Quickly Quantum

Quickly Quantum is an AI-voiced podcast, built and run by a real person. Nothing in this episode is financial advice.

What is Quickly Quantum?

The daily quantum computing briefing you don't need a physics degree to follow. Every day, Quickly Quantum cuts through the hype to bring you the breakthroughs, funding rounds, policy moves, and research that actually matter, with plain-English analysis a smart non-physicist can follow. Hosted by Brian Lampert. AI-voiced, human-built, always skeptical of press releases. Nothing on this show is financial advice.

Also from Brian Lampert: Concrete Compute and Space Stakes.

Today on Quickly Quantum: there's a race happening right now between engineers trying to build a machine that could crack the encryption protecting your bank account and your Bitcoin wallet, and defenders racing to switch the locks before that happens — and nobody, including the people running the race, agrees on who's actually ahead. Before that, in the headlines: the National Science Foundation just wrote a nine-figure check to eight quantum research institutes, and a Caltech AI model just claimed a huge one-GPU speedup on a materials calculation that used to take a room full of GPUs. Welcome back to Quickly Quantum, your daily brief on the quantum frontier. It's Tuesday, August 25, 2026. Let's get into it.

Now, let's start with the check that already cleared. The National Science Foundation is putting more than two hundred ninety million dollars into eight Quantum Leap Challenge Institutes — multi-university research hubs NSF set up back in twenty twenty to chase the goals of the National Quantum Initiative Act — renewing five and standing up three brand new ones. Each gets roughly twenty-eight to thirty-seven million dollars over five years, and the flagship new one, MARQUIS, is led by Princeton with Cornell, MIT, UC Santa Barbara, Stanford, Dartmouth and others, with an advisory board that includes Google Quantum AI, NVIDIA and Applied Materials. Its job is reinventing the Josephson junction — the tiny superconducting switch at the heart of most of today's qubits, the basic building blocks of a quantum computer. According to NSF's own press release, all told this touches thirty-six universities in nineteen states and more than thirty companies. Is this going to ship you a better quantum computer next year? No, and NSF isn't pretending otherwise — this is workforce and foundational-hardware money, not a product roadmap. But it's the clearest signal yet that Washington isn't slowing its quantum bet even as the private-sector numbers get more dramatic — which, speaking of dramatic numbers, brings us to our next story.

That next story is an old paper having a new moment. Back in March, Google Quantum AI, working with the Ethereum Foundation and Stanford researchers, published resource estimates showing that breaking secp256k1 — the elliptic-curve math behind Bitcoin and Ethereum's signatures — could take fewer than five hundred thousand physical qubits, a roughly twenty-fold cut from the prior estimate of about nine million. Now, not everyone's buying the urgency — hardware analysts at Fireblocks replied that five hundred thousand fault-tolerant physical qubits still doesn't exist, anywhere, at any lab. We haven't independently verified how the newer online discourse is reading that March paper. Hold that tension — it's exactly what our main story digs into today.

Alex Pruden, CEO of the quantum-security firm Project Eleven and a former a16z crypto partner, threaded through a different angle on X. His words, verbatim: 'Over the past decade, the real driver of progress in quantum computing has shifted from raw qubit count to error correction effectiveness and efficiency. Research in this area has been accelerating with three new papers this month, potentially pulling Q-Day timelines forward.' Q-Day, for anyone just tuning in, is shorthand for the day a quantum computer gets powerful enough to break current encryption. Pruden's thread claims three August papers are behind this — on more efficient error-correcting qLDPC codes he calls 'mitten codes,' on surface-code scaling, and on three-qubit gates, all techniques for taming the errors that plague real qubits — though we haven't independently verified that specific paper count ourselves. Fair caveat: three incremental error-correction papers is not a demonstrated fault-tolerant machine, which makes this a bet on trajectory, backed by real technical progress, rather than a new measured result.

Away from the codebreaking debate entirely, Caltech's Anima Anandkumar posted a genuinely fun result on X. Her team built a Fourier neural operator — an AI model that learns the shape of a physics equation instead of memorizing answers — that runs density-functional-theory simulations, the standard method for modeling how electrons behave in molecules and materials, in close to linear time instead of the usual explosive slowdown as systems get bigger. Anandkumar says the demo was a magnesium dislocation with about eighty thousand electrons, solved self-consistently on a single GPU — a calculation she says previously needed roughly seven thousand GPUs, a claim from her own post that we haven't independently verified. Worth being precise about what this is: classical AI accelerating a classical simulation, not a quantum computer doing anything. But it matters here because DFT is exactly the kind of chemistry problem quantum computers are supposed to eventually help with, and every time classical methods get faster, they move the goalposts for what actually counts as quantum advantage.

In more grounded industrial news, The Quantum Insider reports that Xanadu and Mitsubishi Chemical are expanding their partnership on EUV lithography — the extreme ultraviolet process used to etch the world's most advanced chips, where a quantum effect called radiation-induced blur has been a stubborn bottleneck for classical simulation. Phase two takes parameters from Xanadu's quantum simulations and feeds them into Mitsubishi's multi-scale models, backed by Canadian and Japanese government innovation programs, aiming at what they're calling a fault-tolerant-quantum-computing-ready software pipeline. We haven't independently confirmed details beyond the companies' own announcement, and there's no quantum-advantage number or deployment timeline attached yet — this is a collaboration expanding, not a result landing. Still, it's a real, funded example of quantum methods hitting an actual manufacturing problem today, which is rarer than the qubit-count headlines might suggest. Now, let's get to the story that ties a lot of this together — the actual race to build a machine that can break the encryption everyone's been talking about all episode.

Our main story today: call it the codebreaker's clock — whether the people trying to build a quantum computer that can crack modern encryption get there before the world finishes swapping the locks. New Scientist has a profile out today on the engineers actually racing to run Shor's algorithm — the quantum-computing method, from 1994, that can factor huge numbers and break the elliptic-curve math protecting almost everything: your bank login, your Bitcoin wallet, most of the internet's encrypted traffic. For most of its history, that's been comfortably theoretical — a machine that could run it at scale assumed to be decades out. That comfort is getting harder to hold onto. Here's why: back in March, Google Quantum AI, working with the Ethereum Foundation and Stanford researchers, found breaking secp256k1 could take fewer than five hundred thousand physical qubits and a runtime measured in minutes — a roughly twenty-fold cut from the prior estimate of about nine million qubits. That's not a small revision — that's the kind of number that gets internal deadlines set. And in fact, that specificity is widely read as the reason Google set its own internal target of twenty twenty-nine to finish migrating its infrastructure to post-quantum cryptography, encryption designed to survive a quantum attacker. That's a striking coincidence of timing — but it's not proof anyone's close, and it's worth pausing on what 'cryptographically relevant' actually means, because it's doing a lot of work in this story. It doesn't mean a computer that can run a few qubits in a lab — it means one stable enough, for long enough, to execute Shor's algorithm against a real key, which requires fault tolerance: enough error-corrected 'logical' qubits, built by piecing together many noisy physical ones, that the machine doesn't fall apart mid-calculation. That's the number Google's paper is actually about — five hundred thousand physical qubits to get the fault tolerance needed. Compare that to what exists today: IBM's Condor superconducting processor, unveiled back in December twenty twenty-three as part of IBM's Quantum System Two, already has one thousand, one hundred twenty-one qubits, and other superconducting chips — like Fujitsu's two hundred fifty-six-qubit processor — go well beyond the old hundred-qubit ballpark too. But none of those larger chips have demonstrated error correction at that scale — meaning none of those qubits are stitched together into the fault-tolerant logical qubits Shor's algorithm would actually need. That gap between raw qubit count and error-corrected qubits is the entire ballgame, and it's what the rest of this segment is about.

So who's actually right? Let's stack up the voices, because this is a live argument, not a settled question. Alex Pruden, over at Project Eleven, adds a second piece: his read is that error correction, not raw qubit count, is now the thing actually moving, pointing at those three fresh August papers on more efficient error-correcting codes he's threaded through. Stack those together and you get a coherent case — the theoretical resource requirement just fell twenty-fold, and the engineering technique for getting there might be getting more efficient too. On the other side, you've got hardware reality. Fireblocks and other hardware analysts pushed back hard, pointing out that five hundred thousand fault-tolerant physical qubits 'does not yet exist' — not close, not almost, just doesn't exist as a demonstrated capability anywhere. And there's a deeper verification problem: Google didn't release the actual circuit details behind its resource estimate, only a zero-knowledge proof — a cryptographic technique that proves a computation was done correctly without showing the work — so outside researchers can't fully check the number. And then there's Peter Shor himself, whose algorithm this whole conversation is named for — he's previously said he didn't expect a machine capable of breaking RSA encryption for at least twenty more years from when he said it, which is a very different clock than twenty twenty-nine. Here's my read, and it's not really a fifty-fifty split, because the two sides aren't disagreeing about the same thing. Nobody serious — not Google, not Pruden, not Ihnatiuk — is claiming the five-hundred-thousand-qubit machine exists today. The disagreement is about slope: is the curve bending down fast enough that twenty twenty-nine is a real target, or is it a marketing deadline dressed up as engineering? I lean toward the slope being real but the finish line still invisible. A twenty-fold cut in required qubits in one paper is the kind of number that should move your estimate — that's genuine evidence, not hype. But 'error correction is improving' has been true, and said, for years now, and the raw qubit counts on real machines — even the thousand-plus-qubit chips out there — haven't been paired with error correction at anywhere near the scale this would need. It's also worth noting NSF's brand-new MARQUIS institute, from earlier, is aimed squarely at reinventing the Josephson junction inside superconducting qubits — the same physical layer where any future fault-tolerant leap would actually have to happen. Public money and private urgency are, for once, pointed at the same bottleneck. Time for the Hype Check. I'm putting this one at a five. The underlying math is real — the twenty-fold reduction is a legitimate result even without the full circuit disclosed. But 'engineer racing to run the most dangerous algorithm' is a headline built on a five-month-old paper and an unconfirmed internal deadline, stacked against a hardware reality that hasn't moved a fraction as fast. Real signal, real number, and way too much of the story's drama doing work the hardware hasn't earned yet.

If today's numbers made your head spin a little, that's exactly why I do this every morning instead of once a year — follow Quickly Quantum wherever you're listening, so tomorrow's episode just shows up. This has been Quickly Quantum, an AI-voiced podcast, created and built by a real human using today's cutting-edge technology. Nothing you heard on this show is financial advice. I'm Brian Lampert, and I'll catch you all tomorrow — take care!