up:: For Press

What gets reported wrong

Almost every error in this subject traces to 1 of about 27 recurring mistakes, and most come from blurring 2 things that sound similar and behave completely differently.

None are obscure. They appear in major outlets regularly, and each one is checkable against a published document.

A second class of error is subtler and more common in careful writing: the claim is right and a qualifier got dropped. A projection restated as a measurement, a draft restated as law, and a survey restated as a forecast are each accurate-sounding and each wrong.

The short version:

  • “Quantum breaks all encryption” is the most common error. It breaks a specific, identifiable half.
  • “Encryption is already broken” has no public evidence behind it and discredits everything else in a piece.
  • Leading with a qubit count quotes the least informative number available.
  • “Exponentially faster at everything” overstates it. The general-purpose search speedup is a square root.
  • Quoting a resource estimate as a status report reads a target specification as a description of today’s hardware.
  • Confusing post-quantum cryptography with quantum cryptography mixes up 2 unrelated technologies.
  • Calling every unconventional processor quantum sweeps 3 separate classical architectures into the wrong story.
  • Four qualifiers get dropped routinely: projection, draft, survey, and population scope.
  • Three milestones get reported as one, and years of engineering separate them.
  • Treating it as a U.S. story misses that Australia is 5 years ahead of most peers.

What are the errors of fact?

Easy to writeWhy it’s wrongAccurate version, ready to use
”Quantum computers will break all encryption”Only public-key cryptography breaks”They break key exchange and digital signatures. The encryption that scrambles data, and hashing, survive with larger sizes."
"Encryption is already broken”No public evidence supports it”The method has existed since 1994. The machine to run it does not."
"Experts say it will happen in [year]“Presents 1 opinion as consensus”A survey of 26 specialists put the chance at 28% to 49% within 10 years and 51% to 70% within 15."
"A quantum computer tries every answer at once”Wrong description of the mechanism”It steers many possibilities so the wrong answers cancel out and the right one remains."
"Quantum computers are exponentially faster at everything”The speedup depends on the problem having structure to exploit”The large speedups apply to a short list of structured problems. The general-purpose search speedup is a square root, so a trillion possibilities take about a million steps rather than 1."
"[Company] built an [N]-qubit machine, so Q-Day is closer”Qubit counts alone say little”Headline counts are error-prone physical qubits. Breaking encryption needs stable logical qubits, each built from many physical ones."
"A new record for [component] brings breaking RSA closer”The component barely contributes to what the attack costs”The record is real. The expensive part of the factoring algorithm is the modular arithmetic, and the published resource estimates call the Fourier transform’s cost negligible beside it."
"[Component] got [N]% cheaper, so the attack got [N]% closer”The speedup applies to a case the target is not in”Check which numbers it works for. A shortcut built for moduli shaped like 2ⁿ minus a small number speeds up elliptic-curve arithmetic, and an RSA modulus has no such shape."
"A 1,200-qubit machine breaks elliptic curve, so we’re nearly there”Reads a target specification as a status report. The same confusion runs backwards, printing a machine already shipping as a future milestone”That figure counts stable logical qubits, and the same estimate puts the machine at fewer than 500,000 error-prone physical ones. The largest built so far hold on the order of 1,000."
"AI broke post-quantum encryption”1 experimental candidate was withdrawn, and it was never a standard or in any product”An AI model helped find a flaw in HAWK, a competition candidate. Its authors withdrew it, and the finalized standards were unaffected.” See Did AI just break post-quantum encryption
Calling HAWK a “cipher”A cipher encrypts; HAWK is a signature scheme, which authenticates”HAWK is a post-quantum digital signature scheme. It never encrypted anything.” The most common precision error in the July 2026 coverage
”AI broke AES”The result applies to a deliberately weakened 7-round version”The attack improves on a reduced 7-round variant of AES-128. Full AES-128 uses 10 rounds and is unbroken."
"Quantum encryption will protect us”Confuses 2 unrelated technologies”The fix is post-quantum cryptography, new mathematics running on ordinary computers."
"People should protect themselves by buying [product]“No such consumer product category exists”The fix arrives through updates from the companies running these systems."
"Turning on Advanced Data Protection guards against this”Names an iCloud storage setting that Apple’s own quantum-secure list excludes”Apple lists iMessage, TLS, VPN, SSH, the iPhone-to-Watch connection, and its developer APIs as quantum-secure. Advanced Data Protection is worth turning on for privacy reasons of its own."
"Texting is end-to-end encrypted now, so it’s quantum-safe”Encrypted RCS runs on classical cryptography”RCS encryption uses MLS, whose published ciphersuites are classical, so a recorded text stays readable later. Signal is the messaging option carrying post-quantum protection."
"This is an iPhone story, since Android has no answer”Signal covers both platforms identically”Signal is one app on Android and iPhone and carries the same post-quantum protection on each, free."
"My data is encrypted, so it’s safe”Misplaces where the exposure is”The exposure is in how the keys were agreed rather than how the contents were scrambled."
"Quantum will break Bitcoin mining”Mining runs on the surviving half”Mining is unaffected. The exposure is to signatures, and depends on whether an address has been spent from."
"It’s a 2035 problem”Ignores retroactive exposure”Data collected today is exposed whenever the machine arrives, and migrations of this size take about a decade."
"This is a U.S. issue”Ignores every other jurisdiction”Australia requires an exit from today’s public-key encryption by the end of 2030, 5 years ahead of most peers."
"The grid will go down on Q-Day”Overstates the failure mode”The concern is an attacker forging commands that verify as authentic, which is serious and different from automatic failure."
"Governments haven’t acted”Multiple binding instruments exist”Seven jurisdictions have published dated schedules, and the U.S. has an act of Congress and 3 executive directives."
"The standards aren’t ready yet”They were finalized on August 13, 2024”NIST finalized the first 3 standards in August 2024 and added a fifth algorithm in March 2025."
"Moving from RSA to elliptic curve buys time”Elliptic curve falls to a smaller machine”Elliptic-curve cryptography needs fewer error-corrected qubits to break than RSA at comparable classical strength."
"Forward secrecy protects against this”It addresses a different attack”Forward secrecy protects against later theft of a long-term key. This attack breaks the temporary key exchange itself."
"Quantum key distribution is the solution”It addresses 1 half on dedicated hardware”It addresses key exchange over a dedicated physical link and addresses none of the signature and authentication half."
"Air-gapped systems are unaffected”Only the collection half”Isolation substantially addresses the eavesdropping half. Those systems still verify software updates and credentials using the same mathematics."
"China is behind, it hasn’t published post-quantum standards”Converts opacity into a conclusion”China is running its own standards competition rather than adopting the NIST algorithms. Its program is substantially state-directed and publishes selectively, so the visible record is a floor rather than a measure."
"China is harvesting encrypted data”Asserted and uncorroborated”It has been asserted, including in a June 2026 Foreign Affairs essay, on that article’s own account and uncorroborated. Collection leaves no trace regardless of who does it."
"Quantum computing will transform finance, logistics, and AI”States research directions as settled results”The 2 well-established uses are breaking public-key cryptography and simulating quantum systems such as molecules and materials. The commercial cases in optimization and machine learning remain open research questions."
"[Startup] built a new kind of quantum chip” said of any unconventional processorSweeps separate architectures into one word”Neuromorphic, optical, and probabilistic processors are largely classical machines with different physics. A probabilistic bit fluctuates between 0 and 1 by thermal noise and stays classical, so none of them touches encryption.”

Source: NIST, “Report on Post-Quantum Cryptography,” NISTIR 8105, csrc.nist.gov; NIST, August 13, 2024, nist.gov; Global Risk Institute Quantum Threat Timeline, globalriskinstitute.org; Roetteler, Naehrig, Svore, and Lauter, ASIACRYPT 2017, arxiv.org; L. K. Grover, 1996, arxiv.org; Babbush, Zalcman, Gidney, Broughton, Khattar, Neven, Bergamaschi, Drake, and Boneh, 30 March 2026, quantumai.google; IEEE Spectrum, “IBM’s Condor Quantum Computer Has Over 1,000 Qubits,” spectrum.ieee.org; National Academies of Sciences, Engineering, and Medicine, “Quantum Computing, Progress and Prospects,” 2019, nap.nationalacademies.org; Camsari, Sutton, and Datta, Applied Physics Reviews 6, 011305, 2019, doi.org; Apple, “Quantum-secure cryptography in Apple operating systems,” support.apple.com; R. Barnes et al., “The Messaging Layer Security (MLS) Protocol,” RFC 9420, July 2023, rfc-editor.org; Signal, “Signal Protocol and Post-Quantum Ratchets,” October 2, 2025, signal.org.

Which qualifiers get dropped?

The harder class of error, because the sentence reads as careful and the missing word is what made it true.

The claimThe qualifier that belongs with itWhy it matters
”It’ll cost $7.1 billion”A projection for priority U.S. federal civilian systems, 2025 to 2035, excluding national security systems, which OMB labels as carrying “a high, but expected, level of uncertainty”Without the scope it reads as a measured total for the whole country
”Today’s encryption is banned after 2035”From an initial public draft, so the years are NIST’s stated intent rather than settled ruleThe dates are propagating through procurement anyway, and calling a draft a law is checkably wrong
”There’s a 1 in 3 chance within a decade”A survey of 26 experts reporting a range, rather than a calculated probabilityIt’s expert judgment, and stating it as measurement invites a fair challenge
”60% of people can be identified from DNA databases”Specific to people of European descent in the United States, the population the study measuredGeneralizing it makes the claim false rather than imprecise

Source: OMB, “Report on Post-Quantum Cryptography,” July 2024, OMB report; NIST IR 8547 initial public draft, csrc.nist.gov; Erlich, Shor, Pe’er, and Carmi, Science 362(6415), 2018, science.org.

Every figure in this resource carries its qualifier at Every figure and where it comes from.

Why is “all encryption” the error that matters most?

Because it’s wrong in a way that changes what a reader does with the information.

Encryption does 2 jobs. One scrambles the contents of your data, and that half survives with larger key sizes. The other lets 2 parties who’ve never met agree on a secret and prove who they are, and that half breaks completely.

Writing that all encryption breaks implies everything must be replaced, which is both false and paralyzing. Writing that a specific, identifiable half breaks is accurate and points at the actual work.

The cleanest evidence is the NSA’s own suite: the same CNSA 2.0 advisory that retires RSA and elliptic-curve cryptography for national security systems keeps AES-256 in place as the required symmetric cipher.

Source: NSA, “Announcing the Commercial National Security Algorithm Suite 2.0,” September 2022, nsa.gov.

Why does the qubit-count habit persist?

Because it’s the number in the press release.

Hardware announcements lead with qubit counts because it’s the figure that sounds like progress and is easiest to compare year over year. It’s also close to meaningless on its own. A machine with many error-prone qubits can be less capable than one with fewer stable ones, and breaking real encryption requires stable logical qubits assembled from many physical ones.

The number that actually moved is better: the estimated requirement to break RSA-2048 fell from 20 million noisy qubits in 2019 to under 1 million in 2025. That’s a change in the methods rather than the hardware, and it’s a far more meaningful trend than any single machine’s specification.

Source: C. Gidney and M. Ekerå, Quantum 5, 433, 2021, arxiv.org; C. Gidney, 2025, arxiv.org.

The same trend runs on the elliptic-curve side. A March 2026 whitepaper from Google Quantum AI, the Ethereum Foundation, and Stanford, which is a preprint rather than a peer-reviewed paper, puts breaking a 256-bit elliptic curve at 1,200 to 1,450 logical qubits and fewer than 500,000 physical ones, against roughly 2,330 logical in the 2017 peer-reviewed estimate the field had been using. Both numbers describe a machine nobody has built, and the largest processors today hold on the order of 1,000 error-prone physical qubits.

Source: Ryan Babbush, Adam Zalcman, Craig Gidney, Michael Broughton, Tanuj Khattar, Hartmut Neven (Google Quantum AI), Thiago Bergamaschi, Justin Drake (Ethereum Foundation), Dan Boneh (Stanford), “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations,” 30 March 2026, quantumai.google; Roetteler, Naehrig, Svore, and Lauter, ASIACRYPT 2017, arxiv.org; IEEE Spectrum, spectrum.ieee.org.

What are the 3 milestones reported as one?

The word “advantage” covers 3 separate achievements, and years of engineering sit between them.

  1. A theoretical speedup. An algorithm that beats the best classical method on paper, counting idealized operations. Shor’s algorithm has had one since 1994.
  2. An advantage under realistic assumptions. The same algorithm still wins once error correction, data loading, repeated sampling, and measurement overhead are counted, on hardware that could plausibly be built.
  3. A commercially useful system. A machine that beats the best available classical alternative on a problem someone pays to solve, measured end to end.

A quantum step that runs faster in isolation can still lose the whole race once the classical work of preparing its input and reading its output is counted, and classical methods keep improving while the quantum machine is being built. Describing a level-1 result in the language of level 3 is how a research paper becomes a revolution in a headline.

Breaking public-key cryptography is unusual because it clears all 3 levels at once if the machine ever exists, which is why the security story runs ahead of every other application.

Source: P. W. Shor, SIAM Journal on Computing 26(5), 1997, arxiv.org; National Academies of Sciences, Engineering, and Medicine, “Quantum Computing, Progress and Prospects,” 2019, nap.nationalacademies.org.

Which processors get called quantum without being quantum?

Three architectures turn up in the same coverage, and each one is a separate technology.

Neuromorphic chips imitate the structure of neurons and synapses to run machine-learning workloads at low power.

Optical or photonic processors compute with light. A few are genuinely quantum and many are classical analog machines, so the word photonic settles nothing by itself.

Probabilistic or thermodynamic processors compute with units that fluctuate randomly between 0 and 1 under thermal noise. The peer-reviewed literature calls these p-bits, places them between ordinary bits and qubits, and describes them as classical entities.

The test that separates them is whether a machine holds quantum states in superposition and entanglement long enough to run a quantum algorithm. A p-bit fluctuates; a qubit holds a quantum state. Only the second kind runs Shor’s algorithm, so only the second kind bears on encryption.

Source: Camsari, Sutton, and Datta, “p-bits for probabilistic spin logic,” Applied Physics Reviews 6, 011305, 2019, doi.org.

How do you check a claim about a new machine?

Five questions, and they catch most of what’s wrong.

  1. What problem did it actually solve? Simulating a molecule, sampling a distribution, and factoring a number relevant to real encryption are 3 entirely different achievements. The third has never happened publicly.
  2. Which number are they quoting? Physical qubits, logical qubits, error rate, and coherence time are different claims, and announcements usually quote the most flattering one.
  3. Who verified it? A company blog, a preprint, and an independently reproduced peer-reviewed result are 3 confidence levels.
  4. Real key or toy key? Demonstrations factoring very small numbers recur every few years and get reported as breaks each time. Ask the key size, then compare it against the 2048-bit keys real systems use.
  5. Who benefits from the framing? Hardware companies raise capital on the machine seeming close, and security vendors sell on the threat seeming urgent. Both can be right about the underlying problem while shading the timing.

Which alarming claims are false?

“Your bank account can be emptied.” Reading old encrypted traffic reveals information about a person rather than granting access to their money.

“Quantum computers can already break passwords.” Passwords sit on the surviving half, since well-run services store a one-way fingerprint rather than the password. See Are my passwords at risk.

“There’s a countdown to Q-Day.” Nobody can date it, and a specific countdown is a sales device.

“Governments are ignoring this.” Multiple binding instruments already exist with dated deadlines. See What laws already exist.

“Encryption experts are panicking.” The consensus position is unusually calm, because the fix exists, it’s published, and it needs deploying.

“Every company has to rebuild from scratch.” Most of an estate is a configuration and library change. The expensive minority is equipment whose cryptography can’t be updated.

Which reassuring claims are false?

“Nothing has happened, so it isn’t real.” The collection is invisible by design, so absence of evidence is exactly what this threat looks like. See Will anyone tell me if it happens.

“We’ll adopt the standards when they’re finalized.” They were finalized in August 2024. This is the most checkably wrong sentence a company can give you.

“We use military-grade encryption.” Not a technical term, and it describes the surviving half.

“Our systems are air-gapped.” A claim about network topology that deserves verification rather than acceptance. See What critical infrastructure is exposed.

“It’s decades away.” Possibly, and it doesn’t help, because data collected now is exposed whenever the machine arrives.

“Our cloud provider handles it.” Providers migrate their own infrastructure, and a substantial share of encryption choices sit on the customer side. See What can I not fix myself.

Which errors are specific to one subject area?

BeatThe error that recurs thereThe accurate version
ConsumerTelling readers to buy or install somethingThe consumer action list is short, free, and mostly automatic. See What should I actually do
BusinessQuoting a per-company migration costNo defensible universal figure exists, because cost scales with estate specifics. See What does this cost
Security and technologyTreating hybrid deployment as a settled questionIt’s actively contested, with France and Germany requiring it and the U.S. accepting standalone. See For a security or technology audience
PolicyReporting 2035 as the deadlineIt’s a policy goal with “as is feasible” in the operative sentence. The binding dates land in 2027, 2030, and 2031. See What laws already exist
Any beat covering hardware or startupsReporting a probabilistic, neuromorphic, or optical processor as quantumThose are separate architectures with separate physics, and none of them runs Shor’s algorithm
Any beat covering ChinaReading the absence of published detail as either a lead or a lagChinese labs rarely open hardware for external benchmarking, so the public record understates activity by an unknown amount. An unknown amount is neither large nor small. See What is China doing

Questions people ask

What’s the single correction a cryptographer makes first? That quantum computers break public-key cryptography rather than all encryption.

Is there any claim here that’s genuinely uncertain? The timing, and everyone honest says so. The mathematics, the standards, and the deadlines are settled. When a machine arrives is a range of expert opinion.

How do I describe the threat without overstating it? State what’s happening now, which is collection, and what waits on the machine, which is decryption and forgery. Keeping those 2 separate is most of accuracy in this subject.

What if a source tells me encryption is already broken? Ask what was broken, at what key size, verified by whom, and whether it was independently reproduced. No public break of real-world encryption has occurred.

Is “Q-Day” acceptable to use? Yes, as an informal shorthand, with the note that it’s a capability threshold rather than a dated event. The framing misleads when it implies a single morning on which every vulnerable system fails together. Capability arrives unevenly, whoever reaches it first has every reason to stay quiet, and different key sizes and algorithms fall at different points. See Will anyone tell me if it happens.

Is a quadratic speedup worth caring about? For symmetric encryption and hashing, it’s the manageable half, and larger key and digest sizes address it. A square-root speedup on a 128-bit key still leaves an astronomically large search, which is why the answer there is a bigger key rather than a new algorithm family.

What’s the most checkable claim a company can make wrongly? That the standards aren’t final. They were finalized on August 13, 2024.

Where do I verify a number quickly? Every figure and where it comes from carries each figure with its accurate wording and source, and The primary documents behind every claim indexes the documents themselves.

Where to go next

Go deeper into the technical detail

The technical version, the calibration toolkit for reading a quantum headline, is How Do You Tell Real Quantum Progress From Hype.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-04 · Maintained by Addie LaMarr, LaMarr Labs.