Blog · From the JoS QUANTUM team

Notes on quantum, in the real world.

Research, engineering write-ups, and perspectives on putting quantum algorithms to work in finance, security, and energy.

Terminal-style summary of quantum oracle sketching tested on fraud detection: loading gate opens with no QRAM — M = Θ(N/ε) samples, each sample becomes one rotation; machine size under 60 logical qubits against a classical Ω(N⁰·⁹⁹) lower bound; error law ε ≈ π²N/2M with slope −1 verified in Qiskit; fraud task 284,807 transactions streamed with the Gram matrix never assembled; Õ(N) loading wall-clock remains, attacked by oracle stacking; MERIQ rescore 48 → 64 of 100, Level 1 → Level 3 — verdict: the loading gate opens for streams, paid in memory, not time
04 Aug 2026 · Research note

Quantum’s data-loading problem: the oracle-sketching escape route, tested on fraud detection

Data loading is the gate that keeps quantum computers out of machine learning on classical data. A 2026 result — quantum oracle sketching — walks around it for streaming data, with an unconditional exponential advantage in machine size. We unpack the mechanism, verify its error law in Qiskit, design a fraud-detection classifier around it — and re-run the MERIQ scorecard that gave this pitch 48/100.

Terminal-style audit of quantum linear algebra against a frontier LLM: weight matrices dense 16k×53k where HHL needs sparse, effective rank low so Tang dequantises, data loading 4×10¹¹ parameters against QRAM, readout needs full activations, logical clock 10⁵ vs 10¹⁹ ops per second so a quadratic speedup pays off only after ~30 years — gates passed 0/4, verdict: the energy wall is classical, quantum needs super-quadratic problems
03 Aug 2026 · Explainer

Can quantum computers fix AI’s energy problem? An audit from the matrix up

AI’s energy bill is a data-movement problem before it is a compute problem. We audit the quantum escape route — HHL, QSVT, kernels, quantum transformers — against the actual matrices of a frontier language model, Ewin Tang’s dequantisation results and the error-correction clock, and say where a quantum advantage could genuinely enter the AI stack.

Terminal-style MERIQ scorecard of the business-risk use case: business value 4/5, quantum advantage 5/5 with a quartic end-to-end speedup, data basis 4/5 on coarse-grid rotation angles, feasibility 4/5 with a demonstrated pipeline, resources 3/5 at fewer than 200 logical qubits — overall 80/100, maturity Level 3 Demonstrated, while the weakest-link rule holds the contrast case at 48/100 and Level 1
27 Jul 2026 · Methodology

Scoring quantum use cases: five criteria and a weakest-link rule

MERIQ, our criteria-based assessment for quantum use cases: a screening gate, five criteria scored against fixed anchors, and a maturity level capped by the weakest criterion — not carried by the average. Our flagship business-risk use case reaches 80/100 and still stops one level short; a fashionable contrast case reaches 48/100 and does not survive the data question.

Terminal-style summary of quantum risk to Bitcoin and Ethereum: breaking ECDLP on secp256k1 needs 1,200 logical qubits and 90M Toffoli gates, ~6.9M BTC vulnerable including 1.7M in P2PK, 20.5M ETH exposed with the top 1,000 accounts crackable in under nine days, and a 41% on-spend attack window from a 9-minute attack against a 10-minute block
17 Jul 2026 · Research note · Part 2

Post-quantum security for Bitcoin and Ethereum: an account-type autopsy

Roughly 6.9 million BTC and 20.5 million ETH sit behind quantum-vulnerable keys. Which script and account types are exposed, why address reuse matters more than your address prefix, and what the 2026 Google–Ethereum Foundation whitepaper means for custody, stablecoins and tokenised assets.

Terminal-style summary of what quantum computers break: RSA, ECDSA and ECDH broken by Shor in polynomial time; AES-256 and SHA-256 intact because Grover is only quadratic; an ML-DSA signature is 2,420 bytes, 38× larger than ECDSA; FIPS 203, 204 and 205 final while FIPS 206 is still draft
17 Jul 2026 · Explainer · Part 1

Post-quantum cryptography: what actually breaks, and what replaces it

A quantum computer does not break “encryption” — it breaks one load-bearing part of it and leaves the rest nearly intact. Why Shor is catastrophic and Grover is not, why bigger keys don’t help, the NIST standards that replace ECDSA, and what they cost in bytes.

Terminal-style summary of Google Willow's surface-code memory: logical error 0.143% per cycle, error suppression Λ = 2.14 confirming below-threshold operation, 101 physical qubits per logical qubit, 1.1 µs cycle time, and an extrapolation to distance 27 and ~1,457 qubits for a 10⁻⁶ logical error rate
16 Jul 2026 · Explainer

Quantum error correction on superconducting hardware: the fast clock and its price

From first principles to a 2026 reality check — how error correction works, why the surface code fits a superconducting chip, what Willow actually demonstrated, and the leakage, drift, decoding and cosmic-ray problems still between it and a machine.

Terminal-style quantum amplitude-estimation run of the business-risk model: tail risk P(loss ≥ €50M), QAE estimate 0.146 vs exact 0.119, quadratic speedup error ~ 1/N, and the Grover × QAE quartic sensitivity analysis
15 Jul 2026 · Demo walkthrough

Inside the risk demo: estimating tail risk on a quantum computer

A guided tour of our interactive quantum risk model — how a network of business risks becomes a quantum circuit, how amplitude estimation reads the tail with a quadratic speedup over Monte Carlo, and how stacking Grover search makes the sensitivity analysis quartic.

Terminal-style estimate for RSA-2048: ~6,190 logical qubits, ~2.6 billion Toffoli gates, ~20 million physical qubits, ~8 hours runtime, projected breakable 2039–2041
10 Jul 2026 · Demo walkthrough

Inside the Shor demo: what it takes to break an RSA key

A guided tour of our interactive Shor estimator — what each number means (logical qubits, Toffoli gates, physical qubits, runtime), the scaling laws behind them, and how a key size becomes a projected break-year.

Chart: physical-qubit estimates to break RSA-2048 and ECC-256 collapsing across successive studies from 2019 to 2026
15 Jul 2026 · Research note

Why quantum error correction — not qubit count — decides when RSA and ECC fall

RSA and ECC will fall to how efficiently Shor’s algorithm compiles into fault-tolerant gates — not raw qubit count. A look at the collapsing resource estimates for RSA-2048 and ECC-256.