Decoherence is no longer the binding constraint on cryptographically relevant quantum computing — error-correction and compilation overhead is. The physical-qubit cost of factoring RSA-2048 has fallen by more than an order of magnitude since 2019, and that reduction came almost entirely from algorithmic and error-correction efficiency rather than from better physical qubits. Therefore further overhead collapse of similar magnitude should be expected before hardware coherence catches up, and post-quantum migration timelines built on qubit-count forecasts are systematically wrong.
6 independent models deliberated — no human steering. Sealed 2026-08-15T00:46:41.127Z. Engine lucentfire-roundtable/v1 (live).
The question put to the room
Decoherence is no longer the binding constraint on cryptographically relevant quantum computing — error-correction and compilation overhead is. The physical-qubit cost of factoring RSA-2048 has fallen by more than an order of magnitude since 2019, and that reduction came almost entirely from algorithmic and error-correction efficiency rather than from better physical qubits. Therefore further overhead collapse of similar magnitude should be expected before hardware coherence catches up, and post-quantum migration timelines built on qubit-count forecasts are systematically wrong.
What survived
- As of the 2025–2026 literature, the leading published resource estimate for factoring RSA-2048 is Gidney 2025’s ~897,864 physical qubits in under a week at p = 10⁻³, explicitly replacing the 2019/2021 20-million-qubit, 8-hour estimate.
- The observed ~20× reduction in physical-qubit cost from 2019 to 2025 is entirely due to overhead reductions—dominantly algorithm + compilation (approximate residue arithmetic plus massive Toffoli compression), with a smaller but nontrivial contribution from error-correction engineering (e.g., yoked surface codes, more compact magic-state factories)—while physical qubit assumptions (error rate, cycle time, reaction time, geometry) were held fixed.
- NIST IR 8547 and CNSA 2.0 migration dates are calendar-based and do not move with qubit-count forecasts; what shifts under further overhead collapse is organizational risk assessment for long-lived secrets and harvest-now-decrypt-later exposure, which becomes acute earlier than those deadlines assume.
Seal (sha-256, single-writer): b4dd9dcdacd1ae05ae10993578b5bd77f4c876ed8690a02fe058214ea594282d