up:: Quantum Computing MOC

How Do You Tell Real Quantum Progress From Hype?

A quantum headline lands, a stock moves, and by mid-morning someone on your leadership team has forwarded it to you with one question attached: does this change our timeline? Most weeks the answer is no, and the reason is that the headline number and the number that governs your cryptographic risk are almost never the same thing. The gap between them is where the hype lives, and closing it takes a handful of questions you can learn to ask in about 5 minutes.

I’m not here to tell you quantum computing is fake. The hardware is advancing for real, the long-run threat to public-key cryptography is real enough that NIST has already published the replacements, and a qubit genuinely does something a bit can’t. What I want to give you is a way to read the news that separates real progress toward a code-breaking machine from progress that’s real but points somewhere else entirely, and from claims that haven’t cleared peer review yet. This is a calibration tool for a procurement decision or a board conversation, not a way to win an argument on the internet.

The one distinction that decodes most headlines

The single most useful habit is to read every qubit count as a physical qubit count until the article proves otherwise. A physical qubit is one piece of quantum hardware, noisy and error-prone, and it’s what a chip’s advertised number almost always refers to. A logical qubit is a single reliable qubit built by weaving many physical ones together with error correction so the group behaves like one qubit that rarely errs. Breaking cryptography takes logical qubits, and the ratio between the two is brutal.

The arithmetic makes a “1,000-qubit chip” headline far less alarming than it sounds. Breaking RSA-2048 with Shor’s algorithm takes roughly 6,190 logical qubits in the most-cited peer-reviewed estimate, realized as about 20 million noisy physical qubits in a 2021 construction and driven under 1 million in a 2025 optimization.12 The largest superconducting processors as of 2026 have crossed 1,000 physical qubits, with IBM’s Condor reaching 1,121, and those are noisy and uncorrected.3 So a record-setting chip that sounds like it’s most of the way to 1,000 qubits is actually a long way from the millions of high-quality physical qubits a cryptographic attack demands, because the headline counts the wrong unit.

When a chip announcement crosses your desk, the first question is simply whether the number is physical or logical. Vendors say physical unless they specifically claim otherwise, and a claim of logical qubits is the interesting one worth reading closely.

Fidelity and error rates outrank the qubit count

The second question gets past qubit quantity to qubit quality, and quality is what actually paces the threat. Gate fidelity scores how faithfully a real quantum operation reproduces the perfect one, on a scale where 100% is flawless and the gap below it is the error the hardware introduced. It matters more than the qubit total because error correction only starts working once fidelity clears a specific line. The leading scheme, the surface code, tolerates a per-operation error rate near 1%, so gates need roughly 99% fidelity or better before adding qubits helps rather than hurts.4

Below that threshold, piling on qubits adds noise instead of capability, and no amount of encoding rescues a deep computation. Above it, cleaner gates lower the number of physical qubits each logical qubit costs, which shrinks the whole machine. That’s why a fraction of a percent of fidelity moves the timeline more than another few hundred qubits do. Leading hardware reached 99.9% fidelity on two-qubit entangling gates only recently, which is a genuine milestone precisely because it’s the number that was holding everything back.5

So when the press release leads with the qubit count and stays quiet about the error rate, that silence is worth more than the number. The useful follow-ups are the two-qubit gate error rate, whether error correction has actually been demonstrated on the machine, and how deep a computation it can hold together. A chip that lowers its logical error rate as you add physical qubits, the way Google’s 2024 result did by encoding one logical qubit in 101 physical ones and suppressing the error rate as the code grew, is the kind of progress that matters.5 A wider chip with the same noisy gates is progress on a different axis.

A lab demonstration is not a fault-tolerant machine

The third habit is to notice which machine a result actually ran on. Today’s quantum computers are NISQ devices, a term the physicist John Preskill coined in 2018 for machines with tens to a few hundred qubits that run “unprotected by quantum error correction.”6 Every headline chip shipping in 2026, including the ones past 1,000 qubits, is a NISQ device, because none of them has the fault-tolerant error correction that would move it into a different class. Preskill put a rough ceiling on what a noisy machine can finish at around 1,000 gates before the errors overwhelm it.6

Set that against the size of a real attack. Factoring RSA-2048 is a computation on the order of 2.6 billion sequential operations run without a single uncorrected error along the way.1 The gap between a thousand-gate ceiling and a 2.6-billion-gate attack is the entire reason a cryptographically relevant quantum computer doesn’t exist yet, and it’s why a demo that factors a small number, or shows “quantum advantage” on a physics-flavored sampling problem, moves the cryptographic clock very little. Those demos run on qubit counts and problem types nothing like a Shor’s attack.

The tell to watch for is a result on a NISQ machine described in language that implies fault tolerance is near. Progress toward a code-breaker is a separate track from progress in quantum computing generally, and a chemistry simulation or an optimization demo can be genuinely valuable while telling you almost nothing about when your keys are at risk. Those are two different clocks, and only one of them is yours.

Peer review outranks the press release

The last habit is the one that would have saved a lot of people a lot of excitement over the years: separate what a peer-reviewed paper actually claims from what the press release around it claims, and weight the track record of the group making the claim. The clearest recent worked example is Microsoft’s topological-qubit announcement, and it rewards a careful, even-handed read rather than a cheer or a dunk.

In February 2025, Microsoft unveiled a chip it called Majorana 1 and announced it as the world’s first quantum processor powered by topological qubits, a design meant to be far more stable than conventional approaches. The supporting peer-reviewed evidence was a paper in Nature, and the paper is real work: it demonstrated a single-shot measurement of fermion parity in an indium-arsenide and aluminum device with a 1% assignment error, which is a hard engineering achievement.7 The distance between that result and the announcement is the calibration lesson.

Read carefully, the Nature paper is more modest than the press. The paper’s own text notes that its measurements “do not, by themselves, determine whether the low-energy states detected by interferometry are topological,” and Nature’s editors attached a note stating that the results “do not represent evidence for the presence of Majorana zero modes in the reported devices.”8 Scott Aaronson, a careful and independent voice, landed on the middle: the claim of a topological qubit had at that point been neither accepted nor rejected by the field, and Microsoft’s history was a fair reason for caution.8 That history matters, because a 2018 Nature paper from a Microsoft-affiliated group claiming quantized Majorana conductance was retracted in 2021 for insufficient scientific rigor after outside physicists found problems in the data.9

The dispute has stayed live and civil in the way science is supposed to. Henry Legg, a physicist at St Andrews, published a formal challenge arguing the group hadn’t demonstrated the basic physics needed for even a single topological qubit and that the analysis tool had flaws, and Microsoft published a rebuttal calling the critique less than a substantial scientific challenge to its findings.10 Independent replication will settle it, and that’s exactly the point. The method here is portable to any big claim: find what the peer-reviewed paper measured, read its own caveats, check whether the press went further than the paper, weigh the group’s track record, and give independent confirmation time to arrive.

A checklist for reading a quantum headline

The four habits collapse into a short set of questions you can run against almost any quantum story before deciding whether it touches your plan. None of them takes a physics background.

Ask thisHype answerReal-progress answerWhy it matters
Physical or logical qubits?A big count, unit unstated (assume physical)Logical qubits, stated plainlyCryptography falls to logical qubits; a CRQC needs thousands of them1
What’s the gate error rate?Not mentionedA two-qubit fidelity at or past 99.9%5Below the ~99% surface-code threshold, extra qubits add noise4
Has error correction been shown?Silence, or “roadmap to”A logical error rate that drops as the code grows5Error correction at scale is the real bottleneck to breaking RSA
Is this a fault-tolerant machine or a demo?”Quantum advantage” on a sampling or chemistry taskA deep computation run under error correctionNISQ demos run on a different clock from a code-breaker6
Peer-reviewed, or a press release?Announcement outruns the paperPaper’s claims match the headline, caveats includedMarketing and peer review are different bars8
Does it name a date for breaking RSA?A confident near-term yearA probability range across horizonsHonest timelines are expert-survey bands, not a countdown11

Run a story through those six and the noisy ones sort themselves out fast. A qubit-count record with no fidelity number and no error-correction claim is real hardware news that changes your risk timeline very little. A demonstrated drop in logical error rate, a two-qubit fidelity comfortably past threshold, or a credible logical-qubit count is the kind of thing worth carrying into a planning conversation.

What actually moves your timeline

The reason none of this counsels waiting is that the clock you manage runs on your data, not on the hardware. Encrypted traffic captured today under harvest now, decrypt later is exposed the moment a CRQC exists, a full migration across a large estate takes years, and there’s no patch for data already collected. Credible expert and government estimates for a CRQC still span roughly 2030 to 2040 and beyond, which is uncertainty wide enough that the sound move is to plan around lead time rather than bet on a year.11

So the calibrated posture sits in between the two loud positions. Quantum computing is neither a fraud nor a machine about to break your keys next quarter, and treating a noisy qubit-count headline as either one leads to a bad decision. The steady read is that the threat is real and not imminent, the standards to migrate to already exist, and the work is paced by your own estate rather than by the next press release. For a board, that turns a stream of alarming and reassuring headlines into a single stable question: are we migrating on a schedule that finishes before the machine arrives, whenever it does?

The quantum threat timeline and the CRQC threshold are the two anchors that keep that question honest, and everything above is really just a way to stop the day’s headline from moving your answer around. Learn to spot the physical-versus-logical swap, ask for the error rate, tell a demo from a fault-tolerant machine, and trust peer review over the press, and you’ll read quantum news the way the people who build these machines read it.

Go deeper


Everything here is the map, given freely. When your team needs the qubit-count headlines translated into a clear risk picture and a dated migration plan for your own systems, that’s the work I do.

Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.

Footnotes

  1. Craig Gidney and Martin Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, arXiv:1905.09749. 2 3

  2. Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” 2025, arXiv:2505.15917.

  3. IEEE Spectrum, “An IBM Quantum Computer Will Soon Pass the 1,000-Qubit Mark,” spectrum.ieee.org.

  4. Austin G. Fowler, Matteo Mariantoni, John M. Martinis, Andrew N. Cleland, “Surface codes: Towards practical large-scale quantum computation,” Physical Review A 86, 032324, 2012, arXiv:1208.0928. 2

  5. Rajeev Acharya et al. (Google Quantum AI), “Quantum error correction below the surface code threshold,” Nature 638, 920-926, 2025, arXiv:2408.13687. 2 3 4

  6. John Preskill, “Quantum Computing in the NISQ era and beyond,” Quantum 2, 79, 2018, arXiv:1801.00862. 2 3

  7. Morteza Aghaee et al. (Microsoft Quantum), “Interferometric single-shot parity measurement in InAs–Al hybrid devices,” Nature 638, 651-655, 2025, nature.com.

  8. Scott Aaronson, “FAQ on Microsoft’s topological qubit thing,” Shtetl-Optimized, February 20 2025, quoting the paper’s own text and the Nature editorial note that the results “do not represent evidence for the presence of Majorana zero modes.” scottaaronson.blog. 2 3

  9. Retraction Note, “Quantized Majorana conductance,” Nature 591, E30, 2021 (retracting H. Zhang et al., Nature 556, 74-79, 2018, for insufficient scientific rigor), nature.com. Context, Elizabeth Gibney, “Evidence of elusive Majorana particle dies,” Nature, 2021, nature.com.

  10. Adrian Cho, “Debate erupts around Microsoft’s blockbuster quantum computing claims,” Science, 2025, science.org; Henry F. Legg critique and Microsoft reply, see also arXiv:2503.08944 and the Microsoft reply in Nature, nature.com.

  11. Michele Mosca and Marco Piani, Quantum Threat Timeline Report, Global Risk Institute / evolutionQ, globalriskinstitute.org. 2