Skip to content
ContentLora

    Tip: press / anywhere to search.

    Explainer

    What quantum computers are good for (and what they are not)

    Quantum computers are expected to excel at simulating molecules and materials and at breaking some public-key encryption, not at speeding up ordinary computing.[1][2] As of October 2026, demonstrated speed-ups are on scientific benchmarks; useful applications still wait on fault-tolerant machines with hundreds to thousands of logical qubits.[3][4]

    Editor reviewedUpdated Quantum computingComputingPhysics

    Not a faster computer, a different one

    A quantum computer is not a faster laptop. It is expected to be very good at a few kinds of problems, especially imitating how atoms and molecules behave and finding hidden patterns and structures in information.[1] For most everyday tasks an ordinary computer will stay better and cheaper.

    The strongest-founded applications are problems with special structure, notably simulating quantum systems and the cryptanalysis enabled by Shor’s algorithm.[5][2] Every candidate application has to beat classical algorithms that keep improving, as IBM’s 2026 advantage claims showed when one was reproduced on GPUs.[6]

    Simulating nature

    Molecules and materials obey quantum mechanics, so a quantum computer could in principle model them directly.[5] Google says its goal is a useful, beyond-classical computation relevant to a real application, and it cites drug discovery, battery design and energy research.[7] In October 2025 its Quantum Echoes experiment measured a physical quantity on Willow about 13,000 times faster than the Frontier supercomputer could, and a companion study applied the method to nuclear magnetic resonance of molecules, though not yet beyond classical reach.[8][3] In July 2026 IBM and Algorithmiq claimed advantage on a simulation of heterogeneous quantum matter.[9]

    Breaking encryption

    Shor’s algorithm would let a large fault-tolerant quantum computer break the public-key encryption that secures much of the internet, which is why NIST has led the development of post-quantum cryptography.[2] Estimates of the hardware needed keep shrinking. In 2019 the figure for 2048-bit RSA was 20 million noisy qubits; a May 2025 estimate brought it under one million.[10][11] In March 2026 Google estimated that 256-bit elliptic-curve cryptography, used widely including in cryptocurrencies, could fall to fewer than 1,200 logical qubits, or fewer than 500,000 physical qubits running for minutes.[4] Google released that estimate with zero-knowledge proofs rather than full attack details.[12]

    For comparison, the largest error-corrected demonstrations in 2026 involve dozens of logical qubits, not thousands.[13][14]

    Benchmarks versus useful work

    Most “beyond classical” results so far are benchmarks designed to be hard for classical computers, such as random circuit sampling. Google said Willow did such a task in under five minutes that would take a supercomputer 10 septillion years, and China’s Zuchongzhi 3.0 reported a similar task as 10^15 times faster than a supercomputer.[15][16] These show the hardware doing something classically hard, but their outputs are random bitstrings that cannot be independently reproduced, which is why Google stressed that its later Quantum Echoes result was verifiable.[17] The IBM-backed quantum advantage tracker was created so claims of useful advantage can be tested by others.[18]

    The yardstick: logical qubits and operations

    The useful milestones are stated in logical qubits and operations. IBM targets 200 logical qubits running 100 million operations by 2029, and 2,000 logical qubits by 2033.[19][20] DARPA defines utility scale as the point where a quantum computer’s computational value exceeds its cost, and is testing whether any approach can reach it by 2033.[21]

    Questions readers ask

    Will quantum computers replace my laptop?

    No. They are expected to help with specific tasks such as modelling physical systems, not with everyday computing.[1]

    How big a quantum computer would break RSA encryption?

    A 2025 Google estimate said fewer than a million noisy physical qubits running for under a week could factor a 2048-bit RSA number. No such machine exists yet.[11]

    Has a quantum computer solved a real-world problem faster than a classical one?

    Not convincingly. Google's Quantum Echoes ran a physics benchmark 13,000 times faster than Frontier, but its molecular-structure follow-up was not yet beyond classical simulation.[8][3]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      Quantum computers are expected to be best at modelling physical systems and finding patterns and structures in information, with possible uses in chemistry and pharmaceuticals. confirmedas of 2026-10-10

    2. [2]

      NIST leads development of post-quantum cryptography to protect data from future quantum computers that could break widely used encryption. confirmedas of 2026-10-10

    3. [3]

      A companion Google study applied the echo technique to nuclear magnetic resonance measurements of molecular structure, but those results were not yet beyond classical simulation. confirmedas of 2025-10-22

    4. [4]

      In March 2026 Google researchers, in work framed around safeguarding cryptocurrency, estimated that 256-bit elliptic-curve cryptography could be broken with fewer than 1,200 logical qubits and 90 million Toffoli gates, or fewer than 500,000 physical superconducting qubits running for a few minutes, under standard hardware assumptions. confirmedas of 2026-03-31

    5. [5]

      NIST describes quantum computers as a new kind of machine that can, in theory, simulate the quantum nature of matter and tackle certain problems that are currently unsolvable. confirmedas of 2026-10-10

    6. [6]

      An August 2026 preprint reported classically reproducing all 2,051 amplitude batches of IBM's 70-qubit doped Clifford sampling experiment in 37.3 minutes on 256 NVIDIA H100 GPUs, with results compatible with IBM's fidelity bound. reportedas of 2026-08-13

    7. [7]

      Google's stated next goal is a first useful, beyond-classical computation relevant to a real-world application, citing areas such as drug discovery, battery design and energy research. confirmedas of 2024-12-09

    8. [8]

      On 22 October 2025 Google reported in Nature that its Quantum Echoes (out-of-time-order correlator) algorithm ran on Willow in about two hours, a task it estimated would take 13,000 times longer on the Frontier supercomputer. confirmedas of 2025-10-22

    9. [9]

      On 30 July 2026 IBM and Algorithmiq claimed quantum advantage for a simulation of heterogeneous quantum matter run on IBM's Heron processor, a problem posted on the quantum advantage tracker about eight months earlier. confirmedas of 2026-07-30

    10. [10]

      A 2019 estimate co-published by the same author put the requirement at 20 million noisy qubits running for eight hours to factor 2048-bit RSA. confirmedas of 2025-05-21

    11. [11]

      A May 2025 Google preprint estimated that a 2048-bit RSA integer could be factored in less than a week by a quantum computer with fewer than a million noisy qubits. confirmedas of 2025-05-21

    12. [12]

      Google said it used zero-knowledge proofs to let others verify its elliptic-curve resource estimate without publishing sensitive attack details. confirmedas of 2026-03-31

    13. [13]

      In March 2026 Quantinuum researchers reported computations with up to 94 error-detected and 48 error-corrected logical qubits on Helios, using iceberg and concatenated codes, with logical gate errors around one in ten thousand - better than the physical gates. confirmedas of 2026-03-10

    14. [14]

      On 24 September 2026 Infleqtion reported entangling 30 logical qubits encoded in 80 physical neutral-atom qubits on its Sqale system, in a circuit of about 1,000 physical operations, and said it targets 100 logical qubits by 2028. reportedas of 2026-09-24

    15. [15]

      Google said Willow performed a random circuit sampling computation in under five minutes that would take one of the fastest supercomputers 10 septillion years. confirmedas of 2024-12-09

    16. [16]

      The University of Science and Technology of China reported in Physical Review Letters in March 2025 that its 105-qubit Zuchongzhi 3.0 superconducting processor ran an 83-qubit, 32-layer random circuit sampling task it estimated at 10^15 times faster than the most powerful supercomputer. confirmedas of 2025-03-06

    17. [17]

      Google called the Quantum Echoes result verifiable because its outputs are physical expectation values that another quantum computer or a natural quantum system can reproduce, unlike random bitstrings. confirmedas of 2025-10-22

    18. [18]

      IBM said in November 2025 that it expected verified quantum advantage by the end of 2026 and launched an open quantum advantage tracker with partners to monitor and test claims. confirmedas of 2025-11-12

    19. [19]

      In June 2025 IBM said it would build IBM Quantum Starling, a fault-tolerant quantum computer with 200 logical qubits able to run 100 million quantum operations, in Poughkeepsie, New York, by 2029. confirmedas of 2025-06-10

    20. [20]

      IBM's roadmap follows Starling with Blue Jay in 2033, targeting 2,000 logical qubits and 1 billion operations. confirmedas of 2025-06-10

    21. [21]

      DARPA's Quantum Benchmarking Initiative aims to determine whether any quantum computing approach can reach utility-scale operation - computational value exceeding cost - by 2033. confirmedas of 2026-10-07

    Revision history (1)
    1. Page created.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "What quantum computers are good for (and what they are not)." ContentLora, updated Oct 10, 2026. https://contentlora.com/explain/what-quantum-computers-are-good-for

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.