Quantum computing will break current encryption within a decade
What's this about?
People disagree about whether quantum computers will break today’s online locks within ten years.
These locks help guard bank deals, messages, and other key data.
What supporters say
- A strong enough quantum computer could solve the math puzzles behind RSA, Diffie-Hellman, and elliptic-curve locks.
- Many sites and banks use these kinds of locks to guard data sent online.
- US tech rule makers have made new post-quantum locks, which resist quantum computer attacks.
- Builders have made progress with qubits, the tiny parts that quantum computers use to process data.
What critics say
- No one has shown a quantum computer that can break RSA-2048 or common elliptic-curve locks.
- Today’s quantum machines still make many mistakes and need far better mistake-fixing systems.
- Early lab tests show useful steps, but they do not prove a huge code-breaking machine will arrive by 2036.
- Experts cannot yet say how fast quantum hardware will improve over the next ten years.
The bottom line
Quantum computers may one day break many current online locks, so groups should start getting ready now.
But the proof does not support a sure claim that they will do so within a decade.
Quantum computing could one day undermine some of the internet’s most important security systems. But the evidence supports a serious need to prepare, not a confident prediction that today’s encryption will be broken by about 2036.
The case for
The core technical threat is real. A sufficiently powerful, error-corrected quantum computer could run Shor’s algorithm, which can crack the mathematical problems behind RSA, Diffie–Hellman and elliptic-curve cryptography. Those systems are widely used to secure online communications, financial transactions and other digital services. 1
This is not merely a theoretical concern. The US National Institute of Standards and Technology, or NIST, has treated the threat seriously enough to standardize new post-quantum encryption methods. That move reflects a broad view among technical and government experts that existing public-key systems have a credible long-term weakness.
Quantum hardware has also made meaningful progress. Researchers have demonstrated important pieces of fault-tolerant computing, including error correction that operates below key error thresholds, logical qubits and repeated correction cycles. These results do not show a machine capable of breaking modern cryptography, but they make such a machine scientifically plausible rather than fanciful. 3
The strongest reason to take a 10-year warning seriously is practical rather than predictive. Replacing cryptography across governments, companies, software and physical devices can take many years. Data stolen today may also be stored and decrypted later if quantum computers become capable enough. NIST has urged organizations to begin moving to post-quantum systems, while the NSA has set transition expectations for national-security networks (see Figure 3). 2
The case against
The available evidence does not establish that a quantum computer able to break RSA-2048 or widely deployed elliptic-curve systems will exist by 2036. Fault-tolerance experiments remain early demonstrations of central engineering ideas. They have not shown the vast number of reliable operations, the system scale or the integrated hardware needed for a long cryptanalytic attack. 4
Estimates of the required quantum hardware do not solve that problem. They vary sharply depending on the type of machine, error rates, qubit connectivity, error-correction overhead, runtime and the systems needed to control the computer. One study suggesting a possible route using as few as 10,000 reconfigurable atomic qubits shows that some designs may reduce the challenge; it does not show that such a computer will be built and operated on a particular date (see Figure 1). 6
The phrase “current encryption” is also too broad. Quantum computers pose their most severe known threat to public-key encryption through Shor’s algorithm. Symmetric encryption, including AES, faces a less dramatic threat from Grover’s algorithm, which is more resource-intensive in practice and can be partly addressed by using larger keys (see Figure 2). Quantum computing would therefore not simply destroy every form of encryption in the same way. 5
There is another reason the forecast is uncertain: the outcome depends on what organizations do before a cryptographically relevant quantum computer arrives. Standardized post-quantum alternatives could replace vulnerable RSA and elliptic-curve systems in time. Government migration plans are best understood as prudent risk management for a slow transition, not as forecasts that quantum cryptanalysis is certain by 2036.
Industry roadmaps offer signs of technical ambition, but they are not independent probability estimates. Their milestones are engineering targets, and commercial incentives limit how much confidence they can provide about a fixed deadline. There is also limited evidence on how quickly and completely the world’s many vulnerable systems will actually migrate.
The bottom line
Quantum computing presents a credible future threat to RSA and elliptic-curve cryptography, and organizations should begin preparing now. The risk is especially important for information that must remain secret for many years.
But the claim that quantum computers will break current encryption within a decade goes beyond the evidence. There is no validated end-to-end demonstration, or independently calibrated forecast, showing that a practical cryptanalysis-capable quantum computer will exist by approximately 2036. The biggest unknown is whether promising laboratory progress can be turned into a large, reliable and affordable machine on that timetable.
Figures & data



All contributions are reviewed for clarity, balance, and evidence. The strongest insights are elevated into the argument graph — with credit to you.
Help improve this analysis →