Today on Quickly Quantum: could the math underneath the government's entire post-quantum encryption migration have a hole in it — and did an Amazon researcher just find it? Before that, in the headlines: IonQ posted record revenue and the stock fell anyway, Rigetti's earnings reveal a company sitting on more cash than it knows what to do with, a German startup says it built a room-temperature quantum computer you can plug into a wall outlet, Pasqal cleared a major hurdle toward going public, and a security researcher's thread on X argues the timeline for a code-breaking quantum computer just got shorter. Welcome back to Quickly Quantum, your daily brief on the quantum frontier. It's Friday, August 7, 2026. Let's get into it. Let's start with IonQ, because this one's a genuine head-scratcher if you just look at the top line. Second-quarter revenue came in at eighty point one million dollars — up two hundred eighty-seven percent year over year — and IonQ raised its full-year guidance to somewhere between two hundred eighty and two hundred ninety million dollars. By normal startup math, that's a stock that should be popping. Instead, shares fell. Why? Because sitting right next to that revenue number is a GAAP net loss of one point nine billion dollars, and here's the thing — that loss isn't really about operations burning cash. It's an accounting artifact from warrant mark-to-market charges tied to IonQ's one point eight billion dollar acquisition of SkyWater, the chip foundry deal that closed this quarter. Warrants get repriced on paper as the stock moves, and when they do, the loss lands on the income statement even though no cash actually left the building for that reason. IonQ also says it's received its first fully integrated quantum processing units out of that deal, which matters for its roadmap toward two hundred fifty-six qubits and, eventually, ten thousand. So is the market wrong to sell this off? Not entirely — adjusted EBITDA losses still ran one hundred twenty point three million dollars, and IonQ hasn't given combined guidance with SkyWater folded in yet, so there are real open questions about the underlying burn rate. The revenue growth is real, and the guidance bump proves the commercial pipeline is filling in. But burying that under a one-point-nine-billion-dollar headline loss, with no combined outlook yet, is asking investors to do homework most of them won't — they saw the loss, not the footnote, and sold first. Rigetti's earnings tell a completely different story. Quantum Zeitgeist reports — and we haven't independently confirmed this one yet — that Rigetti closed the second quarter with five hundred forty-one point three million dollars in cash, cash equivalents, and investments, against just five point one million dollars in revenue and a fifty-two point six million dollar net loss. The cash pile is roughly a hundred times the quarterly revenue. CEO Subodh Kulkarni is leaning into an expanded collaboration with Hewlett Packard Enterprise and the Pittsburgh Supercomputing Center to build a hybrid quantum-classical supercomputer, which he says reflects, quote, growing demand for our approach. Rigetti also has a letter of intent with the Commerce Department for up to a hundred million dollars in CHIPS Act funding, contingent on the government taking an equity stake. This is the flip side of IonQ's story this week: no meaningful revenue yet, but a war chest built to survive years of R&D while the fidelity numbers — Rigetti claims ninety-nine point nine percent single-qubit gate fidelity on its Cepheus-1-108Q system — slowly climb toward something commercial. A big cash balance buys time. It doesn't prove anyone wants to buy what you're building yet. Here's a strange one out of Germany. A startup called SaxonQ says it's built diamond-powered quantum computers that run at room temperature — no dilution refrigerator, no giant cryostat, just a rack-mounted box you can plug into a regular outlet. The qubits live inside nitrogen-vacancy centers in diamond, tiny defects in the crystal lattice that can hold and manipulate quantum information without the extreme cooling superconducting qubits need. SaxonQ claims systems up to one hundred twenty-eight qubits today, with five hundred twelve promised next year, and says these are the first diamond-based systems to break past ten qubits. Here's the catch: Live Science reviewed SaxonQ's technical white paper and found no published, peer-reviewed research demonstrating a functional quantum computer at this scale. This is a vendor claim, not an independently verified result, and diamond qubits have historically struggled to scale past small numbers for exactly the reason you'd expect — controlling that many tiny defects precisely gets harder fast. Room-temperature quantum computing would be a genuinely big deal if it holds up. I just want to see the paper before I believe the qubit count. Pasqal took a step closer to Wall Street today. The SEC declared the company's registration statement effective, clearing the way for its SPAC merger with Bleichroeder to move forward — Bleichroeder shareholders vote on August twenty-fifth, and if it closes, Pasqal lists on Nasdaq under the ticker PSQL. Pasqal builds neutral-atom quantum computers — qubits made from individual atoms trapped and controlled with lasers rather than superconducting circuits — and it's been racking up deployments, including a hundred-forty-qubit system paired with Italy's Leonardo supercomputer and a materials-simulation demonstration with Los Alamos National Lab. That puts Pasqal in the same lane as IonQ, Rigetti, D-Wave, and now Quantinuum and Infleqtion — quantum companies increasingly choosing public listings over private funding rounds to raise the capital this industry burns through. Worth flagging: SEC effectiveness is a procedural green light, not a closed deal. Shareholders still have to vote, and customary closing conditions still apply. But it's one more sign that public markets, not just venture capital, are where quantum computing's bills are getting paid. On X this week, quantum-security researcher Marin Ivezic — posting as @infosec — argued that error correction in this field just stopped being a one-company story. While everyone watched IBM's error-correction campaign, he says four other teams posted results: IonQ hit breakeven with a new qLDPC error-correcting code on trapped ions, Atom Computing ran ninety syndrome-extraction cycles of toric-code correction on neutral atoms, QuEra mapped a roadmap to two hundred fifty-six logical qubits — error-corrected qubits built from many physical ones — for AWS by 2028, and a theory paper on Mitten codes claims one hundred ninety-five logical qubits from just nine hundred seventy-five physical ones, five times the encoding rate of standard surface codes. His conclusion: the risk model for when a code-breaking quantum computer arrives needs updating now, not later. That's an aggressive read of vendor roadmaps and one theory paper — none of it independently verified, and roadmaps in this industry have slipped before. But it's a sharp primer for where we're headed next, because the question of whether today's encryption survives tomorrow's quantum computers just got a very concrete new data point. Our main story today: the paper that has cryptographers pulling up their calendars, because the timeline question we just raised is suddenly a lot less abstract. Here's the setup. On July thirty-first, a researcher named Daniel R. Simon — whose 1994 paper introduced what the field now calls Simon's algorithm, one of the foundational results in quantum computing — posted a preliminary paper. Simon works in Amazon Web Services' Cryptography Group, and the paper claims something that's eluded researchers for more than two decades: a polynomial-time quantum algorithm — meaning one whose running time scales reasonably as the problem grows, instead of exploding exponentially — for something called the Dihedral Coset Problem. Now, stay with me, because this matters even if you've never heard those words before. Most of the encryption the world is migrating to right now — the NIST-finalized standards meant to survive quantum computers, things like ML-KEM and Dilithium — are built on math involving lattices: a grid of points stretched across many, many dimensions. Two of the hard problems on that grid are the Shortest Vector Problem, which asks you to find the shortest meaningful step through the grid, and Learning With Errors, which hides a secret inside equations with deliberately added noise. Both are believed to be too hard for even a quantum computer to crack efficiently, and that belief is the entire foundation of the post-quantum migration governments and companies are racing through right now — a migration you can see happening in small pieces, like the ZeroTier and Carahsoft government networking deal announced this week, which prices in exactly this assumption of lattice safety. Here's where the Dihedral Coset Problem comes in. Back in the two-thousands, mathematician Oded Regev showed a reduction — a mathematical bridge — connecting that problem to those lattice problems, meaning an efficient solution to it could be turned into an attack on the lattice math too. The catch was that Regev's construction depended on something called a subset-sum oracle, an idealized tool that doesn't actually exist as a practical algorithm — a proof of what would follow if a piece existed, when the piece itself was missing. For twenty years, the best real quantum algorithm for the related dihedral subgroup problem, built by Greg Kuperberg, ran in subexponential time — faster than brute force, but not the polynomial time that would actually worry anyone. Simon's paper claims to supply that missing piece: a polynomial-time procedure that doesn't need the imaginary oracle, and one that tolerates a higher rate of faulty quantum measurements than earlier attempts required. So how worried should you actually be? Let's be precise about what this paper is, and just as precise about what it isn't. What it isn't: an attack. Simon's paper doesn't break ML-KEM, doesn't break Dilithium, doesn't demonstrate anyone decrypting anything, and doesn't even estimate how large or reliable a quantum computer would need to be to run this. It's a complexity-theoretic result — a claim about what's mathematically possible in principle, not a working exploit. And it's a preliminary, non-peer-reviewed draft, posted less than two weeks ago. The cryptography community hasn't had time to pressure-test the proof, and results like this have a well-documented habit of springing a leak somewhere in the fine print once enough smart people go looking — that's not a knock on Simon, it's just how theoretical cryptography works, and it's exactly the caution the paper itself invites. What it is: a genuinely credible attempt to close a twenty-year-old gap by one of the field's actual founding figures. Specifically, the paper claims a polynomial-time way to approximate the shortest vector in an n-dimensional lattice to within roughly the square root of n, times a polylogarithmic factor — not the exact shortest vector, but close enough that it doesn't need to be exact to matter for security estimates, plus a related claim for certain Learning With Errors parameters. The specific technical move — dividing quantum samples into groups to erase unwanted information without destroying the quantum phase that carries the hidden answer — is a real attempt to replace Regev's imaginary oracle with something that could actually run on a quantum computer. Here's why this connects to that error-correction thread from earlier. The case for harvest-now-decrypt-later — stealing encrypted data today and sitting on it until a quantum computer can crack it later — always rested on two separate legs. One leg is hardware: is there a big enough, reliable enough quantum computer? The multi-vendor error-correction progress Ivezic flagged is chipping at that leg, roadmap by roadmap. The other leg is math: is the cryptography we're migrating to actually hard for a quantum computer to break, even with a big enough machine? Today's paper, if it survives review, chips at that leg instead. Neither leg is anywhere close to falling. But watching two separate legs get chipped at, in the same week, from completely unrelated directions, is the kind of coincidence that makes people in this beat sit up straighter. My honest skepticism is the same skepticism the paper itself invites: preliminary polynomial-time quantum algorithms for hard number-theoretic problems have a history of not surviving contact with the community, and there's a real chance someone finds the hole in the next few months — that's not pessimism, that's just how this corner of math has behaved for decades. If it does survive scrutiny, the next question isn't whether your data is safe today — it's whether NIST's chosen parameter sizes for ML-KEM and Dilithium hold up against an algorithm like this, which is a much narrower, more answerable question than whether lattice cryptography is dead. Nobody credible is telling you to panic right now, and nobody credible should be telling you the migration is pointless. What they should be telling you is that the safety margin everyone assumed lattice cryptography had just got a little less certain, on paper, this week. Time for the Hype Check. I'm putting this one at a four. The math is real, the pedigree is real, and the gap it claims to close is a genuinely famous one in the field — that's not nothing. But it's an unreviewed preprint with zero demonstrated attack, zero hardware estimate, and a very real chance the proof doesn't hold up once people who do this for a living start pulling at the seams. Four means: pay attention, don't panic, and check back once peer review actually happens. If independent cryptographers can't find a hole in Simon's proof by the end of the year, that's the signal this stops being a preprint curiosity and starts being a parameter review NIST needs to take seriously. If today's episode helped make sense of a paper full of lattice diagrams, that's exactly the listener I'm writing for — so follow Quickly Quantum wherever you get your podcasts, and send this one to anyone in security who needs the plain-English version. This has been Quickly Quantum, an AI-voiced podcast, created and built by a real human using today's cutting-edge technology. Nothing you heard on this show is financial advice. I'm Brian Lampert, and I'll catch you all tomorrow — take care!