Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

New Google Research Shows RSA 2048 Could Be Broken Sooner Than Expected

New Google Research Shows RSA 2048 Could Be Broken Sooner Than Expected

Quick answer: Yes. New Google Quantum AI research shows that a future quantum computer with roughly 1 million noisy qubits and advanced error correction could break 2048-bit RSA in about one week, a twentyfold reduction from the 2019 estimate of roughly 20 million qubits. It matters because this reduction came entirely from algorithmic and error-correction improvements, not new hardware, meaning the timeline for a viable quantum attack keeps shrinking even without a hardware breakthrough. The recommended action is to treat NIST’s 2030 deprecation and 2035 disallowance deadlines for RSA and ECC as firm planning inputs, and begin migrating to finalized post-quantum standards (ML-KEM, ML-DSA) now rather than waiting for the timeline to stabilize.

Key Takeaways

  • Google’s new estimate for breaking RSA-2048 is roughly 1 million qubits, a twentyfold reduction from the 2019 estimate of 20 million, driven by better algorithms and error correction rather than new hardware.
  • The reduction came from two sources: advances in approximate modular exponentiation that cut the qubits needed for factoring, and improved error-correction techniques like a second-layer approach and “magic state cultivation.”
  • Harvest-now-decrypt-later attacks mean data encrypted with RSA or ECC today is already at risk if it must stay confidential long enough for a capable quantum computer to emerge.
  • NIST’s draft guidelines call for deprecating vulnerable public-key cryptosystems by 2030 and fully disallowing them by 2035.
  • FIPS 203 (ML-KEM, based on CRYSTALS-Kyber) and FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium) are the finalized post-quantum standards organizations should be migrating toward now.

Google Sharpens the RSA Timeline

Google Quantum AI has just published a new paper that sharpens the timeline for the end of RSA 2048. The researchers announced that a future quantum computer with roughly 1 million qubits and advanced error correction could break 2048-bit RSA in about one week, a significant shift from earlier estimates.

A Quantum Breakthrough with Implications

For years, the timeline for when RSA and other classical encryption methods might fail has been measured in decades. In 2019, the estimate was roughly 20 million qubits, making a quantum attack feel like a long-off threat. Today, thanks to advances in both algorithms and error correction, that estimate has shrunk to roughly 1 million qubits, a 20-fold reduction.

Here’s how this happened:

  • Better Algorithms: New advances in approximate modular exponentiation drastically reduce the number of qubits required for factoring.
  • Improved Error Correction: New error-correcting techniques, like a second-layer approach and “magic state cultivation,” sharply reduce the required overhead for calculations.

This shift is making the quantum threat to RSA far more concrete and closer than many anticipated.

CBOM Secure

Gain complete visibility with continuous cryptographic discovery, automated inventory, and data-driven PQC remediation.

What This Means for Encryption Today

RSA and elliptic curve encryption form the foundation of internet trust. They protect everything from HTTPS traffic to digital signatures that validate software and devices. As this new paper from Google Quantum AI highlights, the risk of “harvest now, decrypt later” attacks is no longer theoretical. Sensitive data captured today could be decrypted by a future quantum computer if not properly protected.

NIST’s Timelines for Action

Recognizing the growing threat, NIST has issued draft guidelines that lay out a concrete timeline:

  • By 2030: Vulnerable public key cryptosystems should be deprecated.
  • By 2035: Vulnerable systems must be completely disallowed.

These milestones aren’t arbitrary. They underscore the urgency for organizations to assess their cryptographic posture and move toward post-quantum cryptographic (PQC) standards like FIPS 203 (ML-KEM, based on CRYSTALS-Kyber) and FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium).

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

How Encryption Consulting Can Help?

At Encryption Consulting, we help organizations stay ahead of these milestones with expert PQC Advisory Services. Our team works closely with you to:

  • Assess your quantum threat exposure and inventory cryptographic assets.
  • Build a tailored roadmap for PQC migration aligned with NIST and CISA standards.
  • Identify and implement the right post-quantum algorithms (FIPS-203, FIPS-204, FIPS-205, FIPS-206).
  • Perform gap analyses and proof-of-concept trials for PQC deployments.
  • Minimize disruption while ensuring long-term protection against quantum threats.

With the timeline for viable quantum attacks drawing closer, the shift from traditional encryption to PQC isn’t a question of “if” anymore, it’s a question of “when” and “how soon.”

Conclusion

Google’s research does not mean a quantum computer capable of breaking RSA exists today. It means the resource bar for building one keeps dropping through algorithmic refinement alone, and that trend has been consistent for years. Organizations that treat the current gap between theory and practice as a reason to wait are betting against a pattern that has repeatedly proven wrong.

The practical response is not alarm but planning: know where RSA and ECC are still in use, understand which data has a confidentiality window long enough to be exposed to harvest-now-decrypt-later attacks, and begin migrating to finalized post-quantum standards well before NIST’s 2030 and 2035 deadlines force the issue.

Read More: https://security.googleblog.com/2025/05/tracking-cost-of-quantum-factori.html

Frequently Asked Questions

How many qubits would it take to break RSA-2048, according to Google’s latest research?

Roughly 1 million noisy qubits with advanced error correction, enough to factor a 2048-bit RSA key in about one week. This is a twentyfold reduction from the 2019 estimate of approximately 20 million qubits.

Did this reduction come from a new quantum computer breakthrough?

No. It came from two algorithmic and theoretical advances: better approximate modular exponentiation techniques that reduce the qubits needed for factoring, and improved error-correction methods, including a second-layer approach and “magic state cultivation,” that cut computational overhead. No new quantum hardware was required.

Does this mean RSA-2048 can be broken today?

No. A quantum computer with anywhere near 1 million stable, error-corrected qubits does not exist yet. The finding matters because it shows the resource bar keeps falling through algorithmic improvement alone, which shortens the effective planning horizon even without new hardware.

What is “harvest now, decrypt later,” and why does it matter here?

It is the practice of adversaries intercepting and storing encrypted data today, intending to decrypt it once a capable quantum computer exists. As the qubit requirement for breaking RSA keeps shrinking, data with a long confidentiality window is increasingly at risk from this kind of attack, even though no quantum computer can decrypt it yet.

What are NIST’s deadlines for moving off RSA and ECC?

NIST’s draft guidelines call for deprecating vulnerable public-key cryptosystems like RSA and ECC by 2030, with full disallowance by 2035. Organizations should treat these as concrete milestones for planning their post-quantum migration.

Which post-quantum standards should organizations migrate to?

FIPS 203 (ML-KEM, based on CRYSTALS-Kyber) for key exchange and FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium) for digital signatures are the primary finalized standards. SLH-DSA (FIPS 205) is available as a conservative hash-based signature backup.