will quantum computers break encryption can quantum computers break AES 256 can quantum computers break RSA

Will quantum computers break encryption? What's at risk

Adrian Maverick · · 10 min read

Search this question and you will find a 2019 headline saying "not for decades" next to a 2024 one saying it already happened. Both are wrong, and the true answer is more useful than either.

Will quantum computers break encryption?

Some of it. A large, error-corrected quantum computer would break the public-key encryption used to agree on keys and sign things: RSA, Diffie-Hellman and elliptic curves. It would not break well-built symmetric encryption like AES-256 or hashes like SHA-256. No machine that can do this exists as of October 2026, and the replacements are already standardized.

So "encryption" is the wrong unit. Almost everything you use combines two kinds of lock, and only one kind is in trouble. Once you can tell them apart, you can sort your own accounts and devices in a few minutes. That is what the rest of this page is for.

Which encryption will quantum computers break?

Kind of lock Examples Best known quantum attack Verdict
Public-key key agreement RSA, Diffie-Hellman, ECDH, X25519 Shor's algorithm Broken by a large enough machine
Public-key signatures RSA, ECDSA, Ed25519 Shor's algorithm Forgeable by a large enough machine
Symmetric ciphers AES-256, ChaCha20 Grover's algorithm Holds
Hash functions SHA-256, SHA-3 Grover's algorithm Holds
Post-quantum public-key ML-KEM, ML-DSA, SLH-DSA None known that is efficient Designed to hold

The two attacks are not close to equal. Shor's algorithm, published in 1994, solves the exact math problems that RSA and elliptic curves depend on, and it does so exponentially faster than any known classical method. Making the key longer does not save you in any practical way.

Grover's algorithm is a general search speedup. It turns a search through N possibilities into roughly the square root of N steps. That sounds dramatic until you put real numbers in, which is the next section.

NIST's draft transition plan, IR 8547, treats the two groups just as differently. It lists RSA, ECDSA, and both kinds of Diffie-Hellman as deprecated after 2030 at the 112-bit level and disallowed after 2035 at every level. In the same document it says its symmetric standards "are significantly less vulnerable to known quantum attacks" than the public-key ones. The plan is still a draft as of October 2026.

Can quantum computers break AES-256?

No, not in any way that matters. Grover's algorithm cuts the work of guessing a 256-bit key from 2^256 tries to about 2^128 quantum steps, and 2^128 is a number no computer of any kind is expected to count through.

The fine print helps AES further. In its post-quantum FAQ, NIST points out that the full speedup only appears when the steps run one after another, so adding more machines does not shorten the job the way it does for ordinary guessing. Its conclusion: "it is quite likely that Grover's algorithm will provide little or no advantage in attacking AES, and AES 128 will remain secure for decades to come." It adds that applications "can continue to use AES with key sizes 128, 192, or 256 bits."

If a vendor tells you AES-256 is about to fall and you need their product, that claim is at odds with the body that standardized AES.

Will quantum computers break SHA-256 and passwords?

SHA-256 holds for the same reason AES does. Grover's algorithm weakens the search for an input that matches a given hash, but a 256-bit hash starts with a large enough margin to absorb it.

Passwords are a different matter, and quantum computers are not the reason. A short or reused password falls to ordinary computers today. A long random one, stored by a service that hashes it properly, is not something Shor's algorithm helps with at all. If you want to do one thing about passwords this week, make them unique. Quantum does not change that advice.

Has a quantum computer already broken encryption?

No. Two facts are worth keeping, because the headlines will keep coming.

The "cracked RSA" story was a 22-bit number. In 2024, a team at Shanghai University reported an attack on a 22-bit RSA key using D-Wave quantum systems, and by October the coverage read as if RSA itself had fallen. TechTarget collected the response from people who work on this. One of them, DigiCert's Avesta Hojjati, noted the key was "far shorter than the 2048- or 4096-bit keys commonly used in practice today." A 22-bit number is a few million. An ordinary laptop factors it instantly, with no quantum hardware at all.

Running Shor's algorithm for real is still stuck on tiny numbers. Craig Gidney of Google Quantum AI wrote a post in August 2025 titled "Why haven't quantum computers factored 21 yet?". His answer: the circuit for 21 needs 2,405 entangling gates against 21 for the number 15, more than a hundred times as many, and today's hardware is too noisy to run it.

Now the other side, because the gap is closing on paper. The same researcher estimated in May 2025 that a 2,048-bit RSA key "could be factored in less than a week by a quantum computer with less than a million noisy qubits," down from 20 million in his 2019 estimate. In March 2026, Google Research published circuits for breaking 256-bit elliptic curves that it says could run on "fewer than 500,000 physical qubits in a few minutes."

Those are estimates of what a future machine would need, not demonstrations. But they explain why the people who run large systems stopped waiting. How soon such a machine could exist is its own question, and we lay out the published estimates in when is Q-Day.

Why does it matter now if the machine doesn't exist?

Because broken key agreement is retroactive. Someone who records your encrypted traffic today can keep it and decrypt it once a capable machine exists. The tactic is called harvest now, decrypt later, and it means the exposure starts on the day the data is sent, not on the day the computer is built.

Signatures are the opposite. A forged signature is only useful at the moment of the forgery, so a signature made today is not at risk from a machine built in ten years. That is why the industry moved key agreement first and is moving signatures second.

For you, this turns the question into one about shelf life. A message that stops mattering next month is not worth anyone's storage. A medical file, a contract, or a scan of your passport is.

What replaces the encryption that breaks?

New public-key math that Shor's algorithm does not apply to. In August 2024, NIST finalized three standards: ML-KEM (FIPS 203) for key agreement, and ML-DSA and SLH-DSA for signatures. They run on the phone and laptop you already own.

Most services deploy the new key agreement as a hybrid, pairing ML-KEM with a classical algorithm such as X25519, so an attacker has to break both. The symmetric layer underneath, usually AES-256 or ChaCha20, stays exactly as it is. Our guide to what post-quantum encryption is covers how the new math works and which apps already use it.

How to tell which of your own locks are at risk

Here is the sorting rule. Ask of anything encrypted: was the key agreed with someone else over a network, or is it a secret that never leaves my side? Agreed over a network means public-key math was involved, and that is the part to care about. A secret that stays with you is symmetric, and it holds.

Thing you use What protects it Quantum verdict
Laptop or phone disk encryption AES with a key derived on the device Holds
Password manager vault at rest AES-256 or ChaCha20 from your master password Holds
Home Wi-Fi password (WPA2 personal) A shared secret and AES Holds
Websites over HTTPS Public-key agreement, then AES At risk unless the site and browser use hybrid ML-KEM
Messaging apps Public-key agreement, then symmetric Depends on the app; ask whether it is post-quantum
Email between providers Public-key agreement per hop, then AES At risk in transit where the hop is classical
VPN tunnel Public-key agreement, then ChaCha20 or AES At risk unless the VPN adds post-quantum key agreement
Software updates Public-key signatures Safe today; needs new signatures before the machine exists

Two checks you can run today:

  1. Your browser. The 30-second connection test in our post-quantum guide tells you whether your browser already negotiates hybrid ML-KEM.
  2. Your terminal, if you use SSH. Run ssh -Q kex | grep mlkem. If you see mlkem768x25519-sha256, your client supports post-quantum key agreement. The OpenSSH project made it the default in version 10.0 in April 2025, and from 10.1 it warns you when a server does not support it.

Then sort what is left by shelf life. For most people that leaves two things carrying long-lived secrets over the network: email and whatever tunnel their traffic rides in.

That is the gap we built Secria for. Secria Mail uses ML-KEM-1024 together with X25519 on every plan, free included, with nothing to switch on, so every message in your mailbox is sealed against both kinds of attacker. Secria VPN adds an ML-KEM-1024 protected key to every WireGuard session for the same reason.

Frequently asked questions

Can quantum computers break RSA? A large, error-corrected one could, using Shor's algorithm. A May 2025 estimate from Google Quantum AI puts the requirement for RSA-2048 at under a million noisy qubits running for less than a week. No such machine exists as of October 2026.

Can quantum computers break 256-bit encryption? It depends which 256 bits. AES-256 is symmetric and holds. A 256-bit elliptic-curve key is public-key math and falls to Shor's algorithm on a large enough machine. The number alone tells you nothing; the type of lock does.

Will quantum computers break Bitcoin? Bitcoin's signatures use a 256-bit elliptic curve, which is in the breakable group, while its SHA-256 mining is not. Google's March 2026 paper addressed exactly this and described ways for blockchains to migrate. Whether they migrate in time is a governance question more than a technical one.

Will quantum computers break the internet? No. The internet's public-key layer is being replaced while the machines are still being built. Major browsers, several messaging apps and SSH already use post-quantum key agreement by default, and NIST's draft plan sets 2035 as the end date for the old algorithms.

Is post-quantum encryption safe from quantum computers forever? Nobody can promise forever. The NIST algorithms survived years of public attack attempts and have no known efficient quantum attack. Pairing them with a classical algorithm in a hybrid is the hedge, since an attacker then needs to break both.

Quantum computers will retire one family of locks, on a schedule that is already published. The work for the rest of us is to find where that family still guards something with a long shelf life, and move it. You can start with your inbox for free.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.