It started with a soap bubble.
Blow one and watch it drift. For a few seconds it is a perfect thing, a sphere of swirling color, physics balanced on a film thinner than a wavelength of light. Then a draft touches it, or a mote of dust, or nothing you can see at all, and it is gone. Not damaged. Gone. A soap bubble does not degrade gracefully. It exists completely and then it does not exist, and everything it was doing ends in the same instant.
In the last post, I showed you the complete mechanism by which a quantum computer breaks RSA. Superposition loads the problem, interference silences the wrong answers, measurement reads the survivor. The mathematics has been settled since 1994. And I ended on the honest cliffhanger: the machine that runs it does not exist. This post is about why, and about the honest answer to the question everyone eventually asks, which is how long the gap will last.
The short version of why is that we are trying to build a computer out of soap bubbles.
The fragility is not a defect
Everything that makes a qubit powerful comes from its isolation. Qubit is short for quantum bit, and the superpositions and interference we have spent four posts on only exist while the qubit remains genuinely undisturbed, a pond no one has touched. The catch is that the universe is not polite. Every stray photon, every vibration, every whisper of heat is a kind of touch, and a touch acts like a measurement whether anyone intended one or not. Physicists call the resulting collapse decoherence, meaning the process by which a qubit loses its quantum character and becomes an ordinary, definite bit through unwanted contact with its surroundings.
This is why the machines look the way they do. The superconducting processors at IBM and Google live at the bottom of dilution refrigerators colder than deep space. Trapped-ion machines hold single charged atoms in electromagnetic fields inside a hard vacuum. Every layer of that engineering exists to keep the universe from touching the bubble. And even so, the bubble pops. A superconducting qubit holds its quantum state for something on the order of a ten-thousandth of a second. The machine has to finish its work, or protect its work, inside the lifetime of a soap bubble.
Your classical instinct sees the fix immediately. Computers have always been built from unreliable parts. Hard drives fail, bits flip, network packets vanish, and we paper over all of it with redundancy and checksums. Store the data three times, compare copies, majority vote wins. Surely the same medicine works here.
The instinct is right about the disease and wrong about the medicine, in a way that took physicists years to untangle. Because quantum information has two properties that break every classical redundancy trick at once. You cannot copy a qubit. The laws of quantum mechanics flatly forbid duplicating an unknown quantum state, so “store it three times” is not merely hard, it is illegal. And you cannot check on a qubit, because looking at it is a measurement, and measurement destroys the very superposition you were trying to protect. The two most basic moves in classical error correction, copy and compare, are both against the rules.
Spelling Bravo without saying B
Here is the shape of the solution, and it is one of the cleverest ideas of the last thirty years.
Think about a radio operator on a bad connection spelling a word. She does not say the letter B and hope. She says Bravo. The word is longer than the letter, and that is the point. Static can chew off the front or the back of Bravo and the listener still recovers the B, because the letter is no longer stored in any single sound. It is spread across the whole word. The information survives damage to its parts because it does not live in any one part.
Quantum error correction does this with quantum states. It spreads the information of one ideal qubit across many physical qubits, entangled together, so that the quantum state does not live in any individual qubit. The environment can touch individual qubits, pop individual bubbles, and the spread-out information survives. And the checking problem has an answer just as clever as the storage problem: instead of reading the data, which would destroy it, the machine continuously asks the group of qubits indirect questions, along the lines of “do these two neighbors still agree with each other,” questions whose answers reveal where an error happened without revealing, or disturbing, the protected information itself.
The result has a name you need for every conversation about this technology from now on. A physical qubit is one actual, fragile device, one soap bubble. A logical qubit is one reliable, error-corrected unit of quantum information, woven out of many physical qubits and kept alive by constant correction. Shor’s algorithm, the real thing, runs on logical qubits. Every physical qubit count you have ever seen in a headline has to be run through an exchange rate before it means anything.
For years there was a genuinely open question underneath all of this: does the weaving actually help? Error correction itself is built from the same faulty parts it is trying to fix, and if the correction machinery adds more noise than it removes, the whole scheme makes things worse. The theory said that below a certain hardware error rate, adding more physical qubits per logical qubit makes the logical qubit better, exponentially better, rather than worse. That threshold claim was the load-bearing wall of the entire field. As of this year, multiple independent research teams have demonstrated it on real hardware. Adding qubits now provably makes things more reliable, not less. Whatever else is uncertain in this story, the fundamental physics question has been answered, and it was answered yes.
The exchange rate, and where the machines actually are
So the honest scoreboard, as of the summer of 2026, reads like this.
The largest quantum processors in the world hold physical qubits in the hundreds to low thousands. IBM has demonstrated a chip with a little over 1,100 physical qubits, and neutral-atom labs have trapped arrays of several thousand atoms, with the largest array to date holding about 6,100, although that one has not yet been used for computation.
Logical qubits, the ones that matter, are far scarcer. The best demonstrations at the time of writing are 96 logical qubits woven from 448 physical ones, published this January, and 94 logical qubits announced in March at a remarkable roughly two-for-one exchange rate, that second machine reflecting how much the underlying hardware quality matters. Another lab needed roughly 1,200 physical qubits to produce 24 logical ones. The exchange rate is not one number. It depends entirely on how error-prone your bubbles are to begin with, and it currently ranges from two physical qubits per logical qubit to fifty or worse.
Now the other side of the ledger. What does it take to break RSA-2048 with Shor’s algorithm?
This is the number I most want you to watch, because it is the number that keeps falling. In 2012, published estimates put the cost at roughly a billion physical qubits. In 2019, a careful analysis by Craig Gidney and Martin Ekerå brought it down to about 20 million physical qubits running for eight hours. In May 2025, Gidney published a revision: under one million physical qubits, running for under a week, using the same hardware assumptions as before. The improvement came from better algorithms and better error-correcting codes, not better hardware. And in the first half of 2026, new architecture proposals have pushed claimed requirements lower still, first to around 100,000 physical qubits, and then, in one design from a new neutral-atom company, to roughly 10,000. Both of those 2026 figures are designs on paper for machines nobody has built, and neither has been demonstrated.
Hold those two ledgers side by side and you can see the actual race. It is not machines racing toward a fixed finish line. The machines are climbing from thousands of qubits upward while the finish line falls from a billion downward, and both trends have been moving in the same direction for a decade without a single published reversal. Every revision of the requirement has made it smaller. Every generation of hardware has made the machines bigger and cleaner. The gap is closing from both ends.
The Q-Day reality check
Which brings us to the question, and I am going to give you the honest answer rather than the satisfying one.
The moment a quantum computer first breaks real-world encryption has a nickname, Q-Day, and nobody knows when it is. Not the vendors, not the intelligence agencies, not the researchers publishing the estimates. Your classical instinct wants a date, and the honest answer is not a date. It is a probability distribution.
The most serious attempt to pin that distribution down is an annual survey of quantum computing experts run by the Global Risk Institute. The seventh edition, published in March 2026, asked 26 researchers across academia and industry. Their pooled judgment puts the probability of a cryptographically relevant quantum computer within the next ten years somewhere between roughly 30 and 50 percent, and within fifteen years at better than even odds. Read those numbers again slowly, because both halves matter. This is not “imminent,” and anyone selling you imminent is selling. It is also nowhere near “never,” and it is far too likely to ignore, because we do not build critical infrastructure to survive coin flips.
And here is the turn that the whole final post of this series hangs on. For a large class of encrypted data, Q-Day is not the deadline. The deadline is earlier, and for some data it has already passed. The reasoning fits in one sentence, and it is the most important sentence in this post: encrypted traffic can be recorded today, stored cheaply for years, and decrypted the day the machine exists. If the data you are protecting still needs to be secret in the 2030s, then a machine that arrives in the 2030s reads it, no matter that the machine did not exist on the day the data was sent. The industry calls this harvest now, decrypt later (HNDL), and it converts a future probability into a present-tense problem. A useful rule of thumb, from the same researcher who runs that expert survey: add the number of years your data must stay secret to the number of years your migration will take, and if the sum reaches past the arrival of the machine, you are already exposed.
That is why the deadlines that matter are not written by physicists. As of this writing, Google, Microsoft and Cloudflare have set an internal target of 2029 to complete their own migration to quantum-safe cryptography. The United States federal government has signed deadlines into policy measured in single-digit years. The people with the most visibility into the hardware are not behaving like people with decades of slack.
The bombe has one more thing to teach us here, and it is a lesson about timing rather than mathematics. The machine at Bletchley Park was not built after someone proved it would work on a comfortable schedule. It was built under uncertainty, against a threat that could not wait for certainty, and history is not kind to the institutions that waited. Eighty years later, the migration to quantum-safe cryptography is being run on exactly that logic, and it is already underway, with standards published, government deadlines signed, and the largest technology companies rebuilding the plumbing of the internet in plain sight.
What that migration looks like, what those deadlines actually say, and what all of it means for the systems I work with every day, is the final post.

Leave a comment