← ObservatoryThe RecordFR-QE-0005
PROG-QE
FR-QE-0005

Cryptographically Relevant Quantum Computing — RSA Factorisation

A quantum computer can factor commercially relevant RSA cryptographic keys faster than any classical computer.

EscalatingVS-03·since 2026-06-29
Assessment trajectory
Escalatingstate held · last assessed 2026-06-29
Verification Matrix

Verification position derived from the record’s assessments; dates show when Faultline first recorded each stage.

VS-01
Assertion
VS-02
Published evidence
First recorded 2024-01-15
VS-03
Audit
Current from 2026-06-29 — present
VS-04
Replication
VS-05
Operation
Stage first recorded Current verification position Not yet recorded
State Warrant
Current stateEscalatingVS-03
Why this state?Sourced from: Gidney, "How to factor 2048-bit RSA with less than a million noisy qubits" (May 2025, arXiv); Iceberg Quantum QLDPC architecture proposal (early 2026, unvalidated at scale per secondary reporting); Google Quantum AI / Stanford / Ethereum Foundation whitepaper on elliptic-curve cryptography resource estimates (March 2026). All three accessed via secondary technical reporting (The Quantum Insider, postquantum.com) rather than primary papers in full; primary sourcing should be substituted before this assessment is treated as fully verified.
Assessment summaryNo threshold has been crossed since AS-001 — no factorisation of a commercially relevant key has occurred, and none is closer to occurring in any demonstrated sense. What has moved is the resource-estimate trajectory underlying OQ-001. Gidney (Google, May 2025) reduced the estimated physical-qubit requirement for RSA-2048 factorisation from the Gidney-Ekerå (2021) figure of ~20 million to under 1 million, under comparable fault-tolerance assumptions — roughly a 20-fold reduction achieved through improved algorithmic and error-correction engineering rather than any experimental demonstration. A 2026 proposal using QLDPC codes (an architecture distinct from the surface codes assumed in both prior estimates) suggests a further reduction toward ~100,000 physical qubits, though this is unvalidated at scale. A March 2026 Google/Stanford/Ethereum Foundation whitepaper applies the same style of resource-reduction analysis to elliptic-curve cryptography, estimating under 500,000 physical qubits for widely used curves. All three results are theoretical resource estimates — the same evidence category as INST-002's original figure — not experimental progress toward the claim. The pressure state remains ESCALATING; no reclassification is warranted by an estimate revision alone. What is new is the rate: three independent downward revisions within roughly eighteen months is faster compression of the engineering-gap estimate than the original record anticipated, and OQ-001 now has materially fresher input than it did at AS-001.
State entered2024-01-15
Last reaffirmed2026-06-29
Stage provenanceRatified VS-03; stored historical code VS-02 preserved.
Mechanisms

Causal mechanisms recorded for this claim. The State Warrant above remains the authoritative current assessment.

Resistance MechanismRM-001

The engineering gap — three to four orders of magnitude. The Gidney-Ekerå estimate requires approximately 20 million physical qubits for 2048-bit RSA factorisation. Current systems have hundreds to low thousands. The gap is not merely quantitative — scaling by three to four orders of magnitude in qubit count while maintaining below-threshold error rates and the necessary connectivity involves engineering challenges that are not simply extensions of current work. Crosstalk, control complexity, fabrication yield, and classical control overhead all scale non-linearly. The resistance mechanism is not that the gap is unbridgeable in principle, but that it is not bridgeable on any near-term timescale without engineering advances that have not yet been demonstrated even in prototype form.

Resistance MechanismRM-002

Classical algorithm improvement. The claim requires factoring RSA keys faster than any classical computer. Classical factorisation algorithms continue to improve. The general number field sieve has been optimised continuously since 1990. If classical algorithms improve substantially — through better mathematical insights, specialised hardware, or distributed computing advances — the bar for quantum advantage in this specific application rises. The claim is a race; the classical side of the race is not standing still. The resistance mechanism is therefore not just about quantum hardware but about the relative improvement rate of both sides.

BottleneckBN-001

Sequential substrate dependency. This claim cannot be satisfied until FR-QE-0003 (scaling behaviour) and FR-QE-0004 (below-threshold operation) are not merely demonstrated but extended to the scale required. The claim sits at the top of the PROG-QE capability stack; it is the last claim to be satisfiable, dependent on all substrate claims being satisfied first at sufficient scale. This is a sequential dependency bottleneck similar to FR-AM-0004's BN-001, but with a higher and more precisely quantified requirement. The bottleneck is not ambiguous — the Gidney-Ekerå estimate provides a specific qubit and error rate target — but the engineering path to that target is long and undemonstrated at the required scale.

AttractorAT-001

Demonstration of fault-tolerant logical qubit count at hundreds, then thousands. The specific milestones that would move this record from ESCALATING toward RESOLVING are stepwise: demonstration of 100 fault-tolerant logical qubits at below-threshold error rates, then 1000, then 10,000. Each milestone narrows the engineering gap by approximately one order of magnitude. No single experiment resolves the claim; it resolves through a series of engineering milestones, each of which is a necessary but not sufficient condition. The attractor is therefore a progression rather than a single event, distinguishing it from the attractors in FR-QE-0003 and FR-QE-0004.

Assessment History
2024-01-15
Initial assessment — Escalating
The claim has not been satisfied. No quantum computer has factored a commercially relevant RSA key. The most credible direct attempt (INST-005) failed. The engineering gap between current capability and the Gidney-Ekerå resource estimate remains approximately three to four orders of magnitude in physical qubit count, with additional requirements for error rates, connectivity, and operational duration not yet demonstrated at any scale approaching relevance. The pressure state is ESCALATING rather than EMERGING because the substrate advances documented in FR-QE-0003 and FR-QE-0004 (INST-003) show the underlying error-correction engineering progressing on a credible trajectory, even though the gap to the resource requirement remains enormous. Institutional behaviour — NIST's finalisation of post-quantum cryptography standards (INST-004) — reflects institutional acceptance that the risk is credible enough to justify migration, adding pressure to the claim's trajectory independent of any direct technical progress toward satisfaction.
Verification Stage: VS-02 preserved — historically unverified.
2026-06-29
Reassessed, no change — Escalating
No threshold has been crossed since AS-001 — no factorisation of a commercially relevant key has occurred, and none is closer to occurring in any demonstrated sense. What has moved is the resource-estimate trajectory underlying OQ-001. Gidney (Google, May 2025) reduced the estimated physical-qubit requirement for RSA-2048 factorisation from the Gidney-Ekerå (2021) figure of ~20 million to under 1 million, under comparable fault-tolerance assumptions — roughly a 20-fold reduction achieved through improved algorithmic and error-correction engineering rather than any experimental demonstration. A 2026 proposal using QLDPC codes (an architecture distinct from the surface codes assumed in both prior estimates) suggests a further reduction toward ~100,000 physical qubits, though this is unvalidated at scale. A March 2026 Google/Stanford/Ethereum Foundation whitepaper applies the same style of resource-reduction analysis to elliptic-curve cryptography, estimating under 500,000 physical qubits for widely used curves. All three results are theoretical resource estimates — the same evidence category as INST-002's original figure — not experimental progress toward the claim. The pressure state remains ESCALATING; no reclassification is warranted by an estimate revision alone. What is new is the rate: three independent downward revisions within roughly eighteen months is faster compression of the engineering-gap estimate than the original record anticipated, and OQ-001 now has materially fresher input than it did at AS-001.
Sourced from: Gidney, "How to factor 2048-bit RSA with less than a million noisy qubits" (May 2025, arXiv); Iceberg Quantum QLDPC architecture proposal (early 2026, unvalidated at scale per secondary reporting); Google Quantum AI / Stanford / Ethereum Foundation whitepaper on elliptic-curve cryptography resource estimates (March 2026). All three accessed via secondary technical reporting (The Quantum Insider, postquantum.com) rather than primary papers in full; primary sourcing should be substituted before this assessment is treated as fully verified.
Verification Stage: VS-03 after ratified review (stored code VS-02 preserved).
Claim Lineage

Historical narrative recorded for this claim. It does not override the current State Warrant.

1994
Shor's algorithm. The theoretical claim is established immediately and completely. The practical question opens simultaneously. RSA key sizes considered secure against quantum attack are calculated from the algorithm's resource requirements.
1995–2015
Hardware too small to matter. Quantum computers demonstrate Shor's algorithm on trivial inputs. The gap between demonstrated capability and commercially relevant key sizes is so large that no meaningful engineering progress toward the claim is visible. The claim is in EMERGING.
2021
Gidney-Ekerå resource estimate. The most detailed published estimate quantifies the engineering gap: approximately 20 million physical qubits for 2048-bit RSA. This estimate is simultaneously sobering (the gap is enormous) and clarifying (the target is now precisely defined).
2023–24
Substrate progress makes the trajectory credible. FR-QE-0003 and FR-QE-0004 results demonstrate that the error correction engineering required for the claim's substrate is advancing on a credible path. The claim enters ESCALATING.
2024
NIST PQC standards finalised. Global cryptographic infrastructure begins migration away from RSA in anticipation of the claim's eventual satisfaction. The world treats the claim as a future certainty even as the engineering gap remains enormous.
Open Questions

Questions retained in this record. The current State Warrant may have narrowed or reframed earlier questions.

OQ-001

What is the realistic timeline for reaching the Gidney-Ekerå qubit count? Current hardware roadmaps from IBM, Google, and Microsoft project millions of physical qubits within 10–15 years, but roadmap projections have historically been optimistic. The engineering challenges at 20 million qubits are not simply extensions of current work.

Raised 2024-01-15
OQ-002

INST-004 (NIST PQC standards) is the second occurrence of anticipatory institutional evidence as an evidence object type (the first was FR-AM-0004 INST-003, the Helion/Microsoft contract). The corpus now has two instances. Whether anticipatory institutional acts constitute evidence for a claim — and at what weight — is a recurring question that may warrant attention before a third occurrence.

Raised 2024-01-15
OQ-003

This claim sits at the top of the PROG-QE capability stack and depends on all substrate claims being satisfied first. If FR-QE-0003 or FR-QE-0004 encounter unexpected obstacles at larger scales, this claim's trajectory changes without any direct evidence bearing on it. How should a record respond when its substrate records encounter setbacks? No governed procedure exists.

Raised 2024-01-15
OQ-004

IN-006 documents three independent downward revisions to the RSA/ECC resource estimate within roughly eighteen months, compared with one major revision in the preceding decade. Is this pace itself evidence of anything — a maturing theoretical toolkit converging on a real figure, or a sequence of estimates each exploiting a different unproven architectural assumption (surface codes, then QLDPC codes, then a third approach not yet proposed)? Until a fourth estimate either confirms or breaks the trend, this question cannot be answered from the evidence available at AS-002.

Raised 2026-06-29
Mutation Log
MutationDateFieldPrior valueCurrent value
M-0132026-09-06description_restoredLegacy ingestion cutoffs: mechanisms:RM-001, mechanisms:RM-002, mechanisms:BN-001, mechanisms:AT-001Source-restored complete descriptions
M-0122026-07-09description_reorderedDESCRIPTION-REORDERED
M-0112026-07-08reference_correctedREFERENCE-CORRECTED
M-0102026-07-08realization_note_addedREN-001
M-0092026-06-29open_question_raisedOQ-RAISED
M-0082026-06-29assessment_issuedAS-001AS-002
M-0072026-06-29instances_loggedINSTANCES-LOGGED
M-0062024-01-15programme_panel_addedPROGRAMME-PANEL-ADDED
M-0052024-01-15null_condition_metNULL-CONDITION-MET
M-0042024-01-15mechanisms_recordedMECHANISMS-RECORDED
M-0032024-01-15assessment_issuedASSESSMENT-ISSUED
M-0022024-01-15instances_loggedINSTANCES-LOGGED
M-0012024-01-15record_createdRECORD-CREATED
Evidence Sources
6 instances on recordShow sources ↓Hide ↑
IN-001Shor's algorithm — theoretical foundation establishedneutral
IN-002Small-scale Shor demonstrations and resource estimate refinementsneutral
IN-003FR-QE-0003 and FR-QE-0004 substrate progress — engineering gap begins closingsupportive
IN-004NIST post-quantum cryptography standards — world prepares for the claim being satisfiedpartial
IN-005Chinese research group factorisation claim — and rapid refutationcontesting
IN-006Gidney (2025) and successive resource-estimate reductions — RSA and elliptic-curveneutral