VOIDEXJournal

Q-Day in 2026: How New Research Moved the Quantum Threat Closer

Q-Day is when quantum computers break today's encryption. Research in 2025 and 2026 cut the estimates sharply. What changed, and what it means for you.

By the VOIDEX team · 8 min read · 2026-09-29
Q-Day in 2026: How New Research Moved the Quantum Threat Closer

For years, "Q-Day" sounded like a plot device: the moment a quantum computer becomes powerful enough to break the public-key encryption protecting banking, messaging and most of the internet. It was always coming, but always comfortably far away.

Between May 2025 and March 2026, that comfort eroded. A run of research papers cut the estimated size of a code-breaking quantum computer by an order of magnitude and more. None of them announced that Q-Day had arrived. Together, they changed how serious people talk about when it might.

This article walks through what changed, what the caveats are, and what it means for the messages you send today. It also explains why VOIDEX treats the question as already settled for private conversations.

What Q-Day actually means

Q-Day is shorthand for the arrival of a cryptographically relevant quantum computer: a machine large and reliable enough to run Shor's algorithm against real-world key sizes. Shor's algorithm, published in 1994, can efficiently solve integer factoring (which breaks RSA) and discrete logarithms (which break elliptic-curve cryptography, including the curves used by most messengers, TLS and cryptocurrencies).

The obstacle has always been engineering. Quantum bits are fragile. They lose their state in fractions of a second and pick up errors constantly. To run a long algorithm, you need error correction: many noisy physical qubits working together to behave as one reliable logical qubit. The central question for Q-Day is therefore how many physical qubits, at what error rate, for how long.

The 2019 baseline: 20 million qubits

In 2019, Craig Gidney and Martin Ekerå published what became the standard reference estimate. They calculated that factoring a 2048-bit RSA key would take about 20 million noisy qubits running for roughly eight hours. At the time, the largest quantum processors had around fifty to a hundred qubits. The gap looked enormous, and for good reason.

May 2025: under a million

In May 2025, Gidney, at Google Quantum AI, published a revised estimate: RSA-2048 could be factored with fewer than one million noisy qubits in under a week. The improvement came from better algorithms and denser ways of storing error-corrected data, not from new hardware.

The trade was deliberate: fewer qubits, more time. A week-long computation is slower than eight hours, but a machine a twentieth of the size is a very different engineering target. Gidney was careful to note that the assumptions about physical error rates and hardware behaviour still had to be met.

February 2026: Iceberg Quantum's Pinnacle

In February 2026, the company Iceberg Quantum described an architecture it called Pinnacle, claiming RSA-2048 could be broken with fewer than 100,000 physical qubits by using quantum low-density parity-check (QLDPC) codes. These codes can protect logical qubits with far less overhead than the surface codes assumed in earlier estimates.

The caveat is important. This was a design analysed in simulation, not a machine that exists. QLDPC codes also demand qubit connectivity that is much harder to build than the neighbour-to-neighbour layouts of today's leading chips. It is a credible direction, not a delivered result.

March 2026: elliptic curves in minutes

In March 2026, Google Quantum AI published work on the 256-bit elliptic curve discrete logarithm problem, the maths behind the curves used by Bitcoin and Ethereum and closely related to the curves in modern messaging. The estimate: fewer than 500,000 physical qubits, with a runtime measured in minutes.

Google took an unusual step. It withheld the actual circuits, judging them too sensitive to publish, and instead released a zero-knowledge proof that allows others to verify the claimed resource counts without seeing the method. That choice is itself a signal of how seriously the researchers regard the result.

Runtime in minutes matters. An attack that takes a week is suited to harvesting stored data. An attack that takes minutes starts to threaten live systems, such as a cryptocurrency transaction waiting to be confirmed. The Quantum Insider has a useful summary of all three papers.

Meanwhile, the hardware kept moving

Algorithms only matter if hardware can eventually run them. In December 2024, Google announced its Willow chip, a 105-qubit processor that demonstrated error correction below the surface-code threshold. In plain terms: as Google made its logical qubits larger, the error rate went down instead of up. That is the property error correction needs to scale, and it had been a long-standing milestone.

Willow does not break anything. It is orders of magnitude too small. But it answered a question that sceptics had been asking for years: can error correction actually improve as you scale it? For the first time, a real chip said yes.

The careful reading

It would be easy to turn these results into a headline announcing that encryption is about to fall. That would be wrong, and the researchers themselves would object. A fair reading includes these caveats:

  • No machine exists that can run any of these attacks. The largest processors today are measured in hundreds or low thousands of physical qubits, not hundreds of thousands.
  • Resource estimates depend on assumptions about error rates, connectivity and control that current hardware does not fully meet.
  • Simulation is not construction. Architectures like Pinnacle still have to be built and to behave as modelled.
  • Nobody knows the date. Credible experts disagree by a decade or more.

What the research does establish is direction. Every major estimate in the last seven years has moved downward, often sharply, and mostly through better ideas rather than bigger budgets. Ideas can arrive suddenly. That asymmetry is why prudent planning assumes Q-Day could come earlier than the median guess.

What the institutions concluded

Governments reached their conclusion before the 2026 papers. NIST finalised its post-quantum standards, FIPS 203, 204 and 205, in August 2024. Its draft transition guidance, NIST IR 8547, proposes deprecating quantum-vulnerable RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035. The NSA's CNSA 2.0 guidance expects new national security systems to be quantum-safe by January 2027.

Those timelines were set with uncertainty in mind. The recent research makes them look sensible rather than cautious. We cover the full calendar in PQC deadlines: 2030 and 2035.

What Q-Day means for your messages

For private conversations, the real deadline is not Q-Day. It is today.

The reason is harvest now, decrypt later. An adversary does not need a quantum computer to record your encrypted traffic. They only need one on the day they decide to read it. Any message whose key exchange depended solely on elliptic curves becomes readable on Q-Day, however long ago it was sent. If that message needs to stay private for ten or twenty years, the useful question is not "when is Q-Day?" but "is it plausibly within the lifetime of this secret?" After 2025 and 2026, for most personal and business secrets, the honest answer is yes. We go deeper in Harvest Now, Decrypt Later.

Two practical conclusions follow:

  1. Conversations that matter should already use post-quantum key agreement. There is no way to add it to a message after it has been recorded.
  2. Data you publish is a separate question. Encryption only protects what is meant to be private. Public posts are public before and after Q-Day.

How VOIDEX is built for the Q-Day era

VOIDEX made the decision early that private messaging should not wait for a date nobody can predict.

In VOIDEX Messenger, every direct conversation begins with a hybrid key agreement combining classical X25519 and post-quantum ML-KEM-768, in a PQXDH-style handshake. A future quantum computer that breaks X25519 still faces ML-KEM-768. The conversation then continues on a double ratchet with post-quantum re-keying, so each message has its own key, delivering forward secrecy and post-compromise security. Device identities are signed with hybrid Ed25519 plus ML-DSA-65.

Groups and private VOIDEX Channels use MLS, the IETF standard RFC 9420. Every device key change is recorded in a public, append-only key transparency log whose tree heads are signed with Ed25519 and ML-DSA-65, so even the log's signatures are not purely classical.

This is not a claim that VOIDEX cannot be broken. No honest security team says that. It is a design built on standardised algorithms, published as open source, and documented in a public security report, so that anyone can check it rather than take it on trust. We explain the reasoning behind pairing old and new algorithms in Why hybrid post-quantum encryption wins.

The bottom line

Q-Day has no date. What it now has is a smaller target. In seven years the estimated cost of breaking RSA-2048 fell from twenty million qubits to under one million, with serious proposals below one hundred thousand, and elliptic curves came within minutes of runtime on paper. The machines do not exist yet. The case for waiting no longer does either.

VOIDEX is invite-only and free. Request your invitation, or read how VOIDEX protects your messages before you decide.

Sources

  • Gidney, C. and Ekerå, M. "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits" (2019): https://arxiv.org/abs/1905.09749
  • Gidney, C. "How to factor 2048 bit RSA integers with less than a million noisy qubits" (May 2025): https://arxiv.org/abs/2505.15917
  • The Quantum Insider, "Q-Day just got closer: three papers in three months are rewriting the quantum threat timeline" (31 March 2026): https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
  • Google, "Meet Willow, our state-of-the-art quantum chip" (December 2024): https://blog.google/technology/research/google-willow-quantum-chip/
  • NIST Post-Quantum Cryptography Standardization: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
  • NIST IR 8547 (initial public draft, November 2024): https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  • RFC 9420, The Messaging Layer Security Protocol: https://www.rfc-editor.org/rfc/rfc9420

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps