Q-Day
Media headlines and reports from the field of quantum computing often create the impression that the internet could face a security collapse as soon as tomorrow, that we will soon discover new drugs and supermaterials, or, conversely, the belief that none of this will ever work.
As is often the case, the specific message and its credibility depend on the author. In any case, such claims should be treated with caution. The examples above certainly do not represent an accurate interpretation of the current state of the field or expectations for the near future. Quantum computers have the potential to change the world and society, but the exact form this change will take may come as a surprise.
Yes, quantum algorithms pose a threat to the cryptographic methods used today. Part of preparing for Q-Day – the day when a fully functional quantum computer becomes a reality – is the transition to new cryptographic systems. If we do not underestimate this preparation, the primary purpose of quantum computers will not be to break today’s encryption schemes. By then, they will no longer be in use. So what will quantum computers do? Let us be surprised. For now, however, we can try to describe what they are already doing today.
Have you heard that...
…in 2019, Google announced quantum supremacy to the world? Investment and interest immediately skyrocketed. Using its 53-qubit superconducting quantum chip, Sycamore, Google demonstrated a quantum computation completed in 200 seconds that was claimed to require 10,000 years on the world’s most powerful supercomputer.
IBM responded with an analysis suggesting that the computation would take only weeks. In 2021, Chinese researchers implemented an algorithm based on the tensor network method. The computation was carried out on a computing cluster using 512 graphics processing units and took 15 hours. They estimated that the same computation would take only tens of seconds on modern supercomputers—less time than on Google’s Sycamore quantum chip. In this case, supremacy did not hold up. But that is precisely how research works: it re-examines and challenges claims, identifies errors, and, when necessary, corrects previous conclusions.
You may not have heard that...
…at the end of 2023, Google itself announced that simulating Sycamore on the Frontier supercomputer would take just six seconds. At the same time, however, it demonstrated a 67-qubit computation of the same task – random circuit sampling – which would take years on that supercomputer, once again claiming quantum supremacy.
Meanwhile, in 2020, researchers at the University of Science and Technology of China in Hefei used 76 photons in the photonic quantum computer Jiuzhang to solve a different task – Gaussian boson sampling – in 200 seconds. They estimated that the same computation would take a billion years on a supercomputer. By 2023, however, this time had been reduced to nine minutes, and a non-quantum simulation was successfully performed, although Jiuzhang remained faster.
It is not impossible that someone will develop an algorithm that eliminates a particular demonstration of quantum supremacy for computing systems with hundreds of qubits. Ultimately, however, a quantum computer will dominate in some task, because efficiently simulating complex quantum systems and processes is simply not possible. Achieving supremacy, however, does not necessarily imply practical usefulness or pose a threat to current cryptographic systems.
Did you know that...
…in October 2025, Oxford Ionics, a member of IonQ, demonstrated a two-qubit gate with an accuracy of 99.99%, improving its own world record for two-qubit gate fidelity? It may seem like an easily overlooked piece of news, but in reality, it could be more important than a spectacular claim of supremacy. This level of accuracy is crucial for quantum computing because it opens the path towards fault-tolerant quantum computers.
The number of qubits alone, without considering their quality, does not tell the whole story. Due to noise, the quality of quantum computations deteriorates rapidly as the number of qubits and operations increases. An accuracy of 99.99% gives hope that we now have a quantum system—trapped ions—operating in a regime where quantum error correction can work in practice.
You may not have known that...
…it is important to distinguish between the number of physical qubits—quantum two-level physical systems such as photons, atoms, ions, superconducting transmons, and others that are intended to perform computations—and the number of logical qubits, which contain fully encoded quantum information and take part in quantum algorithms. A logical qubit is typically composed of several physical qubits that collectively combat quantum gate errors and quantum decoherence during computation, while protecting the logical information being processed.
In the case of superconducting quantum chips, we are now talking about thousands of qubits – for example, IBM’s Condor chip has 1,121 qubits, while D-Wave’s Advantage2 has 4,400 qubits. However, there are only a handful of logical qubits, and they are still error-prone. At the end of 2024, Google’s Willow chip not only demonstrated quantum supremacy but, more importantly, achieved positive error correction for a single logical qubit for the first time. Its 101 qubits, with two-qubit gate fidelities of 99.67%, can function as one logical qubit with the help of error correction. It may not make front-page headlines, but for superconducting quantum devices, it represents a truly important milestone.
The Helios trapped-ion quantum processor, developed in 2025, operates with 98 qubits – barium cations – and two-qubit gates with a fidelity of 99.921%. As a result, it can create up to 48 logical qubits. Helios is currently the most powerful quantum computing infrastructure.
99.9% vs. 99.99%. The graph shows the relationship between the number of physical and logical qubits depending on implementation fidelity.
We have come to understand that...
…quantum supremacy is no longer the goal and is generally considered to have been achieved. By quantum supremacy, we mean any case in which an existing classical computer cannot be used in a way that allows it to perform a particular computation faster than an existing quantum computer. We already have several such examples. Some may not stand the test of time, but new ones continue to emerge. Having learned from these developments, we have softened the rhetoric and increasingly speak of quantum advantage instead of quantum supremacy. The goal is a quantum computation whose result we genuinely cannot obtain through simulations without a quantum computer.
…the computational complexity of simulating noisy quantum computers does not fall into the class of problems we consider exponentially difficult. In 2022, Dorit Aharonov, Xun Gao, Zeph Landau, Yunchao Liu, and Umesh Vazirani introduced a polynomial-time algorithm for sampling from the probability distribution produced by a noisy random quantum circuit. From this perspective, efforts to perform random circuit sampling on quantum computers may appear unnecessary.
However, algorithms of this kind do not mean that quantum advantage does not exist. In terms of computational complexity, there is no fundamental difference between using central processing units (CPUs) and graphics processing units (GPUs). Nevertheless, GPUs significantly accelerate certain tasks, and modern supercomputers are built largely around them. Quantum processing units (QPUs), even when noisy and therefore computationally equivalent to CPUs for certain tasks, may provide similar accelerations—something we could describe as quantum advantage.
We do not expect that...
…today’s noisy quantum computers will demonstrate quantum advantage without functioning error correction. Their significant contribution, however, may be to make simulations of quantum systems more efficient even without it. While this will not be a universal solution, and the speed-up is unlikely to be dramatic enough to compare seconds of quantum computing time with millions of years of supercomputer time, it may nevertheless be highly useful.
…we will have devices capable of breaking today’s cryptographic systems without functioning error correction. A good indication is the fact that the largest number factored on a quantum computer remains the number 15, dating back to 2001. The reason is pragmatic. Shor’s algorithm for factoring the number 15 requires 21 two-qubit gates and seven qubits. Factoring the number 21 requires only 15 qubits, but the number of two-qubit gates increases to as many as 2,405. And that is before even considering their error rates.
Factoring the number 15 in an IBM experiment from 2001.
Author of the article: Mário Ziman, Institute of Physics, Slovak Academy of Sciences, Bratislava
Illustrations: Diana Cencer Garafová, QUTE.sk – Slovak National Center for Quantum Technologies

