# JoS QUANTUM > JoS QUANTUM GmbH is a quantum technology company based in Frankfurt am Main, Germany. We develop quantum algorithms for the simulation of complex systems using quantum computers, focused on real industrial use cases in finance, security, and energy — together with the engineering judgment to estimate what those algorithms will, and won't, require from quantum hardware. ## What we do - **Quantum algorithm development** for simulating complex systems, with deep expertise in quantitative finance and quantum communication security. - **Hardware requirement estimation**: qubit counts, gate depth, and error-correction overhead for running an algorithm at useful scale. - **Quantum amplitude estimation** for business-risk modelling — a quadratic speedup over Monte Carlo, developed with Deutsche Börse Group (2021). - **Quantum communication & security**: QKD security proofs and post-quantum cryptography migration, backed by granted patents. ## Services - Keynote on quantum technology (0.5–1 h) - Introduction to quantum computing (2 h) - Introduction to quantum communication & security (2 h) - Training & in-depth algorithm development (1–5 days) - Proof of concept (3–24 months) - Strategy advisory on future priorities (ongoing) ## Pages - [Home](https://jos-quantum.de/): Overview, services, research papers, and patents. - [Services](https://jos-quantum.de/offer/): Engagement formats by time commitment. - [Learn](https://jos-quantum.de/learn/): Interactive explainers that teach how quantum computing actually works — what's real, what's marketing, and what the numbers honestly say. No math required. - [Quantum Myth-Buster](https://jos-quantum.de/learn/quantum-myth-buster/): Interactive quiz — ten claims about quantum computing from headlines and vendor slides ("tries all solutions at once", "breaks all encryption soon", "more qubits is better", …), each judged true / false / it-depends, then answered honestly with sources (Gidney 2025 RSA estimate, Lee et al. FeMoco, Google below-threshold error correction). - [Resource-Reality Simulator](https://jos-quantum.de/learn/resource-reality-simulator/): Interactive resource estimator — pick one of six tasks (H₂ demo, FeMoco catalyst, RSA-2048 via Shor, portfolio tail risk via QAE, quantum-data ML, route optimization via Grover), choose a hardware fidelity level, and see logical qubits, error-correction overhead (≈2·d² per logical qubit), total physical qubits and runtime — plotted against today's ~1,200-qubit machines, with an honest verdict per case. - [RSA break-cost estimator](https://jos-quantum.de/shor/): Interactive demo estimating the quantum resources Shor's algorithm needs to break an RSA key, and the year hardware roadmaps are projected to reach them. Resource model anchored to Gidney & Ekerå 2019 (~3n logical qubits, ~0.3n³ Toffoli gates, ~20M physical for RSA-2048) and the qLDPC "Pinnacle" architecture (Webster, Berent et al. 2026, arXiv:2602.11457, <100k physical — an Iceberg Quantum blueprint, widely miscredited to IonQ, whose own 2026 factoring result is a 30-bit number). The break-year is read off the running maximum of dated vendor milestones, interpolated on a log axis; above the last of them (1,000,000 physical qubits, Google Quantum AI, 2029) it falls back to a trend extrapolation and says so — so RSA-2048 lands at 2028–2029 under qLDPC (dated) and 2031–2032 under the surface code (extrapolated). Carries a compiled convergence chart, 2012–2035: published RSA-2048 estimates against dated milestones for superconducting, ion-trap and neutral-atom machines, with solid/dashed marking time and filled/hollow marking provenance, a requirement trend that saturates toward a floor of 4,667 physical qubits (1,400 logical at the best published 30% code rate) rather than falling without limit, a band carrying the literature's own 2026 spread of 100,000 to 13,000,000 physical qubits for the same problem, every qubit count labelled with the runtime it was quoted at (Cain et al. 2026 appears twice: 11k qubits over years, 102k over 97 days) and a derived convergence window of 2028–2029 that rests on a single dated claim — Google's 2029 million-qubit target, whose removal moves the crossing to 2030. Also covers the post-quantum standards that mitigate it (FIPS 203/204/205/206) and the honest caveats. - [Quantum business-risk model](https://jos-quantum.de/risk/): Interactive demo estimating tail risk with quantum amplitude estimation, runnable in the browser on a simulator. - [MERIQ use-case scorer](https://jos-quantum.de/meriq/): Interactive public edition of the MERIQ rubric — the three-question screening gate, five criteria (business value, quantum advantage, data basis, technical feasibility, resource requirements) suggested from fifteen plain-language questions and overridable against the published anchors, the equal-weighted 0–100 score, the weakest-link maturity level, and the datable/undatable production horizon, with a radar comparison against the flagship business-risk scorecard (80/100, L3) — computed entirely client-side. Optionally, visitors can submit their scorecard (plus title, industry, scaling axis, context, and an optional contact e-mail) to JoS QUANTUM's use-case library under an explicit consent-based licence; submissions are stored on Google Cloud in Frankfurt and the page carries the full GDPR notice. The proprietary layer (sub-question catalogue, calibration weights, benchmark library) is not part of the tool. - [MERIQ whitepaper](https://jos-quantum.de/meriq/whitepaper/): Landing page for *The MERIQ Whitepaper v1.0* (August 2026, 16 pages, PDF) — the full MERIQ scorecard, released behind an e-mail form. Publishes what the methodology article does not: the complete catalogue of thirty-four per-criterion sub-questions (fifteen of which are in the interactive scorer, nineteen new) with the evidence each demands, a new anchor note ruling how advantages denominated in machine size or sample complexity rather than runtime are scored (an unconditional space separation scores 3 by default; rungs 4–5 stay reserved for work-reducing speedups), the validation protocol (the rubric's falsifiable claim is an ordering, not a prediction that any single use case will work), and five worked assessments in finance and security scored line by line: business-risk driver ranking 80/100 L3, tail-probability estimation 76/100 L3, RSA-2048 cryptanalysis via Shor 76/100 L2 (included as a calibration reference for the advantage and data axes, not as an offering), oracle-sketched streaming fraud detection 64/100 L3, and variational QML fraud detection 48/100 L1. Two cases tie at 76 on different maturity levels, demonstrating the weakest-link cap. The calibration weights and the benchmark library of past assessments remain unpublished. The PDF itself is not linked or indexed; it is delivered by the form on the landing page. - [MERIQ whitepaper (German landing page)](https://jos-quantum.de/meriq/whitepaper/de/): German-language landing page for the same asset as /meriq/whitepaper/, declared as its hreflang alternate. Same gated e-mail form, same lead API and the same English PDF — only the page copy is German; the portfolio table is quoted verbatim from the paper and therefore stays English. Published for the German-speaking finance audience the LinkedIn campaign addresses; the page states explicitly that the whitepaper, the scorer and the rest of the site are English. - [JoS Quantum Intelligence](https://jos-quantum.de/intelligence/): Public landing page for JoS Quantum Intelligence, a subscriber-only platform (separate application, session login, not indexed) tracking the quantum hardware field as curated, sourced data. Five modules over one corpus: (1) vendor profiles and a filterable comparison across superconducting, trapped-ion, neutral-atom, photonic and annealing vendors — physical qubits, logical qubits demonstrated, one- and two-qubit and readout error, coherence, connectivity, native gate sets, error-correction approach and relevant threshold, cloud access channels; (2) roadmap milestones on a shared time axis, switchable between physical and logical qubits because the two are not comparable quantities, with demonstrated results drawn solid/filled and projections dashed/open, plus a structured slippage record (a milestone that moves keeps its originally announced date); (3) MERIQ use-case benchmarks carrying the published layer of each scorecard — five criterion scores against the published anchors, the rationale for each, the weakest-link cap, the binding criterion (a list, since ties are meaningful), the datable/conditionally-datable/undatable verdict and the horizon, plus score history where a research result moved a case (the sketched-streaming fraud card's 48 → 64 move on April 2026 oracle sketching is the worked example) and a per-modality earliest-plausible window derived by hand from published requirements against dated vendor milestones, stored with its reasoning rather than computed, so a vendor projection is never laundered into a JoS forecast; (4) an editorial change record with a significance grading, plus periodic written briefs; (5) investor-relations analysis of the listed pure plays (IonQ, Rigetti, D-Wave), the parents (IBM, Alphabet), the pre-IPO candidates (Quantinuum) and private rounds, reading SEC filings and earnings calls for one question a roadmap page cannot answer — whether the announced capital expenditure is funded — with verbatim quotes, per-figure basis (filed / company-reported / JoS estimate, the last always used for derived figures such as burn and runway) and an unconditional not-investment-advice disclaimer. Provenance is enforced in the data layer rather than by editorial care: every figure carries a status (demonstrated / announced / projected / estimated), a basis (peer-reviewed / company-reported / third-party / JoS estimate), an as-of date and a citation with a mandatory access date; a scorecard whose arithmetic contradicts the published MERIQ rules, a citation that does not resolve, or a field shaped like one of MERIQ's unpublished sub-question ids will fail the deploy rather than reach a subscriber. Physical qubits and logical qubits, and array capacity versus atoms actually operated (Atom Computing's 1,225 trap sites versus 1,180 qubits), are kept in separate fields so the conflations that dominate secondary coverage cannot recur. Interface is English and German; curated analysis is written in English. Access is sales-led: the page carries a request-access form (name, e-mail, company required; role and a free-text "what are you deciding" field optional) posting to the same lead API as the whitepaper gate, with a honeypot field, per-IP rate limiting and the full GDPR notice; accounts are provisioned by hand and trials expire on a stated date. - [JoS Quantum Intelligence (German landing page)](https://jos-quantum.de/intelligence/de/): German-language landing page for the same platform as /intelligence/, declared as its hreflang alternate. Same request-access form and the same lead API; only the page copy is German, and the worked use-case extract is quoted verbatim from the platform's own output and therefore stays English. Published for the German-speaking finance and industry audience; the page states explicitly that the interface is bilingual while the curated analysis is English. - [Blog](https://jos-quantum.de/blog/): Research notes and demo walkthroughs from the JoS QUANTUM team. ## Blog - [Can quantum computers fix AI's energy problem? An audit from the matrix up](https://jos-quantum.de/blog/quantum-computing-for-ai/) (2026-08-04): Explainer. Tests the claim that AI's energy wall forces quantum computing into the AI stack, and answers no — with the reasoning published. Classical half: AI's energy problem is data movement, not arithmetic (Horowitz ISSCC 2014: a 32-bit DRAM read at ~640 pJ costs ~170× a 32-bit FP multiply at ~3.7 pJ); roofline arithmetic shows batch-1 LLM decoding runs at ~2 FLOP/byte against an H100's ~295 FLOP/byte break-even, so the multipliers idle while 405 GB of weights stream past; IEA projects data centres from ~415 TWh (2024) to ~945 TWh (2030) while Koomey's law has slowed to a doubling every ~2.6 years against demand growing 4-5×/year (Epoch AI). CPU→GPU→TPU is one von Neumann architecture with progressively less data movement (systolic arrays touch each byte many times); the credible classical successors attack bytes, not FLOPs — photonic MZI meshes (analogue-limited to ~8 bits, DAC/ADC conversion eats the win, real today as interconnect), neuromorphic/in-memory compute (memristor crossbars, IBM NorthPole ~10× inference energy advantage, Loihi 2) — and quantum computing does not belong in that list because it raises energy per operation and trades only in complexity class. Quantum half: amplitude encoding compresses N-dim vectors into log N qubits; HHL solves sparse well-conditioned Ax=b in O(log(N)·s²κ²/ε) vs conjugate gradients O(N·s·√κ·log(1/ε)); QSVT (Gilyén et al., Martyn et al. "grand unification") applies degree-d polynomials to singular values of block-encoded matrices at O(d) queries, with 1/x needing degree O(κ log(κ/ε)). Four fine-print gates (after Aaronson "Read the fine print"): loading (generic data needs Ω(N) state-prep or O(N)-cell QRAM; Jaques–Rattew critique), sparsity/conditioning (dense s=N erases the log; Frobenius block-encoding pays it in subnormalisation), readout (tomography ~N/ε² to extract the full vector; only functionals are cheap), repetition (per-token calls multiply all overheads). Barren plateaus (McClean 2018) and exponential kernel concentration (Thanasilp 2024) hit the variational route, with the Cerezo et al. bind that provably trainable circuit families tend to be classically simulable. Tang dequantisation stated precisely: low-rank data-loaded linear algebra is dequantised (Tang STOC 2019; Chia–Gilyén–Li–Lin–Tang–Wang JACM 2022) while sparse high-rank implicit systems remain BQP-complete quantum turf — the common "Tang killed sparse" reading is corrected. The audit: Llama 3.1 405B (126 layers, d_model 16,384, FFN 53,248, 4.05×10¹¹ params, trained BF16 served FP8) fails all four gates — dense weights, effectively low-rank spectra (LoRA rank 8-64 suffices, the compressibility Tang-style sampling exploits), explicit learned data at QRAM-hostile scale, full activations consumed per layer per token ~10¹² times — so the workload is the constructed counterexample to quantum linear algebra. Five-year projection: frontier runs reach 10²⁸-10²⁹ FLOP around 2030 needing 1-5 GW campuses; the binding walls are power, HBM supply and capital — economic, not complexity-theoretic — and are being managed by FP4, MoE sparsity, optical interconnect and near-memory compute, while no roadmap (IBM Starling 2029: ~200 logical qubits) reaches within orders of magnitude of the ~10⁴ logical qubits a minimal quantum transformer needs (~15M physical at surface-code overheads). QEC crossover arithmetic (echoing Babbush et al. PRX Quantum 2021 and the MERIQ quadratic/super-quadratic anchor split): at an optimistic 10⁵ logical ops/s vs a 10,000-GPU cluster at 10¹⁹ FLOP/s, a quadratic speedup breaks even only at N≈10²⁸ sequential ops ≈ 30 years of runtime, so the popular "Grover compresses GPT-4 training from three months to hours" claim inverts to ~10⁶ years; quartic or exponential separations cross over within seconds. Where quantum genuinely enters AI: quantum data (Huang et al., Science 2022 — exponential sample advantage learning from quantum experiments, no loading gate), sparse implicit structured cores (PDE/lattice systems consumed as observables), structured discrete optimisation (Decoded Quantum Interferometry, Jordan et al. arXiv:2408.08292 — super-polynomial advantage on optimal polynomial intersection via decoding, evidence quantum optimisation wins on structure), and sampling for generative models. Ties to MERIQ: generic QML-on-classical-data fails the data-basis criterion at screening; the surviving use cases answer the data question by construction.(https://jos-quantum.de/blog/quantum-use-case-assessment/) (2026-07-27): Methodology. Introduces MERIQ (Maturity Evaluation Rubric for Industrial Quantum use cases), JoS QUANTUM's criteria-based assessment for quantum computing use cases — a proprietary framework conceived 1 May 2026; the article publishes the criteria, anchors and derivation rules, while the per-criterion sub-question catalogue, engagement calibration weights and benchmark library of past assessments remain protected company assets of JoS QUANTUM GmbH, available in advisory engagements. Step 0 screening gate (all pass/fail): classically expensive with no cheap shortcut (a closed form, low-dimensional reformulation or effective importance sampling disqualifies; a high-dimensional Monte Carlo without those escapes qualifies even if it finishes overnight, because a speed or accuracy edge over the best classical method is itself a competitive edge), structurally quantum-aligned, industrially relevant with an identified buyer. Five criteria scored 1–5 against named anchors: business value (no owner → operational → material → board-level → mandated regulatory deliverable; includes marginal-gain leverage), expected quantum advantage (none/dequantised → heuristic → subroutine-only → proven end-to-end but quadratic, which per Babbush et al. (PRX Quantum 2021) is unlikely to survive fault-tolerance overheads → proven super-quadratic with a fault-tolerant resource estimate on a realistic instance), data basis (unloadable/QRAM-scale → large and unstructured → available with effort → compact but precision-constrained to a coarse rotation-angle grid, because arbitrary-angle Clifford+T synthesis costs ~3·log2(1/ε) T gates of magic states (Ross–Selinger) → minimal and native), technical feasibility (concept → paper → simulated → demonstrated pipeline → hardware-validated), and resource requirements, inverted (beyond roadmaps → thousands of logical qubits → early fault-tolerant 100–1,000 → first-generation tens → available now). Every use case names a scaling axis (e.g. number of risk items n → 2^n scenarios). Three derived outputs: overall score (equal-weighted sum → 0–100; bands 0–34/35–54/55–74/75–89/90–100 → L1–L5), maturity level = min(band, lowest criterion) — the weakest-link cap — on the ladder Exploratory / Conceptual / Demonstrated / Pilot-ready / Production-ready (so Level 4 mechanically requires hardware that exists), and a production horizon that is datable (hardware-gated roadmap milestone) or undatable (research-gated). Flagship scorecard, sensitivity analysis of business risk (the risk-demo / RISQ use case): V4 A5 D4 F4 R3 = 80/100, band L4 capped to Level 3 Demonstrated by R=3 (<200 error-corrected logical qubits, early-fault-tolerant class, arXiv:2103.05475); horizon datable and among the smallest hardware gaps of any proven-advantage finance use case. The <200-logical-qubit footprint is anchored to named superconducting roadmaps — IBM Starling (2029: 200 logical qubits, 100M gates on qLDPC codes; Blue Jay 2033+: ~2,000 logical qubits), IQM (fault tolerance by 2030 with hundreds of logical qubits; 2026 directional tile codes ~30 physical qubits per logical), Google (useful error-corrected machine framed around 2029, million-physical-qubit roadmap endpoint) — and on trapped ions to Quantinuum's Apollo generation (2029). Logical qubits are not platform-neutral: superconducting platforms run ~µs error-correction cycles with heavier encoding overhead, trapped-ion gates are 2–3 orders of magnitude slower with leaner encodings, so resource scores and production horizons are stated per platform class. Distinguishes the plain tail estimate (QAE, quadratic, A=4) from the driver ranking (Grover-over-QAE, quartic, A=5): the unit of assessment is the (question, algorithm, data model) triple, not a business domain. Contrast scorecard, generic QML classification for fraud detection: V4 A2 D1 F3 R2 = 48/100, capped to Level 1 Exploratory by D=1 (amplitude-encoding millions of labelled transactions erases any speedup); horizon undatable. Reconciles with the July 2026 SoftBank–Quantinuum use-case timeline, whose near-term fraud-detection route (TDA/Laplacian moments on structured k-partite graphs, hybrid pipeline) is a different triple and would score differently. Also cross-references MIT FutureTech's Quantum Economic Advantage Calculator (arXiv:2508.21031) and the Choi–Moses–Thompson tortoise-and-hare framework (arXiv:2310.15505): the crossover problem size at which fewer algorithmic steps beat the slower quantum clock underpins the quadratic/super-quadratic anchor split and is a computable counterpart to the production horizon. Cites DIN SPEC 91480:2024-11 (Benchmarking quantum computers with determined KPIs, DIN Media) as the fourth aligned instrument and the supply-side measurement standard behind the technical-feasibility and resource criteria: standardised application benchmarks (Q-score, Algorithmic Qubits, VQE, QPE, generative QML, quantum LINPACK) and low-level characterisation (randomised benchmarking, coherence times, readout fidelity) turn feasibility and resource evidence from asserted into measured and vendor-agnostic — the flagship's circuit family decomposes into DIN building-block benchmarks (state preparation, Grover diffusion, QFT) — while DIN adds nothing to business value, advantage proofs or the data-loading question, which remain MERIQ's demand-side differentiators. An upcoming whitepaper will publish the full scorecard with sub-questions and worked assessments across finance, security and energy. - [Post-quantum security for Bitcoin and Ethereum: an account-type autopsy](https://jos-quantum.de/blog/post-quantum-bitcoin-ethereum/) (2026-07-17): Research note, part 2 of 2. Applies the 2026 Google Quantum AI / Ethereum Foundation / Stanford whitepaper (Babbush, Gidney, Neven, Drake, Boneh; arXiv:2603.28846) to digital assets. Breaking ECDLP on secp256k1 needs ≤1,200 logical qubits and 90M Toffoli gates (or ≤1,450 and 70M), under half a million physical qubits on a superconducting architecture — a ~20× reduction, published with the circuits withheld behind an SP1/Groth16 zero-knowledge proof. Attack taxonomy: on-spend (inside a block interval), at-rest (exposed keys, days of compute), on-setup (one offline break yields a permanent reusable exploit). Fast-clock architectures (superconducting, photonic, silicon) derive a key in ~9 minutes against Bitcoin's 10-minute block, giving a 41% theft window on any broadcast transaction; slow-clock (neutral atom, ion trap) cannot. Counterintuitively faster chains are safer: Litecoin ~2.7%, Dogecoin <1/8000. Bitcoin: ~6.9M BTC vulnerable, 1.7M in P2PK; Taproot (bc1p) is a security regression that re-exposes public keys on-chain, with BIP-360's P2MR the proposed patch; address reuse flattens the distinction between script types, so exposure is a property of behaviour not address prefix; a leaked HD-wallet xpub plus one derived key compromises the whole derivation tree. Quantum mining is not a threat (Grover is quadratic, doesn't parallelise). Ethereum: all five vulnerabilities are at-rest — Account (20.5M ETH, EOAs cannot rotate keys), Admin (~70 contracts, ~$200B stablecoins/RWAs, ~15h to crack), Code (15M ETH L2 TVS), Consensus (BLS12-381, 37M ETH staked), Data Availability (KZG trusted setup — a single on-setup break gives a permanent backdoor usable without any further quantum access). The obstacle to migration is bytes, not cycles: ML-DSA verifies faster than Ed25519 and verification is what every full node does for every signature in every block, but an ECDSA signature plus compressed public key costs ~100 bytes against 3,732 for ML-DSA-44, so at fixed block size a transaction grows by more than an order of magnitude — a block-space argument of the kind that produced the 2017 Bitcoin Cash hard fork, with the paper warning that the resource costs "portend network centralization". Compute bites only in the EVM (no PQC precompiles means verification in bytecode is prohibitively expensive, hence EIP-7932) and on the consensus layer, where the problem is capability rather than speed: ML-DSA cannot aggregate as BLS12-381 does. Deployed mitigations: Project Eleven's yellowpages, ERC-4337/EIP-7702, EIP-7932, and production PQC on QRL, Algorand, XRP Ledger and Solana. Includes risk-committee questions on custody address hygiene, xpub sharing, issuer key governance, L2 proof systems (zk-STARKs hash-based and resistant; optimistic rollups and pairing-based SNARKs not), and the dormant-asset problem (~2.3M BTC unmoved 5+ years, unmigratable, and the Do Nothing / Burn / Hourglass / digital-salvage policy debate). - [Post-quantum cryptography: what actually breaks, and what replaces it](https://jos-quantum.de/blog/post-quantum-cryptography-basics/) (2026-07-17): Explainer, part 1 of 2. A quantum computer does not break "encryption" — Shor's algorithm breaks integer factorisation and discrete logarithms in polynomial time, eliminating RSA, Diffie–Hellman, ECDH, ECDSA and EdDSA outright, while Grover's quadratic speedup barely dents symmetric ciphers and hashes (swamped by error-correction constants, parallelises poorly, inherently serial). Growing key size defeats Grover but not Shor, whose cost scales only polynomially in modulus size: a 1,024-bit elliptic curve needs ~5,000 logical qubits vs ~1,200 for 256-bit, making large curves "at best partial and temporary" protection. Encryption and signatures fail on opposite clocks: key exchange is harvest-now-decrypt-later (already urgent), signatures are safe until Q-Day then instantly forgeable — worst where a public key is permanently published and controls value, i.e. blockchains. Mosca's inequality (x + y > z). NIST standards: FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA all final August 2024; FIPS 206 FN-DSA (Falcon) still draft as of mid-2026 due to floating-point Gaussian-sampler side-channel concerns; HQC selected March 2025 as a code-based backup KEM. Redundancy is deliberate — SIKE was destroyed by a classical attack in 2022. The price is size: ECDSA 64-byte signatures vs FN-DSA-512 ~666 B, ML-DSA-44 2,420 B, SLH-DSA-128s 7,856 B (~123×). The common objection that PQC is too slow to compute is mostly a myth for the scheme that will actually deploy: normalised to ML-DSA-44 = 1, Ed25519 signs at 0.15 and verifies at 1.3, RSA-2048 signs at 80 and verifies at 0.4 — so ML-DSA verifies faster than Ed25519 and signs 80× faster than RSA, and verification is the operation that scales with network size. Compute does explode for SLH-DSA (14,000× slower signing for 128s; 720× for 128f) and FN-DSA depends on hardware floating point (3× signing, degrading to RSA-2048 speed when emulated; non-associative FP addition makes cross-platform test vectors and side-channel safety hard, which is why FIPS 206 is late and realistic deployment is ~2033). ML-DSA's real cost is lost versatility — no BLS-style aggregation. Hybrid classical+PQC deployment (X25519+ML-KEM-768, Signal PQXDH, iMessage PQ3) is the standard pattern. NIST IR 8547 deprecates classical public-key crypto after 2030, disallows after 2035 — a statement about migration duration, not about when a quantum computer arrives. - [Quantum error correction on superconducting hardware: the fast clock and its price](https://jos-quantum.de/blog/qec-superconducting-hardware/) (2026-07-16): Explainer, first in a platform-by-platform series. Builds quantum error correction from first principles (repetition codes; why no-cloning, measurement collapse and continuous errors each have an escape; stabilizers and syndromes; the surface code as the code a planar chip can actually be wired for; code distance and the threshold), then assesses it against real superconducting hardware. Google's Willow measured Λ = 2.14 — below threshold, beyond break-even at 2.4× — with a distance-7 logical error of 0.143% per cycle on 101 physical qubits at a 1.1 µs cycle. Extrapolating that Λ, a 10⁻⁶ logical qubit needs distance 27 and ~1,457 physical qubits. The remaining obstacles are engineering, not physics: measured gate errors (0.33%) still sit 3× above what the famous resource estimates assume (0.1%); leakage costs 4 of 101 qubits; decoders must sustain sub-1.1 µs throughput forever; TLS defects swing T1 by an order of magnitude on 15-minute timescales; ~2.5 coax lines per qubit against 19 µW of cooling power makes a million qubits a refrigeration problem; and cosmic rays wipe the whole chip for ~20,000 correction rounds about once an hour, which no code distance addresses. The compensating advantage is the clock: superconducting is a fast-clock architecture, and that is why it got below threshold first. - [Inside the risk demo: estimating tail risk on a quantum computer](https://jos-quantum.de/blog/risk-demo-explained/) (2026-07-15): Walkthrough of the quantum business-risk model. How a network of business risks is encoded as a state-preparation circuit (Ry rotations for intrinsic probabilities, controlled-Ry for conditional triggers), how quantum amplitude estimation reads the tail probability P(loss ≥ threshold) with a quadratic speedup over Monte Carlo (error ~1/N vs ~1/√N), and how stacking Grover search over QAE makes the sensitivity analysis — ranking which risk drives the tail — quartic. Fewer than 200 error-corrected qubits at production scale. - [Why quantum error correction — not qubit count — decides when RSA and ECC fall](https://jos-quantum.de/blog/qec-shor-rsa-ecc/) (2026-07-15): Research note. RSA and ECC will fall to how efficiently Shor's algorithm compiles into fault-tolerant gates, not to raw qubit count. A look at the collapsing physical-qubit estimates for RSA-2048 and ECC-256 across successive studies. - [Inside the Shor demo: what it takes to break an RSA key](https://jos-quantum.de/blog/shor-demo-explained/) (2026-07-10): Walkthrough of the RSA break-cost estimator. What each number means — logical qubits (~3n), Toffoli gates (~0.3n³), physical qubits, runtime — the scaling laws behind them, and how a key size becomes a projected break-year. The error-correction code alone swings the machine size ~200× and the break-year by three years; doubling your RSA key does not buy a decade. Explains why the roadmap envelope is never continued past its last dated milestone, and why a qubit count quoted without its runtime is a number without a unit. ## Research - [A Quantum Algorithm for the Sensitivity Analysis of Business Risks](https://arxiv.org/abs/2103.05475) (2021): Braun, Decker, Hegemann, Kerstan, Schäfer. The Grover-over-QAE construction behind the business-risk demo, analysed on a Deutsche Börse Group risk model. ## Contact - Email: contact@jos-quantum.de - Location: Platz der Einheit 2, c/o TechQuartier, 60327 Frankfurt am Main, Germany - LinkedIn: https://www.linkedin.com/company/jos-quantum