Can quantum computers crack passwords and encryption?

Can quantum computers crack passwords? Shor breaks RSA and elliptic curves, Grover barely dents AES-256 and long passwords. What changes, when, and what to do.

A calm capybara in a quiet laboratory looks up at a large quantum computer, a tiered chandelier-like cooling unit with coiled cables hanging from the ceiling, while holding a very long, intricate key close to its chest.
On this page

Can quantum computers crack passwords? Not in the way headlines suggest. A large enough quantum computer would break the public-key cryptography (RSA and elliptic curves) that websites and apps use to agree on keys and sign data, but it would only modestly speed up guessing passwords and symmetric keys such as AES-256. As of September 2026, no quantum computer can do either, and experts disagree on when one will.

Below, without hype: what a quantum computer really does, the two algorithms that matter, what breaks and what stays safe, why "harvest now, decrypt later" matters today, and what it all means for your passwords and notes.

What is a quantum computer, honestly?

A normal computer stores bits, each either 0 or 1. A quantum computer stores qubits, which can be in a combination of 0 and 1 at the same time (a superposition), and several qubits can be linked so that their states depend on one another (entanglement). A computation shapes these states step by step, and at the end you measure them, which gives you ordinary bits again.

You may have read that a quantum computer "tries every answer at once". That is the most common myth, and it is wrong in a way that matters. When you measure a superposition you get one random result, not a list of all results. A quantum algorithm is useful only if it can arrange the computation so that wrong answers cancel out and the right answer becomes likely before you look, much like waves that cancel or reinforce each other. That trick works spectacularly for a few problems with hidden structure, and only a little, or not at all, for most others. The computer scientist Scott Aaronson has kept this correction at the top of his blog for years.

Qubit
The quantum version of a bit. Physical qubits are fragile and make frequent errors, so a useful machine combines many physical qubits into one reliable "logical" qubit with error correction. Estimates for code breaking count both kinds, which is why the numbers below can look inconsistent.

The two quantum algorithms that matter for security

Almost every question about quantum computers and security comes down to two algorithms from the 1990s, one very powerful and one surprisingly weak.

Shor's algorithm: the one that breaks public-key locks

In 1994 Peter Shor showed that a quantum computer could factor large numbers and compute discrete logarithms efficiently. Those two math problems are exactly what RSA and elliptic-curve cryptography rely on. For an ordinary computer they take longer than the age of the universe at today's key sizes. For a large, error-corrected quantum computer, estimates run from minutes to days.

This matters because public-key cryptography (also called asymmetric cryptography) does two jobs on the internet:

  • Key exchange. When your browser connects to a site, both sides agree on a fresh secret key without ever sending it. Today this is usually X25519, an elliptic-curve method.
  • Signatures. Certificates prove you are talking to the real site, and software updates prove they came from the real vendor. These use RSA or elliptic-curve signatures such as ECDSA.

Shor's algorithm breaks both. It is not a faster way of guessing: it recovers the private key from the public key directly.

Grover's algorithm: a square-root speedup for guessing

In 1996 Lov Grover found a quantum algorithm for unstructured search: finding the one input that passes a test, such as the key that decrypts a message or the password that matches a hash. Where a classical computer needs about N tries, Grover needs about the square root of N steps. For a 128-bit key, that is roughly 2^64 steps instead of 2^128, which is why people say Grover "halves the bits".

Three facts make that less scary than it sounds:

  1. The steps must run one after another. It was proven in the late 1990s that the full speedup requires running the steps in series. Splitting the work across many quantum computers helps only by the square root of their number: 100 machines are 10 times faster, not 100 times.
  2. Each step is expensive. Every step must run the whole test (for example, a full AES encryption) as a quantum circuit with error correction, which is far slower than the same work on an ordinary chip.
  3. The math already has a margin. Halving 256 bits leaves 128, which is still far beyond reach.

NIST's post-quantum FAQ sums this up: Grover's algorithm "will provide little or no advantage in attacking AES", AES-128 will stay secure for decades, and current systems can keep using AES with 128-, 192- or 256-bit keys.

Public-key locks

RSA and elliptic curves. Agree on keys and sign certificates and updates.
Shor's algorithm

Broken

A large quantum computer recovers the private key. Being replaced by post-quantum algorithms.

Symmetric locks

AES, SHA-256, Argon2id. Encrypt stored data and check passwords.
Grover's algorithm

Weakened, not broken

Guessing gets a square-root speedup at best. Big keys and long random passwords stay out of reach.
Two kinds of locks, two quantum algorithms. Shor's algorithm breaks the public-key locks used to agree on keys and sign things. Grover's algorithm only speeds up guessing against the symmetric locks that protect the data itself.

Will quantum computers break encryption? What breaks and what stays safe

"Encryption" covers several different tools, and quantum computers affect them very differently. Here is the short version, based on NIST's draft transition plan, NIST IR 8547, and its PQC FAQ.

ToolWhat it doesQuantum attackVerdict
RSA, Diffie-Hellman, elliptic curves (X25519, ECDSA)Key exchange and signaturesShorBroken once a large machine exists. Being replaced now
AES-128Encrypts dataGroverWeakened on paper. NIST expects it to stay secure for decades
AES-256Encrypts dataGroverSafe. Still about 128 bits of effort even for Grover
SHA-256Fingerprints dataGroverFine. NIST uses it as a yardstick for its post-quantum security levels
Argon2id, bcrypt, scryptStore and check passwordsGroverLittle practical change. The password's strength decides
A password itselfProves it is youGrover, on stolen hashes onlyLong random passwords stay safe. Weak ones were already weak

The pattern is simple. Anything whose security rests on a public key needs to be replaced. Anything that rests on a secret shared or derived in advance (a symmetric key, a hash, a password) needs at most a bigger margin, and good choices already have one.

Can quantum computers crack passwords?

Start with how passwords are cracked today. Attackers steal a database of password hashes, then guess on their own graphics cards, as fast as the storage method allows. With a fast hash like MD5, one RTX 5090 card manages about 220 billion guesses per second. With a slow, memory-hungry method like Argon2id at Cappa's settings (64 MiB of memory, 3 passes), our estimate is about 3,000 guesses per second per top card; our master password guide explains where these numbers come from. And most real accounts fall to something simpler still: phishing, malware or a password reused from an old breach.

Grover's algorithm could, in principle, search the space of possible passwords faster. But look at what the "test" in each Grover step would be: a full run of the password hash, as a quantum circuit. For Argon2id, that means touching 64 MiB of memory three times, with the memory itself held in qubits. 64 MiB is about 537 million bits. The latest estimates for breaking elliptic-curve cryptography need about 1,200 to 1,450 logical qubits in total; a straightforward quantum Argon2id would need hundreds of thousands of times more just to hold its memory. Researchers have only begun to analyze quantum attacks on memory-hard functions, and the early results confirm that memory and reversibility make them costly.

An experiment in the attacker's favor

To see the most Grover could possibly do, we compared two attackers who stole a database protected with Cappa's Argon2id settings:

  1. A classical cluster of 10,000 top graphics cards, making 30 million guesses per second: the same pessimistic scenario as in our master password guide.
  2. One imaginary, idealized quantum computer running Grover's algorithm. We assume it evaluates one Argon2id guess in 0.01 seconds (in our test, one laptop core needs about 75 milliseconds, so this is seven times faster), has all the error-corrected memory it needs, and pays only one evaluation per Grover step, although a real circuit needs at least two. No machine like this exists or appears on any published roadmap.
A password from a list of 1 billion known passwords: GPU clusterabout 17 seconds
Same list: idealized quantum computerabout 4 minutes
4 random words: GPU clusterabout 2 years
4 random words: idealized quantum computerabout 5 days
6 random words: GPU clusterabout 120 million years
6 random words: idealized quantum computerabout 120 years
16 random keyboard characters: GPU clusterabout 2 × 10¹⁶ years
16 random keyboard characters: idealized quantum computerabout 1.5 million years

Logarithmic scale: each step in bar length is ten times more time. Bar length is the base-10 logarithm of the time in seconds.

Average time to find passwords of different types after a database theft, if every guess costs one Argon2id run (64 MiB, 3 passes). Classical: 10,000 graphics cards at 30 million guesses per second in total. Quantum: a hypothetical, deliberately generous machine taking about 0.785 × √N Grover steps of 0.01 seconds each. Keyboard characters means the 94 printable ASCII symbols. Our estimates, as of September 2026.

Three things stand out. First, Grover really does shrink the numbers for strong passwords. Second, it is slower than ordinary hardware for weak passwords: a list of a billion leaked passwords falls in seconds on graphics cards, which test guesses in parallel, while Grover must take its steps one by one. Third, the defense is the same as always: more random bits. Seven random words push even the idealized machine to about 10,000 years.

So quantum computers do not change the advice: for anything that protects encrypted data, such as a master password, let a generator choose six or more random words or 16 or more random characters.

Harvest now, decrypt later: why it matters today

If no quantum computer can break anything yet, why is everyone rushing? Because of a strategy called harvest now, decrypt later. An attacker who can record internet traffic today, a well-funded intelligence agency for example, can store it for years and decrypt it once a large quantum computer exists.

Today

Someone records an encrypted connection, including the key exchange.
stored for years

Later

Shor's algorithm recovers the session key from the recorded key exchange.
decrypts

Readable

Everything sent in that session, if it was not encrypted again inside.
Harvest now, decrypt later. The attack only needs a recording today and a quantum computer later. It works against traffic whose session key was agreed with classical public-key cryptography alone.

This is why the U.S. government's June 2026 executive order on post-quantum cryptography names the risk of adversaries collecting data now to decrypt later, and why key exchange is being upgraded first. Google's 2029 migration timeline puts it plainly: the threat to encryption "is relevant today", while the threat to signatures lies in the future. A forged signature only helps an attacker who has a quantum computer at the moment of the attack; a recording can wait.

What is at risk is data that must stay secret for a long time: medical and legal records, business plans, private diaries and messages, anything sent over a connection whose key was agreed with RSA or elliptic curves alone. It also covers files encrypted "to" a public key, such as PGP email.

The fix is already rolling out. Current versions of all major browsers combine the classical key exchange with the post-quantum ML-KEM, and more than 65% of human traffic to Cloudflare was protected this way as of April 2026. Our post-quantum cryptography explainer covers how that works.

When will a quantum computer break RSA? What experts estimate

The honest answer is that nobody knows. What we can do is look at three kinds of evidence: how big a machine the attack needs, how big machines are today, and what experts and large organizations expect.

How big a machine the attack needs

Estimates have fallen sharply, mostly thanks to better algorithms and error correction rather than bigger hardware:

PublishedWhoTargetEstimated machine
2019Gidney and EkeråRSA-2048about 20 million noisy qubits, about 8 hours
May 2025Gidney (Google)RSA-2048fewer than 1 million noisy qubits, under a week
March 2026Babbush, Gidney, Boneh and others (Google)256-bit elliptic curvesfewer than 500,000 physical qubits, minutes
March 2026Cain, Preskill and others (Caltech, Oratomic)P-256 and RSA-2048as few as 10,000 atom qubits; P-256 in days with 26,000, RSA-2048 10 to 100 times longer

All of these assume hardware that does not exist yet: qubits with error rates around 0.1%, working together by the hundreds of thousands (or, for neutral atoms, tens of thousands) for days. Note also that elliptic curves, the cryptography most of the web now uses for key exchange, look easier to break than RSA.

How big machines are today

Google's Willow chip (December 2024) has 105 physical qubits and showed that error correction gets better as it scales up, an important milestone. IBM's roadmap targets a machine called Starling with 200 logical qubits in 2029. Neutral-atom labs have trapped arrays of more than 6,000 atoms, though not yet computing with all of them in an error-corrected way. None of these can run Shor's algorithm against a real key, and public demonstrations remain tiny: a widely reported 2024 "RSA break" on a D-Wave machine concerned a 22-bit number, while real keys are 2,048 bits.

What experts and institutions expect

  • The Global Risk Institute's Quantum Threat Timeline Report 2025, published in March 2026, surveyed 26 experts. On average they put the chance of a machine that can break RSA-2048 within 24 hours at 28% to 49% within 10 years and 51% to 70% within 15 years. The report came out before the two March 2026 papers above.
  • In March 2026 Google moved its own migration deadline to 2029, and in April 2026 Cloudflare did the same.
  • NIST's draft plan, IR 8547 (an initial public draft from November 2024, not yet final as of September 2026), proposes deprecating RSA and elliptic-curve algorithms at the 112-bit security level (such as RSA-2048) after 2030 and disallowing all of them after 2035.
  • The June 2026 U.S. executive order directs federal agencies to move high-value and high-impact systems to post-quantum key establishment by the end of 2030 and to post-quantum signatures by the end of 2031. The EU's coordinated roadmap (June 2025) asks member states to start by the end of 2026 and protect high-risk uses by the end of 2030.

What this means for your notes in Cappa

Cappa encrypts your notes in your browser with AES-256-GCM, using a random 256-bit vault key. That vault key is stored on the server only in wrapped form, encrypted with keys your browser derives from your master password (Argon2id with 64 MiB of memory and 3 passes, then HKDF-SHA-256) and, separately, from your recovery code. No public-key cryptography is involved in encrypting or unlocking your notes, so there is nothing for Shor's algorithm to attack there. See AES-256 explained and Argon2 explained for how those pieces work.

What a future quantum computer could still do is what a classical attacker can do already: guess your master password offline after stealing a copy of the database, paying the Argon2id cost for every guess. The chart above shows why a long random master password keeps that out of reach either way.

The connection to Cappa is a different matter, because like every website it relies on TLS, which uses public-key cryptography. Cappa's traffic goes through Cloudflare, which terminates TLS. In our test in September 2026, cappa.page negotiated the hybrid post-quantum key exchange X25519MLKEM768 with a client that offered it, so current browsers get post-quantum key exchange automatically.

Even if someone recorded a connection from an older browser without it and broke it years later, your notes inside would still be AES ciphertext. The recording would show what Cappa's security documentation describes for someone watching traffic behind TLS: ciphertext, metadata, session cookies and the sign-in key your browser derives from your master password. It would not contain your master password or your vault key. Someone holding that sign-in key could try to guess your master password offline, again at the full Argon2id cost per guess, and until you change your master password could use it to sign in to your account, though still not to read your notes.

What you can do today

  1. Keep your browser and operating system updated. Post-quantum key exchange arrives through updates, with nothing to switch on. You can check your browser at Cloudflare's test page.
  2. Use long random passwords for anything that protects encrypted data. Six random words or 16 or more random characters; add a word if the data must stay secret for decades.
  3. Use a password manager and never reuse passwords. Reused and phished passwords are how accounts fall today.
  4. Choose tools that encrypt your data on your device with keys only you hold, so stored data does not depend on a public-key lock. The idea is explained in end-to-end encrypted notes.
  5. For long-lived secrets, prefer messengers and services that already use post-quantum key exchange, such as Signal and iMessage.

FAQ

Is AES-256 quantum safe?

Yes, as far as anyone knows. Grover's algorithm would at best reduce a 256-bit key to about 128 bits of effort, which is still far out of reach, and NIST notes that the attack parallelizes poorly. The U.S. NSA's quantum-resistant CNSA 2.0 suite for national security systems keeps AES-256 as its cipher.

Has a quantum computer already broken RSA?

No. Headlines in 2024 about a quantum "RSA break" concerned a 22-bit number, while real RSA keys are 2,048 bits and the difference grows exponentially. The latest estimates say the job needs hundreds of thousands to about a million high-quality qubits working together, far more than any machine has as of September 2026.

Do I need to change my passwords because of quantum computers?

No. A quantum computer does not make a strong, unique password guessable, and it does little against weak ones that ordinary hardware does not already do faster. Change a password when it is weak, reused or possibly exposed, and use a password manager.

What is Q-Day?

Q-Day is the informal name for the day a quantum computer can break today's public-key cryptography, often measured by factoring a 2,048-bit RSA key. Nobody knows the date. Surveyed experts on average consider it more likely than not within 15 years, and several governments and companies aim to finish switching between 2029 and 2035.

Are passwords stored with Argon2id quantum safe?

Argon2id itself is not the weak point: a quantum attacker would still have to run it for every guess, with its memory held in scarce qubits. What decides whether a stolen hash can be cracked is the password behind it. A long random password stays out of reach, and a short or common one is already at risk from graphics cards.

Written by the Cappa team

We build Cappa, a private Markdown notes app that encrypts your notes on your device before they are synced. We write about the decisions behind it, including the limits, so you can judge them yourself.