Introduction
A major milestone in quantum computing has emerged from China. On June 24, 2025, Earth.com reported that researchers at Shanghai University, led by Wang Chao, used a D‑Wave Advantage quantum annealer to factor a 22-bit RSA key—marking the most advanced quantum factorization in this domain to date . While this result does not immediately endanger real-world RSA implementations (which rely on keys at least two orders of magnitude larger), it demonstrates an accelerating trend in quantum capability that could threaten conventional encryption in years to come.
Background: Why RSA Matters
RSA encryption underpins much of today’s secure communication—from HTTPS websites to VPNs and encrypted messaging. Invented in 1977 by Rivest, Shamir, and Adleman, RSA depends on the difficulty of factoring a large semiprime integer into two primes . Classical computers still take subexponential time to break keys of realistic size; the largest factorization achieved by conventional means stands at 829 bits (RSA-250), requiring weeks of supercomputing effort .
Quantum algorithms—especially Shor’s algorithm—promise exponential speedups. However, universal, gate-based quantum computers capable of implementing Shor’s algorithm at scale remain years away from factoring real-world RSA keys. In contrast, quantum annealers like D‑Wave excel at optimization tasks but are not general-purpose quantum computers .
The China Experiment
Using the D‑Wave Advantage system, the Shanghai team converted factoring into a Quadratic Unconstrained Binary Optimization (QUBO) problem—suitable for a 5,000+ qubit annealer. They successfully factored a 22-bit integer, demonstrating greater qubit efficiency and noise control than in previous studies (which had maxed around 19 bits) .
To achieve this, they refined Ising model coefficients and reduced noise coupling—resulting in more reliable factor extraction . This work also tested against SPN ciphers like PRESENT and Rectangle, marking the first time a quantum annealer attacked such structures in practice .
While 22 bits is tiny compared to real-world standards, this “proof of concept” validates a roadmap: improved annealer design, better connectivity, and larger qubit counts could gradually escalate the size of factorable keys.
Why This Matters
1.
Acceleration of Quantum Threat
Experts warn that quantum advancements are steadily eroding the assumption of cryptographic safety. Analyst Prabhjyot Kaur of Everest Group emphasized that quantum computing “can seriously threaten data security and privacy for various enterprises” .
2.
Not Just Shor’s Algorithm
Quantum annealers offer an alternative path—sidestepping certain physical constraints faced by gate-based machines. While not as powerful for arbitrary algorithms, they excel in optimization tasks, like formulating factorization as combinatorial search .
3.
Impending “Q-Day”
“Q-Day” refers to the moment quantum computers can break current encryption. Institutions like NIST have already released initial post-quantum cryptography (PQC) standards (FIPS 203, 204, 205) and selected HQC for future protocols . The White House has urged agencies to phase out vulnerable keys proactively .
Current State of RSA vs. Quantum
| Aspect | Classical Computing | Quantum Annealing | Gate-Based Quantum |
| Largest broken key | 829 bits (RSA-250) | 22 bits (this study) | None for large keys yet |
| Scaling | Weeks on supercomputers | Exponential in bit size | Theoretical polynomial (Shor) |
| Speed | Very slow past 829 bits | Limited by annealer qubits | Limited by qubit count & error correction |
| Resource requirement | Massive classical cluster | Thousands of physical qubits | Millions of physical qubits |
While gate-based systems require complex qubit error correction, annealers like D‑Wave’s avoid deep circuits but currently scale poorly. Both paradigms illustrate potential routes to threat, some faster than others.
National and Industry Response
NIST and Federal Guidance
NIST has issued foundational PQC specs: FIPS 203–205 in August 2024, and selected HQC variants in March 2025 . The U.S. government has urged agencies to replace vulnerable keys immediately. Wall Street Journal analysts liken this to a long-term infrastructure effort .
Business Imperative
Enterprise cybersecurity teams are advised to:
- Audit all RSA/ECC key usage
- Deploy hybrid PQC libraries (e.g., Open Quantum Safe)
- Build crypto-agile systems allowing algorithm swaps without overhaul
Delaying will leave decades-old data at risk under a “harvest now, decrypt later” threat model.
Road to Quantum Resistance
- Post-Quantum Cryptography (PQC)
NIST-endorsed algorithms like CRYSTALS-Kyber are designed to resist quantum attacks . - Hybrid Key Exchange
Combining classical RSA/ECC with PQC layers ensures both backward compatibility and prospective resistance. - Crypto-Agility
Modular system design to swap cryptographic primitives without rearchitecting software platforms. - Continuous Monitoring
Quantum capability should be tracked closely, with threat models reassessed annually.
Future Trends and Monitoring
- D‑Wave’s roadmap includes a Zephyr-topology processor with over 7,000 qubits by year-end, promising enhanced connectivity and reduced embedding overhead .
- Gate-based scaling like Google’s Willow (105 qubits) remains far from RSA-breaking capability but tracks in a similar time horizon — estimated a decade from now .
- Research momentum—the scalable annealing demonstration and ongoing HPC gains—fortify the urgency for post-quantum readiness.
Conclusion
The Shanghai University factorization of a 22-bit RSA key on a quantum annealer does not immediately jeopardize real-world cryptography. However, it is a strategic warning. Quantum computing, via both annealing and gate-based methods, is advancing at a steady clip—reshaping the timeline for RSA vulnerability. Entities reliant on long-term data confidentiality—such as healthcare systems, government, financial institutions, and encrypted archives—face increasing urgency to transition to PQC. The next decade may redefine digital security; the time to prepare is now.
Works Cited
“China Breaks RSA Encryption with a Quantum Computer, Threatening Global Data Security.” Earth.com, 24 June 2025, https://www.earth.com/news/china-breaks-rsa-encryption-with-a-quantum-computer-threatening-global-data-security/ .
“Post-Quantum Cryptography.” Wikipedia, Wikimedia Foundation, 25 June 2025, https://en.wikipedia.org/wiki/Post-quantum_cryptography .
“RSA Cryptosystem.” Wikipedia, Wikimedia Foundation, 21 June 2025, https://en.wikipedia.org/wiki/RSA_cryptosystem .
“Security Highlight: China’s Quantum Leap, and Why RSA Isn’t at Risk (Yet).” Keysight, 28 Oct. 2024, https://www.keysight.com/blogs/en/tech/nwvs/2024/10/28/security-highlight-quantum-leap-in-china-and-why-rsa-isnt-at-risk-yet .
“China’s Quantum Threat to Cybersecurity.” CSO Online, 14 Oct. 2024, https://www.csoonline.com/article/3562701/chinese-researchers-break-rsa-encryption-with-a-quantum-computer.html .
“Google Says Its Breakthrough Quantum Chip Can’t Break Modern Cryptography.” The Verge, 12 Dec. 2024, https://www.theverge.com/2024/12/12/24319879/google-willow-cant-break-rsa-cryptography .