VOIDEXJournal

Quantum Computing in 2026: Where It Stands and What It Means

Quantum computing in 2026 explained for smart readers: qubits, error correction, Google Willow, new resource estimates, and what it means for encryption.

By the VOIDEX team · 8 min read · 2026-09-29
Quantum Computing in 2026: Where It Stands and What It Means

Few technologies attract as much excitement and as much confusion as quantum computing. Headlines swing between "it is decades away" and "it will break the internet next year". Neither is quite right. In 2026 the field is making real, measurable progress, and the most important numbers for anyone who cares about encryption have moved sharply in one direction.

This is a clear-eyed guide to where things stand, written for readers who want the substance without the physics degree. At the end we explain why VOIDEX chose to be post-quantum from the start, rather than waiting to see how the story ends.

What a qubit actually is

A classical computer stores information in bits, each either 0 or 1. A quantum computer uses qubits, which can exist in a superposition of 0 and 1 and can be entangled with each other, so that the state of one is linked to the state of others. A useful way to think of it: a quantum computer does not try every answer at once, as popular articles sometimes claim. Instead, a well-designed quantum algorithm arranges for the wrong answers to cancel out and the right answer to become likely when the machine is measured.

That trick only works for certain problems. Quantum computers are not faster general-purpose computers. They will not speed up your spreadsheet. But for a handful of mathematical problems, including the ones that protect most of today's internet, the advantage could be enormous.

The problem with qubits: noise

The catch is that qubits are extraordinarily fragile. Heat, stray electromagnetic fields and tiny imperfections in control signals all disturb them. Every operation introduces a small chance of error, and those errors accumulate quickly. A long computation on raw, noisy qubits simply collapses into nonsense.

This is why the raw number of qubits on a chip says less than it seems. What matters is how reliable they are, and whether errors can be corrected faster than they appear.

Error correction and logical qubits

Quantum error correction spreads the information of one reliable qubit across many physical qubits. The group is called a logical qubit. By constantly checking the physical qubits for signs of error, without directly measuring the information they protect, the system can detect and fix mistakes as the computation runs.

There is a threshold at the heart of this idea. If the physical qubits are good enough, adding more of them to a logical qubit makes it more reliable. If they are not good enough, adding more makes things worse, because each extra qubit brings its own errors. For decades, crossing that threshold convincingly was one of the central goals of the field.

Google Willow: below threshold

In December 2024 Google Quantum AI announced Willow, a 105-qubit superconducting chip. The significant result was not the qubit count. It was that Google showed error rates falling as it scaled up the error-correcting code, operating below the surface-code threshold. Put simply, bigger logical qubits became better logical qubits, which is the behaviour a large, fault-tolerant machine needs.

Google also reported a benchmark task that Willow completed in under five minutes and estimated would take a leading classical supercomputer an astronomically long time. Benchmarks like this are designed to show quantum advantage on a specific, contrived problem, and they do not by themselves threaten encryption. The error correction result is the one that matters for cryptography, because it is a step on the road to machines that can run long, useful algorithms.

The resource estimates that changed the conversation

The question everyone in security asks is simple: how large does a quantum computer need to be to break the encryption we use today? Between 2025 and 2026, three pieces of research moved that answer significantly.

Gidney, May 2025

In May 2025 Craig Gidney of Google Quantum AI published an estimate that RSA-2048, the kind of public-key encryption that has protected web traffic and digital signatures for decades, could be factored in under a week by a machine with fewer than one million noisy qubits. His 2019 estimate, written with Martin Ekerå, had been around 20 million. The machine required had shrunk roughly twentyfold in six years, driven by better algorithms and better error correction techniques rather than new hardware.

Iceberg Quantum, February 2026

In February 2026 Iceberg Quantum published an architecture it calls Pinnacle, suggesting RSA-2048 could be broken with fewer than 100,000 physical qubits by using quantum low-density parity-check (QLDPC) codes, a more efficient family of error-correcting codes. This is a simulation and a design, not a machine that exists. It is still a meaningful signal about where the engineering could go.

Google, March 2026

In March 2026 Google Quantum AI reported that the 256-bit elliptic curve discrete logarithm problem, the mathematics behind the signatures used by Bitcoin and Ethereum and by many modern key exchanges, could be solved with fewer than 500,000 physical qubits in a matter of minutes. Unusually, Google withheld the detailed circuits and instead published a zero-knowledge proof that its result is correct, a sign that the researchers considered the details sensitive. The Quantum Insider summarises all three papers.

The caveats that matter

It is important to read these results carefully, because overstatement is its own kind of misinformation.

  • No one has broken RSA-2048 or 256-bit elliptic curve cryptography. These are estimates of what a future machine would need, not demonstrations.
  • Physical qubits are not the whole story. The estimates assume specific error rates, connectivity and speeds. Real machines must meet all of them at once, at scale, for long periods.
  • Building a machine with hundreds of thousands of high-quality qubits is a formidable engineering challenge. Nobody has one today.
  • Timelines remain genuinely uncertain. Serious people disagree about when a cryptographically relevant quantum computer, the machine sometimes associated with "Q-Day", will exist. We look at the arguments in Q-Day 2026.

Yet the direction is unmistakable. Each new estimate has been smaller than the last, and progress in algorithms and error correction has repeatedly outpaced expectations.

What this means for encryption

The encryption that protects most of the internet relies on two families of mathematics: factoring large numbers (RSA) and discrete logarithms, including on elliptic curves. A large, fault-tolerant quantum computer running Shor's algorithm could solve both. Symmetric encryption such as AES is far less affected; larger keys are enough.

There are two reasons this matters now, even if Q-Day is years away.

The first is harvest now, decrypt later. Traffic recorded today can be stored and decrypted once a capable machine exists. Anything that must stay secret for longer than the time until Q-Day is already at risk.

The second is that governments have set deadlines. NIST finalized its first post-quantum standards on 13 August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). In March 2025 it selected HQC as a backup key encapsulation mechanism. NIST's draft transition plan proposes deprecating quantum-vulnerable RSA and elliptic curve algorithms after 2030 and disallowing them after 2035. Our guide to the 2030 and 2035 deadlines covers the details.

Major messaging platforms have responded. Signal adopted post-quantum key agreement in 2023 and added a post-quantum ratchet in 2025, and Apple introduced its PQ3 protocol for iMessage in 2024. The industry has accepted that the migration has to start before the threat arrives.

Why VOIDEX is already post-quantum

VOIDEX made post-quantum protection part of its foundation rather than an upgrade. Direct messages in VOIDEX Messenger begin with a hybrid key agreement that combines the classical X25519 with ML-KEM-768, the NIST standard. The hybrid design means an attacker would have to break both: the well-studied classical algorithm and the new post-quantum one. If either holds, the conversation holds.

After that first exchange, a double ratchet with post-quantum re-keying gives each message its own key. That provides forward secrecy, so an old key cannot unlock new messages, and post-compromise security, so a conversation can heal after a device compromise. Identity signatures pair Ed25519 with ML-DSA-65, and the tree heads of VOIDEX's public key transparency log are signed the same way.

Groups and private channels use MLS, the IETF standard for group encryption. Keys are created on members' devices, and VOIDEX's servers store only public keys and ciphertext. The cryptographic core is open source, and the VOIDEX security report explains every piece. For a deeper look at the algorithm itself, read ML-KEM-768 explained.

The logic is simple. If you cannot know exactly when a quantum computer will arrive, the only safe time to protect today's conversations is today.

The bottom line

Quantum computing in 2026 is not a finished technology, and it is not science fiction either. Error correction now works in the way it must for large machines to be possible. The estimated size of a code-breaking computer has fallen from tens of millions of qubits to hundreds of thousands in a few years. Nobody can say precisely when the crossover will come, and that uncertainty is exactly why the careful choice is to move now.

VOIDEX is invite-only and post-quantum by design. Ask for an invitation, or read the full VOIDEX security report.

Sources

  • Google, Meet Willow, our state-of-the-art quantum chip (December 2024): https://blog.google/technology/research/google-willow-quantum-chip/
  • Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits (May 2025): https://arxiv.org/abs/2505.15917
  • The Quantum Insider, Q-Day just got closer: three papers in three months (March 2026): https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline/
  • NIST, Post-Quantum Cryptography Standardization: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
  • NIST IR 8547 (initial public draft, November 2024): https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  • Signal, SPQR and the Triple Ratchet (October 2025): https://signal.org/blog/spqr/
  • Apple Security Research, iMessage with PQ3 (February 2024): https://security.apple.com/blog/imessage-pq3/

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps