Interactive tool · Security

When does your RSA key break?

Enter a key size. See the quantum resources Shor's algorithm needs to break it — and the year quantum-hardware roadmaps are projected to get there.

Why this matters

RSA secures most of today's internet — banking, email, software updates, government records. Its safety rests on one assumption: factoring large integers is computationally infeasible.

Peter Shor showed in 1994 that a large enough quantum computer factors integers in polynomial time, breaking RSA outright. Today's hardware is far from that scale — but the requirement is falling and the hardware is rising. The only real question is when. The estimator below puts a number on it.

bits

Nothing is sent anywhere — analysis runs entirely in your browser. Generate a real RSA pair locally with OpenSSH, then paste rsa_demo.pub into the box above:

ssh-keygen -t rsa -b 2048 -f rsa_demo -N ""

Bump -b to 4096 and watch the break-year move out.

rsa-break-estimator — jos-quantum.de

                

Resource model anchored to Gidney & Ekerå 2019 (arXiv:1905.09749, ~3n logical qubits, ~0.3 n³ Toffoli gates, ~20M physical for RSA-2048) and the qLDPC «Pinnacle» architecture (Webster, Berent et al. 2026, arXiv:2602.11457, <100k physical for RSA-2048 — an Iceberg Quantum blueprint, frequently miscredited to IonQ, whose own 2026 factoring result is a 30-bit number). Surface code and qLDPC bracket a continuum of estimates that has fallen ~200× in six years — the chart below traces it.

The break-year reads the requirement against the dated milestones of the public vendor roadmaps, interpolated on a log axis; where a requirement sits above the last of them — 1,000,000 physical qubits, Google Quantum AI, 2029 — the estimate is a trend extrapolation and the terminal says so. The runtime and the qubit count are one point on a space–time tradeoff, not two independent facts: the same architecture buys fewer qubits by running longer, so neither figure means anything quoted without the other.

When the lines cross

The requirement is falling as the hardware rises. Plot both on one log axis and the picture is a convergence — the open question is only when, not whether.

Log-scale chart, 2012 to 2035, of physical qubits. A falling black curve carries published resource estimates for breaking RSA-2048 — one billion qubits in 2012, twenty million in 2019, under a million in 2025, about a hundred thousand in 2026 — bending toward a floor of 4,667 qubits, with a grey band around it spanning the literature’s own 2026 disagreement of 100,000 to 13,000,000. Rising below it are dated hardware milestones for superconducting, ion-trap and neutral-atom machines, from Sycamore’s 53 qubits in 2019 to Google’s projected million in 2029. A shaded column marks the derived convergence window of 2028 to 2029.
Published resource estimates for breaking RSA-2048 (black circles) against dated hardware milestones by modality (square = superconducting, triangle = ion trap, diamond = neutral atom). Solid or dashed is time — before or after today; filled or hollow is provenance — a published result or demonstrated machine against a vendor projection or a configuration outside the runtime bound. The black dashed curve is the fitted trend, decaying toward a floor of 4,667 physical qubits: the 1,400 logical qubits of the best current compilation, encoded at the best published code rate (30 %). The grey band is the literature’s own spread in 2026 — 100,000 to 13,000,000 physical qubits for the same problem — carried forward. The shaded column is the derived convergence window, 2028–2029. Sources: Fowler et al. 2012; Gidney & Ekerå 2019; Gouzien & Sangouard 2021; Gidney 2025; Zhou et al. 2025; Webster et al. 2026; Cain et al. 2026; vendor roadmaps from IBM, Google Quantum AI, Quantinuum, IonQ and Atom Computing. Full size (SVG) · PNG.

Three things this chart does that the usual version does not

Every qubit count carries its runtime

A qubit count without a runtime is a number without a unit. The same neutral-atom architecture (Cain et al. 2026, on the chart twice) is 11,000 qubits or 102,000 qubits depending only on how long you are willing to wait — and the cheap end takes years. Each label therefore names both, and configurations that miss the 100-day bound are drawn hollow and kept out of the fit.

The extrapolation saturates

A straight line on a log axis keeps falling without limit and reaches fewer physical qubits than the algorithm has logical ones. The curve instead bends toward 4,667 — 1,400 logical qubits at a 30 % code rate. That is a floor for the current state of two fields, not a law: it moves down if someone publishes a leaner compilation or a better code.

The window is derived, and it names what it rests on

A qLDPC estimate is never crossed against a planar superconducting roadmap. Per modality: superconducting reaches the 100,000-qubit requirement in 2028; ion trap tops out at 50,000 by 2035 and neutral atom at 1,180, so neither crosses. And the headline window rests on a single dated claim — Google’s 2029 million-qubit target. Drop it and the crossing moves to 2030.

The figure is compiled, never drawn: every mark, curve, band and label is generated from the estimate corpus and the dated vendor-milestone data, so a new paper or a slipped roadmap reaches the picture by re-running the command rather than by editing a file.

The fix: post-quantum cryptography

Shor breaks RSA and elliptic-curve cryptography — both reduce to the same hidden-subgroup problem a quantum computer solves efficiently. The mitigation is already standardised: cryptography built on problems Shor cannot touch.

Standard Algorithm Use Hard problem Status
FIPS 203 ML-KEM (Kyber) Key encapsulation Module lattice (MLWE) Final · 2024
FIPS 204 ML-DSA (Dilithium) Signatures Module lattice (MLWE) Final · 2024
FIPS 205 SLH-DSA (SPHINCS+) Signatures Hash functions Final · 2024
FIPS 206 FN-DSA (Falcon) Signatures NTRU lattice Draft · 2025/26

Why Shor can't break them

Shor solves the abelian hidden-subgroup problem — exactly what factoring (RSA) and discrete log (ECC) reduce to. Lattice and hash problems do not, so Shor gives no exponential speedup; only Grover's quadratic speedup applies, defeated by modestly larger parameters.

Harvest now, decrypt later

An adversary can record encrypted traffic today and decrypt it once a quantum computer arrives. Any secret that must stay confidential into the 2030s should migrate to post-quantum algorithms now — the deadline is set by your data's lifetime, not the computer's arrival date.

JoS QUANTUM works the defensive side of this story: quantum key distribution and ML-based security proofs for quantum communication protocols. See our patent portfolio and QKD as a Quantum Machine Learning task (npj Quantum Information, 2025).

Honest caveats