Photonic Estimates Networked RSA-2048 Factoring at 7 Million Qubits and 3.9 Days. Its White Paper Leaves Out the Inputs Needed to Check It.
10 December 2025 – Photonic Inc. published an estimate of what a networked quantum computer would need to factor a 2048-bit RSA integer with Shor’s algorithm. The Vancouver-based company put the requirement at 7 million physical qubits running for 3.9 days. It released the white paper, titled “SHYPS to Shor’s: A Call for Distributed QRE,” with its announcement.
Stephanie Simmons, Photonic’s founder and chief quantum officer, presented the results in a talk on 10 December at Q2B Silicon Valley, held from 9 to 11 December at the Santa Clara Convention Center in California. Photonic said the estimate counts the cost of operations inside each module and across the links between modules. The company described it as the first precise estimate for Shor’s algorithm on a distributed architecture with a high-rate quantum low-density parity-check code, or QLDPC code.
Photonic compared its figure with two estimates led by Craig Gidney of Google Quantum AI. Gidney and Martin Ekerå first posted their estimate of 20 million noisy qubits and 8 hours in 2019, and the journal Quantum published it in 2021. In May 2025, Gidney lowered the figure to fewer than one million qubits and less than a week.
Photonic argued that both estimates assume a monolithic machine, with every qubit in a single module. On that reading, they leave out the cost of networking modules together. In the white paper, Photonic wrote that all current approaches to resource estimation had overlooked the cost of networking between modules. Simmons said that accounting for networking and connectivity makes possible like-for-like comparisons across vendors and architectures.
Quantum resource estimation, or QRE, is the calculation of the physical qubits and runtime an algorithm needs on a given hardware design. In the white paper, Photonic describes three established kinds of estimate, from counts of error-free logical qubits to hardware-aware models of a specific machine. It argues that estimates should also include the performance of links between modules.
Photonic built its calculation on SHYPS codes, short for subsystem hypergraph product simplex codes, a QLDPC family it introduced in February 2025 with an accompanying preprint. Photonic wrote that surface codes need roughly 1,000 physical qubits for each application-grade logical qubit. By its account, SHYPS codes bring the ratio to 100:1 or better, but only on architectures with long-range connectivity.
For the algorithm, Photonic adapted Gidney and Ekerå’s surface-code arithmetic optimizations to its own distributed architecture. The count includes multi-qubit operations, error-corrected non-Clifford gates and their auxiliary qubits, the company wrote. Photonic also wrote that its implementation is not yet fully optimized and that it expects the improvements in Gidney’s 2025 paper to make its numbers more competitive.
In the white paper, Photonic did not state the physical error rates, operation times, module sizes or logical qubit counts behind the 7 million figure, or the rate of entanglement between modules. It also did not report separate costs for operations inside modules and for links between them.
Photonic’s T Centre Qubits and Networked Architecture
Simmons and Michael Thewalt, both physicists at Simon Fraser University, founded Photonic in 2016. In its December announcement, the company said it is headquartered in Vancouver, with operations in the US and the UK and a team of more than 150. Its qubits are T centres, defects in silicon that combine an electron spin with nuclear spins. T centres have an optical transition in the telecommunications O-band, near 1,326 nanometers.
Photonic calls its architecture, in which optical fiber links silicon modules, Entanglement First. The company traces the design to a 2020 PRX Quantum paper on the T centre’s spin-photon interface and a 2024 PRX Quantum paper by Simmons.
In November 2023, Photonic announced US$100 million in new funding and a collaboration with Microsoft. In the announcement of its architecture, Simmons said Photonic would be the first quantum computing company to offer a scalable, distributed and fault-tolerant solution within five years. In a preprint posted in June 2024, Photonic reported entanglement between T centres on two chips in separate cryostats, about 40 meters of fiber apart. It used that entanglement to run a teleported CNOT gate sequence.
On 6 November 2025, DARPA selected Photonic as one of 11 companies advancing to Stage B of its Quantum Benchmarking Initiative. In the year-long stage, each company details its research and development plan for a utility-scale quantum computer, including risk-reduction prototypes.
My Analysis
Gidney’s two estimates, with Ekerå in 2019 and alone in 2025, assumed a planar grid of qubits with nearest-neighbor connections, a 0.1% physical gate error rate, a surface-code cycle of 1 microsecond and a control-system reaction time of 10 microseconds. Both papers state those assumptions in their abstracts. Neither headline estimate prices slower links between separately built modules, which is why Photonic calls them monolithic. Photonic and IBM are both designing machines built from linked modules.
Photonic is right that estimates for modular machines should count the cost of links. Photonic published its own answer, 7 million physical qubits for 3.9 days, in a white paper that leaves out the inputs behind it, so readers cannot check it. Taken at face value, the reported totals are larger in qubits and in qubit-days than Gidney’s monolithic estimate from May.
The white paper gives me no grounds to move my expectations for a cryptographically relevant quantum computer, or CRQC, in either direction. Its inputs are unpublished, and the machine it describes is far beyond the hardware Photonic has demonstrated. Two earlier studies do weaken one argument for waiting, that a CRQC is distant because nobody can build a million qubits as a single device.
Why Shor’s Estimates Need a Network Line Item
Dmitry Filippov, Peter Yang and Prakash Murali of the University of Cambridge argued in a preprint posted in August 2025 that single devices face yield, size and wiring limits at the million-qubit scale. At their assumed footprint of more than a square millimeter per superconducting qubit, a chip with a million qubits would need about a square meter of wafer. They judged direct control wiring for each of a million qubits impossible in practice. Trapped ions and neutral atoms, in their assessment, face comparable limits from qubit loss and the size of control electronics.
IBM’s Tour de gross paper, posted in June 2025, describes a modular computer built on bivariate bicycle codes, another QLDPC family. In it, IBM researchers use long-range couplers inside each module and a second type of coupler to entangle modules with each other. Photonic places its modules in separate cryostats joined by fiber. IBM and Photonic will both pay for links between modules.
The Cambridge group noted that two established estimation tools, Microsoft’s Azure Quantum Resource Estimator and Google’s Qualtran, did not model quantum networks or entanglement distillation. In distillation, many noisy Bell pairs shared between modules are converted into fewer, cleaner ones. Someone costing a distributed machine with those tools, as the Cambridge group reviewed them in 2025, would get no figure for the links.
Photonic argues that monolithic estimates depend on a million qubits in one module operating for days without failure. Photonic’s own machine would need its modules and links to keep the computation logically correct for the length of each run, with failures absorbed by error correction or retries. I track that requirement as continuous operation in my CRQC Quantum Capability Framework, and it applies to both designs.
Distributed Shor Estimates Before Photonic
Researchers were estimating Shor’s algorithm on networked hardware almost two decades before Photonic introduced SHYPS codes. Rodney Van Meter’s doctoral thesis, posted to arXiv in 2006, was titled “Architecture of a Quantum Multicomputer Optimized for Shor’s Factoring Algorithm.” In 2009, Van Meter, Thaddeus Ladd, Austin Fowler and Yoshihisa Yamamoto proposed a distributed architecture in which semiconductor spin qubits are coupled through nanophotonic waveguides and cavities. Gidney and Ekerå list that design’s factoring estimate in their table of historical estimates at 6.5 billion physical qubits and 410 days. Gidney left it out of his 2025 comparison chart because it used substantially different assumptions.
Gidney and Ekerå also sketched a distributed version of their own construction. Their adders split each register into pieces that barely interact. They put eight machines of about 4 million qubits each, joined by 150-qubit-per-second quantum channels, at roughly double the runtime. They presented this as a preliminary analysis and left the detailed work for later. Photonic classifies the same paper as a monolithic estimate that excludes distributed costs.
In August 2025, the Cambridge group described a distributed resource estimator that models node size and the generation and distillation of entanglement. Its eight benchmark applications include 2048-bit RSA. With 45,000-qubit nodes, entanglement generated at 10 MHz, a 0.01% physical error rate and 50-nanosecond operations, they put the monolithic cost at 8.67 million qubits for 16.3 hours and the distributed cost at 20.9 million qubits for 1.25 days, at Bell-pair error rates of both 1% and 0.1%. Across all eight applications, distributed machines with 45,000-qubit nodes needed on average 1.4 times as many qubits as monolithic machines and 4 times their runtime. The group described its framework as the first to integrate network processes with a full model of the fault-tolerant stack.
IBM researchers had also reported end-to-end resource estimates for their modular QLDPC design in June, for random circuits and a simulation of a 10-by-10 transverse-field Ising model, with no RSA-2048 case.
I found no earlier distributed estimate for RSA-2048 on a high-rate QLDPC code, so Photonic’s narrow claim matches the published record as far as I can tell. I cannot check the word “precise,” because the white paper does not show the calculation. Photonic’s broader statement in the same white paper, that all current approaches had overlooked the cost of networking between modules, does not match the record. The Cambridge group had modeled that cost almost four months earlier and published its parameters.
Photonic’s 7 Million Qubits Against the Google Estimates
Photonic compared its result with Gidney’s rounded 2025 figures of one million qubits and seven days. Gidney computed 897,864 physical qubits and 4.96 days, then rounded both up to leave slack. I give both versions in the table, with qubit-days as a simple spacetime measure. Qubit-days are physical qubits multiplied by days of runtime, the unit Gidney and Ekerå used to compare historical estimates.
All four rows are projections made under hardware assumptions that do not match, so the table compares reported totals and cannot isolate the effect of architecture. Gidney’s runtimes are expected times that include repeated attempts, and Photonic does not say whether 3.9 days is one run or an expected time. For 2019, the table uses the paper’s rounded headline figures. Gidney and Ekerå’s own table of historical estimates gives an expected runtime of 0.31 days and an expected volume of 5.9 million qubit-days.
| Estimate | Architecture | Physical qubits | Runtime | Qubit-days | Hardware assumptions published |
|---|---|---|---|---|---|
| Gidney and Ekerå, 2019 | Single device, surface code | 20 million | 8 hours | 6.7 million | Yes |
| Gidney, 2025, rounded up | Single device, surface code | 1 million | 7 days | 7 million | Yes |
| Gidney, 2025, as computed | Single device, surface code | 897,864 | 4.96 days | 4.5 million | Yes |
| Photonic, 2025 | Linked modules, SHYPS QLDPC code | 7 million | 3.9 days | 27.3 million | No |
Against Gidney and Ekerå’s 2019 estimate, which uses related arithmetic, Photonic reports a qubit count lower by a factor of 2.9 and a runtime 11.7 times longer, for a qubit-day total about four times as large. Against Gidney’s computed 2025 figures, Photonic reports 7.8 times the qubits and a runtime 21% shorter than Gidney’s expected time, for about six times the qubit-days. Photonic calls its result competitive with the 2019 estimate. Photonic’s estimate has fewer qubits than the 2019 one but a longer runtime and more qubit-days. Whether that makes the design competitive depends on engineering costs that none of these papers model.
In the qubit-days column, I count every physical qubit as the same unit of cost, whatever the platform. A superconducting qubit needs a dilution refrigerator at millikelvin temperatures. Photonic’s 2024 experiment ran its T centres at 1.5 kelvin, and a single T centre can host more than one spin qubit. Even with those caveats, Photonic trades qubits for time at a steeper rate than Gidney did between 2019 and 2025.
Photonic’s answer to the 2025 comparison is that Gidney’s estimate excludes distributed costs. That is true, and the increase from adding them is unknown. I know of no published distributed version of Gidney’s 2025 layout. The two published attempts to size a networking penalty for Shor’s algorithm, Gidney and Ekerå’s sketch and the Cambridge study, used other constructions and parameters.
Photonic and Gidney also used different algorithms. Photonic built on the 2019 arithmetic. In Gidney and Ekerå’s abstract circuit model, that arithmetic uses about 6,200 logical qubits, and Photonic has not said how many its adaptation uses. Gidney’s 2025 paper uses the approximate residue arithmetic of Chevignard, Fouque and Schrottenloher. With it, Gidney brought the peak to about 1,400 logical qubits at the cost of about 6.5 billion Toffoli gates, roughly twice the 2019 count.
Code-Level Savings Versus the Whole-Machine Estimate
In February, Photonic said SHYPS codes could run quantum algorithms with up to 20 times fewer physical qubits than surface codes. Simmons said at the launch that the codes had “moved the goalposts for useful quantum computing 20x closer.” In the white paper, Photonic claims a reduction of 10 times or more in physical qubits per logical qubit. On reported totals against the 2019 estimate, Photonic’s whole machine uses 2.9 times fewer qubits and runs 12 times longer.
Photonic does not explain how a tenfold saving per logical qubit becomes a 2.9-fold saving for the whole machine. The candidates include magic-state production for billions of Toffoli gates, the auxiliary qubits that SHYPS logic uses, communication qubits at each link, and code distances large enough to protect a 3.9-day run. A resource breakdown separating encoded data, logical workspace, magic-state production and communication would show which of them accounts for the difference.
For idle logical qubits, Google’s surface-code overhead is already below Photonic’s reference figure. In Gidney’s 2025 layout, idle qubits are stored in yoked surface codes at 430 physical qubits per logical qubit. Qubits in active use are encoded in distance-25 patches of 1,352 physical qubits each. Of the 1,537 logical qubit patches in the layout, 1,280 are in yoked storage.
The 12-fold longer runtime is the other half of Photonic’s trade. Photonic does not say whether module links, the speed of spin operations or the logical clock of SHYPS codes limits it.
Inputs Missing From the White Paper
Gidney and Ekerå stated their hardware assumptions in their abstract and published the script that produced their cost tables. Gidney released the code and data for his 2025 estimate on Zenodo. In its white paper, Photonic states none of the following:
- Physical error rates for gates, measurements and idle qubits, and any loss or leakage.
- The syndrome-cycle time and the classical reaction time, which Gidney and Ekerå set at 1 and 10 microseconds.
- The rate and fidelity of Bell pairs between modules, and any entanglement distillation applied to them.
- The number of modules, the qubits in each and the topology of the links.
- The SHYPS code parameters, the logical qubit count and the number of Toffoli gates.
- The target success probability, and whether 3.9 days is a single run or the expected time including repeated runs.
- What counts as a qubit, given that each T centre combines an electron spin with one or more nuclear spins.
Gidney and Ekerå gave an order-of-magnitude rule of thumb for surface codes. Under that rule, a machine running at a physical error rate of 0.01% instead of 0.1% needs code distances roughly half as large and about one-eighth of the spacetime volume for the same computation. Photonic has not said how its SHYPS construction responds to the same change. Without its noise model, a reader cannot separate the effect of Photonic’s architecture from the effect of its fidelity assumptions.
Photonic describes its estimate as precisely calculated and says other QLDPC calculations relied on more estimation, without citing them. Gidney and Ekerå published their assumptions and supporting code and still called their numbers “ballpark figures,” warning of large systemic uncertainties. Simmons presented distributed QRE as a basis for comparing vendors and architectures. Readers of the white paper cannot run that comparison until Photonic publishes its inputs.
Photonic’s Demonstrated Hardware Versus the Machine in the Estimate
Photonic’s June 2024 preprint reported entanglement between two T centres, each on a chip in its own cryostat at 1.5 kelvin, linked through about 40 meters of fiber. The measured Bell-pair fidelity was 0.60, plus or minus 0.08, with a 40-nanosecond timing window. In a separate two-photon interference measurement, Photonic reported rates of 0.09 per second with a 5-nanosecond filter and about one per second with a 100-nanosecond filter, and bounded the Bell-pair rate at half the two-photon rate. It ran the teleported CNOT by post-selection, without feed-forward gate operations, and called the results preliminary demonstrations.
In the same experiment, Photonic predicted fidelities of 98.4% for one conditional gate between the electron and nuclear spins and at least 98.6% for the other. It measured combined nuclear-spin preparation-and-measurement fidelities of 87% and 89% for the two T centres.
Photonic’s preprint also projected Bell pairs at 99.8% fidelity and about 200 kHz, assuming best-in-class optical components and the spectral properties measured for T centres in bulk silicon. Photonic’s own bound puts the demonstrated Bell-pair rate at no more than half a pair per second, more than five orders of magnitude below the projection. The Cambridge group found that the entanglement rate a distributed machine needs depends on how fast its qubits operate, from about 5 to 10 kHz for slower technologies to at least 4 MHz for superconducting qubits. Photonic has not disclosed the entanglement rate that the machine in its estimate would need between modules, so nobody outside the company can say whether 200 kHz would be enough.
Photonic’s SHYPS work combines code constructions with circuit-level simulations. As of 11 December 2025, I found no public report from Photonic of an error-corrected logical qubit on T-centre hardware. The published link experiment used two T centres, against 7 million qubits in the white paper’s machine. Photonic does not map that machine to a date, although it lists roadmap timing among the purposes of resource estimation. Five years from Simmons’s November 2023 statement is 2028. Her goal was a scalable, distributed and fault-tolerant solution, not a machine that factors RSA-2048. DARPA’s Stage B review covers Photonic’s research and development plan and risk-reduction prototypes for a utility-scale machine, and selection for Stage B does not validate this estimate.
Photonic’s Estimate and the Q-Day Timeline
For RSA-2048, Gidney’s May 2025 estimate remains the reference, at fewer than a million physical qubits for less than a week under monolithic assumptions. Photonic’s reported totals are above it in qubits and qubit-days and its inputs are unpublished, so I keep Gidney’s figure as the reference for Q-Day planning.
Two published analyses have costed a distributed Shor’s computation. In the configurations they examined, Gidney and Ekerå’s sketch and the Cambridge study found overheads of 1.6 to 2.4 times the qubits and 1.8 to 2 times the runtime. Those multipliers do not transfer to other codes, algorithms or hardware. They do show that the lack of a single million-qubit device does not, by itself, rule out a CRQC.
The estimates discussed here assume physical error rates of 0.1% in Gidney’s case and 0.01%, with 10 MHz links between modules, in the Cambridge case. Photonic has not stated its assumptions. As of December 2025, no platform had demonstrated volume manufacture of fault-tolerant modules or days of uninterrupted fault-tolerant operation, and in 2024 Photonic’s link reached 60% Bell-pair fidelity at under one pair per second.
Gidney ended his 2025 paper by agreeing with the draft transition timeline in NIST’s IR 8547, which he summarized as deprecating vulnerable systems after 2030 and disallowing them after 2035. The draft applies the 2030 deprecation to quantum-vulnerable algorithms at the 112-bit security level, which includes RSA-2048, and disallows all of them after 2035. Gidney wrote that his reason was not an expectation of large quantum computers by 2030. He preferred “security to not be contingent on progress being slow.” Organizations migrating to post-quantum cryptography plan against those dates and the deadlines other regulators have set, whichever architecture reaches a CRQC first.
What a Checkable Distributed Estimate Would Include
Photonic could turn its white paper into the benchmark it describes by publishing six things:
- A parameter table covering operation and cycle times, reaction time, physical error rates by operation, idle and loss errors, the rate and fidelity of links between modules, and the entanglement distillation protocol.
- The machine layout, meaning the number of modules, the qubits in each and the link topology.
- The logical layer, meaning the SHYPS code parameters, logical qubit count, number of Toffoli gates and magic-state strategy.
- The success model, meaning the target probability of success, the retry policy and whether the runtime is one run or the expected time to a successful factorization.
- An allocation of qubits to data, workspace, magic-state production and communication, with the critical path that sets the runtime.
- A controlled comparison that holds the workload and code fixed while varying the interconnect assumptions, with a sensitivity sweep over those assumptions.
Photonic expects Gidney’s 2025 arithmetic to improve its result. An estimate built on that arithmetic would be a new calculation, separate from the one in the white paper. Checking this one does not require it.
Gidney and Ekerå published their estimation script with the 2019 paper, and Gidney posted the code and data behind his 2025 estimate. Anyone can rerun those numbers under different hardware assumptions. If Photonic released its distributed estimate the same way, researchers could run the comparison across vendors and architectures that Simmons described in Photonic’s announcement.