The Quantum Capability Asymmetry
The quantum capability asymmetry is the gap between how many actors can record encrypted traffic today and how few will be able to read it later. Recording is cheap, widely available, and already happening at scale. Reading requires a cryptographically relevant quantum computer, which is a machine nobody has built and which will remain out of reach for almost everyone when the first ones exist.
Those two facts point in opposite directions, and the space between them is where the strategic problem lives. Archives are being accumulated now by a broad set of actors, and they will become readable by a narrow one.
The short version:
- Collection has democratized. Cold storage costs a fraction of a cent per gigabyte per month, which puts bulk retention of recorded ciphertext within reach of well-resourced criminal groups as well as intelligence services. See Store-Now-Decrypt-Later Actor Landscape.
- Decryption will concentrate. Breaking RSA-2048 needs roughly 6,190 logical qubits, and even the most optimized published estimate still calls for hundreds of thousands of error-corrected physical qubits. That’s a national-scale engineering program.
- The imbalance runs through allies too. SIPRI notes that states reaching Q-Day first could read the communications of less advanced states “including their communications with other, advanced states.”
- You cannot verify who holds this capability. Unlike a nuclear program, a quantum computer needs no enrichment plant and produces no detectable test, so possession leaves no signature an adversary or a treaty regime can observe.
- The governance vocabulary is missing. Collection is not an attack under current norms, so nothing is triggered at the moment the harm is created, and the arms-control literature treats quantum as a tool for verification rather than as a capability requiring it.
Think of two curves on the same chart running in opposite directions. One is the cost of recording a conversation you cannot understand, which has fallen for 30 years and keeps falling. The other is the cost of understanding it later, which sits at the price of a machine that does not yet exist. Every year the first curve drops, more actors start recording. The second curve barely moves, and when it finally does, it moves for very few.
Who can harvest encrypted traffic today?
A wider set of actors than the nation-state framing suggests. Intelligence services remain the strongest fit on every axis, because passive bulk collection is an established discipline, the archives already exist, and a foreign ministry’s cables keep their value for decades. But the storage economics that once made bulk harvesting exclusively governmental have largely eroded, and warehousing very large volumes of recorded ciphertext for years is now a modest operating expense.
The collection side still favors actors with privileged network access, though it isn’t a hard wall. Stolen encrypted backups, compromised network appliances, and malicious access at a hosting or transit provider all put ciphertext in an attacker’s hands without a government’s reach.
The full actor-class breakdown, scored on reach, storage, and motive, is in Store-Now-Decrypt-Later Actor Landscape. What matters for the asymmetry is the direction: the number of actors who can plausibly collect has been rising for years, and nothing about the quantum transition reverses it.
Who will actually be able to decrypt it?
Far fewer, and the reason is engineering rather than budget.
The published resource estimates are the measure of what decryption costs, because they describe the machine rather than the spending. For RSA-2048, peer-reviewed work puts the requirement at roughly 6,190 logical qubits in the abstract circuit model, which lays out as a board of about 14,000 logical tiles and about 20 million noisy physical qubits in a 2021 construction and dropping to under a million physical qubits in a 2025 optimization. Elliptic curve is cheaper: a 256-bit curve needs about 2,330 logical qubits in the 2017 analysis, and a 2026 Google Quantum AI whitepaper puts it at 1,200 to 1,450 logical qubits and under 500,000 physical.
Source: Gidney and Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” arXiv:1905.09749; Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” arXiv:2505.15917; Roetteler et al., “Quantum resource estimates for computing elliptic curve discrete logarithms,” arXiv:1706.06752; Google Quantum AI, cryptocurrency whitepaper.
Two things follow from those numbers.
- The requirement is a fleet of error-corrected qubits, not a clever algorithm. Every logical qubit is built from many physical ones running continuous error correction, which is why the physical counts run into the hundreds of thousands even after a decade of optimization. See Quantum Error Correction.
- The trend is downward, and the floor is still high. The RSA-2048 physical estimate fell by more than an order of magnitude between 2021 and 2025, which is genuine progress and still leaves a machine far beyond anything demonstrated.
So decryption capability is gated by an industrial achievement. That gate does not open for a well-resourced criminal group, and it does not open for most states.
Why do the two curves run in opposite directions?
Because collection and decryption are limited by completely different things, and only one of them gets cheaper with time in the way ordinary technology does.
Collection is limited by storage and access. Storage follows the cost curve of commodity hardware, which has fallen relentlessly, and access has broadened as more of the world’s traffic passes through infrastructure that can be compromised or lawfully tapped. Both trends favor more actors over time.
Decryption is limited by error-corrected quantum computing, which is a research frontier rather than a commodity. Its cost falls through scientific breakthroughs at unpredictable intervals rather than through manufacturing scale, and the first machines will belong to whoever funded the frontier.
| Collecting encrypted traffic | Decrypting it later | |
|---|---|---|
| What limits it | Storage cost and network access | Error-corrected quantum computing at scale |
| How the cost falls | Steadily, with commodity hardware | In unpredictable steps, through research breakthroughs |
| Who can do it today | Intelligence services, well-resourced criminal groups, some commercial collectors | Nobody yet |
| Who can do it later | A widening set | A small number of states, plus corporations funding the frontier |
| Trace left at the target | Silent at both endpoints | Silent, and performed entirely on the actor’s own hardware |
| Visible to outsiders | Effectively invisible | Effectively invisible, with no infrastructure footprint to detect |
| Timing | Present tense and continuous | Deferred, and dated by nobody credibly |
The result is a capability profile with an unusual shape. Most intelligence capabilities are expensive at the moment of use, so cost restrains who acts and when. Here the acting is cheap and available to many right now, and the payoff is expensive and available to few much later. The archives accumulating today are assets whose redemption rights belong to a different, smaller group than the one building them.
Why does this reach states that never harvested anything?
Because the exposure comes from being recorded, and any state whose traffic crosses infrastructure it does not control is recordable regardless of what it does.
SIPRI puts the consequence directly: the uneven pace of quantum progress “raises the prospect of intelligence imbalances, where states that reach Q-day earlier than others could gain covert access to the sensitive communications of less advanced states, including their communications with other, advanced states.”
That final clause is the part usually missed. A country’s cables to its allies sit in the same archives, so a first mover reads the weaker state’s internal traffic and its diplomatic exchanges with everyone else. Migration by the advanced partner does not retroactively protect what was already recorded on the weaker end of the link.
SIPRI also names who carries this exposure: “Many developing countries rely on standard encryption to secure government, financial, healthcare, energy and other critical infrastructure systems.” It hedges what follows, and the hedge is worth keeping: without timely updates to quantum-resilient protections those systems “may become more vulnerable to interception or exploitation by technologically advanced actors,” which raises concerns about “a new form of digital asymmetry in the international system.”
Source: SIPRI, Military and Security Dimensions of Quantum Technologies: A Primer, July 2025, PDF.
Who actually has the capacity to migrate, and what is genuinely scarce, is covered in What happens to countries that cannot afford this.
Why can’t anyone verify who holds this capability?
This is the part with no precedent, and it’s the reason the asymmetry resists the usual remedies.
Every strategic capability that arms control has successfully addressed left physical evidence. A nuclear weapons program needs enrichment or reprocessing facilities, distinctive supply chains, and historically a test that seismometers around the world can hear. Verification regimes exist because there is something observable to verify.
A quantum computer has none of that. SIPRI makes the point in the course of explaining why progress will be uneven: “Unlike nuclear or space technologies, quantum systems do not necessarily require large-scale physical infrastructure and may advance asymmetrically across states.”
Three consequences follow.
- Possession is unobservable. No treaty regime can count machines it cannot detect, and no state can be confident about which of its rivals has crossed the threshold.
- Use is also unobservable. Reading an archive happens entirely on the reader’s own hardware, so it generates nothing at either endpoint that could be logged or noticed. The absence of any warning is structural rather than a monitoring shortfall.
- Attribution fails in both directions. Demonstrating absence is impossible, and so is demonstrating use, so the reassurance mechanisms that stabilize other domains have nothing to attach to.
Why doesn’t the governance conversation cover this?
Two gaps, and each is documented rather than inferred.
Collection is not an attack. The norms of responsible state behavior in cyberspace are written around damage: interference with critical infrastructure, harm to emergency response, attacks on the technical operation of the internet. Passive recording of encrypted traffic damages nothing at the moment it happens, so it triggers no formulation and no response. The harm arrives years later, at decryption, by which point the collection is historical and unattributable.
The arms-control literature treats quantum as an instrument rather than as an object. SIPRI’s own section on arms control, verification, and confidence-building is devoted to how quantum sensing might improve verification of other regimes, proposing quantum gravimeters and magnetometers for detecting clandestine nuclear tests and quantum links for securing treaty data exchanges. It contains no mechanism for verifying quantum computing capability itself. The same report identifies the institutional shortfall plainly: “there is currently a lack of dedicated institutions that focus on assessing quantum’s impact on peace and security,” and “existing ethical and societal initiatives rarely address arms control, deterrence or dual-use risks.”
Source: SIPRI, Military and Security Dimensions of Quantum Technologies: A Primer, July 2025, PDF; Malekos Smith and Persi Paoli, Quantum Technology, Peace and Security: A Primer, UNIDIR, Geneva, 2024.
The practical result is that the one measure available to a state on the weak side of the asymmetry is unilateral: migrate its own systems, and shrink the window during which its traffic is worth recording. There is no verification regime to join and no norm to invoke.
Common misconceptions
- “Only nation-states can harvest.” The storage cost that once made bulk retention governmental has collapsed, and the actor pool for opportunistic and targeted collection is wider than the nation-state framing implies.
- “Only nation-states will be able to decrypt.” Probably true, and it’s a conclusion from resource estimates rather than an assumption. Corporations funding frontier quantum research are also plausible holders, which is a different distribution from the nuclear case.
- “Migrating now protects data already collected.” It protects everything recorded from the migration onward. Traffic already in an archive stays exactly as readable as the day it was captured.
- “An early mover only reads its adversaries.” Archives are indiscriminate. A state’s exchanges with allies sit in the same collection, so the exposure follows the weakest endpoint on any link.
- “Arms control will handle this.” No verification mechanism exists for quantum computing capability, and the arms-control work on quantum is about using quantum sensing to verify other treaties.
- “This is a future problem.” The collection is present tense. Only the decryption is deferred.
Questions people ask
Which countries will get a cryptographically relevant quantum computer first? No published source can answer that honestly, and the resource estimates are the reason: the requirement is hundreds of thousands of error-corrected physical qubits, which nobody has demonstrated, so any ranking is a projection rather than an observation. What the estimates do establish is that the threshold is high enough to exclude most actors.
Is harvesting illegal under international law? International law leaves peacetime intelligence collection unregulated by any general rule, and the cyber norms formulations are built around damage rather than around recording, which is why passive collection sits outside the frameworks that would otherwise apply.
How is this different from ordinary espionage? Ordinary espionage requires you to be capable at the moment you act. Harvest-now-decrypt-later separates the act from the capability by years or decades, so an actor can build an archive long before knowing whether it will ever be readable, and at almost no cost for being wrong.
Can a country tell whether its traffic has been harvested? No. Passive collection leaves no trace on the sender or the receiver, which is what makes it structurally different from an intrusion. See The No-Warning Problem.
Does quantum key distribution solve the asymmetry? It addresses future key exchange over specialized links and does nothing for archives already recorded, and it requires infrastructure that the states most exposed here are least able to deploy. See Quantum Key Distribution (QKD).
If decryption is so expensive, why worry now? Because the cost that matters today is the cost of collection, which is already low, and because data recorded now stays recorded. The question for any given dataset is whether it will still be sensitive when the machine arrives, which is what Mosca’s inequality formalizes.
Could a smaller state leapfrog? SIPRI’s point that quantum needs no large-scale physical infrastructure cuts both ways. It means progress is harder to monitor, and it means the field is less predictable than nuclear, so the set of eventual holders is genuinely uncertain rather than obviously fixed.
What can a state on the weak side of this actually do? Migrate its own systems, which shrinks the window during which its traffic is worth recording, and press for capacity-building support. SIPRI suggests multilateral funding for post-quantum upgrades and technical assistance for system audits as the constructive international role.
The map is free and I keep it that way. When this asymmetry has to be turned into a defensible position for a specific institution and the data it holds, that’s the work I do at LaMarr Labs.
Go deeper
- Store-Now-Decrypt-Later Actor Landscape for who is collecting
- Harvest Now, Decrypt Later (HNDL) for the underlying threat model
- What happens to countries that cannot afford this for the capacity side
- The No-Warning Problem for why none of this announces itself
- Cryptographically Relevant Quantum Computer (CRQC) for what the machine has to be
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.