Quantum computing will break current encryption within a decade

Depends on scope
Why — conclusion confidence High: Shor threat to RSA and elliptic-curve cryptography is well established · No validated end-to-end demonstration or calibrated 2036 forecast · Scaling from fault-tolerance experiments to operable cryptanalysis is unresolved · Post-quantum migration choices affect real-world breakability
Updated 2026-09-15 3 supporting · 3 opposing arguments
PRO 51%CON 49%
Pro 36% · Con 35% — Nuanced 29% — evidence balanced
What the evidence says Evidence quality: Moderate
Graded from the quality of the cited sources · Evidence Protocol

What's this about?

People disagree about whether quantum computers will break today’s online locks within ten years.

These locks help guard bank deals, messages, and other key data.

What supporters say

  • A strong enough quantum computer could solve the math puzzles behind RSA, Diffie-Hellman, and elliptic-curve locks.
  • Many sites and banks use these kinds of locks to guard data sent online.
  • US tech rule makers have made new post-quantum locks, which resist quantum computer attacks.
  • Builders have made progress with qubits, the tiny parts that quantum computers use to process data.

What critics say

  • No one has shown a quantum computer that can break RSA-2048 or common elliptic-curve locks.
  • Today’s quantum machines still make many mistakes and need far better mistake-fixing systems.
  • Early lab tests show useful steps, but they do not prove a huge code-breaking machine will arrive by 2036.
  • Experts cannot yet say how fast quantum hardware will improve over the next ten years.

The bottom line

Quantum computers may one day break many current online locks, so groups should start getting ready now.

But the proof does not support a sure claim that they will do so within a decade.

The fuller picture Reading level: Standard

Quantum computing could one day undermine some of the internet’s most important security systems. But the evidence supports a serious need to prepare, not a confident prediction that today’s encryption will be broken by about 2036.

The case for

The core technical threat is real. A sufficiently powerful, error-corrected quantum computer could run Shor’s algorithm, which can crack the mathematical problems behind RSA, Diffie–Hellman and elliptic-curve cryptography. Those systems are widely used to secure online communications, financial transactions and other digital services. 1

This is not merely a theoretical concern. The US National Institute of Standards and Technology, or NIST, has treated the threat seriously enough to standardize new post-quantum encryption methods. That move reflects a broad view among technical and government experts that existing public-key systems have a credible long-term weakness.

Quantum hardware has also made meaningful progress. Researchers have demonstrated important pieces of fault-tolerant computing, including error correction that operates below key error thresholds, logical qubits and repeated correction cycles. These results do not show a machine capable of breaking modern cryptography, but they make such a machine scientifically plausible rather than fanciful. 3

The strongest reason to take a 10-year warning seriously is practical rather than predictive. Replacing cryptography across governments, companies, software and physical devices can take many years. Data stolen today may also be stored and decrypted later if quantum computers become capable enough. NIST has urged organizations to begin moving to post-quantum systems, while the NSA has set transition expectations for national-security networks (see Figure 3). 2

The case against

The available evidence does not establish that a quantum computer able to break RSA-2048 or widely deployed elliptic-curve systems will exist by 2036. Fault-tolerance experiments remain early demonstrations of central engineering ideas. They have not shown the vast number of reliable operations, the system scale or the integrated hardware needed for a long cryptanalytic attack. 4

Estimates of the required quantum hardware do not solve that problem. They vary sharply depending on the type of machine, error rates, qubit connectivity, error-correction overhead, runtime and the systems needed to control the computer. One study suggesting a possible route using as few as 10,000 reconfigurable atomic qubits shows that some designs may reduce the challenge; it does not show that such a computer will be built and operated on a particular date (see Figure 1). 6

The phrase “current encryption” is also too broad. Quantum computers pose their most severe known threat to public-key encryption through Shor’s algorithm. Symmetric encryption, including AES, faces a less dramatic threat from Grover’s algorithm, which is more resource-intensive in practice and can be partly addressed by using larger keys (see Figure 2). Quantum computing would therefore not simply destroy every form of encryption in the same way. 5

There is another reason the forecast is uncertain: the outcome depends on what organizations do before a cryptographically relevant quantum computer arrives. Standardized post-quantum alternatives could replace vulnerable RSA and elliptic-curve systems in time. Government migration plans are best understood as prudent risk management for a slow transition, not as forecasts that quantum cryptanalysis is certain by 2036.

Industry roadmaps offer signs of technical ambition, but they are not independent probability estimates. Their milestones are engineering targets, and commercial incentives limit how much confidence they can provide about a fixed deadline. There is also limited evidence on how quickly and completely the world’s many vulnerable systems will actually migrate.

The bottom line

Quantum computing presents a credible future threat to RSA and elliptic-curve cryptography, and organizations should begin preparing now. The risk is especially important for information that must remain secret for many years.

But the claim that quantum computers will break current encryption within a decade goes beyond the evidence. There is no validated end-to-end demonstration, or independently calibrated forecast, showing that a practical cryptanalysis-capable quantum computer will exist by approximately 2036. The biggest unknown is whether promising laboratory progress can be turned into a large, reliable and affordable machine on that timetable.

Figures & data

Cited sources by side and evidence strengthEach bar counts DISTINCT sources cited on that side, once per source at its highest evidence strength.Supporting5 strong sources53 moderate sources38Opposing5 strong sources52 moderate sources27Nuanced3 strong sources32 weak sources25strongmoderateweak
The evidence base behind this claim: 20 distinct cited sources
Every source cited on this claim, counted once at its highest evidence strength and grouped by the side it supports. Generated from this page's own evidence rows — the same records the verdict is computed from — so the chart and the score cannot disagree. Strength labels follow the scoring methodology.
Resource-estimation chart from the 2025 study “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits,” comparing the qubit and runtime requirements for breaking elliptic-curv
This is the most directly relevant quantitative figure for the decade claim: it shows why estimates of a cryptographically relevant machine vary substantially with architecture, error rates, connectivity, and fault-tolerance assumptions, rather than treating a qubit count as a simple prediction.
NIST comparison graphic or table showing the different effects of Shor’s algorithm and Grover’s algorithm on public-key and symmetric cryptography, including RSA, Diffie–Hellman, elliptic-curve crypto
It corrects the overbroad phrase “all current encryption”: quantum computers pose a severe threat to RSA, Diffie–Hellman, and ECC, while symmetric encryption and hashes suffer a much smaller, addressable security reduction.
NIST post-quantum migration timeline showing cryptographic inventory, standards adoption, transition deadlines, and the “harvest now, decrypt later” risk
This visual distinguishes urgency from prediction: organizations must begin migration years before a cryptographically relevant quantum computer appears because systems are difficult to inventory and replace, and intercepted data may remain vulnerable to later decryption.

All contributions are reviewed for clarity, balance, and evidence. The strongest insights are elevated into the argument graph — with credit to you.

Help improve this analysis →
𝕏 Share Facebook LinkedIn