New PNAS paper claims quantum computers max out at ~1,000 qubits. It's already being used to delay PQC migration.
Problem: the latest ECC attack estimate needs just 1,193 qubits. RSA-2048 needs 1,399. Both falling fast.
Even if the ceiling is real, it doesn't save you.
#PQC #QuantumSecurity #QuantumReady
https://postquantum.com/quantum-research/the-1000-qubit-ceiling/

A New Algorithm Shrinks the Quantum Attack Surface for ECC
15 Mar 2026 - When Clémence Chevignard, Pierre-Alain Fouque, and André Schrottenloher submitted their latest paper to EUROCRYPT 2026, they already had a track record that the cryptographic community was watching closely. In 2024, the same team at INRIA Rennes had published a method that slashed the qubit requirements for quantum factoring of RSA integers - work that Craig Gidney at Google Quantum AI subsequently used as a foundation to bring the estimated physical qubit cost of breaking RSA-2048 from 20 million down to under one million. That result sent tremors through every risk committee tracking quantum timelines. Now the