Hardware
Quantum Computing
Hardware
A quantum algorithm is only as good as the machine underneath it. Five very different technologies are competing to be that machine, and each one is good at something the others are bad at: some hold information for a long time but operate slowly, others are fast but forget almost immediately. Those trade-offs decide when — and whether — a quantum computer will ever be able to break the encryption protecting the internet. This page looks at what the hardware can actually do today, and how far that is from what codebreaking would require.
Reading the Numbers
What a Qubit Has to Survive
A classical bit is a switch: it stays where you put it until something moves it. A qubit is more like a spinning coin caught mid-flip — it holds a blend of both answers at once, and the blend is what makes quantum computing powerful. It is also extremely delicate. A stray vibration, a wisp of heat, a passing magnetic field, and the coin lands. The computation is over.
Everything in quantum hardware engineering follows from that one fact. Build the qubit out of something that barely interacts with the world, and it survives longer — but then it is also hard for you to talk to. Make it easy to control, and the environment finds it just as easily. Every platform on this page is a different answer to that same trade-off.
The Four Numbers Everyone Quotes
How long it lasts. Coherence time is how long a qubit keeps its state before noise wipes it out. The headline figure is usually T1 (energy decay), measured in microseconds for superconducting chips and in seconds for trapped ions.
How fast it works. Gate speed is how long one operation takes. Superconducting circuits are the sprinters (tens of nanoseconds); trapped ions are far slower (microseconds to milliseconds). What actually matters is the ratio: how many operations fit inside one coherence time.
How often it gets it right. Fidelity is the accuracy of an operation. The number to watch is two-qubit gate fidelity, because operations that entangle a pair of qubits are the hardest and the most error-prone. 99.9% sounds excellent until you remember a useful algorithm may need billions of gates.
How many talk to each other. Connectivity is which qubits can directly interact. Trapped ions and neutral atoms can pair up any two qubits (all-to-all connectivity); superconducting chips only connect neighbours on a grid, so distant qubits need chains of extra operations that each add error.
Raw qubit count — the number in the press release — is the least informative figure of the five. A hundred good qubits beat a thousand bad ones, because errors compound.
Physical Implementations of Qubits
Superconducting Qubits — Speed and Scale
How Superconducting Qubits Work — and Where They Are Now
A superconducting qubit is a tiny electrical circuit, printed on a chip much like an ordinary microprocessor, and then cooled until the metal loses all electrical resistance. At that point the circuit stops behaving like a wire and starts behaving like an artificial atom with distinct energy levels, two of which are used as the 0 and 1 (the standard design is a transmon, built around a Josephson junction). Because they are fabricated rather than found in nature, they can be designed and mass-produced — which is why this platform is the most industrially advanced.
IBM Nighthawk, announced in November 2025, is the current flagship: 120 qubits wired together by 218 tunable couplers in a square grid, roughly 20% more connections than the previous Heron generation. That extra wiring lets it run circuits about 30% more complex, up to 5,000 entangling operations, with 7,500 targeted for the end of 2026 and 10,000 for 2027. A companion chip, Loon, exists purely to prove out the plumbing for error correction: multi-layer routing, long-range couplers, fast qubit reset. IBM also moved production to a 300 mm wafer facility, and its error-decoding hardware now processes error reports in under 480 nanoseconds — a year ahead of its own schedule.
Google Quantum Echoes (October 2025) was the field's first verifiable advantage claim: unlike the 2019 random-circuit-sampling result, whose output was meaningless outside the benchmark, this one measured molecular structure with UC Berkeley collaborators and can be re-run and checked on other quantum hardware. Willow delivered 99.97% single-qubit and 99.88% two-qubit fidelity across all 105 qubits at once.
And in July 2026, IBM made its own move. Three preprints posted with partners Qedma and Algorithmiq were presented together as the arrival of a “quantum advantage era”. The strongest of them, with the University of Chicago, ran a depth-70 circuit on 97 physical qubits using a technique called doped Clifford sampling, which produces a mathematically checkable confidence bound on the result. It is a real advance in verification. Whether the three results collectively justify the phrase “era” is contested, and classical algorithms have a long record of catching up with claims like these within a year.
Trapped Ions — The Accuracy Leader
Quantinuum, IonQ, and the Race Past Four Nines
A trapped-ion qubit is a single charged atom held in place by electric fields inside a vacuum chamber, with lasers or microwaves used to flip it between two of its internal energy states. The appeal is that every ion of a given element is identical — no fabrication variation, nothing to calibrate away — and the atom is isolated from almost everything. Coherence lasts seconds rather than microseconds. The cost is speed: operations are thousands of times slower than on a superconducting chip.
Quantinuum's Helios (November 2025) is the commercial benchmark: 98 barium ions reaching 99.92% two-qubit fidelity. Its architecture physically shuttles ions between separate memory and processing zones on the chip (a design called QCCD), so any two qubits can be brought together to interact — avoiding the chains of extra operations a fixed grid requires. In 2025 Helios demonstrated 48 error-corrected logical qubits from those 98 physical ions, a 2:1 ratio and the best encoding efficiency anyone has shown. As of August 2026 the system is being offered as a managed service inside Oracle's cloud.
IonQ passed the “four nines” mark in October 2025, reporting two-qubit fidelity above 99.99% — the highest figure any platform has published. It came from its Oxford Ionics acquisition, whose approach drives the ions with microwave electronics built into a standard semiconductor chip rather than with precisely aligned lasers, which makes the system considerably easier to manufacture. The previous record, 99.97%, was Oxford Ionics' own from 2024. IonQ's 100-qubit Tempo system is in commercial service, with a 256-qubit successor slated for demonstration during 2026.
Neutral Atom, Photonic, and Topological Platforms
Neutral Atoms — The Breakout Platform
Uncharged atoms held in a grid of focused laser beams (optical tweezers), entangled by briefly exciting them into enormous, long-reaching orbits (Rydberg states). The atoms can be physically rearranged mid-computation, giving flexible connectivity. In January 2026 QuEra published 96 error-corrected logical qubits built from 448 atoms — double the previous record for any technology — and arrays beyond 6,000 atoms have been demonstrated. Google opened its own neutral-atom lab in Boulder in March 2026.
Photonic — The Manufacturing Bet
Qubits encoded in single particles of light. Photons barely interact with anything, so they do not decohere and need no refrigeration for the chip itself — but that same aloofness makes it very hard to get two of them to interact on demand, which is exactly what a two-qubit gate requires. Photon loss, not decoherence, is the dominant error. PsiQuantum's Omega architecture bets that standard silicon chip factories can simply out-manufacture the problem; the company has raised well over $1.3 billion on that thesis, with sites under construction in Australia and Chicago.
Topological — Contested
The idea is to store information in a pattern spread across a whole device rather than at any single point, so local noise cannot corrupt it — error resistance built into the physics instead of bolted on. Microsoft announced Majorana 1 in February 2025 and Majorana 2 in 2026, claiming coherence measured in seconds. The evidence is disputed: Nature's own reviewers said the 2025 paper did not demonstrate the underlying particles, and a peer-reviewed critique published in June 2026 alleged tuning and analysis errors. Microsoft has formally rejected the critique. No topological qubit has been independently confirmed.
Cat Qubits — Fewer Spares Needed
AWS's Ocelot chip encodes a qubit in a superconducting oscillator in a way that makes one type of error astronomically rare while leaving the other type ordinary. Because you know in advance which error to look for, the correction machinery can be far cheaper — AWS claims up to a 90% reduction in the number of spare qubits needed. Bit-flip times approaching a full second have been measured, over a thousand times longer than conventional superconducting qubits. Ocelot itself is tiny (5 data qubits) and cannot compute; it is a proof of the architecture.
The Scalability Challenge — Physical vs. Logical Qubits
The Five Things Standing in the Way
1. Qubits forget. Every platform loses its quantum state to the environment eventually. Nighthawk's 350 μs is roughly triple Willow's, which is real progress — but a codebreaking run needs to execute millions of operations in sequence, and each one eats into the budget.
2. Errors have to stay under a threshold. Error correction only helps if the underlying hardware is already good enough; below roughly 1% error per operation, adding more qubits makes things better, and above it, worse. Google crossed that line publicly in December 2024, showing errors falling as its code grew from a 3×3 to a 7×7 patch. Quantinuum's 0.08% error rate sits comfortably below it.
3. The spares are expensive. One reliable qubit costs many noisy ones. The surface code's ~1000:1 ratio has been beaten repeatedly — IBM's qLDPC code reached 24:1, Quantinuum 2:1, QuEra 4.7:1 while running an actual algorithm — but most of these results are for storing a logical qubit. Doing full error-corrected computation on stored qubits is harder and less far along.
4. The wiring does not scale. Every qubit needs control lines, amplifiers, and readout electronics. For superconducting machines all of that has to reach inside a refrigerator colder than space without carrying heat in or letting signals interfere. It also has to run in real time: error correction is useless if the diagnosis arrives after the qubit has already decayed, which is why IBM's 480-nanosecond decoder matters as much as its qubit count.
5. The gap to codebreaking is still large. Breaking RSA-2048 needs somewhere around 1,400 logical qubits, assembled from under a million physical ones, running for about a week. The best machines today have roughly a hundred noisy physical qubits and fewer than a hundred logical ones at low protection levels. Closing that is not one more generation of chip; it is a change of architecture.
Implications for Cryptographic Security
Progress Is Real. The Gap Is Also Real.
Both things can be true at once, and most confused reporting comes from picking one. Google's October 2025 result and IBM's July 2026 papers are genuine science: the field has moved from “we did something no classical computer can copy” to “we did something no classical computer can copy, and here is how you can check it.” But Quantum Echoes ran on a 65-qubit slice of Willow doing physics, and IBM's flagship experiment used 97 physical qubits with error detection, not the full error correction that codebreaking assumes. Neither is a step on the path to factoring; they are steps on the path to trusting the machine.
The estimates keep moving — downwards. In 2019 breaking RSA-2048 was costed at 20 million physical qubits over eight hours. By 2025 the same author had it under a million, over about a week, purely through better arithmetic and cheaper error correction. In 2026 vendors began claiming that different error-correcting codes could push it towards 100,000, though those figures are architecture-specific and disputed. The lesson for anyone planning a migration: the threat date depends on mathematics as much as on hardware, and mathematics has been moving faster.
Timelines have tightened but not collapsed. IBM targets fault tolerance in 2029 with Starling (200 logical qubits); Quantinuum's roadmap runs through Sol in 2027 and Apollo in 2029; Google aims for useful fault-tolerant systems by the end of the decade. Cryptographically relevant machines come after those milestones, not with them — most credible estimates land in the mid-2030s, with substantial uncertainty in both directions.
Which is why migration is a today problem. An adversary can record encrypted traffic now and decrypt it whenever a capable machine arrives (“harvest now, decrypt later”). Anything that must stay secret for a decade — medical records, state communications, long-lived intellectual property — is already exposed to that strategy, regardless of when the hardware lands.