- Oratomic says a quantum computer able to threaten widely used encryption can be built with about 10,000 atomic qubits, not the millions earlier estimates suggested.
- Attackers can copy encrypted data now and read it later, so data that must stay secret for years faces risk today.
- Leaders should list long-lived data, set a migration date for each system, and ask vendors for written post-quantum plans.
Every encrypted file carries a quiet promise. Nobody will read this before it stops mattering. Research published this spring puts that promise in doubt. A quantum startup says the machine needed to break common encryption may be much smaller than earlier estimates. The useful question is not when a quantum computer arrives. It is how long your secrets must hold.
What Oratomic announced
Oratomic has launched with research done alongside scientists at Caltech. Its first team includes John Preskill and co-founder Manuel Endres. The firm aims to deliver a quantum machine of practical scale before this decade closes.
Its researchers say such a machine can be built with about 10,000 qubits. Here, the qubits are atoms that can be moved around during a calculation. The machine would be fault-tolerant. That means it keeps giving correct answers even though quantum bits are fragile and make mistakes.
Earlier estimates for breaking encryption ran to millions of qubits. Oratomic says its figure "dramatically" lowers the hardware needed. CyberScoop, a cybersecurity news outlet, reports that Oratomic published this research in the spring.
Some limits matter here. This is a company describing its own research and its own goal. The sources contain no independent check of the estimate. Endres has trapped arrays of 6,000 atomic qubits. That is fewer than 10,000. The announcement does not say the full machine exists.
How the threat works
Much of today's encryption rests on maths problems. Ordinary computers cannot solve them in a practical time. Shor's algorithm is a method a large enough quantum computer could use to solve them. Oratomic says its machine could run that method.
CyberScoop puts the risk simply. Such machines could break the mathematical "locks" that secure data.
Oratomic's design lets atoms be rearranged mid-calculation. The company says this gives more flexible links between qubits. It also says error correction becomes more efficient. Error correction is how a quantum computer catches its own mistakes. The company ties its lower estimate to this design.
The attack that starts before the machine exists
CyberScoop, in an opinion piece, describes "harvest now, decrypt later". Adversaries steal encrypted data today and store it. They wait until they have the computing power to open it. CyberScoop reports that the White House named this threat in its June order.
This changes who carries the risk. The opinion piece says hospitals, banks and utilities use technology that may need to stay secure for decades. Data in that position is at risk long before a capable quantum computer exists. A copy taken today is only as safe as the lock on it.
The clocks do not match
Oratomic notes that global guidelines set 2035 for the move to post-quantum encryption. That is later than the company's own goal for a large-scale machine. The gap between those dates is the point.
Others have set earlier dates. CyberScoop reports that Google is aiming for 2029 for its own move.
CyberScoop also describes a June White House order. The order, as CyberScoop describes it, directs high-value federal systems to adopt post-quantum methods for key establishment by the end of 2030. Digital signatures follow by the end of 2031.
The National Security Agency is also moving national security systems toward its CNSA 2.0 standards.
The lesson here is that a secret's real deadline is its shelf life plus the time to migrate. Add those two numbers. Then compare the total with the dates above. If the total runs past them, the work belongs on this year's plan.
What leaders should ask
Start with an inventory. Which systems use encryption? Which hold data that must stay secret past 2035? Rank those first. They carry the harvest risk today.
Then ask whether each system can swap its encryption method without replacing the whole platform. CyberScoop raises this point for military systems. It applies to any long-lived product.
Ask every key vendor for a written post-quantum plan with dates. Set an internal migration date for each system. Do not wait for a regulator to set one.
Oratomic's numbers are one company's claim, and they deserve scrutiny. But the question they raise does not depend on them. Treat the promise on your encrypted data as having an end date. Then write that date down.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Oratomic.





