Cryptanalytically Relevant Quantum Computers
- Cryptanalytically Relevant Quantum Computers (CRQCs) are fault-tolerant quantum devices designed to break RSA-2048 and 256-bit ECC by executing full-scale implementations of Shor’s algorithm.
- They utilize advanced reversible arithmetic circuits and architecture-sensitive error correction to meet operational cryptanalytic thresholds.
- Benchmark studies reveal that achieving CRQC capability requires vast qubit counts, low logical error rates, and significant infrastructure investments.
A cryptanalytically relevant quantum computer (CRQC), also termed a cryptographically relevant quantum computer in some literature, is a fault-tolerant quantum computer whose logical width, logical error rate, and execution time are sufficient to break deployed cryptographic schemes at standard security levels, rather than merely to demonstrate toy or compiled instances of quantum algorithms. In the literature centered on Shor’s algorithm, the canonical threshold is the ability to attack RSA-2048 and standard elliptic-curve systems such as 256-bit ECC; more recent work also uses the term for machines that can reach economically meaningful elliptic-curve targets such as secp256k1, or, in some claims, standardized lattice schemes (Bagourd et al., 17 Dec 2025, Parker et al., 2023, Scholten et al., 2024, Dallaire-Demers et al., 19 Aug 2025, Luo, 17 May 2026).
1. Definition and threshold concept
The defining feature of a CRQC is not quantumness per se, but cryptanalytic sufficiency. In the gate-model setting, that means a machine able to execute long-depth, fault-tolerant implementations of Shor’s algorithm for factoring and discrete logarithms on parameters that matter operationally, such as RSA-2048 and 256-bit elliptic curves. The literature explicitly distinguishes such machines from NISQ devices, which are noisy, small, and not fault-tolerant, and from compiled demonstrations in which most of the true scaling burden has been removed (Bagourd et al., 17 Dec 2025, Scholten et al., 2024).
This threshold concept is operational rather than purely asymptotic. A CRQC must have enough logical qubits to encode the arithmetic registers, enough non-Clifford throughput to sustain modular arithmetic, and a logical error rate low enough that the full computation completes before failure. In this sense, “cryptanalytically relevant” denotes the point at which quantum computation becomes capable of breaking real trust anchors, not merely of exhibiting small algorithmic instances. Work on secp256k1 benchmarks makes the same point by insisting that progress should be tracked against the full 256-bit elliptic-curve discrete logarithm problem (ECDLP), not against sparse or interval-restricted puzzles (Dallaire-Demers et al., 19 Aug 2025).
A recurrent conclusion in the survey literature is that current and near-future systems do not meet this threshold. One broad assessment states that currently available quantum computers are not believed to pose security risks, and that there is a credible expectation that quantum computers will perform economically impactful computations before they become cryptanalytically relevant (Scholten et al., 2024).
2. Algorithmic basis and computational bottlenecks
The canonical CRQC threat model is built on Shor’s algorithm. For factoring, the quantum subroutine is order finding: given an integer and a coprime , one seeks such that
If is even and satisfies the usual nontriviality conditions, factors can be recovered through
For cryptanalytic purposes, the difficulty lies not in these classical postprocessing steps but in coherent modular exponentiation and phase estimation/order finding, which require large reversible arithmetic circuits (Bagourd et al., 17 Dec 2025).
For elliptic-curve cryptanalysis, the corresponding hidden-subgroup implementation uses a unitary of the form
followed by Fourier sampling and classical postprocessing. Here too, the practical resource drivers are reversible arithmetic, logical qubit count, and non-Clifford supply, especially Toffoli count and Toffoli depth (Dallaire-Demers et al., 19 Aug 2025).
These bottlenecks are architecture-sensitive. One resource analysis for Shor’s elliptic-curve algorithm on a two-dimensional nearest-neighbor lattice proposes a carry-lookahead adder with Toffoli depth
using only ancillas, and combines dynamic circuits, mid-circuit measurements, classically controlled operations, the windowed method, Montgomery representation, and quantum tables to reduce long-range overhead on local architectures (Gu et al., 27 Oct 2025).
The asymmetry between public-key and symmetric cryptanalysis is central to the CRQC concept. In the resource-estimation literature, public-key cryptography becomes vulnerable earlier because Shor’s algorithm gives polynomial-time attacks on factoring and discrete logarithms, whereas symmetric cryptanalysis relies on Grover-like search or structured quantum cryptanalysis that generally yields only quadratic or subquadratic improvements in the effective work factor (Gheorghiu et al., 2019, Kaplan et al., 2015, Kim et al., 2018).
3. Experimental demonstrations and the gap to relevance
Experimental realizations of Shor-type factoring span NMR, photonics, superconducting qubits, photonic qubit recycling, trapped ions, and IBM quantum hardware. The cited progression includes Vandersypen et al. on NMR, Lu et al. and Lanyon et al. on photonic compiled demonstrations, Lucero et al. on a Josephson phase-qubit processor, Martin-Lopez et al. on qubit recycling, Monz et al. on trapped ions, and Amico et al. on IBM Q hardware. Across this line of work, the consistent pattern is that the demonstrations are small, compiled, or highly specialized, rather than full-scale realizations of the algorithmic workload relevant to RSA or ECC (Bagourd et al., 17 Dec 2025).
Direct experiments on cloud-accessible hardware reinforce this distinction. One experimental study of Shor’s algorithm on several cloud-based quantum computers reports a substantial gap between current hardware and the requirements for factoring cryptographically relevant integers, observing that circuit constructions still need to be highly specific for each modulus and that machine fidelities are unstable, with high and fluctuating error rates (Bagourd et al., 17 Dec 2025).
The practical reasons are standard and cumulative: insufficient qubit counts, noise and decoherence, readout error, crosstalk, deep modular-exponentiation circuits, and the absence of fault tolerance. Emulation-based work aimed at cryptographic algorithms reaches the same bottom line from a different angle. Using cuQuantum on GPU hardware, one study reports simulation up to 32 qubits on a single A100 GPU and concludes that current NISQ hardware is too noisy and too small to be cryptanalytically relevant for RSA, ECC, DH, or DSA in practice (Harshvardhan et al., 2023).
A persistent misconception is therefore that any successful “factoring on a quantum computer” demonstration constitutes a cryptanalytic threat. The literature consistently rejects that inference: proof-of-principle execution on , 0, or other tiny moduli demonstrates principle, not cryptanalytic scale (Bagourd et al., 17 Dec 2025).
4. Quantitative resource estimates for RSA and ECC
Resource estimation is the core quantitative content of CRQC analysis. For RSA-2048 and ECC-256, the literature reports large but highly assumption-dependent costs, with architecture, code choice, gate fidelity, schedule optimization, and target runtime all materially affecting the totals. One energy-focused review notes that published spacetime-volume estimates for breaking a public key span roughly six orders of magnitude, from about 1 to 2 qubit-days (Parker et al., 2023).
| Target and model | Reported resources | Interpretation |
|---|---|---|
| RSA-2048, plausible spacetime-volume estimate | 3 qubit-days; about 20 million qubits; around 7.1 hours | Representative large-scale CRQC benchmark (Parker et al., 2023) |
| RSA-2048, one-day attack, 4 | 5 physical qubits; 4098 logical qubits | Surface-code-style estimate (Gheorghiu et al., 2019) |
| P-256, one-day attack, 6 | 7 physical qubits; 2330 logical qubits | ECC requires fewer resources than comparable RSA (Gheorghiu et al., 2019) |
| secp256k1 ECDLP, aggressive surface code, low-depth-optimal | about 813,220 physical qubits; runtime about 22.22 hours | Architecture- and schedule-specific benchmark (Dallaire-Demers et al., 19 Aug 2025) |
| NIST P-256 on a 2D lattice with improved adder | about 4300 logical qubits; logical Toffoli fidelity about 8 | Layout-aware logical benchmark (Gu et al., 27 Oct 2025) |
The comparative message is stable even when the numbers vary. For fixed classical security levels, RSA is typically more resource-intensive than ECC. A widely cited benchmark gives, for one-day attacks at 9, 0 physical qubits for RSA-2048 at classical security 112, versus 1 physical qubits for ECC P-224 at the same classical security level (Gheorghiu et al., 2019).
Recent ECDLP-focused work has shifted attention from generic ECC to concrete Bitcoin-relevant targets. A graded suite of secp256k1-shaped challenges from 6 to 256 bits calibrates classical cost against Pollard’s rho records and quantum cost against Shor resource estimates under surface code, repetition cat code, and LDPC cat code models. Under explicit and testable assumptions on physical error rates, code distances, and non-Clifford supply, those scenarios place the full 256-bit instance within a 2027–2033 window (Dallaire-Demers et al., 19 Aug 2025). This is not presented as a prediction, but as a benchmark crossing window under stated assumptions.
5. Fault tolerance, architecture, and operating cost
The decisive engineering distinction between a quantum demonstration and a CRQC is fault tolerance. A real cryptanalytic machine must encode logical qubits, repeatedly extract syndromes, and deliver logical failure rates compatible with extremely large circuit volumes. One broad assessment uses 2 as a rough proxy for circuit size and treats 3 as a loose upper bound on the logical error rate needed for success, emphasizing that very small logical error rates imply demanding physical error-rate and code-distance requirements (Scholten et al., 2024).
Architecture-specific modeling has become increasingly explicit. In the secp256k1 benchmark literature, surface-code estimates are parameterized by physical error rates, code distances, and factory throughput; the repetition cat code assumes cycle time near 500 ns and strong noise bias; and LDPC cat-code estimates are derived from published cat-code architecture models. For 256-bit ECDLP, the cited point estimates range from about 126,133 cat qubits and about 9 hours runtime in the repetition cat code to about 38,581 cat qubits and about 17–18 hours runtime in the most aggressive LDPC cat-code case (Dallaire-Demers et al., 19 Aug 2025).
Operating a CRQC is itself a large-scale industrial problem. One energy study decomposes electrical demand as
4
and, using 5 qubit-days together with an estimated 6.25 W/qubit for a future superconducting-transmon CRQC, arrives at about 125 MW of total electrical power, 890 MWh per key broken, and about $64,000 in electricity cost alone at the 2022 average U.S. industrial electricity price of 7.19¢/kWh (Parker et al., 2023). The same study emphasizes that these estimates exclude build cost, maintenance, labor, administration, liquid helium, and other non-electric inputs, and are therefore a framework rather than a precise forecast.
This operating-cost perspective sharpens the meaning of “relevance.” A CRQC is not only a computer with enough qubits; it is an installation with enough fault-tolerant throughput, power, and support infrastructure to execute a full cryptanalytic workload in a useful time window. The plausible implication is that early CRQCs, if built, would remain concentrated in nation-states and large organizations for a significant period (Parker et al., 2023).
6. Special-purpose quantum devices, hybrid attacks, and disputed shortcuts
Although CRQC discourse is usually organized around universal fault-tolerant gate-model machines, some work extends the notion of cryptanalytic relevance to special-purpose quantum devices used inside hybrid attacks. A prominent example uses a quantum annealer as the “best publicly available special-class quantum computer” in a hybrid GNFS attack. On D-Wave Advantage system 4.1—reported as 5760 qubits, Pegasus topology, 40279 couplers, 10,000 samples, and 20 μs annealing time—the quantum device is used only for 6-smoothness detection, not for end-to-end factorization, and the largest announced instance solved with quantum annealing is a 29-bit integer, 7 (Żołnierczyk, 2024).
Earlier annealing work on the low-noise D-Wave 2000Q reached much smaller scales. Using QUBO/Ising encodings and favoring the block multiplication table method, that line reports successful factorizations up to 8 bits under the tested settings, with major limitations from logical-variable count, minor embedding into the Chimera graph, coefficient-range constraints, and the rapid growth of physical-qubit overhead (Mengoni et al., 2020).
These results do not make annealers CRQCs in the standard Shor sense. The hybrid GNFS approach explicitly does not reduce the complexity class of factorization; it preserves the subexponential GNFS structure and merely offloads a critical smoothness subproblem to the annealer (Żołnierczyk, 2024). The near-term significance is pragmatic rather than asymptotic.
The literature is especially skeptical of claims that hybrid or heuristic methods collapse CRQC resource requirements by orders of magnitude. Two critiques of a sublinear QAOA-based factoring proposal argue that the claim of challenging RSA-2048 with 372 qubits is unsupported because it depends on an unvalidated Schnorr-lattice scaling assumption. One implementation finds that, even with a perfect optimizer replacing QAOA, the method succeeds only up to 70-bit integers and fails to find enough factoring relations for random 80-bit integers and beyond (Khattar et al., 2023, Grebnev et al., 2023). Within CRQC discourse, these critiques are important because they distinguish genuine end-to-end cryptanalytic scalability from reductions in the qubit count of an isolated subroutine.
7. Benchmarks, scope expansion, and security implications
Benchmarking has become a central methodological issue because CRQC status cannot be inferred from isolated resource numbers alone. The secp256k1 challenge ladder is a direct response to this problem: it defines reproducible elliptic-curve targets from 6 to 256 bits, all preserving the Bitcoin curve shape 9, and uses them as a transparent ruler for early fault-tolerant progress toward an economically meaningful attack target (Dallaire-Demers et al., 19 Aug 2025).
The scope of CRQC analysis is also expanding beyond RSA and ECC. One paper claims a polynomial-time quantum attack on ML-KEM, Falcon, Hawk, and NTRU variants over 2-power cyclotomic rings by combining a tower decomposition of the Principal Ideal Problem with abelian hidden-subgroup subroutines. For ML-KEM-1024, it reports 0, about 1 total logical gates, about 1400 logical qubits, and about 2 physical qubits under surface-code assumptions (Luo, 17 May 2026). This suggests that, in some strands of the literature, a quantum computer becomes cryptanalytically relevant not only when it can run Shor at RSA/ECC scale, but when it can execute a full secret-recovery pipeline against standardized post-quantum schemes.
At the same time, not every quantum cryptographic risk requires a CRQC. In the QCCA1 model, one paper shows that a single quantum decryption query can recover the full secret key of standard LWE-based encryption with constant success probability, whereas classical key recovery requires linearly many decryption queries (Alagic et al., 2018). This establishes a different boundary: some quantum threats arise from quantum oracle access rather than from the arrival of a large fault-tolerant cryptanalytic machine.
From an infrastructure perspective, the significance of CRQCs lies in the collapse of both confidentiality and authenticity. Engineering inventories of quantum-vulnerable systems emphasize “harvest now, decrypt later” exposure for recorded traffic and signature forgery for certificates, software signing, identity systems, and blockchain ownership layers once a CRQC can run Shor-style attacks at scale (Benitez, 29 Sep 2025). The dominant response in the broader literature is therefore managed migration to quantum-safe cryptography, not reliance on continued distance from the CRQC threshold (Scholten et al., 2024).
In summary, the CRQC concept functions as a threshold notion linking quantum algorithms, fault-tolerant architecture, and real cryptographic breakability. Its canonical form remains the fault-tolerant Shor machine capable of attacking RSA-2048 or 256-bit ECC, but the term increasingly serves as a benchmark for any quantum system whose end-to-end resources suffice for economically meaningful cryptanalysis. Across survey, benchmark, and experimental work, the consistent present-tense assessment is that current hardware is far from that threshold, while the consistent long-run assessment is that the threshold is defined by scalable fault tolerance, not by isolated demonstrations or optimistic subroutine counts (Bagourd et al., 17 Dec 2025, Scholten et al., 2024).