Harvest Now, Decrypt Later Threat: The Quantum Computing Arms Race

Harvest Now, Decrypt Later Threat: The Quantum Computing Arms Race

In December 2024, Google unveiled a chip called Willow and announced it had achieved something researchers had been chasing for years: below-threshold error correction, meaning that adding more qubits to the system actually reduced errors rather than compounding them. In November 2025, IBM announced Nighthawk — a 120-qubit processor targeting quantum advantage in a commercially useful computation by the end of 2026 — and alongside it, a processor called Loon designed to validate the architecture required for fault-tolerant quantum computing on a single chip.

Scientists at China’s University of Science and Technology, in March 2025, unveiled Zuchongzhi 3.0, a 105-qubit superconducting processor that processed random circuit tasks a quadrillion times faster than classical supercomputers — results that rival Google’s Willow benchmark and confirm that China’s hardware is operating in the regime where classical simulation becomes infeasible.

Three announcements. Three separate programs. One consistent signal: the quantum computing race has entered a phase where progress is measured in months, not years, and the institutions tracking it are no longer asking whether cryptographically relevant quantum computers will arrive but when.


Further reading: AI Layoffs 2026: Nearly 80,000 Tech Jobs Gone


The Hardware Race: Three Very Different Bets

The US-China quantum competition is real, but it is not a straightforward sprint between two identical programs. The leading players are pursuing architecturally distinct approaches, and the divergence matters for understanding both the timeline and the ultimate capability landscape.

Google

Google’s approach uses superconducting transmon qubits operating at near absolute zero. Its advantage is deep hardware expertise accumulated since its 2019 Sycamore processor first claimed quantum supremacy, and a numbered milestone roadmap that targets a useful, error-corrected quantum computer by 2029. The Willow chip’s below-threshold error correction result — the first time any hardware had achieved this on real quantum processors — was the most technically significant single milestone of the past two years. It validated a theoretical prediction that had underpinned fault-tolerant quantum computing roadmaps for decades but had never been demonstrated at scale. Google has also claimed a specific algorithm that outperforms classical supercomputers by a factor of 13,000.

IBM

IBM’s approach is more engineering-driven and roadmap-explicit than Google’s. The Nighthawk processor’s target of 7,500 reliable quantum gate operations by end-2026 is a specific, measurable benchmark rather than a general capability claim — a deliberate choice that reflects IBM’s positioning as the provider building toward commercial utility rather than scientific demonstrations. IBM CEO Arvind Krishna has consistently framed quantum advantage as a near-term business differentiator, not a decade-away aspiration.

The IBM roadmap calls for fault-tolerant computing by 2029, with fault tolerance defined as the ability to run algorithms far longer and more complex than current noise levels permit. Research papers on quantum error correction more than tripled between 2024 and 2025 — from 36 to over 120 publications — suggesting the IBM timeline is tracking against a rapidly deepening theoretical base.

Microsoft

Microsoft took the most unconventional path, announcing in February 2025 its Majorana 1 processor — the world’s first chip built on topological qubits, a fundamentally different physical implementation that is theoretically more stable and scalable than superconducting approaches, with a design architecture intended to reach one million qubits on a single chip. The topological approach has been theoretically promising for years but practically elusive; Majorana 1’s announcement confirmed the physics works. Whether Microsoft can turn that confirmation into a production system fast enough to compete with Google and IBM’s more mature hardware stacks is the central open question in the race.

China

China’s program operates on a different structural model. Rather than a single organisation, it is a coordinated national ecosystem — USTC producing the flagship Zuchongzhi and Jiuzhang processors under researcher Pan Jianwei, Origin Quantum building commercial systems including the 180-qubit Wukong-180 released in 2026, and major technology companies including Alibaba, Huawei, and Baidu operating quantum research divisions in closer coordination with national strategy than their Western counterparts typically do with government.

China is reportedly the world’s largest state investor in quantum technology, with estimates suggesting $10 billion to $15 billion in committed funding — compared with the US government’s $1 billion over five years and the EU’s $1 billion over ten. The asymmetry in state backing is significant. Private investment in the US quantum sector runs far higher, but the coordination advantage that state-directed programs provide in hardware manufacturing, talent concentration, and long-horizon research is not easily replicated by market-driven competition alone.

What It Breaks: The Cryptographic Stakes

The reason quantum computing has moved from a physics curiosity to a geopolitical concern is a single mathematical result from 1994: Peter Shor’s algorithm. Shor’s algorithm shows that a sufficiently powerful quantum computer can solve the prime factorisation and discrete logarithm problems that underpin RSA and elliptic-curve cryptography — the encryption schemes protecting all modern digital communication, essentially, from financial transactions to diplomatic cables to classified military networks.

Current hardware

Shor’s algorithm is not a threat. Breaking a 2048-bit RSA key would require millions of error-corrected logical qubits operating for an extended period. Today’s best systems operate in the hundreds of physical qubits, with the distinction between physical and logical qubits — the error-corrected, fault-tolerant units that Shor’s algorithm requires — representing a gap of potentially two to three orders of magnitude that no current machine has closed. In October 2024, researchers at Shanghai University cracked a 22-bit encryption key using a quantum computer — a result that generated significant media attention. For context, real-world RSA keys are 2048 bits. The gap between 22 and 2048 is not linear; it is exponential in the resources required.

The practical cryptographic threat timeline, as security planners currently model it, centres on a date security analysts call Q-Day — the point at which a cryptographically relevant quantum computer, capable of breaking real-world encryption at useful speed, becomes operational. The central estimate used by most Western security agencies and NIST migration planners is 2033 to 2035. Neither Google’s Willow chip nor IBM’s Nighthawk processor has moved that estimate.

What has moved is the urgency around preparation — for a specific reason that has nothing to do with current hardware capability. The threat that has accelerated government and enterprise action is what cryptographers call “Harvest Now, Decrypt Later”: state-level adversaries intercepting and storing encrypted data today, with the intention of decrypting it once a cryptographically relevant quantum computer arrives. For data whose sensitivity extends beyond a decade — military planning documents, diplomatic communications, infrastructure schematics, long-term financial instruments — the harvest is already happening. The decryption risk begins not at the moment a CRQC is built, but at the moment data with long-term sensitivity is captured.

The Migration Timeline: Where Quantum Computing Policy Stands

NIST published its first finalised post-quantum encryption standards in August 2024 — three algorithms (FIPS 203, 204, and 205) designed to resist known quantum attacks, based on lattice and hash mathematical problems that Shor’s algorithm cannot efficiently solve. The regulatory framework built around these standards sets a compressed migration schedule.

NSA’s Commercial National Security Algorithm Suite 2.0 requires implementation of post-quantum algorithms for new national security systems from 2025, with legacy infrastructure following between 2030 and 2033. NIST’s own migration guidance targets deprecation of RSA and elliptic-curve algorithms in federal use after 2030, with complete disallowance — including legacy interoperability — after 2035. President Trump’s Executive Order 14144, signed in early 2025, maintained PQC urgency while streamlining the roadmap, delegating oversight to NSA and OMB and requiring TLS 1.3 adoption by January 2030.

Enterprise adoption is moving

By Q1 2026, the Cybersecurity and Infrastructure Security Agency reported that roughly 38% of Fortune 500 firms had completed at least a partial cryptographic inventory — up from 12% in late 2024. Cloudflare’s January 2026 transparency report noted that hybrid post-quantum handshakes accounted for 4.2% of edge TLS connections on opted-in zones, double the rate six months earlier. The numbers reflect genuine acceleration, but also imply that more than 60% of the largest US companies have not yet completed even the inventory step that precedes any actual migration.

The technical bottleneck for most enterprises is not choosing an algorithm — NIST has made that decision — but the sheer scale of the certificate and key management infrastructure that must be updated. Legacy systems that hard-coded RSA and elliptic-curve cipher suites a decade ago require firmware updates, vendor SLA negotiations, and in some cases full hardware replacement. For critical infrastructure operators — power grids, financial clearing systems, healthcare networks — the migration is closer in scope to a multi-year infrastructure programme than a software update.

Quantum Computing: The Honest Timeline

The Q-Day central estimate of 2033 to 2035 is not a guarantee; it is a planning assumption derived from current hardware trajectories and the engineering distance between today’s noisy intermediate-scale quantum processors and the fault-tolerant machines that cryptographic attacks require. IBM’s fault-tolerant computing target of 2029 would, if achieved on schedule, compress that window significantly. China’s state investment levels and parallel research ecosystem introduce a variable that Western analysts consistently describe as the hardest to model — not because Chinese hardware is further ahead than the public disclosures suggest, but because the opacity of the program makes the distance between public benchmarks and classified capability impossible to assess with confidence.

Migration math uncertainty

If the Q-Day window is 2033 to 2035 and the enterprise migration timeline for complex infrastructure runs seven to ten years, organisations that have not begun their cryptographic inventory in 2026 are already operating inside their minimum viable preparation window. The harvest-now-decrypt-later threat means the clock on sensitive long-lived data started earlier still.

The quantum computing arms race matters not because any quantum computer today can break modern encryption. None can. It matters because the decisions being made now — in government procurement, enterprise security architecture, and the research laboratories of Hefei and Mountain View and Yorktown Heights — will determine whether the cryptographic infrastructure the global economy runs on is ready before the hardware that threatens it arrives.


Further reading: State Regulation vs Federal AI Law: The Battle That Will Define the Tech Decade


Sources: Quantum Security Defence, “Quantum Computing Progress 2026: IBM, Google and Q-Day” (June 2026); Red Stag Labs, “Latest Breakthroughs in Quantum Computing” (June 2026); Technerdo, “Quantum Computing Milestones 2025-2026” (April 2026); Beyond Tomorrow, “NIST Post-Quantum Standards Rollout” (June 2026); CyberArk, “NIST’s New Timeline for Post-Quantum Encryption” (March 2025); Quantum Security Defence, “NIST PQC Enterprise Summary” (April 2026); SafeLogic PQC Compliance Standards; The Quantum Insider, “Top Chinese Quantum Computing Companies in 2026” (June 2026); QuantumZeitgeist, “China Quantum Computing Companies” (May 2026); CKGSB Knowledge, “China’s Quantum Computing Strategy” (December 2025); Unbox Future, “2026: The Year Quantum Computing Achieves Quantum Advantage” (May 2026); Inform Bytes (April 2026); Programming Helper Tech (January 2026).