Skip to content

How Many Qubits Would It Take to Break RSA?

A qubit count alone cannot tell you whether a machine could break RSA. Errors, error correction and running time also matter.

EveryoneIntro1 min read· Updated Oct 8, 2026

Free video lesson · 1:24

How Many Qubits Would It Take to Break RSA?

Quantum Computing & Encryption for Beginners

Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.

An RSA attack estimate needs a qubit type, error assumptions and a runtime, not just a count.

Read the video transcript

There is no single qubit count that tells you when RSA can be broken. RSA is a public-key method for protecting information. The answer depends on the machine, its mistakes, and how long the attack can run.

A qubit is a working unit in a quantum computer. A physical qubit is an actual part of the machine. It can make errors. Researchers can use groups of physical qubits to make more reliable units called logical qubits.

That means a thousand physical qubits and a thousand logical qubits are very different resources. Counting them as if they were the same would hide the work needed to handle errors.

For example, a 2025 study estimated that one common RSA size could be broken with fewer than a million physical qubits in under a week, under its hardware assumptions. That was a calculation, not a machine doing it.

So read the whole estimate. What kind of qubits? How reliable must they be? How much time does the calculation need? The number alone cannot tell you whether a machine can perform the attack.

For the basic unit, watch What Is a Qubit? For the protection being developed against these attacks, watch What Is Post-Quantum Cryptography?

TL;DR

The short answer

There is no single qubit count that tells you when RSA can be broken. RSA is a public-key method for protecting information. The answer depends on the machine, its mistakes, and how long the attack can run.

A simple example

A qubit is a working unit in a quantum computer. A physical qubit is an actual part of the machine. It can make errors. Researchers can use groups of physical qubits to make more reliable units called logical qubits.

That means a thousand physical qubits and a thousand logical qubits are very different resources. Counting them as if they were the same would hide the work needed to handle errors.

For example, a 2025 study estimated that one common RSA size could be broken with fewer than a million physical qubits in under a week, under its hardware assumptions. That was a calculation, not a machine doing it.

So read the whole estimate. What kind of qubits? How reliable must they be? How much time does the calculation need? The number alone cannot tell you whether a machine can perform the attack.

Read the assumptions beside the number

An estimate might count physical qubits, which are the individual devices, or logical qubits, which are protected units built from many devices. A useful comparison also states the error assumptions and how long the computation would run.

Check your understanding

Can two machines with the same physical-qubit count necessarily run the same attack?

Decision

Answer

No. Error rates, connections, error correction and runtime requirements can change what the machines can do.

Keep learning

Follow the free video course one question at a time. For help applying these ideas at work, explore team training or a cryptography audit.