New quantum-computing research has significantly reduced the estimated resources needed to break widely used public-key cryptography, increasing pressure on organizations still relying on RSA-2048 and 256-bit elliptic-curve cryptography. A 2025 Google Quantum AI preprint reported that RSA-2048 factoring could, in theory, be achieved in less than a week with fewer than 1 million noisy qubits, down roughly 20× from earlier estimates, by combining techniques such as approximate residue arithmetic, yoked surface-code storage, and magic state cultivation. Separate reporting also described architectural work that could cut the hardware needed for RSA-2048 attacks by about tenfold, reinforcing the trend that algorithmic and engineering advances are shrinking the gap between theory and practical cryptanalytic capability.
A 2026 paper on the elliptic-curve discrete logarithm problem similarly reduced the logical-qubit footprint for Shor-based attacks, estimating that a 256-bit prime-field curve could be targeted with about 1,333 logical qubits, down from 2,124 in a prior low-width design. Commentary on the new results highlighted an additional Caltech advance in lower-overhead fault tolerance and argued that, taken together, these developments could bring quantum attacks against systems such as Bitcoin signatures closer than previously expected, with some estimates dropping from millions of physical qubits to around 25,000 under favorable assumptions. While the work remains theoretical and depends on future fault-tolerant hardware, the direction of travel is clear: advances in quantum algorithms and error correction are accelerating the case for migration to post-quantum cryptography.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
An April 2026 research paper introduced a space-efficient quantum algorithm for elliptic-curve discrete logarithms that reduced logical-qubit requirements by improving reversible modular inversion. For a 256-bit prime-field curve, the authors estimated their design would use 1,333 logical qubits, down from 2,124 in a prior low-width implementation.
On April 1, 2026, Scott Aaronson summarized two quantum-computing announcements: a Caltech fault-tolerance result using high-rate codes and a Google result on a lower-overhead implementation of Shor's algorithm for breaking 256-bit elliptic-curve cryptography. He said the combined effect made systems such as Bitcoin signatures appear vulnerable sooner than previously estimated, with Caltech reportedly projecting roughly 25,000 physical qubits instead of millions.
By February 2026, reporting described a new architecture that could cut the quantum hardware needed to break RSA-2048 by about tenfold. This represented a further resource-efficiency development in quantum attacks against RSA, though the provided reference includes no additional technical detail.
In May 2025, a Google Quantum AI preprint by Craig Gidney reported that RSA-2048 could theoretically be factored in less than a week using fewer than 1 million noisy qubits on a fault-tolerant quantum computer. The reduction was attributed to techniques including approximate residue arithmetic, yoked surface-code storage, and magic state cultivation.
A 2019 resource estimate by Google Quantum AI scientist Craig Gidney assessed that factoring RSA-2048 would require roughly 20 million physical qubits under fault-tolerant assumptions. This estimate later became the baseline for subsequent reductions in projected quantum resources.
4 references tracked. Mallory keeps watching after this page renders.
arxiv.org
Open sourcescottaaronson.blog
Open sourcethequantuminsider.com
Open sourcepostquantum.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.