{"work":{"id":"bd1d7c03-8dbc-468f-979f-49215d18eb4c","openalex_id":"https://openalex.org/W4416445983","doi":"10.48550/arxiv.2505.15917","arxiv_id":"2505.15917","raw_key":null,"title":"How to factor 2048 bit RSA integers with less than a million noisy qubits","authors":null,"authors_text":"Craig Gidney","year":2025,"venue":"quant-ph","abstract":"Planning the transition to quantum-safe cryptosystems requires understanding the cost of quantum attacks on vulnerable cryptosystems. In Gidney+Eker{\\aa} 2019, I co-published an estimate stating that 2048 bit RSA integers could be factored in eight hours by a quantum computer with 20 million noisy qubits. In this paper, I substantially reduce the number of qubits required. I estimate that a 2048 bit RSA integer could be factored in less than a week by a quantum computer with less than a million noisy qubits. I make the same assumptions as in 2019: a square grid of qubits with nearest neighbor connections, a uniform gate error rate of $0.1\\%$, a surface code cycle time of 1 microsecond, and a control system reaction time of $10$ microseconds.\n  The qubit count reduction comes mainly from using approximate residue arithmetic (Chevignard+Fouque+Schrottenloher 2024), from storing idle logical qubits with yoked surface codes (Gidney+Newman+Brooks+Jones 2023), and from allocating less space to magic state distillation by using magic state cultivation (Gidney+Shutty+Jones 2024). The longer runtime is mainly due to performing more Toffoli gates and using fewer magic state factories compared to Gidney+Eker{\\aa} 2019. That said, I reduce the Toffoli count by over 100x compared to Chevignard+Fouque+Schrottenloher 2024.","external_url":"https://arxiv.org/abs/2505.15917","cited_by_count":3,"metadata_source":"pith","metadata_fetched_at":"2026-08-05T02:28:24.338817+00:00","pith_arxiv_id":"2505.15917","created_at":"2026-05-09T03:06:06.370035+00:00","updated_at":"2026-08-05T02:28:24.338817+00:00","title_quality_ok":true,"display_title":"How to factor 2048 bit RSA integers with less than a million noisy qubits","render_title":"How to factor 2048 bit RSA integers with less than a million noisy qubits"},"hub":{"state":{"work_id":"bd1d7c03-8dbc-468f-979f-49215d18eb4c","tier":"hub","tier_reason":"10+ Pith inbound or 1,000+ external citations","pith_inbound_count":66,"external_cited_by_count":3,"distinct_field_count":4,"first_pith_cited_at":"2024-06-13T17:20:49+00:00","last_pith_cited_at":"2026-07-02T08:38:27+00:00","author_build_status":"not_needed","summary_status":"needed","contexts_status":"needed","graph_status":"needed","ask_index_status":"not_needed","reader_status":"not_needed","recognition_status":"not_needed","updated_at":"2026-08-21T11:29:34.829712+00:00","tier_text":"hub"},"tier":"hub","role_counts":[{"context_role":"background","n":19},{"context_role":"baseline","n":2},{"context_role":"method","n":1}],"polarity_counts":[{"context_polarity":"background","n":18},{"context_polarity":"baseline","n":2},{"context_polarity":"support","n":1},{"context_polarity":"use_method","n":1}],"runs":{},"summary":{},"graph":{},"authors":[]}}