Can quantum computers crack passwords and encryption?
Can quantum computers crack passwords? Shor breaks RSA and elliptic curves, Grover barely dents AES-256 and long passwords. What changes, when, and what to do.

On this page
Quantum computers won't crack passwords the way headlines suggest. A large enough quantum computer would break the public-key cryptography (RSA and elliptic curves) that websites and apps use to agree on keys and sign data, but it would only modestly speed up guessing passwords and symmetric keys such as AES-256. As of September 2026, no quantum computer can do either, and experts disagree on when one will.
Below, without hype: what a quantum computer really does, the two algorithms that matter, what breaks and what stays safe, why "harvest now, decrypt later" matters today, and what it all means for your passwords and notes.
What is a quantum computer, honestly?
A normal computer stores bits, each either 0 or 1. A quantum computer stores qubits, which can be in a combination of 0 and 1 at the same time (a superposition), and several qubits can be linked so that their states depend on one another (entanglement). A computation shapes these states step by step, and at the end you measure them, which gives you ordinary bits again.
You may have read that a quantum computer "tries every answer at once". That is the most common myth, and it is wrong in a way that matters. When you measure a superposition you get one random result, not a list of all results. A quantum algorithm is useful only if it can arrange the computation so that wrong answers cancel out and the right answer becomes likely before you look, much like waves that cancel or reinforce each other. That trick works spectacularly for a few problems with hidden structure, and only a little, or not at all, for most others. The computer scientist Scott Aaronson has kept this correction at the top of his blog for years.
- Qubit
- The quantum version of a bit. Physical qubits are fragile and make frequent errors, so a useful machine combines many physical qubits into one reliable "logical" qubit with error correction. Estimates for code breaking count both kinds, which is why the numbers below can look inconsistent.
The two quantum algorithms that matter for security
Almost every question about quantum computers and security comes down to two algorithms from the 1990s, one very powerful and one surprisingly weak.
Shor's algorithm: the one that breaks public-key locks
In 1994 Peter Shor showed that a quantum computer could factor large numbers and compute discrete logarithms efficiently. Those two math problems are exactly what RSA and elliptic-curve cryptography rely on. For an ordinary computer they take longer than the age of the universe at today's key sizes. For a large, error-corrected quantum computer, estimates run from minutes to days.
This matters because public-key cryptography (also called asymmetric cryptography) does two jobs on the internet:
- Key exchange. When your browser connects to a site, both sides agree on a fresh secret key without ever sending it. Today this is usually X25519, an elliptic-curve method.
- Signatures. Certificates prove you are talking to the real site, and software updates prove they came from the real vendor. These use RSA or elliptic-curve signatures such as ECDSA.
Shor's algorithm breaks both. It is not a faster way of guessing: it recovers the private key from the public key directly.
Grover's algorithm: a square-root speedup for guessing
In 1996 Lov Grover found a quantum algorithm for unstructured search: finding the one input that passes a test, such as the key that decrypts a message or the password that matches a hash. Where a classical computer needs about N tries, Grover needs about the square root of N steps. For a 128-bit key, that is roughly 2^64 steps instead of 2^128, which is why people say Grover "halves the bits".
Three facts make that less scary than it sounds:
- The steps must run one after another. It was proven in the late 1990s that the full speedup requires running the steps in series. Splitting the work across many quantum computers helps only by the square root of their number: 100 machines are 10 times faster, not 100 times.
- Each step is expensive. Every step must run the whole test (for example, a full AES encryption) as a quantum circuit with error correction, which is far slower than the same work on an ordinary chip.
- The math already has a margin. Halving 256 bits leaves 128, which is still far beyond reach.
NIST's post-quantum FAQ sums this up: Grover's algorithm "will provide little or no advantage in attacking AES", AES-128 will stay secure for decades, and current systems can keep using AES with 128-, 192- or 256-bit keys.
Public-key locks
Broken
Symmetric locks
Weakened, not broken
Will quantum computers break encryption? What breaks and what stays safe
"Encryption" covers several different tools, and quantum computers affect them very differently. Here is the short version, based on NIST's draft transition plan, NIST IR 8547, and its PQC FAQ.
| Tool | What it does | Quantum attack | Verdict |
|---|---|---|---|
| RSA, Diffie-Hellman, elliptic curves (X25519, ECDSA) | Key exchange and signatures | Shor | Broken once a large machine exists. Being replaced now |
| AES-128 | Encrypts data | Grover | Weakened on paper. NIST expects it to stay secure for decades |
| AES-256 | Encrypts data | Grover | Safe. Still about 128 bits of effort even for Grover |
| SHA-256 | Fingerprints data | Grover | Fine. NIST uses it as a yardstick for its post-quantum security levels |
| Argon2id, bcrypt, scrypt | Store and check passwords | Grover | Little practical change. The password's strength decides |
| A password itself | Proves it is you | Grover, on stolen hashes only | Long random passwords stay safe. Weak ones were already weak |
The pattern is simple. Anything whose security rests on a public key needs to be replaced. Anything that rests on a secret shared or derived in advance (a symmetric key, a hash, a password) needs at most a bigger margin, and good choices already have one.
Can quantum computers crack passwords?
Start with how passwords are cracked today. Attackers steal a database of password hashes, then guess on their own graphics cards, as fast as the storage method allows. With a fast hash like MD5, one RTX 5090 card manages about 220 billion guesses per second. With a slow, memory-hungry method like Argon2id at Cappa's settings (64 MiB of memory, 3 passes), our estimate is about 3,000 guesses per second per top card; our master password guide explains where these numbers come from. And most real accounts fall to something simpler still: phishing, malware or a password reused from an old breach.
Grover's algorithm could, in principle, search the space of possible passwords faster. But look at what the "test" in each Grover step would be: a full run of the password hash, as a quantum circuit. For Argon2id, that means touching 64 MiB of memory three times, with the memory itself held in qubits. As a thought experiment: 64 MiB is about 537 million bits, while the latest estimates for breaking elliptic-curve cryptography need about 1,200 to 1,450 logical qubits in total. A naive circuit that simply held Argon2id's memory in qubits would need hundreds of thousands of times more. That is an illustration, not a proven minimum: cleverer attacks can trade memory for time, so this memory-size comparison does not establish the minimum qubits needed to attack Argon2id. Research on quantum attacks against memory-hard functions is young; this 2021 paper models them for Argon2i and related designs and measures their cost as circuit width times depth.
An experiment in the attacker's favor
To see the most Grover could possibly do, we compared two attackers who stole a database protected with Cappa's Argon2id settings:
- A classical cluster of 10,000 top graphics cards, making 30 million guesses per second: the same pessimistic scenario as in our master password guide.
- One imaginary, idealized quantum computer running Grover's algorithm. We assume it evaluates one Argon2id guess in 0.01 seconds (in our test, one laptop core needs about 75 milliseconds, so this is seven times faster), has all the error-corrected memory it needs, and pays only one evaluation per Grover step, although a real circuit needs at least two. No machine like this exists or appears on any published roadmap.
Three things stand out. First, Grover really does shrink the numbers for strong passwords. Second, it is slower than ordinary hardware for weak passwords: a list of a billion leaked passwords falls in seconds on graphics cards, which test guesses in parallel, while Grover must take its steps one by one. Third, the defense is the same as always: more random bits. Seven random words push even the idealized machine to about 10,000 years.
So quantum computers do not change the advice: for anything that protects encrypted data, such as a master password, let a generator choose six or more random words or 16 or more random characters.
Harvest now, decrypt later: why it matters today
If no quantum computer can break anything yet, why is everyone rushing? Because of a strategy called harvest now, decrypt later. An attacker who can record internet traffic today, a well-funded intelligence agency for example, can store it for years and decrypt it once a large quantum computer exists.
Today
Later
Readable
This is why the U.S. government's June 2026 executive order on post-quantum cryptography names the risk of adversaries collecting data now to decrypt later, and why key exchange is being upgraded first. Google's 2029 migration timeline puts it plainly: the threat to encryption "is relevant today", while the threat to signatures lies in the future. A forged signature only helps an attacker who has a quantum computer at the moment of the attack; a recording can wait.
What is at risk is data that must stay secret for a long time: medical and legal records, business plans, private diaries and messages, anything sent over a connection whose key was agreed with RSA or elliptic curves alone. It also covers files encrypted "to" a public key, such as PGP email.
The fix is already rolling out. Current versions of all major browsers combine the classical key exchange with the post-quantum ML-KEM, and more than 65% of human traffic to Cloudflare was protected this way as of April 2026. Our post-quantum cryptography explainer covers how that works.
When will a quantum computer break RSA? What experts estimate
The honest answer is that nobody knows. What we can do is look at three kinds of evidence: how big a machine the attack needs, how big machines are today, and what experts and large organizations expect.
How big a machine the attack needs
Estimates have fallen sharply, mostly thanks to better algorithms and error correction rather than bigger hardware:
| Published | Who | Target | Estimated machine |
|---|---|---|---|
| 2019 | Gidney and Ekerå | RSA-2048 | about 20 million noisy qubits, about 8 hours |
| May 2025 | Gidney (Google) | RSA-2048 | fewer than 1 million noisy qubits, under a week |
| March 2026 | Babbush, Gidney, Boneh and others (Google) | 256-bit elliptic curves | fewer than 500,000 physical qubits, minutes |
| March 2026 | Cain, Preskill and others (Caltech, Oratomic) | P-256 and RSA-2048 | as few as 10,000 atom qubits; P-256 in days with 26,000, RSA-2048 10 to 100 times longer |
All of these assume hardware that does not exist yet: qubits with error rates around 0.1%, working together by the hundreds of thousands (or, for neutral atoms, tens of thousands) for days. Note also that elliptic curves, the cryptography most of the web now uses for key exchange, look easier to break than RSA.
How big machines are today
Google's Willow chip (December 2024) has 105 physical qubits and showed that error correction gets better as it scales up, an important milestone. IBM's roadmap targets a machine called Starling with 200 logical qubits in 2029. Neutral-atom labs have trapped arrays of more than 6,000 atoms, though not yet computing with all of them in an error-corrected way. None of these can run Shor's algorithm against a real key, and public demonstrations remain tiny: a widely reported 2024 "RSA break" on a D-Wave machine concerned a 22-bit number, while real keys are 2,048 bits.
What experts and institutions expect
- The Global Risk Institute's Quantum Threat Timeline Report 2025, published in March 2026, surveyed 26 experts. On average they put the chance of a machine that can break RSA-2048 within 24 hours at 28% to 49% within 10 years and 51% to 70% within 15 years. The report came out before the two March 2026 papers above.
- In March 2026 Google moved its own migration deadline to 2029, and in April 2026 Cloudflare did the same.
- NIST's draft plan, IR 8547 (an initial public draft from November 2024, not yet final as of September 2026), proposes deprecating RSA and elliptic-curve algorithms at the 112-bit security level (such as RSA-2048) after 2030 and disallowing all of them after 2035.
- The June 2026 U.S. executive order directs federal agencies to move high-value and high-impact systems to post-quantum key establishment by the end of 2030 and to post-quantum signatures by the end of 2031. The EU's coordinated roadmap (June 2025) asks member states to start by the end of 2026 and protect high-risk uses by the end of 2030.
What this means for your notes in Cappa
Cappa encrypts your notes in your browser with AES-256-GCM, using a random 256-bit vault key. That vault key is stored on the server only in wrapped form, encrypted with keys your browser derives from your master password (Argon2id with 64 MiB of memory and 3 passes, then HKDF-SHA-256) and, separately, from your recovery code. No public-key cryptography is involved in encrypting or unlocking your notes, so there is nothing for Shor's algorithm to attack there. See AES-256 explained and Argon2 explained for how those pieces work.
What a future quantum computer could still do is what a classical attacker can do already: guess your master password offline after stealing a copy of the database, paying the Argon2id cost for every guess. The chart above shows why a long random master password keeps that out of reach either way.
The connection to Cappa is a different matter, because like every website it relies on TLS, which uses public-key cryptography. Cappa's traffic goes through Cloudflare, which terminates TLS. In our test in September 2026, cappa.page negotiated the hybrid post-quantum key exchange X25519MLKEM768 with a client that offered it, so current browsers get post-quantum key exchange automatically.
Even if someone recorded a connection from an older browser without it and broke it years later, your notes inside would still be AES ciphertext. The recording would show what Cappa's security documentation describes for someone watching traffic behind TLS: ciphertext, metadata, session cookies and the sign-in key your browser derives from your master password. It would not contain your master password or your vault key. Someone holding that sign-in key could try to guess your master password offline, again at the full Argon2id cost per guess, and until you change your master password could use it to sign in to your account, though still not to read your notes.
What you can do today
- Keep your browser and operating system updated. Post-quantum key exchange arrives through updates, with nothing to switch on. You can check your browser at Cloudflare's test page.
- Use long random passwords for anything that protects encrypted data. Six random words or 16 or more random characters; add a word if the data must stay secret for decades.
- Use a password manager and never reuse passwords. Reused and phished passwords are how accounts fall today.
- Choose tools that encrypt your data on your device with keys only you hold, so stored data does not depend on a public-key lock. The idea is explained in end-to-end encrypted notes.
- For long-lived secrets, prefer messengers and services that already use post-quantum key exchange, such as Signal and iMessage.
FAQ
Is AES-256 quantum safe?
Yes, as far as anyone knows. Grover's algorithm would at best reduce a 256-bit key to about 128 bits of effort, which is still far out of reach, and NIST notes that the attack parallelizes poorly. The U.S. NSA's quantum-resistant CNSA 2.0 suite for national security systems keeps AES-256 as its cipher.
Has a quantum computer already broken RSA?
No. Headlines in 2024 about a quantum "RSA break" concerned a 22-bit number, while real RSA keys are 2,048 bits and the difference grows exponentially. The latest estimates say the job needs hundreds of thousands to about a million high-quality qubits working together, far more than any machine has as of September 2026.
Do I need to change my passwords because of quantum computers?
No. A quantum computer does not make a strong, unique password guessable, and it does little against weak ones that ordinary hardware does not already do faster. Change a password when it is weak, reused or possibly exposed, and use a password manager.
What is Q-Day?
Q-Day is the informal name for the day a quantum computer can break today's public-key cryptography, often measured by factoring a 2,048-bit RSA key. Nobody knows the date. Surveyed experts on average consider it more likely than not within 15 years, and several governments and companies aim to finish switching between 2029 and 2035.
Are passwords stored with Argon2id quantum safe?
Argon2id itself is not the weak point: a quantum attacker would still have to run it for every guess, with its memory held in scarce qubits. What decides whether a stolen hash can be cracked is the password behind it. A long random password stays out of reach, and a short or common one is already at risk from graphics cards.


