The hardware paradigms of quantum computing
Six ways to build a quantum computer, compared on what decides whether they can correct their own errors: how often operations fail, how fast a correction cycle runs, which qubits can talk to each other, and what each has shown so far. Every number sourced and dated.

Ask what a quantum computer is made of and you get six different answers. Google and IBM build small superconducting circuits. Quantinuum and IonQ hold charged atoms in electric fields. QuEra and Atom Computing hold neutral atoms with laser beams. PsiQuantum and Xanadu send single particles of light through chips. Intel and a handful of startups trap single electrons in silicon. Microsoft is trying to build a qubit that protects itself, and physicists are still arguing about whether it exists.
Each of these is a hardware paradigm: a different physical object used as a qubit, with its own speed, its own ways of failing and its own way of growing. This post compares the six. It sets qubit counts aside and looks at the things that decide whether a machine can correct its own errors: how often operations fail, how fast one round of error correction runs, which qubits can talk to each other, and what each platform has already shown in a published experiment. Error correction is the step every platform has to clear before it can run a useful computation.
We took every number from a paper, a preprint or a first-party document published up to 18 August 2026, and we give the date of each, because a “state of the art” without a date ends up comparing machines from different years. We also keep three kinds of numbers apart: a record set on one chosen pair of qubits, a result measured across a whole device, and a company’s roadmap. The device-wide numbers are in the scorecard; the records, vendor figures and roadmaps have a table of their own.
The finding, in one paragraph. Trapped ions and neutral atoms have gone furthest on error correction: both have run dozens of logical qubits with logical gates between them, and both still rely on post-selection for that logic. Superconducting circuits run a correction cycle in about a microsecond, against tens to hundreds of milliseconds for ions and atoms. They were the first to show a logical memory that improves as the code grows, but have not shown a logical gate better than their physical ones. Spins and photonics are at small codes, and the topological qubit is itself in dispute.
The first section explains the handful of concepts the comparison uses. If you already know what a logical qubit and a code distance are, skip ahead to the platforms.
What every platform has to get right
A qubit, and its errors. A qubit is any physical object with two states we can prepare, change and read out. Every operation on it fails some fraction of the time. That fraction is the error rate, and papers often report its complement, the fidelity: 99.9% fidelity means an error rate of 0.1%, one failure in a thousand. The operation that fails most often is almost always the two-qubit gate, the step that entangles two qubits, so two-qubit error is the first number to look at. It comes in two flavours. A record is the best error reached on one chosen pair of qubits. A device-wide number is the average or median across all the qubits in a processor, and that is what a program running on the machine gets.
Coherence. A qubit holds its state for a limited time before noise scrambles it. That time is its coherence, and it ranges from tens of microseconds in superconducting circuits to seconds in atoms and ions. What matters is how many operations fit inside that window.
Speed. Gates take anywhere from nanoseconds to hundreds of microseconds, depending on the platform. Measuring a qubit is usually slower than operating on it. In an error-corrected computer the unit of time that matters is one full cycle of error correction: run the gates that check for errors, measure, reset, and let a classical computer (the decoder) work out what went wrong. A platform’s cycle time sets the pace of everything built on top of it.
Connectivity. Which qubits can interact directly. On a chip, a qubit usually talks only to its neighbours, so moving information across the chip costs extra operations. Ions and atoms can be physically moved, so any qubit can be brought next to any other, at the price of the time it takes to move them.
Error correction. A single physical qubit is too noisy to compute with for long. Error correction spreads one unit of information across many physical qubits, which together form a logical qubit, and repeatedly measures a pattern of checks that reveals errors without disturbing the information. The recipe is called a code, and its distance is, roughly, how many simultaneous physical errors it can survive. Bigger codes cost more qubits and survive more. The deal only works when the physical error rate is below the code’s threshold. Above it, a bigger code makes things worse; below it, each step up in distance makes the logical qubit better. For the surface code, the code designed for chips with a grid layout, the threshold is around 1% two-qubit error. Reaching useful logical error rates with it costs roughly a thousand physical qubits per logical qubit. Codes that can use long-range connections do the same job with far fewer.
Three more terms appear in the results. Break-even is the point where a logical qubit lasts at least as long as the best physical qubit inside it. Post-selection means throwing away the runs in which an error was detected and reporting only the rest. It makes numbers look better, and the fraction thrown away is a real cost that headlines tend to leave out. Magic states are the special prepared states a code needs for the few operations it cannot do directly; useful algorithms consume them by the million, so making them cheaply is its own milestone.
A ladder for error-correction results. To compare platforms we place each one on a six-rung ladder:
- L0: physical qubits only.
- L1: a small code runs, but the logical qubit is worse than its physical parts.
- L2: break-even.
- L3: below threshold; the logical error rate falls as the code grows.
- L4: many logical qubits, with logical gates between them that beat break-even.
- L5: logical error rate at or below one in a million, the regime useful algorithms need.
A rung counts as reached when a published experiment meets it without throwing runs away. A rung reached only with post-selection is marked as such. No platform has reached L5.
What we record for each platform. Seven things: how many qubits it runs together; its device-wide two-qubit error, with records noted separately; how long gates, measurements and a full cycle take; how long it holds its state; which qubits can interact; the highest rung of the ladder it has reached in a published experiment; and the part of the machine that has to grow next.
Each platform below is described in the same order: how it works, what it does well, what it pays for that, where it stands on the ladder, and what limits its growth.
Superconducting circuits
How it works. The qubit is a small electrical circuit, patterned on a chip much like a conventional processor and cooled to about a hundredth of a degree above absolute zero. One component, a Josephson junction, gives the circuit two distinct energy levels that serve as 0 and 1. Microwave pulses lasting tens of nanoseconds operate on the qubit, and reading it out takes a few hundred nanoseconds. Google, IBM, Rigetti, IQM and USTC build this kind of machine.
What it does well. Speed. Google’s Willow chip, 105 qubits, runs a full error-correction cycle in 1.1 microseconds. Its two-qubit error, measured across the whole chip with every qubit running, is 0.33%. The best single pairs do better and commercial fleets do worse; both are in the records table. The largest machines in service are IBM’s 156-qubit Heron and 120-qubit Nighthawk.
What it pays. Qubits and wiring. Every qubit needs its own control lines running into the refrigerator. Qubits sit on a fixed grid and talk only to their neighbours, which is why the surface code, with its thousand-to-one overhead, is the natural choice here.
Error correction. In December 2024 Willow became the first processor to show a logical qubit improving as its code grew. Each step up in code distance, from three to five to seven, cut the logical error by a factor of 2.14. At distance seven the logical error was 0.143% per cycle, with decoding done in real time. A July 2026 follow-up that tuned the chip with reinforcement learning brought that to 7.7×10⁻⁴. USTC’s 107-qubit Zuchongzhi 3.2 became the second processor below threshold in December 2025, improving by a factor of 1.40 per step. These are memory experiments: one logical qubit kept alive. Logic between logical qubits at better-than-physical quality is still ahead. Google’s colour-code experiment prepared logical states and, with post-selection, injected magic states.
What limits growth. Wiring and fabrication defects. Defects keep fleet error rates between one part in a thousand and one in a hundred, while the best pairs sit near 6×10⁻⁴. IBM’s alternative to the surface code is a family of codes (qLDPC codes) that need long-range connections. It is testing the couplers for them on an experimental chip called Loon, and its decoder already meets the sub-microsecond budget in simulation. Google’s own reading is that superconducting qubits are the easiest platform to scale in time; in March 2026 it added neutral atoms as a second platform.
Trapped ions
How it works. The qubit is a single charged atom held in place by electric fields, in vacuum. Two internal energy states of the atom serve as 0 and 1. Laser or microwave pulses operate on it, and when it is read out the ion either glows or stays dark. Every ion of a given isotope is identical, so all the qubits in the machine start out the same. Quantinuum, IonQ and Oxford Ionics build this kind of machine.
What it does well. The lowest errors of any platform, and free connectivity. Quantinuum’s Helios runs 98 ions with an average two-qubit error of 7.9×10⁻⁴ across the whole processor, and a single-qubit error of 2.5×10⁻⁵. The best result on a single pair of ions is about ten times lower (records table). A gap of that size shows up on every platform, and the device-wide number is the one that sets the error-correction budget. Ions in one chain interact through their shared motion, so any ion in the chain can entangle with any other. Larger processors divide the trap into zones and physically shuttle ions to the zone where a gate will happen, so a program can ask for a gate between any two qubits directly.
What it pays. Time. A two-qubit gate on Helios takes about 70 microseconds, and one full layer of gates across the machine takes about 55 milliseconds: roughly 25 ms moving ions, 20 ms cooling them down again and 10 ms of actual gates. In an earlier study of the H2 machine, transport and cooling took almost the whole run time and gates one or two percent of it. Coherence of several seconds makes this workable, and an error-corrected ion computer will still run its cycles thousands of times slower than a superconducting one.
Error correction. Helios has run 94 error-detected or 48 error-corrected logical qubits out of its 98 ions, both with post-selection. For the circuits tested, the logical errors were 10 to 100 times below the physical ones, and a 94-logical-qubit entangled state reached 94.9% fidelity. Getting 48 logical qubits from 98 physical ones is possible because all-to-all connectivity allows codes far cheaper than the surface code. Smaller experiments have exercised the harder pieces of a universal computer: a logical magic state with an error near 7×10⁻⁵ after discarding 14.8% of attempts, and switching between two codes to perform operations that neither code supports on its own.
What limits growth. Architecture rather than ion quality. A long chain of ions becomes hard to address and its motion gets crowded. Grids of trap zones need junctions, parallel gate zones and a lot of control hardware. Linking separate traps with light works, and the first two-module gate reached 86% fidelity, far below a local gate. The number to watch is how many zones and links can run in parallel while keeping the error rate of the small system.
Neutral atoms
How it works. The qubit is a single neutral atom (rubidium, caesium, strontium or ytterbium) held by a tightly focused laser beam, an optical tweezer, inside a vacuum cell at room temperature. Two ground states of the atom serve as 0 and 1 and keep their state for seconds. To entangle two atoms, a laser pulse briefly lifts them into a highly excited “Rydberg” state in which each blocks the other; the pulse takes a few hundred nanoseconds. Because the tweezers can be steered, atoms can be moved between storage, gate and readout zones in the middle of a computation. QuEra, Atom Computing, Pasqal and the Harvard and Caltech groups build this kind of machine.
What it does well. Size, and error correction. Arrays of thousands of atoms have been held, and one has been kept running for hours by reloading atoms continuously (records table). Two-qubit error has caught up with the other platforms: 99.5% across 60 atoms in parallel was reached in 2023, and the best Rydberg gate now averages 99.854% across eight sites; vendor figures sit lower (records table).
What it pays. The clock. A gate takes about 300 nanoseconds. Moving an atom takes 0.1 to 1 millisecond, and reading atoms out by imaging them takes “routinely 5–20 milliseconds”, in the words of the field’s own July 2026 strategic plan. Atom Computing’s measured error-correction cycles took 80–150 milliseconds, against 1.1 microseconds on Willow. Atoms are also lost at a rate of 0.05–1% per operation and have to be replaced; at least the loss is detectable, and decoders use that.
Error correction. The 448-atom machine built by Harvard, MIT and QuEra (Nature, November 2025) ran a surface-code memory below threshold: distance five beat distance three by a factor of 2.14. It also performed logical operations between logical qubits, and by reusing atoms mid-circuit it ran up to 96 logical qubits at distance four, with post-selection. Atom Computing ran error correction for 90 cycles in June 2026, replacing lost atoms as it went. Earlier, 48 logical qubits on 280 atoms beat physical qubits with post-selection in 2023, and the first logical magic-state distillation ran in 2025. As with ions, being able to move qubits makes cheap codes possible: 96 logical qubits from 448 atoms is a far lower overhead than the surface code on a fixed grid.
What limits growth. Laser power is the stated limit on the road to ten thousand or a hundred thousand atoms, and the clock stays the cost to beat.
Semiconductor spins
How it works. The qubit is the spin of a single electron (or hole) trapped in a tiny semiconductor structure called a quantum dot, or the spin of a single atom placed in silicon. The devices are made with the tools of chip fabrication. Voltage and microwave pulses operate on the spins. A two-qubit gate switches on the interaction between two neighbouring dots for a short time. Readout converts the spin into a tiny charge signal and senses it nearby. Intel, HRL, Diraq, imec, Silicon Quantum Computing and RIKEN build this kind of device.
What it does well. Density and manufacturing. A spin qubit is about a hundred nanometres across, and several groups now make devices on 200 or 300 mm production lines. Diraq and imec reported four foundry-made devices with every operation above 99% fidelity and two-qubit errors from 0.44% to 0.96%. HRL’s processor reported a mean two-qubit error of 0.3% and runs with a 70-million-transistor controller sitting next to the chip at 4 kelvin. Gates are fast, around 100–500 nanoseconds. Intel’s wafer-scale number (records table) measures how uniform the process is; the processor built from it has 12 dots in a line.
What it pays. Control. Errors rise when an array runs as a device: the best single-qubit errors on one dot are ten times lower than when all five dots in the same array are driven together (records table), and two-qubit errors across foundry devices stay around 0.5–1%. Readout is slow, because the charge signal is tiny. Connectivity is nearest-neighbour. The operated arrays are small: a germanium device ran 18 qubits together in a 2026 preprint, Intel has run 12, and Silicon Quantum Computing an 11-qubit donor processor.
Error correction. One error type at a time so far. HRL ran a distance-five repetition code on seven qubits for 200 rounds, with a logical error near 5×10⁻³ per round and a factor of 4.7 improvement from distance three to five. A repetition code protects against one kind of error; a logical qubit has to handle both kinds, and that full demonstration is still ahead for spins.
What limits growth. The hardware around the qubits. HRL’s seven-qubit experiment used 296 wires for 54 dots and a controller dissipating 3.5 watts at 4 kelvin. A large processor will have to share wires and pulses across many dots. Each dot also comes out of fabrication slightly different and has to be tuned on its own. Semiconductor manufacturing gives dense, repeatable structures; the yield of a classical chip has to be demonstrated separately for a quantum one. The decisive demonstration will be a large foundry-made array whose device-wide two-qubit error stays where the best small devices are today.
Photonics
How it works. The qubit is a single particle of light, a photon, sent down one of two paths or arriving in one of two time slots (PsiQuantum, Quandela, QuiX, ORCA), or a specially shaped state of many photons in one light mode (Xanadu). Beam splitters and phase shifters act as single-qubit gates. Photons pass through each other without interacting, so a photonic computer works differently from the others. It prepares small entangled groups of photons in advance, then performs the computation by measuring them in a particular pattern. Photons keep their state at room temperature; only the detectors need cooling. The error that matters is loss, a photon that never arrives. The leading scheme, fusion-based computing, tolerates about 10% total loss per photon.
What it does well. Components. PsiQuantum’s manufacturing paper (Nature, February 2025) reports 99.22% fidelity for the two-photon “fusion” measurement when both photons were detected, all made on 300 mm wafers; the other component records are in the table. Its photon sources deliver a photon about 26% of the times they are asked, which is why many sources have to be combined. PsiQuantum has yet to disclose an operating computer.
What it pays. Loss. Xanadu’s Aurora (Nature, January 2025) is the largest photonic system operated as a computer: 12 qubit modes per clock tick at 1 MHz, running a distance-two repetition code with real-time decoding. It sits far above threshold. Loss on its key paths was about 56% against budgets near 1%, and its on-chip GKP states, the specially shaped light states that carry the qubit, reach 0.62 dB of squeezing, a measure of their quality, where the scheme needs 9.75 dB.
Error correction. Aurora’s distance-two repetition code with real-time decoding is the strongest error-correction result on a photonic computer. No photonic platform has shown a logical qubit below threshold.
What limits growth. Loss and sources. The schemes assume about 1% loss per component; Aurora measured 56% on its key paths, and PsiQuantum’s sources deliver one photon in four attempts. PsiQuantum’s public roadmap is in the records table.
Topological qubits
How it works, in principle. Microsoft is trying to build a qubit whose information is stored in a collective state of a superconducting nanowire, a “Majorana” state, that noise cannot easily reach. If it works, far less error correction would be needed. Whether the devices host that state is the open question.
Where it stands. The peer-reviewed result (Nature, February 2025) is a single-shot measurement of parity (whether the wire holds an even or odd number of electrons), with a 1% error, in an indium-arsenide/aluminium nanowire. The authors write that the measurement does not by itself determine whether the states are topological. Nature’s editorial note says the results “do not represent evidence for the presence of Majorana zero modes”. Microsoft’s announcement the same day spoke of the first topological qubits. Later reports of qubit lifetimes (records table) have not settled the question. In June 2026 Nature published a Matters Arising arguing that the readout regions were disordered and lacked the required energy gap; Microsoft’s reply stands by its results. Separately, a QuTech experiment read out parity in a two-site Kitaev chain, a minimal “poor man’s Majorana” with limited protection. So far there is no error correction, no logical qubit and no independent replication. On our ladder the platform is a disputed L0.
Two machines outside the table
D-Wave’s Advantage2, with more than 4,400 qubits, is an annealer: it solves optimisation problems by slowly steering a physical system toward its lowest-energy state. That is a different model of computation from the gate model the other platforms run; in theory the two are related, and in practice today’s annealers are special-purpose machines. D-Wave’s Science paper claiming a simulation beyond classical reach drew two rebuttals within weeks, and D-Wave maintains that its largest instances remain out of classical reach. Analog simulators such as QuEra’s Aquila and Pasqal’s Orion run programmable physics experiments on neutral-atom hardware; they are useful instruments rather than general computers. Both kinds run without error correction, so they stay out of the scorecard.
The scorecard
One representative device-wide value per cell. The records, vendor figures and roadmaps are in the next table, each with its date.
| Platform | Largest system run together | Two-qubit error, device-wide | Speed | Connectivity | Highest error-correction result |
|---|---|---|---|---|---|
| Superconducting | 156 (IBM Heron); 120 (IBM Nighthawk); 105 (Google Willow) | 0.14% native gate, 0.33% CZ, across Willow | Gates under 60 ns; full cycle 1.1 µs | Neighbours on a grid | Logical memory below threshold (L3); one or two logical qubits |
| Trapped ions | 98 (Quantinuum Helios) | 7.9×10⁻⁴ across the processor | Gate ~70 µs; one layer ~55 ms | Any to any, by moving ions | 48 error-corrected logical qubits with gates, post-selected (L4) |
| Neutral atoms | 448 (Harvard/MIT/QuEra logical processor) | 0.5% on 60 atoms in parallel | Gate ~300 ns; move 0.1–1 ms; readout 5–20 ms; cycle 80–150 ms | Any to any, by moving atoms | Below threshold (L3); 96 logical qubits with gates, post-selected (L4) |
| Semiconductor spins | 18 (germanium); 12 (Intel); 11 (SQC donors) | 0.3% mean (HRL); 0.44–0.96% (Diraq/imec) | Gate 100–500 ns; readout slower | Neighbours, 1D or small 2D | Repetition code, 200 rounds (L1) |
| Photonics | Aurora: 12 qubit modes per clock tick | Fusion 99.22% when both photons arrive; loss ~56% | 1 MHz clock | Any to any, by routing light | Distance-two code, above threshold (L1) |
| Topological | One to four prototype qubits | No two-qubit gate yet | Parity readout in 3.6 µs | — | Parity readout, disputed (L0) |
Records, vendor figures and roadmaps
These are the numbers the scorecard keeps out: a best result on one pair, one component or one array; a specification page or announcement (vendor); a target or programme (roadmap); or a past demonstration that never became a deployed machine (history).
| Platform | What | Value and source | Kind | Date |
|---|---|---|---|---|
| Superconducting | Two-qubit error on one pair | 6×10⁻⁴, fluxonium CNOT, stable for 24 days | record | 2024 |
| Two-qubit fidelity on a two-qubit device | above 99.9% (IQM) | record | 2025 | |
| Median CZ error, 54-qubit IQM Radiance | 0.5% (specification), gates up to 60 ns | vendor | 2026 | |
| Largest chip shown, IBM Condor | 1,121 qubits, demonstrated once, never the deployed device | history | Dec 2023 | |
| Trapped ions | Two-qubit error on two ions | 8.4×10⁻⁵ (Oxford Ionics and IonQ) | record | 2025 |
| Single-qubit error on one ion | 1.5×10⁻⁷ (Oxford) | record | 2024 | |
| Neutral atoms | Atoms held in one array | 6,100 caesium atoms, 12.6 s coherence, 99.983% single-qubit fidelity, no entangling gates (Caltech) | record | 2024 |
| Continuous operation | more than 3,000 atoms for over two hours with reloading (Harvard) | record | 2025 | |
| Rydberg CZ fidelity over eight gate sites | 99.854% | record | Apr 2026 | |
| QuEra Gemini, 260 qubits | 99.2% two-qubit fidelity; one run per second (specification) | vendor | 2026 | |
| Photonics | PsiQuantum components on 300 mm wafers | state preparation and measurement 99.98%; chip-to-chip transfer 99.72% over 42 m of fibre; detectors 98.9% median efficiency (manufacturing paper) | record | Feb 2025 |
| PsiQuantum utility-scale machine | $125 million DARPA agreement for the final validation stage; the “end of 2027” target of April 2024 has no official successor date | roadmap | 2025 | |
| Xanadu on-chip GKP squeezing | 0.62 dB effective, against the 9.75 dB the scheme needs | record | 2025 | |
| Semiconductor spins | Quantum-dot devices per wafer (Intel) | more than 24,000, 96% behaving as single-electron devices; the processor has 12 dots | record | 2024 |
| Best reproducible two-qubit pair (HRL) | 0.09% | record | 2026 | |
| Single-qubit error, one dot alone vs all five driven (RIKEN) | below 10⁻⁴, rising to about 10⁻³ | record | 2025 | |
| Topological | Tetron lifetimes in its two measurement bases | 14.5 µs and 12.4 ms | preprint | Jul 2025 |
| “Majorana 2” parity lifetime on one wire | 22 s | vendor | Jun 2026 |
Two clocks
The table splits into two groups. Superconducting circuits and spins run gates in nanoseconds and a full cycle in about a microsecond. Ions and atoms run a cycle in milliseconds to hundreds of milliseconds, because measuring, moving and cooling take far longer than the gates. Google’s cryptography whitepaper calls these fast-clock and slow-clock machines; this post uses the same labels.
Each group pays in a different currency. The slow machines compensate with coherence: seconds against tens of microseconds, so the number of cycles a qubit survives is similar or better. They also compensate with connectivity, which buys cheaper codes: 48 logical qubits from 98 ions and 96 from 448 atoms, against roughly a thousand physical qubits per logical qubit on a grid. The fast machines compensate with repetition. A million cycles per second is what let Willow measure its improvement factor to two decimal places and test a decoder at scale in real time. Their bill comes in qubits: physical qubits per logical qubit, and wires per physical qubit.
How to read a hardware announcement
Five questions settle most of what an announcement leaves vague.
- How many qubits ran together? A fabricated dot, a loaded atom, a physical qubit and a logical qubit are different things, and they belong in separate columns.
- What is the error across the whole device? A best pair shows a component can work. The device-wide average is what a program gets.
- How long is a full cycle? A fast gate helps little when measurement, reset, transport or decoding holds up the next round.
- Which rung of the ladder is this? Error detection with post-selection, a repetition code, a logical memory below threshold and a universal set of logical gates are different claims.
- What is the date on the roadmap? “A million qubits” is a target until there is a device, a methods section and benchmark data.
Words like “foundry-made” and “all-to-all” deserve the same questions. A foundry can produce a two-qubit cell long before it produces a large array with good yield, and an ion processor can offer all-to-all connectivity while paying tens of milliseconds to move the ions.
“Logical qubit” is the phrase that most needs a footnote. Google’s is a single distance-seven memory, measured per cycle. Quantinuum’s 94 are error-detected distance-two codes and its 48 are error-corrected distance-four codes, both with post-selection. Atom Computing and Microsoft’s 24 were distance-two error-detected qubits with loss correction. Harvard’s 48 beat physical qubits through error detection. All of these are real results, each is a different object, and the fraction of runs thrown away is the cost the headline leaves out.
One outside yardstick exists. DARPA’s Quantum Benchmarking Initiative asks whether any approach can reach a useful scale by 2033. In November 2025 it moved eleven companies to its Stage B: two superconducting (IBM, Nord Quantique), two trapped-ion (IonQ, Quantinuum), two neutral-atom (Atom Computing, QuEra), three spin (Diraq, Quantum Motion, Silicon Quantum Computing) and two photonic (Xanadu, Photonic Inc.). Microsoft and PsiQuantum sit in a separate track with the same final goals. Selection is a judgement of plausibility rather than a result, and eleven companies across five platforms means the agency whose job is to pick a winner has not picked one.
What this means for cryptography
Our first article looked at the circuits for a quantum attack on elliptic-curve keys: about 1,200–1,450 logical qubits and 70–90 million Toffoli gates, the basic reversible logic operation those circuits are built from. Those are logical resources. Turning them into a physical machine takes exactly the fields in our scorecard. Google’s whitepaper does that conversion under stated assumptions: a physical error rate of one in a thousand, a surface code on a flat superconducting chip, and a ten-microsecond reaction time for the control system. It arrives at fewer than half a million physical qubits and 18–23 minutes per key, or 9–12 minutes if the part of the algorithm that does not depend on the key is precomputed.
The same whitepaper shows why the platform matters. Producing 70 million Toffoli gates in nine minutes needs half a million magic states per second. At 50,000 qubit-cycles per magic state and one-microsecond cycles, that takes 25,000 physical qubits, small next to the half million running the rest of the algorithm. At hundred-microsecond cycles, the same rate needs 2.5 million qubits for magic states alone. So on a slow-clock machine, attacks on keys already exposed on-chain arrive before attacks on a transaction in flight; on a fast-clock machine they arrive together. Cleaner qubits shrink the machine rather than the time. Microsoft’s cross-platform estimates put RSA-2048 at 37 million qubits and 6.2 years with hundred-microsecond cycles at a one-in-a-thousand error rate, and at 8.6 million qubits and 3.0 years with an error rate of one in ten thousand. With nanosecond gates and the original qubit count, the same job takes 1.5 days. Connectivity is a lever of its own: a March 2026 neutral-atom analysis using codes that need long-range connections estimates a 256-bit elliptic-curve key in about ten days on 26,000 atoms with one-millisecond cycles, a hundredth of the qubits at a thousandth of the speed.
A credible attack estimate therefore names its platform. On ions or atoms, low error and free connectivity cut the qubits per logical qubit while slow cycles stretch the wall clock. On superconducting circuits or spins, nanosecond gates give the clock while today’s error rates, local connections and wiring multiply the qubits.
Where this leaves us
Trapped ions and neutral atoms have gone furthest on the ladder, with dozens of logical qubits and logical gates on each (48 from 98 ions, up to 96 from 448 atoms). Both still rely on post-selection for that logic, and both pay with cycles of tens to hundreds of milliseconds. Superconducting circuits have the fastest clock and two processors below threshold, and no logical gate better than their physical ones yet; their bill is qubits and wiring. Spins and photonics are at the repetition-code rung, spins with manufacturing on their side and a control problem, photonics with component records and loss far above the budget. The topological qubit is still a disputed physical qubit. Nobody has reached L5, and the one agency running a cross-platform evaluation has kept eleven companies from five platforms in the race.
What each needs next: superconducting circuits, logic between logical qubits; ions, many zones and modules running in parallel at the quality of the small system; atoms, a faster clock; spins, a full logical qubit; photonics, a machine; topological qubits, an independent replication.
We keep this scorecard as a dated, sourced artifact and revise it as the numbers move. If a number here is wrong or stale, tell us, and the next revision will say who caught it.
We are not affiliated with any of the companies or research groups discussed. Every figure comes from the linked papers, preprints and first-party documents; where a number rests on a vendor specification rather than a paper, the text says so. Revised on 22 August 2026 alongside the paper version of this scorecard: records, vendor figures and roadmaps moved into their own table, the ladder corrected (the trapped-ion logical gates are marked post-selected), wording simplified.