so do the runtimes (minutes, days or a month). But the direction is not in doubt: in under seven years, the size of the machine we need to worry about has fallen by about three orders of magnitude on paper.

Why the number keeps falling

It is tempting to read that chart as "quantum computers got a thousand times better". They did not. Most of the drop came from people doing more with the same assumptions.

Better algorithms. Shor's algorithm from 1994 is a mathematical idea, not a program. Turning it into the cheapest possible circuit is an optimization problem that researchers have only recently attacked seriously, and each pass finds savings in the arithmetic.

Better codes. The surface code, the workhorse of error correction, is robust and simple but expensive, spending hundreds of physical qubits per logical one. Newer codes spend far fewer, if the hardware can support them. Neutral atoms, which can be physically moved around, are a natural fit, which is why several of the lowest estimates assume them.

Trading qubits for time. A smaller machine can often do the same job by running longer. Going from minutes to days sounds like a big concession, but for an attacker holding recorded traffic, a few days per key is still a working attack.

What has not changed

All of these are estimates for machines that do not exist. No one has built a fault-tolerant quantum computer running error correction continuously for days, and doing so is still a very hard engineering problem. Labs have trapped arrays of thousands of atoms and built tens of logical qubits, but not both at once, at low enough error rates, for long enough.

There is also a healthy dose of uncertainty in each paper. Some assume connectivity or decoding speeds that no machine has shown. The honest summary is that the paper barrier has dropped sharply, while the engineering barrier is still high and its timing is unknown.

What the people with the most at stake are doing

The clearest signal is not a forecast but a deadline. On March 25, 2026, Google set 2029 as the year it aims to finish moving its own systems to post-quantum cryptography, citing progress in hardware, error correction and resource estimates. Cloudflare announced the same target shortly after. Regulators are slower but pointing the same way: NIST's draft plan deprecates today's weakest RSA and elliptic curve settings after 2030 and disallows them after 2035.

None of these organizations is claiming Q-Day arrives in 2029. They are saying that migrations take years, estimates keep dropping, and being early costs far less than being late.

How to read the timeline without the hype

A few rules of thumb for the next "Q-Day is closer than you think" story:

  • Think in ranges, not years. Credible views span roughly the early 2030s to the 2040s. Anyone quoting a single year is selling something.
  • Ask what the estimate assumes. Qubit type, error rate, connectivity and runtime. A 10,000-qubit estimate that takes a month is a different claim from a 500,000-qubit one that takes minutes.
  • Separate paper progress from hardware progress. Resource estimates can fall overnight. Machines improve on a slower, steadier curve.
  • Plan with the inequality, not the date. As in our first post, what matters is whether your data's shelf life plus your migration time outlasts the earliest plausible Q-Day. For long-lived data, it already does.

Next week: why the part of the internet that keeps your messages private went post-quantum years ago, while the part that proves who you are talking to is only getting started.

If you enjoy plain-language explanations like this one, subscribe below. We publish them alongside updates on what we are building at FirstPoint.