A Cryptography Engineer’s Perspective on Quantum Computing Timelines
Privacy Guides Community [Unofficial]
April 10, 2026
The same author talked about there being a practical limit to circuit depth https://x.com/FiloSottile/status/1544680637638008833
Direct quote being
> This MAXDEPTH is realistically around 2⁴⁰, which makes a quantum attack against a 128-bit cipher take more than 2¹²⁸ anyway.
I’m unsure if they meant 256-bit ciphers take more than 2¹²⁸. But still, from what I gather, O(sqrt(n)) is an ideal runtime, not what’s possible in practice.
Discussion in the ATmosphere