RSA-2048 is safe from today’s quantum computers. It may not be safe from quantum mechanics as written.
Last year, Craig Gidney estimated that fewer than a million noisy qubits could factor a 2,048-bit RSA number in under a week, assuming 0.1% gate errors and fast surface-code cycles. (Here is my minimal RSA explainer.) Nobody has that machine. But suppose we build it—and quantum mechanics runs out of resolution first.
Joscha Bach recently put the worry crisply: if quantum amplitudes are discrete, error correction may eventually hit a wall.
Here is the whole problem. An equal superposition over \(n\) qubits has \(2^n\) branches, each with amplitude
\[ 2^{-n/2}. \]
If nature has a smallest nonzero amplitude \(\delta\), then beyond \(n=-2\log_2\delta\), that state cannot exist. This is not ordinary noise. Quantum error correction can restore an allowed state after small local errors; it cannot restore distinctions that physics itself has deleted. If discreteness merely behaves like weak local noise, error correction may absorb it. If broad states are globally forbidden, it cannot.
That leaves three possible universes.
1. Reality has a fixed ceiling
There is a minimum amplitude, a finite mesh of states, or a maximum information capacity. These are different proposals, but each eventually limits quantum scale.
The difficulty is specifying the rule. An amplitude is basis-dependent: a state can be sparse in one basis and spread across everything in another. So “round tiny amplitudes to zero” is not a physical theory until you say which representation nature rounds, and how.
Tim Palmer’s recent Rational Quantum Mechanics does make a concrete proposal. Motivated by gravity, it restricts the allowed points in Hilbert space and predicts a finite qubit information capacity: roughly 200–400 for current technologies and never more than 1,000. It therefore predicts that Shor’s exponential advantage saturates and RSA-2048 remains practically unbreakable. This is not the consensus. It is a speculative, unusually falsifiable theory—and a huge deal if right.
To believe this universe, you must believe that the continuum in our equations is an approximation, and that nature has a scale-dependent grain we have not yet reached.
2. Amplitudes are computable, but precision has no fixed ceiling
Every real experiment remains finite. Every amplitude it produces has a finite rule. But there is no universal cutoff shared by all possible experiments: a larger process can generate finer amplitudes.
Where do the extra digits live? Not inside one infinitely precise dial. They are produced by more physical history—more qubits, gates, time, and error-correction overhead. A finite Clifford+T circuit, for example, only generates amplitudes from a countable algebraic set. Longer circuits generate finer values. Ordinary quantum complexity theory is perfectly happy here: even rational transition amplitudes suffice for BQP.
This is the slippery middle case. “For every required finite precision, some larger finite process supplies it” does not mean “one physical object stores infinitely many digits.” To believe it, you need nature’s local composition rule to remain valid without a universal ceiling, while paying for each larger computation with larger resources.
If this is our universe, scalable quantum computing can work without a physically real continuum.
3. The full continuum is real
Textbook quantum mechanics allows arbitrary complex amplitudes, including noncomputable numbers containing more information than any finite program.
Quantum computing does not need those numbers. Uniform circuits built from finite gate sets already give BQP. An exact noncomputable constant in a gate would act like an oracle: the answer was hidden in the hardware, not discovered by interference.
To believe this third universe literally, you must believe nature instantiates infinitely informative quantities—not merely that continuous mathematics is our best model. No finite quantum computer could prove that. It could only push any cutoff farther away.
When do we find out?
There is no scientifically defensible “expected cutoff.” But a simple amplitude-floor model gives a useful ruler. A broad 53-qubit state contains amplitudes around \(10^{-8}\); a 1,000-qubit state, around \(3\times10^{-151}\); a 2,000-qubit state, around \(9\times10^{-302}\).
Google’s 53-qubit Sycamore experiment already puts pressure on a simple computational-basis floor much above \(10^{-8}\). Its Willow result then showed logical errors falling as a surface code grew—real evidence that error correction works below threshold, though only at small scale.
The next tests may come fast. IBM forecasts, rather than has demonstrated, 200 logical qubits and 100 million gates in 2029, followed by 2,000 logical qubits and a billion gates in 2033. Palmer predicts failure in this neighborhood. If both sides keep their dates, they collide within a decade.
Do not read the numbers too literally. Logical-qubit counts probe an amplitude floor only when the computation actually spreads across the preferred basis selected by the cutoff theory. Optimized Shor circuits need not materialize one uniform \(2^{2048}\)-branch register. RSA-2048 also remains far beyond IBM’s announced 2033 machine.
Still, the stakes are wonderfully sharp. If Palmer-like limits exist below the scale Shor needs, today’s vulnerable public-key cryptography may be protected by a failure of textbook quantum mechanics. If fault-tolerant machines keep scaling, they will rule out progressively finer versions of that story.
Large quantum computers are therefore not merely applications of quantum mechanics. They are experiments on whether quantum composition keeps working when we ask it to carry an absurd amount of structure. If it does, the fixed ceiling retreats. If logical errors stop falling for a reproducible reason engineering cannot explain, we may have found the grain.