Quantum Computing: Is It Bullshit? (The Honest Answer)
The biggest number a quantum computer has ever factored using Shor's algorithm, the method that would break today's encryption, is 21. Three times seven. My kid could do that at three. Yet governments and companies are spending billions to protect themselves from these machines, and you'll hear that the internet breaks in 2029. So which is it? Is quantum computing a real threat, or is it bullshit?
I've spent 30 years in cybersecurity and I've watched five cryptographic panics come and go. This is the sixth. Most of them turned out to be half true. So I went past the press releases and into the research itself, the papers cryptographers and physicists are actually arguing about. Here's how I think this one plays out.
In this guide, we'll look at the evidence on both sides, a realistic timeline, why you still need post quantum cryptography even if the skeptics are right, and the specific moves to make now. Everything has been checked again against the sources on 1 October 2026.
TL;DR if you've only got 30 seconds
No quantum computer has factored a number it didn't already know the answer to. The "record" is still 21.
But error correction is genuinely improving, and the estimates of what's needed to break encryption keep falling.
My view: a code-breaking machine is most likely between 2032 and 2040. Google's 2029 is its own migration deadline, not a forecast.
Migrate to post quantum cryptography calmly anyway: data stolen today can be decrypted later, and migrations take a decade.
Cryptocurrency vs Cryptography: The Confusion Driving the Panic
A few months ago, YouTubers told tens of millions of people that quantum computers were about to kill "crypto". They cited Scott Aaronson, the quantum computing researcher best known for puncturing hype, who wrote in April 2026 that experts he trusts think a code-breaking machine "ought to be possible by around 2029". They cited Google's 2029 plan. And they cited a new paper estimating that about 26,000 physical qubits could break the kind of encryption Bitcoin uses.
Before we look at any of that, one clarification, because it's doing a lot of the work in this panic. "Crypto" means two completely different things.
Cryptocurrency is Bitcoin and its relatives. Cryptography is the maths that protects every password, every bank transfer and every encrypted message you send. It's what makes buying something online safe. And not all of it is at risk. The part quantum computers threaten is public-key cryptography: the maths that lets two strangers agree a secret key, and that proves who signed something. Its security rests on hard maths problems, factoring huge numbers (RSA) and a related problem called the discrete logarithm (elliptic curves, which Bitcoin uses). Shor's algorithm, run on a big enough quantum computer, solves both. Hash functions and the symmetric encryption that protects data once a key is agreed are far less affected. Thumbnails say "crypto" and mean the coins; the videos often switch to the maths without saying so. Both are in scope, because Bitcoin is built on cryptography too, but they're very different problems. We'll come back to Bitcoin at the end.
What Google's 2029 Date Actually Means
Almost nobody repeating the 2029 date has read what Google wrote. In a March 2026 blog post, Google set itself a deadline: finish moving its own products and infrastructure to post quantum cryptography by 2029. That's a migration target. It isn't a prediction that a working code-breaking quantum computer will exist by then, and nobody at Google said it was.
Those are two completely different statements. One says "we want to be ready early". The other says "the internet breaks in 2029". If you read the headlines, you'd think it was the second.
The Skeptic Case: 21 Is Still the Record
So what does the evidence actually look like? Start with the record. The first quantum factorisation, in 2001, factored 15. Not a 15-digit number: the number 15, which is three times five. The next record, in 2012, was 21. A 2019 attempt at 35 failed. As of October 2026, there's no new genuine record.
It's worse than it sounds. Even those demos used what's called compiled Shor's algorithm: the researchers built knowledge of the answer into the setup. That's not factoring, it's confirming. Bigger "records" you may have seen in press releases relied on similar shortcuts.
The cryptographer Peter Gutmann of the University of Auckland made the point brilliantly. In a 2025 paper with Stephan Neuhaus, Replication of Quantum Factorisation Records with an 8-bit Home Computer, an Abacus, and a Dog, they matched every record with a 1981 home computer, an abacus, and a dog trained to bark three times. Bruce Schneier, one of the most respected cryptographers alive, wrote it up approvingly. Gutmann's talk on the subject is bluntly titled "Why Quantum Cryptanalysis is Bollocks", and his summary line is: "Quantum cryptanalysis is the string theory of security." Lots of theory, almost no data.
That's the skeptic case. Hold it in your head, because the other side has evidence too.
The Other Side: Error Correction Is Working
In my opinion, the skeptics aren't entirely right either. The big obstacle to useful quantum computers is noise: qubits make errors. The fix is error correction, which combines many noisy physical qubits into one reliable "logical" qubit. For years nobody could show that adding more qubits actually reduced errors. Now they can.
Google showed a bigger error-correcting code beating a smaller one in a 2023 Nature paper, though only by about 4%. Its Willow chip went much further in December 2024: each step up in code size roughly halved the error rate. That's the first strong evidence that scaling works.
Logical qubit counts are climbing too. In the video I quoted 12, from Microsoft and Quantinuum in 2024. Quantinuum's Helios machine has since run 48 error-corrected logical qubits.
Now compare that with what's needed. The best current estimate for breaking RSA-2048, the encryption behind much of the internet, is about 1,400 logical qubits and fewer than a million physical ones (Craig Gidney, Google, 2025). For the elliptic-curve maths Bitcoin uses, Google researchers estimated 1,200 to 1,450 logical qubits in March 2026. So 48 isn't most of the way there. It's a few percent of the way there. But it's moving in the right direction, and the estimates of what's needed keep falling: the Oratomic and Caltech paper behind the "26,000 qubits" headline counts physical neutral-atom qubits, far fewer than the roughly one million physical qubits assumed in earlier estimates, though it's still a design on paper. (Physical and logical counts can't be compared directly: one logical qubit is built from many physical ones.)
Credentialed scientists still argue it can never scale. The mathematician Gil Kalai of the Hebrew University argues that correlated noise will stop error correction from ever reaching the level needed. His position hasn't been refuted. It's contested.
So here's where to land. One side has receipts that scaling works at small sizes. The other argues it will never scale to break RSA. Both have evidence, and neither has won. That makes a code-breaking quantum computer an engineering problem with an unknown completion date: not imminent, but not quite bollocks either.
Press Release vs Paper: Microsoft's Majorana 1
Here's a perfect example of the gap you're being sold. In February 2025, Microsoft announced its Majorana 1 chip and said it had created "an entirely new state of matter". Millions of views followed. Then people read the paper.
The peer-reviewed Nature paper was far more careful. It said its measurements couldn't, by themselves, show the exotic states the press release was celebrating. Press release said breakthrough. Paper said maybe. The argument has continued with Microsoft's Majorana 2 announcement in 2026.
That's the pattern. Quantum sells. Calm doesn't. One camp says a code-breaking machine is impossible, the other says it's imminent, and in my view both are wrong. The evidence is thinner than the panic.
Why You Still Need Post Quantum Cryptography Anyway
So why is everyone, including me, still telling you to swap today's public-key encryption for post quantum cryptography? Because it's insurance against a plausible threat, even if progress is as slow as the skeptics say. If Gutmann's "never" turns out to be right, the insurance wasn't needed. But you can't wait to find out.
There's a simple test called Mosca's inequality, after the Canadian researcher Michele Mosca. It says: if X plus Y is greater than Z, you have a problem today.
X: how long your data must stay secret. For government, banking, medical and legal records, that can be 20 years or more.
Y: how long the migration takes. For a global switch to new encryption, think 10 to 15 years. Past migrations, like moving off the old MD5 and SHA-1 algorithms, took about that long.
Z: how long until a quantum computer can break today's encryption. Unknown. If my 2032 to 2040 window is right, that's roughly 6 to 14 years from now.
Twenty plus fifteen is 35. If Z is 6, or even 14, you're already exposed. Not because we know the date, but because the maths doesn't care whether we do. And attackers don't need the quantum computer today to cause the damage. The US government's June 2026 executive order on post-quantum cryptography names the risk of "adversaries collecting United States information now, and decrypting it later". That's harvest now, decrypt later: steal the encrypted data today, open it when the machine arrives.
This rhymes with Y2K, but it isn't identical. With Y2K we knew the date. Here we're planning a 10-year migration against a threat with an unknown completion date. The serious question isn't "when does quantum break crypto?" It's "how do we migrate in time without knowing?" The answer is: start anyway.
Four Wildcards Nobody Is Pricing In
Most people predicting quantum timelines ignore four things that could move them.
1. AI. If we get AI far smarter than us in the next decade, the quantum debate could become irrelevant: it might crack hard maths problems on ordinary computers, or solve error correction overnight. Sam Altman has written that superintelligence may be "a few thousand days" away, and Dario Amodei wrote in October 2024 that "powerful AI" could arrive as early as 2026. AI is already helping: Google DeepMind's AlphaQubit made 30% fewer errors than the standard fast decoder for error correction in 2024, and a real-time version followed in December 2025.
2. State actors. China Telecom's 504-qubit Tianyan-504 machine is on a public cloud, though its performance hasn't been independently checked. And intelligence agencies like the NSA have often been years ahead of public cryptography. We don't know what they have, and we never have.
3. Hardware leapfrogs. Most public timelines assume superconducting qubits. But other ways of building qubits, using trapped neutral atoms, particles of light (photonic) and proposed exotic states of matter (topological), are racing in parallel. The 26,000-qubit estimate was for neutral atoms. A dark horse could win quietly.
4. The cure might be broken. NIST ran a competition to pick post-quantum algorithms. One candidate, SIKE, was broken in 2022 by an ordinary computer in about an hour on a single core. Not by a quantum computer. And the cryptographer Daniel J. Bernstein has argued NIST overstated the security margin of the smallest version of Kyber, one of the chosen algorithms. That's a dispute about margins, not a break, but the cure may need its own cure.
A Realistic Quantum Timeline
So here's what I'd remember. Yes, quantum computers will probably break today's public-key cryptography. Most likely between 2032 and 2040. Possibly later, and possibly never. The 2029 panic is wrong, and so are the deniers. The window has likely tightened because of AI and better designs. Tighter than the skeptics admit, slower than the panic merchants claim.
That's not just my read. In the Global Risk Institute's latest expert survey, published in March 2026, experts put the chance of a code-breaking quantum computer within about 10 years at 28 to 49%, and within about 15 years at 51 to 70%. And anyone who tells you the exact year, Altman, Aaronson, Gutmann, other YouTubers, me, is overconfident.
3 Post Quantum Cryptography Moves to Make Now (and 4 Things to Ignore)
Your job is to migrate calmly to hybrid systems, whichever extreme turns out to be true. Three things to actually do:
Audit the data that must stay secret past 2040. And include data that needs to stay secret into the early 2030s, since that's where my risk window starts. Legal files, intellectual property, medical records, anything classified. If attackers are recording it now, it's exposed today.
Plan your post quantum migration. NIST finalised three standards in August 2024: ML-KEM, ML-DSA and SLH-DSA. Start with an inventory of everywhere you use encryption, then plan the switch.
Use hybrid schemes. Combine today's algorithms with post-quantum ones, so an attacker has to break both. My advice during the transition: never post-quantum alone. SIKE showed why: a new algorithm can look solid for years and then fall. Security agencies differ on whether hybrid should be required, but it's the safer default while the new standards earn their trust.
The deadlines are already set. You don't have to guess at Z to have a schedule:
| Who | Deadline |
|---|---|
| US federal high-value systems | Post-quantum key exchange by 31 Dec 2030, signatures by 31 Dec 2031 (Executive Order 14412, June 2026) |
| European Union | Start by end of 2026, high-risk systems by end of 2030 (EU roadmap) |
| United Kingdom | Plan by 2028, priority migration by 2031, complete by 2035 (NCSC) |
| Google (its own systems) | 2029 |
And four things you can safely ignore:
The 2029 doom date. It's Google's migration target, not a quantum computer's birthday.
Generic "quantum kills Bitcoin" claims. The real risk is more specific, as we'll see next.
"Quantum-safe" consumer VPNs and wallets. Premature and mostly marketing. Buying one today doesn't protect you from anything that matters yet.
Anyone confident about the year. Including me.
If you're thinking about a career in this, post quantum migration is going to be a decade of work for security teams. It sits squarely in the skills I covered in I Scored 3,500 Jobs. These 6 Cyber Skills Win., especially security architecture.
Bitcoin and Quantum Computers: What's Actually at Risk
A specific word for Bitcoin holders, because I know you care about this. Bitcoin doesn't use RSA. It uses elliptic-curve signatures. Shor's algorithm breaks those too: different lock, same lock pick. But the risk isn't evenly spread.
Mining is fine for now. It relies on the SHA-256 hash function, which only gets a small quantum speed-up, and Bitcoin's difficulty adjustment absorbs it. The exposure is in coins whose public key is already visible on the blockchain. Google researchers estimate that's about 6.9 million BTC, roughly a third of all bitcoin, including about 1.7 million in early addresses from Satoshi's era. Other estimates range from 4 to 10 million. Once a quantum computer can run Shor's at scale, those wallets can be drained.
So if you hold Bitcoin, don't reuse addresses, and move coins from old addresses to a fresh, modern wallet well before a machine like that exists. Why does moving help? Modern Bitcoin addresses show only a hash (a scrambled fingerprint) of the public key until you spend from them, so an unused modern address doesn't expose the key a quantum computer would need. That reduces your exposure, though it isn't fully quantum-proof. Don't sell over a YouTube video, either. The protocol can probably be upgraded: there's a proposal, BIP-360, to add quantum-resistant outputs, but it's still a draft, and the upgrade politics could get ugly.
Y2K wasn't fake. The panic was wrong, and the migration was right. This rhymes with it: ignore the noise, migrate calmly, not because we know the answer, but because we don't. And quantum is only one piece of a bigger shift. AI is now finding vulnerabilities on its own, which I cover in The Future of Cybersecurity Just Changed.
Frequently Asked Questions
Is quantum computing real or hype?
Both. Quantum computers are real and error correction is improving, but no quantum computer has yet factored a number it didn't already know the answer to. The largest Shor's algorithm 'record' is 21, and even that used a shortcut. A code-breaking machine is an engineering problem with an unknown finish date, not a certainty for 2029.
What is post quantum cryptography?
Post quantum cryptography means encryption and digital signatures built on maths that quantum computers aren't known to break. NIST published the first three standards in August 2024: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures.
When will quantum computers break encryption?
Nobody knows. In the Global Risk Institute's 2026 expert survey, 28 to 49% of the probability falls within about 10 years and 51 to 70% within about 15 years. My view is 2032 to 2040 is most likely, possibly later, and possibly never.
What is harvest now, decrypt later?
It's the risk that attackers record encrypted data today and store it until a quantum computer can decrypt it. The US government's June 2026 executive order on post-quantum cryptography names it as a risk, which is why data that must stay secret for decades needs protecting now.
Can quantum computers break Bitcoin?
A large enough quantum computer could forge Bitcoin signatures for coins whose public key is already visible on the blockchain, about 6.9 million BTC by one 2026 estimate. Mining is far safer, because the hashing it uses only gets a small quantum speed-up. Don't reuse addresses, and move coins from old addresses well before such a machine exists.
What should my organisation do about quantum risk now?
Find the data that must stay secret past about 2040, and into the early 2030s for the most sensitive, inventory where you use encryption, and plan a migration to hybrid schemes that combine today's algorithms with post-quantum ones. US federal high-value systems must switch key exchange by the end of 2030 under Executive Order 14412.
About the Author
Nathan House, Founder & CEO of StationX
Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.