How Many Qubits Would It Take to Break RSA?
A qubit count alone cannot tell you whether a machine could break RSA. Errors, error correction and running time also matter.
Free video lesson · 1:24
How Many Qubits Would It Take to Break RSA?
Quantum Computing & Encryption for Beginners
Music: “Thinking Music” by Kevin MacLeod. Creative Commons Attribution 4.0.
An RSA attack estimate needs a qubit type, error assumptions and a runtime, not just a count.
Read the video transcript
There is no single qubit count that tells you when RSA can be broken. RSA is a public-key method for protecting information. The answer depends on the machine, its mistakes, and how long the attack can run.
A qubit is a working unit in a quantum computer. A physical qubit is an actual part of the machine. It can make errors. Researchers can use groups of physical qubits to make more reliable units called logical qubits.
That means a thousand physical qubits and a thousand logical qubits are very different resources. Counting them as if they were the same would hide the work needed to handle errors.
For example, a 2025 study estimated that one common RSA size could be broken with fewer than a million physical qubits in under a week, under its hardware assumptions. That was a calculation, not a machine doing it.
So read the whole estimate. What kind of qubits? How reliable must they be? How much time does the calculation need? The number alone cannot tell you whether a machine can perform the attack.
For the basic unit, watch What Is a Qubit? For the protection being developed against these attacks, watch What Is Post-Quantum Cryptography?
The short answer
There is no single qubit count that tells you when RSA can be broken. RSA is a public-key method for protecting information. The answer depends on the machine, its mistakes, and how long the attack can run.
A simple example
A qubit is a working unit in a quantum computer. A physical qubit is an actual part of the machine. It can make errors. Researchers can use groups of physical qubits to make more reliable units called logical qubits.
That means a thousand physical qubits and a thousand logical qubits are very different resources. Counting them as if they were the same would hide the work needed to handle errors.
For example, a 2025 study estimated that one common RSA size could be broken with fewer than a million physical qubits in under a week, under its hardware assumptions. That was a calculation, not a machine doing it.
So read the whole estimate. What kind of qubits? How reliable must they be? How much time does the calculation need? The number alone cannot tell you whether a machine can perform the attack.
Read the assumptions beside the number
An estimate might count physical qubits, which are the individual devices, or logical qubits, which are protected units built from many devices. A useful comparison also states the error assumptions and how long the computation would run.
Check your understanding
Can two machines with the same physical-qubit count necessarily run the same attack?
Answer
No. Error rates, connections, error correction and runtime requirements can change what the machines can do.
Keep learning
Follow the free video course one question at a time. For help applying these ideas at work, explore team training or a cryptography audit.