In December 2024, Google published a result in Nature that most physicists consider the most important quantum computing experiment of the decade so far. Its 105-qubit Willow chip ran a surface code error-correction scheme and got a logical error rate of 0.143 percent per cycle, with errors falling by a factor of about 2.14 each time the code grew. That was the first clean demonstration that adding more physical qubits can make a quantum computer less error-prone rather than more.
In the same paper, Google’s own team noted that reaching an encoded error rate of one in a million would need more than a thousand physical qubits for a single logical qubit. Useful algorithms need hundreds or thousands of logical qubits. That arithmetic is the entire state of the field in one line.
Quantum computing is real science with real hardware and real progress. It is also heavily over-marketed, and a press release announcing a new chip is routinely reported as though a working machine had arrived. This is a status check as of September 2026: what is demonstrated, what is merely claimed, and what the difference is.
What a qubit is, without the hand-waving
A classical bit is a physical system with two stable, distinguishable states, and we call them 0 and 1. A qubit is a physical system with two distinguishable states that also obeys quantum mechanics, which means its state before measurement is described by a pair of complex numbers called amplitudes.
Write the state as a combination of the two basis states with amplitudes α and β. The rule is that |α|² + |β|² = 1, and when you measure, you get 0 with probability |α|² and 1 with probability |β|². The state collapses at that point. You never observe the amplitudes directly.
This matters because the amplitudes are not just probabilities. They are complex numbers with a phase, so they can cancel each other out. That is interference, and it is the actual resource quantum algorithms exploit. A quantum algorithm is a carefully constructed sequence of operations that arranges for the amplitudes of wrong answers to cancel and the amplitudes of the right answer to reinforce, so that when you finally measure, the useful outcome is the likely one.
Physically, a qubit can be the two lowest energy levels of a superconducting circuit, two electronic states of a trapped ion, two states of a neutral atom in an optical tweezer, or a photon’s polarisation. All are fragile.
Superposition and entanglement
Superposition is that combined state before measurement. The popular description of a qubit “being 0 and 1 at the same time” is misleading, because it suggests you get two answers for the price of one. You do not. Measurement gives you exactly one bit per qubit.
Entanglement is the property that makes quantum computing more than a curiosity. Two or more qubits can share a joint state that cannot be written as a description of each qubit separately. Measuring one immediately constrains what you can get from the other, no matter the distance between them. Because n entangled qubits require 2ⁿ amplitudes to describe, a 300-qubit entangled register has more amplitudes than there are atoms in the observable universe.
That number is where most of the hype comes from, and it is also where most of the misunderstanding lives. You cannot read out 2ⁿ amplitudes. You get n bits. The whole art is in designing interference patterns that concentrate the answer you want into those n bits, and only a handful of problems are known to permit it.
Why physical qubits are not logical qubits
Qubits decohere. Their fragile phase relationships leak into the environment through stray electromagnetic fields, thermal vibration and imperfect control pulses. Google reported a mean T₁ energy-relaxation time of 68 microseconds on Willow, which is excellent for a superconducting chip and still vanishingly short compared with the length of a useful computation.
Classical computers handle errors with redundancy: store three copies, take the majority. You cannot do that with qubits, because the no-cloning theorem forbids copying an unknown quantum state, and because measuring to check for errors destroys the superposition you were protecting.
Quantum error correction gets around this by encoding one logical qubit across many physical qubits, then repeatedly measuring carefully chosen combinations of qubits (called stabilisers or syndromes) that reveal whether an error occurred and where, without revealing the encoded data itself.
The surface code
The surface code is the leading scheme for superconducting hardware. Qubits sit on a two-dimensional grid; half hold data and half repeatedly measure their neighbours. The code distance d is the width of the grid, and a distance-d code needs roughly d² physical qubits and can correct up to (d−1)/2 errors.
Its appeal is that it needs only nearest-neighbour connections, which suits chips. Its cost is brutal overhead. The essential requirement is that physical error rates sit below a threshold of roughly 1 percent; below it, increasing d suppresses logical errors exponentially, and above it, adding qubits makes things worse. Google’s Willow result was the first convincing demonstration of operating below that threshold, with a distance-7 logical qubit outliving its best physical qubit by a factor of 2.4.
IBM has bet on a different family, quantum low-density parity-check (qLDPC) codes. Its bivariate bicycle “gross code” encodes 12 logical qubits into 144 data qubits plus 144 check qubits, and IBM claims comparable protection to the surface code with roughly ten times fewer physical qubits. The catch is that qLDPC codes need long-range connections between distant qubits, which is hard to build on a chip. IBM’s Loon test processor exists specifically to prove those couplers work.
The hardware approaches, honestly compared
| Approach | Main players | Strengths | Weaknesses |
|---|---|---|---|
| Superconducting circuits | IBM, Google, Rigetti, IQM | Fast gates (nanoseconds), chip fabrication, largest single-chip counts | Short coherence, millikelvin dilution refrigerators, nearest-neighbour only |
| Trapped ions | Quantinuum, IonQ, AQT | Best gate fidelities, all-to-all connectivity, identical qubits | Slow gates (microseconds), hard to scale past hundreds |
| Neutral atoms | QuEra, Atom Computing, Pasqal, Infleqtion | Thousands of atoms already trapped, atoms can be physically moved | Atom loss, slower and lower-fidelity gates than ions |
| Photonics | PsiQuantum, Xanadu, ORCA | Room-temperature operation possible, uses semiconductor foundries | Photons are hard to make interact; needs enormous component counts |
| Topological | Microsoft | Would be intrinsically error-protected if it works | The underlying physics is still contested |
| Silicon spin | Intel, Diraq, Quantum Motion | Tiny qubits, standard CMOS fabrication | Fewest qubits demonstrated; uniformity problems |
Topological deserves a specific caution. Microsoft announced its Majorana 1 chip in February 2025, claiming eight topological qubits. The approach depends on Majorana zero modes, exotic quasiparticles that Microsoft-affiliated researchers have claimed to observe before. A 2018 Nature paper making such a claim was retracted in 2021 after the data was found to be incomplete, and subsequent papers have drawn criticism from other groups for insufficient evidence. The physics may still be sound. The claim is not settled, and it should not be reported as though it were.
Verified milestones through 2026
These are results with published papers, delivered hardware or specifications on company spec sheets, with dates.
| Date | Organisation | Result |
|---|---|---|
| Aug 2024 | NIST | First post-quantum cryptography standards finalised (FIPS 203, 204, 205) |
| Dec 2024 | Willow, 105 qubits: below-threshold surface code error correction (Nature) | |
| Feb 2025 | Microsoft | Majorana 1 topological chip announced; scientific evidence disputed |
| May 2025 | Google Research (Gidney) | Revised RSA-2048 estimate: under 1 million noisy qubits, under a week |
| Oct 2025 | “Quantum Echoes” algorithm, claimed first verifiable quantum advantage | |
| Nov 2025 | Quantinuum | Helios: 98 fully connected qubits, 99.921% two-qubit fidelity, 50 logical qubits |
| Nov 2025 | IBM | Nighthawk (120 qubits, 218 couplers) and Loon (qLDPC couplers) announced |
| 2026 | IBM | Kookaburra, first qLDPC logical-memory prototype, on roadmap |
Two things stand out. First, the largest honest logical-qubit figure anyone advertises is in the dozens, not the thousands. Quantinuum’s Helios lists 50 logical qubits from 98 physical ions, which is a remarkable ratio achievable only because trapped ions have such low error rates, and those logical qubits are not all protected to the same depth.
Second, headline “quantum supremacy” numbers keep shrinking under scrutiny. Google’s 2024 claim that Willow performed in five minutes a random circuit sampling task that would take a classical machine 10²⁵ years drew immediate criticism, both because the benchmark has no practical use and because classical simulation methods have repeatedly improved after such claims. Google’s October 2025 Quantum Echoes result is a stronger form of the claim because it is verifiable, but it too is a physics benchmark rather than a commercial workload.
What quantum computers would actually be good at
The honest list is short.
- Simulating quantum systems. Molecules, catalysts, superconductors, nuclear physics. This is the original motivation and the one with the clearest theoretical advantage, because you are using one quantum system to model another.
- Factoring and discrete logarithms. Shor’s algorithm gives an exponential speedup and would break RSA and elliptic-curve cryptography. This one is certain, and it is why post-quantum standards exist.
- Unstructured search and some optimisation subroutines. Grover’s algorithm gives a quadratic speedup. Quadratic is much weaker than exponential, and after accounting for error-correction overhead the crossover point for real problems is far away.
- Certain linear algebra and differential equation problems, under restrictive conditions on how data goes in and comes out.
Now the claims where evidence is thin: general machine learning, portfolio optimisation, logistics and route planning, broad drug discovery, and databases. In most, either no proven speedup exists or it vanishes once you count the cost of loading classical data into a quantum state. Any pitch that opens with “optimisation” deserves a specific question about which algorithm and what proven speedup.
The cryptography timeline
The RSA question has a moving answer. In 2019, Craig Gidney and Martin Ekerå estimated that breaking RSA-2048 would take about 20 million noisy qubits running for eight hours. In May 2025, Gidney published a revised estimate of under one million noisy qubits and under a week, using better arithmetic and error-correction techniques.
That is a twenty-fold reduction from algorithmic improvement alone, with no new hardware. It is also still roughly a thousand times more physical qubits than IBM’s 1,121-qubit Condor, the largest superconducting processor built to date, and Condor’s qubits are not error-corrected. Nobody knows how fast that gap closes, which is why NIST finalised ML-KEM, ML-DSA and SLH-DSA in August 2024 and told administrators to begin migrating immediately. Encrypted traffic captured today can be stored and decrypted later, so the migration deadline is set by how long your data needs to stay secret, not by when a quantum computer arrives.
The commercial reality
Quantum computing today is sold mostly as cloud access, through AWS Braket, Microsoft Azure Quantum and IBM’s own platform, plus a smaller number of on-premises installations bought by national labs and governments. Sector revenue is small relative to capital raised and to the public market valuations of listed quantum firms.
Almost all current spending is research: pharmaceutical and materials groups building expertise, banks running pilots, defence agencies hedging. That is reasonable. It is not the same as a machine doing production work more cheaply than a classical cluster, and as of September 2026 no independently verified case of that exists for a commercially valuable problem.
IBM says it expects “verified quantum advantage” by the end of 2026 and has proposed community validation of submitted claims rather than press releases, which is a healthier structure than the field has had. Note the framing: even the most aggressive major vendor targets a first defensible advantage claim at the end of 2026 and a fault-tolerant machine in 2029.
What this means for you
- If you handle long-lived secrets, start post-quantum migration now. Inventory where you use RSA and elliptic-curve crypto, and plan a move to the NIST standards. This is the one action with a clear cost-benefit case today.
- If you are evaluating a vendor claim, ask three questions: How many logical qubits, at what logical error rate, and what classical method is the comparison against? Vagueness on any of these is the answer.
- Ignore raw physical qubit counts as a progress measure. A 1,000-qubit machine with poor fidelity is less useful than a 100-qubit machine with excellent fidelity. Watch two-qubit gate error rates and logical qubit counts instead.
- If you work in chemistry or materials, it is worth building literacy now. Yours is the field with the strongest theoretical case, and the learning curve is long.
- Treat any timeline more precise than “the early 2030s” for broadly useful fault-tolerant machines as marketing. The vendors’ own roadmaps say 2029 at the earliest for a first fault-tolerant system, and roadmaps slip.
Frequently asked questions
Is quantum computing a scam?
No. The physics is sound, the error-correction results are genuine, and the engineering progress since 2019 is substantial. The problem is a gap between what labs demonstrate and what press releases imply, plus a public-market appetite for quantum-branded stocks that rewards loud announcements.
Will quantum computers replace regular computers?
No. They are special-purpose accelerators for a narrow class of problems, and they will be attached to classical machines that do everything else. Nothing about a quantum processor helps run a spreadsheet or a web server.
How close are we to breaking Bitcoin or bank encryption?
Not close, on any published hardware. The best current estimate needs on the order of a million high-quality physical qubits with full error correction, and the largest machines have a few hundred physical qubits. The reason to migrate now is data recorded today being decrypted years from now.
What is the difference between a logical qubit and a physical qubit?
A physical qubit is one piece of hardware. A logical qubit is an error-corrected qubit built out of many physical ones, and is the only kind that can survive a long computation. Ratios range from roughly 2:1 on the best trapped-ion systems to over 1,000:1 for a deeply protected surface-code qubit.
Should my company be buying quantum computing time?
Only if you are funding research or building skills deliberately. There is no production workload today where a quantum machine beats a classical one on cost or result quality.
What to watch instead of qubit counts
The field’s real scoreboard has three entries. First, two-qubit gate error rate, because everything downstream depends on it and progress there is slow and hard-won. Second, the number of error-corrected logical qubits with a demonstrated logical error rate below their physical components, which is where the dozens-not-thousands reality sits. Third, whether a logical operation, not just logical memory, has been performed at scale, since storing a protected qubit and computing with it are different problems and the second is much harder.
Those three numbers will tell you more in ten seconds than any announcement. If IBM ships Kookaburra and demonstrates qLDPC logical memory, or if Google performs logical gates on multiple below-threshold logical qubits, the field will have moved genuinely. If the next headline is a larger physical qubit count or a new sampling benchmark, it has not.
Sources
- Nature — Quantum error correction below the surface code threshold
- Google Research — Making quantum error correction work
- Wikipedia — Willow processor
- IBM Quantum — IBM lays out clear path to fault-tolerant quantum computing
- IBM Quantum — Hardware and roadmap
- Tom’s Hardware — IBM unveils new 120-qubit Quantum Nighthawk processor
- Post-Quantum — IBM unveils Nighthawk and Loon quantum chips
- Quantinuum — Helios system specifications
- arXiv — How to factor 2048 bit RSA integers with less than a million noisy qubits (Gidney, 2025)
- NIST — NIST Releases First 3 Finalized Post-Quantum Encryption Standards
- Wikipedia — Topological quantum computer
- The Quantum Insider — The Companies Building Quantum Computing Chips in 2026
- Quantum Zeitgeist — Top Quantum Hardware Companies 2026 by Modality
- pdpspectra — Quantum Computing Landscape 2026
Image credit: Photo: OJB Quantum — CC BY 4.0 (via Wikimedia Commons)
