{
 "_about": "Every quantum factoring or key-breaking claim that reached the press, with what was actually done. 'kind' is shor, adiabatic, hybrid, ecc or stunt. CC BY 4.0, Nan · hongdam.net.",
 "rows": [
  {"date": "2001-12", "who": "Vandersypen and others, IBM Almaden and Stanford", "claimed": "15 = 3 × 5 by Shor's algorithm", "did": "Seven nuclear spins in a molecule ran a circuit compiled with the answer known. The first hardware Shor.", "bits": 4, "kind": "shor", "verdict": "Real, tiny, compiled.", "src": ["vandersypen2001"]},
  {"date": "2012-03", "who": "Xu and others, USTC", "claimed": "143 factored on four qubits", "did": "An adiabatic minimisation, not Shor; the problem was reduced to a few unknown bits first. In 2014 Dattani and Bryans showed the same run had also 'factored' 56,153, because the trick only depends on how the factors' bits differ.", "bits": 8, "kind": "adiabatic", "verdict": "No route to big numbers.", "src": ["xu2012", "dattani2014"]},
  {"date": "2012-10", "who": "Martín-López and others, Bristol", "claimed": "21 = 3 × 7 by Shor's algorithm", "did": "Photons and a recycled qubit; compiled. Still the largest Shor factorisation on hardware in 2026.", "bits": 5, "kind": "shor", "verdict": "Real, tiny, compiled.", "src": ["martinlopez2012"]},
  {"date": "2016-03", "who": "Monz and others, Innsbruck", "claimed": "A scalable Shor's algorithm on five trapped ions — 15", "did": "The first run of the full Kitaev-style period finding without shortcuts in the quantum part, on 15.", "bits": 4, "kind": "shor", "verdict": "Real, tiny, cleaner.", "src": ["monz2016"]},
  {"date": "2019-03", "who": "Amico, Saleem and Kumph, IBM", "claimed": "35 on IBM Q hardware", "did": "The attempt failed: noise swamped the answer. An honest negative result.", "bits": 6, "kind": "shor", "verdict": "Did not work.", "src": ["amico2019"]},
  {"date": "2021-03", "who": "Claus Peter Schnorr", "claimed": "'This destroys the RSA cryptosystem' (a classical lattice method)", "did": "No challenge number was factored; the sentence was dropped in a revision; later work found the method fails past about 80 bits.", "bits": 0, "kind": "stunt", "verdict": "Nothing was destroyed.", "src": ["schnorr2021", "schneier2021"]},
  {"date": "2022-12", "who": "Yan and 23 others", "claimed": "372 qubits could challenge RSA-2048", "did": "Schnorr's method with a small quantum optimiser in the loop; the hardware run split a 48-bit number on ten qubits. The classical part is the part that does not scale.", "bits": 48, "kind": "hybrid", "verdict": "Aaronson: 'cargo cult quantum factoring'.", "src": ["yan2022", "aaronson2023"]},
  {"date": "2024-05", "who": "Wang Chao and others, Shanghai University", "claimed": "RSA broken on a D-Wave annealer (the October 2024 headlines)", "did": "A 22-bit number, 2,269,753, on a quantum annealer. Annealing has no known advantage at scale.", "bits": 22, "kind": "adiabatic", "verdict": "22 bits against 2048.", "src": ["wang2024"]},
  {"date": "2024-12", "who": "Wang Chao and others", "claimed": "'A first successful factorization of RSA-2048 integer by D-Wave'", "did": "On integers whose two primes differ in two low bits — every one of which Fermat's 1643 method splits in milliseconds. Not an RSA key.", "bits": 2048, "kind": "stunt", "verdict": "The number was chosen to be easy.", "src": ["wang2024b"]},
  {"date": "2025-04", "who": "Wang Chao's group, reported by the SCMP", "claimed": "A 90-bit RSA number on a D-Wave machine", "did": "No paper located as of September 2026.", "bits": 90, "kind": "adiabatic", "verdict": "Unconfirmed.", "src": ["wang2025"]},
  {"date": "2025-07", "who": "Steve Tippeconnic", "claimed": "A 5-bit elliptic-curve key broken on IBM's 133-qubit machine", "did": "A 15-qubit circuit over a 32-element group; the answer, k = 7, is found by classical post-processing of the readouts.", "bits": 5, "kind": "ecc", "verdict": "A toy key, run for real.", "src": ["tippeconnic2025"]},
  {"date": "2026-04", "who": "Giancarlo Lelli; the Q-Day Prize", "claimed": "A 15-bit curve key recovered on IBM Heron processors — one bitcoin awarded", "did": "About 98,000 gates on cloud hardware. Bitcoin developers reproduced the recovery from random bits, since 32,767 candidates can simply be checked; the hardware output was 'statistically indistinguishable from coin flips'.", "bits": 15, "kind": "ecc", "verdict": "Project Eleven's CEO: 'not Q-Day'.", "src": ["qday2026", "qday2026b"]}
 ],
 "largest_shor_hardware": {"number": 21, "year": 2012, "note": "the largest integer split by Shor's algorithm on a physical machine as of September 2026, and it was compiled"}
}
