Site icon The Word 360

Quantum Computing and Encryption: How Close Is the Threat in 2026?

Quantum Computing and Encryption: How Close Is the Threat in 2026?

Quantum Computing and Encryption: How Close Is the Threat in 2026?

&Tab;&Tab;<div class&equals;"wpcnt">&NewLine;&Tab;&Tab;&Tab;<div class&equals;"wpa">&NewLine;&Tab;&Tab;&Tab;&Tab;<span class&equals;"wpa-about">Advertisements<&sol;span>&NewLine;&Tab;&Tab;&Tab;&Tab;<div class&equals;"u top&lowbar;amp">&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;<amp-ad width&equals;"300" height&equals;"265"&NewLine;&Tab;&Tab; type&equals;"pubmine"&NewLine;&Tab;&Tab; data-siteid&equals;"173035871"&NewLine;&Tab;&Tab; data-section&equals;"1">&NewLine;&Tab;&Tab;<&sol;amp-ad>&NewLine;&Tab;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;&Tab;<&sol;div>&NewLine;&Tab;&Tab;<&sol;div><p dir&equals;"ltr">No quantum computer can break the encryption that protects your bank&comma; your messages&comma; or your crypto wallet today&period; What has changed is the estimate of how big a quantum computer would need to be&period; Google researcher Craig Gidney&&num;8217&semi;s 2025 paper cut the requirement for breaking RSA-2048 from 20 million noisy qubits to under one million&comma; and a Google white paper in March 2026 reported that elliptic curve encryption&comma; which Bitcoin uses&comma; could fall to fewer than 500&comma;000&period; In response&comma; NIST&comma; the US National Security Agency&comma; the European Union&comma; and Google have set migration deadlines that run from 2029 to 2035&period;<&sol;p>&NewLine;<p dir&equals;"ltr">This article explains what quantum computers can and cannot break&comma; how far hardware is from those estimates&comma; which deadlines apply&comma; and what it means for crypto holders&period; It is not financial&comma; legal&comma; or security advice&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">Can Quantum Computers Break Encryption Today&quest;<&sol;h2>&NewLine;<p dir&equals;"ltr">No&period; The Quantum Insider&&num;8217&semi;s April 2026 overview notes that breaking RSA-2048 would take roughly one million physical qubits running fault-tolerant error correction&period; A September 2026 preprint from Georgia Tech researchers states that current fault-tolerant systems achieve only dozens of logical qubits&period; A logical qubit is an error-corrected qubit built from many fragile physical ones&comma; and the attacks described below need hundreds or thousands of them&period;<&sol;p>&NewLine;<p dir&equals;"ltr">The threat is real but sits in the future&period; The reason to act now is that migrating encryption takes years&comma; and some data has to stay secret for decades&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">What Quantum Computers Can and Cannot Break<&sol;h2>&NewLine;<h3 dir&equals;"ltr"><strong>Public Key Encryption<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">RSA&comma; elliptic curve cryptography&comma; and Diffie-Hellman key exchange are the vulnerable group&period; They rely on math problems that Shor&&num;8217&semi;s algorithm solves exponentially faster than any known classical method&comma; according to The Quantum Insider&period; These systems protect online banking&comma; e-commerce&comma; VPNs&comma; software updates&comma; and blockchain signatures&period; When people talk about &&num;8220&semi;Q-Day&comma;&&num;8221&semi; they mean the day a quantum computer can run Shor&&num;8217&semi;s algorithm at that scale&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr"><strong>Symmetric Encryption<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">AES and similar ciphers are far less affected&period; Grover&&num;8217&semi;s algorithm gives only a quadratic speedup against them&period; The Quantum Insider explains that AES-128 would offer roughly the security of a 64-bit key against a quantum attacker&comma; while AES-256 keeps roughly 128-bit security&comma; which it calls strong by current standards&period; Doubling the key length is enough&comma; so symmetric encryption does not need to be replaced&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">Why the Estimates Keep Falling<&sol;h2>&NewLine;<h3 dir&equals;"ltr"><strong>RSA-2048<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">Gidney&&num;8217&semi;s paper&comma; posted on May 21&comma; 2025&comma; estimates that RSA-2048 could be factored with fewer than one million noisy qubits in under a week&period; The paper compares this with a 2019 estimate of 20 million qubits and eight hours&period; The calculation assumes a 0&period;1 percent gate error rate&comma; a one-microsecond surface code cycle&comma; and a square grid of qubits with nearest-neighbor connections&period; The savings come from approximate residue arithmetic&comma; a way of storing idle qubits called yoked surface codes&comma; and magic state cultivation&period;<&sol;p>&NewLine;<p dir&equals;"ltr">Those assumptions describe hardware that does not exist yet&period; The paper lowers the bar but does not claim anyone can clear it&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr"><strong>Elliptic Curve Cryptography<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">On March 30&comma; 2026&comma; Google Quantum AI released a white paper on attacking 256-bit elliptic curve cryptography&period; As reported by The Quantum Insider&comma; it estimates fewer than 1&comma;200 logical qubits and fewer than 500&comma;000 physical qubits&comma; with the attack finishing in minutes on a sufficiently advanced machine&period; The researchers said quantum attacks are not yet feasible and described the improvement as roughly an order of magnitude&period; Instead of publishing the attack details&comma; they used zero-knowledge proofs so others could verify the claim without receiving the technique&period;<&sol;p>&NewLine;<p dir&equals;"ltr">A preprint posted on September 15&comma; 2026 to the IACR Cryptology ePrint Archive&comma; by Sunghyeon Jo and Gye Jin Lee of Georgia Tech and QED Audit&comma; cut the logical qubit requirement further&period; Tech Times reported that it reduces the coefficient from 3n to 5n&sol;2&comma; which comes to roughly 640 logical qubits for P-256 plus lower-order terms&comma; and that it lowers the gate count from cubic to near-quadratic&period; It has not been peer-reviewed&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr"><strong>Claims to Treat With Caution<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">Not every low estimate is credible&period; QDayIsComing&period;com&comma; a site that itself argues for an early Q-Day&comma; reports that papers from a group called the Advanced Quantum Technologies Institute in October 2025 and March 2026 claimed RSA and elliptic curve encryption could fall to fewer than 5&comma;000 qubits&comma; and that independent researchers contested the method&period; Gidney&&num;8217&semi;s paper is the one the cryptography community has broadly accepted&period; A headline with a very small qubit count deserves a check on who wrote it and whether anyone outside the group has verified it&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">How Far Is Hardware From Those Numbers&quest;<&sol;h2>&NewLine;<p dir&equals;"ltr">IBM&&num;8217&semi;s published roadmap gives a sense of scale&period; IBM plans a machine called Starling at its Poughkeepsie&comma; New York facility&period; It is meant to run circuits of 100 million gates on 200 logical qubits&comma; with demonstrations in 2028 and 2029 and full capability in 2029&period; An interim processor called Kookaburra is planned for 2026&period;<&sol;p>&NewLine;<p dir&equals;"ltr">Two cautions apply&period; The roadmap is IBM&&num;8217&semi;s plan&comma; not a delivered product&period; And 200 logical qubits is well below the roughly 1&comma;200 that Google&&num;8217&semi;s elliptic curve paper estimates&comma; though the two use different architectures and are not directly comparable&period; The gap between today&&num;8217&semi;s dozens of logical qubits and the thousands needed is the main reason serious researchers say Q-Day has not arrived&period;<&sol;p>&NewLine;<p dir&equals;"ltr">Timeline predictions vary widely&period; The Quantum Insider&&num;8217&semi;s April 2026 summary lists quantum company estimates of 10 to 15 years&comma; academic estimates of 15 to 25 years&comma; and government planning assumptions around 2040 to 2045&period; Ethereum Foundation researcher Justin Drake has estimated at least a 10 percent chance of private key recovery by 2032&comma; as quoted by The Quantum Insider in July 2026&period; The range of expert opinion is wide&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">The Deadlines Already Set<&sol;h2>&NewLine;<h3 dir&equals;"ltr"><strong>NIST<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">NIST approved its first three post-quantum standards on August 13&comma; 2024&period; FIPS 203 covers ML-KEM for key exchange&comma; FIPS 204 covers ML-DSA for digital signatures&comma; and FIPS 205 covers SLH-DSA&comma; a hash-based signature scheme&period; In March 2025 it selected HQC as an additional key exchange algorithm&comma; and Falcon is in development as another signature scheme&period; NIST IR 8547 states that NIST will deprecate and ultimately remove quantum-vulnerable algorithms from its standards by 2035&period; The Quantum Insider&&num;8217&semi;s May 2026 summary adds that RSA-2048 and P-256 are slated for deprecation by 2030&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr"><strong>NSA and the European Union<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">The NSA&&num;8217&semi;s CNSA 2&period;0 suite sets a staged schedule for national security systems&comma; according to The Quantum Insider&period; New systems must support quantum-resistant cryptography by 2027&comma; with software and firmware signing moving exclusively to CNSA 2&period;0 from January 1&comma; 2027&comma; and full quantum resistance required across national security systems by 2035&period; It specifies ML-KEM-1024 and ML-DSA-87&period; The EU roadmap asks member states to publish national strategies and begin inventories by the end of 2026&comma; move critical infrastructure by the end of 2030&comma; and finish medium-risk uses by the end of 2035&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr"><strong>Google<&sol;strong><&sol;h3>&NewLine;<p dir&equals;"ltr">Google announced in March 2026 that it would complete its own post-quantum migration by 2029&comma; earlier than NIST&&num;8217&semi;s 2035 removal date&comma; citing advances in quantum hardware&comma; error correction&comma; and updated estimates of how quickly a machine could break today&&num;8217&semi;s standards&period; The Quantum Insider reported that Google is prioritizing digital signatures over encryption in transit&comma; and that it plans to ship ML-DSA in Android 17&period; Google did not tie the date to a specific milestone&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">Harvest Now&comma; Decrypt Later<&sol;h2>&NewLine;<p dir&equals;"ltr">The urgency comes from a specific attack&period; Adversaries can collect encrypted traffic today and store it until a quantum computer can decrypt it&period; The Quantum Insider describes this as a risk for data with long-term sensitivity&comma; such as government secrets&comma; medical records&comma; and intellectual property&period; A file that must stay confidential until 2045 is already exposed if it is captured in 2026 and decrypted in 2040&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">What It Means for Bitcoin and Crypto<&sol;h2>&NewLine;<p dir&equals;"ltr">Blockchains depend on elliptic curve signatures&comma; so the March 2026 Google paper drew attention across the industry&period; It describes two attack types&period; An on-spend attack targets a transaction while it is waiting to be confirmed&period; An at-rest attack targets wallets whose public keys are already visible on the chain&period; The paper notes that Bitcoin&&num;8217&semi;s proof-of-work mining is not directly vulnerable to the same class of algorithm&period;<&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&&num;8217&semi;s July 2026 report&comma; citing the Google paper&comma; puts about 6&period;9 million bitcoin&comma; roughly one third of the supply&comma; in addresses with already-exposed public keys&period; About 1&period;7 million of those sit in early pay-to-public-key addresses&period;<&sol;p>&NewLine;<p dir&equals;"ltr">Bitcoin developers have two proposals under discussion&period; BIP-360&comma; published in February 2026 by Hunter Beast&comma; Ethan Heilman&comma; and Isabel Foxen Duke&comma; introduces an output type called Pay-to-Merkle-Root that keeps public keys off the chain until coins are spent&period; Cointelegraph notes it does not upgrade existing coins automatically and does not add post-quantum signatures&period; BIP-361&comma; proposed in April 2026 by Jameson Lopp and five co-authors&comma; lays out a three-phase plan to phase out vulnerable address types&comma; and it drew strong criticism from people who called it confiscatory&period; Neither source reviewed for this article reported either proposal as activated&period; Security researcher Conor Deegan has flagged Ethereum&&num;8217&semi;s KZG trusted setup&comma; Zcash&&num;8217&semi;s Sapling protocol&comma; and Litecoin&&num;8217&semi;s MimbleWimble as other designs with elliptic curve parameters built in&period;<&sol;p>&NewLine;<p dir&equals;"ltr">This section describes technical risk&comma; not a prediction of any asset&&num;8217&semi;s price&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">What You Can Do Now<&sol;h2>&NewLine;<p dir&equals;"ltr">Individuals have little to do beyond keeping devices&comma; browsers&comma; and wallet software updated&comma; since the main migration happens in the software they use&period; Organizations have more work&period; NIST advises applying its standards now&comma; and the EU timeline starts with inventories&comma; which means listing where RSA and elliptic curve cryptography are used&period; For crypto holders&comma; the exposed-key problem is tied to older address types whose public keys are already visible on the chain&comma; so following Bitcoin&&num;8217&semi;s BIP discussions and your wallet provider&&num;8217&semi;s upgrade notes is the practical step&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr">Frequently Asked Questions<&sol;h2>&NewLine;<h3 dir&equals;"ltr">When will quantum computers break encryption&quest;<&sol;h3>&NewLine;<p dir&equals;"ltr">Nobody knows&period; Google has set 2029 as its own migration deadline&comma; while The Quantum Insider&&num;8217&semi;s April 2026 summary lists government planning assumptions of roughly 2040 to 2045&period; No machine today has the hundreds or thousands of logical qubits that the attacks require&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr">Is Bitcoin safe from quantum computers&quest;<&sol;h3>&NewLine;<p dir&equals;"ltr">Not permanently&period; Bitcoin&&num;8217&semi;s mining is not directly vulnerable&comma; but its signatures are&period; About 6&period;9 million BTC sit in addresses with exposed public keys&comma; according to the Google paper as reported in July 2026&period; Developers have proposed BIP-360 and BIP-361&comma; though neither is active&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr">Is AES-256 quantum-safe&quest;<&sol;h3>&NewLine;<p dir&equals;"ltr">Largely yes&period; Grover&&num;8217&semi;s algorithm weakens symmetric encryption only quadratically&comma; leaving AES-256 with roughly 128-bit security against a quantum attacker&comma; according to The Quantum Insider&period; RSA and elliptic curve cryptography are the algorithms that need replacing&period;<&sol;p>&NewLine;<h3 dir&equals;"ltr">What is harvest now&comma; decrypt later&quest;<&sol;h3>&NewLine;<p dir&equals;"ltr">It is the practice of recording encrypted data today so a future quantum computer can decrypt it&period; It matters most for information that must stay secret for 10 to 20 years or more&period;<&sol;p>&NewLine;<h2 dir&equals;"ltr"><strong>References and Sources<&sol;strong><&sol;h2>&NewLine;<p dir&equals;"ltr">NIST&comma; &&num;8220&semi;Post-Quantum Cryptography&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;csrc&period;nist&period;gov&sol;projects&sol;post-quantum-cryptography">https&colon;&sol;&sol;csrc&period;nist&period;gov&sol;projects&sol;post-quantum-cryptography<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">Craig Gidney&comma; arXiv&comma; &&num;8220&semi;How to factor 2048 bit RSA integers with less than a million noisy qubits&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;arxiv&period;org&sol;abs&sol;2505&period;15917">https&colon;&sol;&sol;arxiv&period;org&sol;abs&sol;2505&period;15917<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">IBM Quantum&comma; &&num;8220&semi;IBM lays out clear path to fault-tolerant quantum computing&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;www&period;ibm&period;com&sol;quantum&sol;blog&sol;large-scale-ftqc">https&colon;&sol;&sol;www&period;ibm&period;com&sol;quantum&sol;blog&sol;large-scale-ftqc<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&comma; &&num;8220&semi;How Quantum Computing Affects Cryptography&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;04&sol;06&sol;how-quantum-computing-affects-cryptography&sol;">https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;04&sol;06&sol;how-quantum-computing-affects-cryptography&sol;<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&comma; &&num;8220&semi;Google Shortens Timeline for Quantum-Safe Encryption Transition&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;03&sol;25&sol;google-shortens-timeline-for-quantum-safe-encryption-transition&sol;">https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;03&sol;25&sol;google-shortens-timeline-for-quantum-safe-encryption-transition&sol;<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&comma; &&num;8220&semi;Google Suggests Quantum Attacks on Cryptocurrency Encryption May Require Fewer Resources&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;03&sol;31&sol;google-suggests-quantum-attacks-on-cryptocurrency-encryption-may-require-fewer-resources&sol;">https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;03&sol;31&sol;google-suggests-quantum-attacks-on-cryptocurrency-encryption-may-require-fewer-resources&sol;<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&comma; &&num;8220&semi;Quantum Security Deadlines are Here&comma; What Happens Next&quest;&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;05&sol;08&sol;post-quantum-migration-timelines-government-industry-impact&sol;">https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;05&sol;08&sol;post-quantum-migration-timelines-government-industry-impact&sol;<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">The Quantum Insider&comma; &&num;8220&semi;The Growing Quantum Security Challenge Facing Bitcoin and Digital Assets&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;07&sol;29&sol;growing-quantum-security-challenge-bitcoin-digital-assets&sol;">https&colon;&sol;&sol;thequantuminsider&period;com&sol;2026&sol;07&sol;29&sol;growing-quantum-security-challenge-bitcoin-digital-assets&sol;<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">Tech Times&comma; &&num;8220&semi;Elliptic Curve Encryption&&num;8217&semi;s Quantum Attack Cost Falls on Two Fronts in Georgia Tech Paper&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;www&period;techtimes&period;com&sol;articles&sol;327545&sol;20260915&sol;elliptic-curve-encryptions-quantum-attack-cost-falls-two-fronts-georgia-tech-paper&period;htm">https&colon;&sol;&sol;www&period;techtimes&period;com&sol;articles&sol;327545&sol;20260915&sol;elliptic-curve-encryptions-quantum-attack-cost-falls-two-fronts-georgia-tech-paper&period;htm<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">Cointelegraph&comma; &&num;8220&semi;Bitcoin&&num;8217&semi;s Quantum Defense Plan&colon; What BIP-360 Actually Changes&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;cointelegraph&period;com&sol;features&sol;bitcoin-s-quantum-upgrade-path-what-bip-360-changes-and-what-it-does-not">https&colon;&sol;&sol;cointelegraph&period;com&sol;features&sol;bitcoin-s-quantum-upgrade-path-what-bip-360-changes-and-what-it-does-not<&sol;a><&sol;p>&NewLine;<p dir&equals;"ltr">QDayIsComing&period;com&comma; &&num;8220&semi;Three Papers in Three Months&colon; Why Q-Day May Now Be 2029&comma; Not 2035&&num;8221&semi;&colon; <a href&equals;"https&colon;&sol;&sol;qdayiscoming&period;com&sol;articles&sol;three-papers-q-day-2029">https&colon;&sol;&sol;qdayiscoming&period;com&sol;articles&sol;three-papers-q-day-2029<&sol;a><&sol;p>&NewLine;

Exit mobile version