Last updated: July 2025
Key Takeaways
- Quantinuum’s H1-1 trapped-ion processor solved a memory task using 12 qubits that requires between 62 and 382 bits of classical memory — a separation proven without relying on unproven complexity assumptions
- The 99.941(7)% median two-qubit partial-entangler fidelity achieved on existing hardware confirms that quantum processors can already access the exponentiality of Hilbert space at operationally relevant fidelity levels
- For your organization: the “unproven conjecture” buffer that justified delaying PQC migration has narrowed — unconditional quantum advantage on current hardware compresses your safe planning window
[IMAGE: A trapped-ion quantum processor suspended in a vacuum chamber, with entangled photon beams forming geometric lattice patterns in deep teal and violet light against a near-black background, macro lens perspective revealing individual ion trap electrodes in cinematic 8K detail]
The Assumption Your Security Architecture Depends On Is Weakening
Every CISO who has deferred a post-quantum migration has, consciously or not, made a bet: that quantum hardware capable of breaking classical cryptographic assumptions is still years away, and that today’s quantum advantage claims rest on unproven mathematical conjectures that may never fully materialize.
That bet just got harder to justify.
In a preprint published on arXiv (identifier: 2509.07255v2), Quantinuum’s research team demonstrated what they term quantum information supremacy — a quantum advantage that carries no asterisk. Unlike previous sampling-based supremacy claims from Google and IBM, which depend on the unproven hardness of classical simulation, this result establishes an unconditional separation between quantum and classical information resources. The math does not require a conjecture to hold. The advantage is provable.
For security architects, the distinction matters enormously. A conjecture-dependent advantage can be dismissed as theoretical. An unconditional one cannot.
What “Unconditional” Actually Means in This Context
Quantum information supremacy, as defined by Quantinuum’s research, is a benchmark in which a quantum processor demonstrably outperforms any classical system on a specific task — not because classical simulation is assumed to be hard, but because it is proven to require more resources than the quantum system uses.
The specific task constructed for this demonstration requires between 62 and 382 bits of classical memory for the most space-efficient classical algorithm. The same task runs on the H1-1 processor using 12 qubits.
This is not a sampling experiment where classical hardness is inferred from complexity theory. The memory separation is a direct, measurable resource comparison. Classical systems need more memory. Full stop.
“Our result provides the most direct evidence yet that currently existing quantum processors can generate and manipulate entangled states of sufficient complexity to access the exponentiality of Hilbert space. This form of quantum advantage — which we call quantum information supremacy — represents a new benchmark in quantum computing, one that does not rely on unproven conjectures.” — Quantinuum research team, arXiv:2509.07255v2
The mechanism underlying this separation is the exponentiality of Hilbert space — the mathematical structure that gives quantum systems their representational power. A 12-qubit system operating at high fidelity can encode and manipulate a state space that grows exponentially with qubit count, a resource classical bits cannot replicate without proportionally scaling memory.
Technical Deep-Dive: Hardware Fidelity and the Memory Gap
H1-1 Performance Parameters
The H1-1 is a trapped-ion quantum computer. Trapped-ion architectures are notable for their high gate fidelity and long coherence times relative to superconducting alternatives — characteristics that matter when the task requires manipulating entangled states with sufficient precision to maintain the quantum advantage across the full computation.
The critical hardware metric here: median two-qubit partial-entangler fidelity of 99.941(7)%. At this fidelity level, the error rate per two-qubit gate is approximately 0.059% — low enough that a 12-qubit circuit can execute without error accumulation destroying the entanglement structure the advantage depends on.
The Classical-Quantum Resource Gap
| Metric | Classical System | H1-1 Quantum Processor |
|---|---|---|
| Memory resource required | 62–382 bits (most space-efficient algorithm) | 12 qubits |
| Advantage type | N/A | Unconditional (no complexity assumptions) |
| Basis for hardness claim | Proven memory lower bound | Hilbert space exponentiality |
| Reliance on unproven conjectures | N/A | None |
| Two-qubit gate fidelity | N/A | 99.941(7)% |
| Prior supremacy benchmarks (Bell tests) | Not computationally difficult | Not applicable to this task |
The research team explicitly distinguishes this result from Bell inequality tests, noting that Bell tests are “not computationally difficult tasks” — they demonstrate non-locality but not computational resource advantage. This benchmark targets computational resource separation directly.
Why Previous Supremacy Claims Left Room for Doubt
Google’s 2019 Sycamore result and subsequent sampling-based supremacy demonstrations share a structural vulnerability: the classical hardness of the task is inferred from complexity-theoretic assumptions. If those assumptions are wrong — or if a classical algorithm is found that efficiently simulates the quantum circuit — the advantage evaporates. IBM researchers demonstrated this concern in practice by improving classical simulation of Sycamore’s circuits.
Quantinuum’s approach sidesteps this entirely. The classical memory lower bound is proven, not assumed. The quantum processor uses fewer resources. The separation is unconditional.
The shift from conjecture-dependent to unconditional quantum advantage is not a incremental improvement in benchmark quality — it is a categorical change in what the result proves about the computational power of existing quantum hardware.
Industry Context: What This Accelerates
NIST Timelines and the Compliance Pressure Already in Motion
NIST finalized its first three post-quantum cryptographic standards in August 2024: ML-KEM (CRYSTALS-Kyber), ML-DSA (CRYSTALS-Dilithium), and SLH-DSA (SPHINCS+). The U.S. Office of Management and Budget issued guidance requiring federal agencies to inventory cryptographic assets and begin migration planning. CISA’s post-quantum roadmap targets 2035 as the deadline for federal systems to complete migration from RSA and ECC.
The Quantinuum result does not break RSA today. Twelve qubits running a memory task is not Shor’s algorithm at scale. But it does something strategically significant: it removes the “hardware isn’t there yet” argument from the delay calculus. Quantum processors operating at 99.941% two-qubit fidelity can already access the exponentiality of Hilbert space on 12-qubit tasks. The question is no longer whether quantum hardware can achieve this class of advantage — it is how quickly qubit counts and fidelity scale to cryptographically relevant circuit depths.
The Economic Argument for Acting Now
Migration costs scale with delay. Organizations that begin cryptographic inventory and hybrid deployment now face a manageable transition. Organizations that wait until quantum hardware reaches cryptographically relevant scale face emergency migration under active threat conditions — a scenario where vendor timelines, certificate authority backlogs, and internal change management compress simultaneously.
Gartner estimated in 2023 that organizations beginning PQC migration after 2026 will face 3-5x higher remediation costs compared to those starting in 2024-2025, driven by legacy system complexity and compressed timelines. The Quantinuum result strengthens the case for front-loading that investment.
The BeQuantum Perspective: Unconditional Advantage Changes the Threat Model
At BeQuantum, our PQC Layer and Digital Notary infrastructure are built on a specific architectural assumption: that the transition from classical to post-quantum cryptography is not a future event to plan for — it is an ongoing operational requirement that organizations must address in layers, starting now.
The Quantinuum result reinforces why we designed the PQC Layer around hybrid key encapsulation mechanisms (hybrid KEM) that combine classical ECDH with ML-KEM in a single handshake. This approach means that even if classical key exchange is compromised by a future quantum attack, the ML-KEM component maintains confidentiality. The hybrid design also means organizations do not need to wait for full PQC ecosystem maturity before gaining protection.
For content authenticity and blockchain verification — core functions of BeQuantum’s Digital Notary — the unconditional nature of this quantum advantage benchmark matters for a specific reason: the integrity of timestamped cryptographic proofs depends on the long-term hardness of the signature schemes underlying them. An unconditional demonstration that quantum processors can access Hilbert space exponentiality at current fidelity levels is a signal to audit which signature schemes in your notarization pipeline remain quantum-resistant under NIST’s finalized standards.
Organizations running IceCase hardware security modules should verify that their firmware supports ML-DSA for signing operations — the algorithm NIST selected precisely because its security does not depend on the hardness assumptions that quantum advantage results like this one erode.
What You Should Do in the Next 90 Days
Step 1: Audit your cryptographic inventory for conjecture-dependent assumptions (Days 1–30) Map every TLS certificate, code-signing key, and key encapsulation mechanism in your environment. Flag any RSA or ECC-based system where long-term confidentiality matters — these are your highest-priority migration targets. Tools like CISA’s post-quantum cryptography discovery guidance provide a structured framework for this audit.
Step 2: Deploy hybrid KEM on your highest-risk key exchange paths (Days 30–60) You do not need to complete a full migration to reduce exposure. Deploying ML-KEM in hybrid mode alongside existing ECDH on your VPN gateways, API authentication layers, and certificate authority infrastructure provides immediate quantum resistance on the paths most likely to be targeted by harvest-now-decrypt-later attacks. Prioritize any data with a confidentiality requirement extending beyond 2030.
Step 3: Establish a quantum hardware monitoring function (Days 60–90) The Quantinuum result will not be the last unconditional quantum advantage demonstration. Assign ownership — whether internal or through a managed security provider — for tracking quantum hardware fidelity milestones, NIST standard updates, and cryptographic deprecation timelines. The organizations that respond fastest to the next milestone will be those with monitoring already in place.
Frequently Asked Questions
Q: Does this result mean quantum computers can break RSA or ECC today? A: No. The Quantinuum demonstration uses 12 qubits on a specific memory task — not Shor’s algorithm, which requires thousands of logical qubits with error correction to attack RSA-2048 at scale. What the result proves is that existing quantum hardware can achieve unconditional computational advantage, removing the conjecture-dependent buffer that previously allowed organizations to discount near-term quantum risk. The hardware trajectory now has a proven capability floor, not just a theoretical ceiling.
Q: How is “quantum information supremacy” different from Google’s 2019 quantum supremacy claim? A: Google’s Sycamore result demonstrated that a specific sampling task was faster on quantum hardware than on classical simulators — but the classical hardness of that task depended on unproven complexity-theoretic assumptions. Subsequent classical algorithm improvements narrowed the claimed advantage. Quantinuum’s result establishes a memory separation that is proven, not assumed: the classical algorithm requires 62–382 bits of memory; the quantum processor uses 12 qubits. No complexity conjecture is required for the separation to hold.
Q: Should we wait for peer review before updating our threat model? A: The arXiv preprint (2509.07255v2) has not yet completed formal peer review. However, the underlying mathematical framework — Bell inequalities, Hilbert space structure, and classical memory lower bounds — draws on well-established quantum information theory. Security architects should treat this as a credible signal requiring a threat model review, not a confirmed worst-case scenario requiring emergency response. The appropriate action is accelerating planned PQC migration steps, not reactive system shutdowns.