In December 2025, researchers at the University of Science and Technology of China (USTC) reported that a 107-qubit processor called Zuchongzhi 3.2 had crossed the error correction threshold. Google’s Willow team had published the same class of result 12 months earlier. Two laboratories in the world have now put that milestone into a peer-reviewed journal, and one of them is in Hefei.
Twelve months looks like a comfortable margin. It is also the distance between two publication dates, and a publication date is not a capability date. Chinese quantum research runs under export restrictions on quantum cryptography technology, institutional control over researcher travel, and a national security review layer with no Western equivalent. Under those conditions, what gets published is a subset of what gets done.
We can’t resolve that ambiguity, and neither can anyone outside a small set of Chinese institutions. What we can do is read the published record precisely, and that turns out to be the more useful skill anyway. China makes a good case study for it. World-leading peer-reviewed results, unverifiable commercial claims, and outright marketing all appear in the same news cycle, often in the same article.
Two milestones that keep getting confused
Most coverage of Chinese quantum hardware runs together two achievements with very different consequences.
Random circuit sampling is a benchmark. A processor executes a random sequence of quantum gates, the team measures the output distribution, and researchers estimate how long a classical supercomputer would need to reproduce it. The task was designed to be hard for classical machines and useful for nothing else. It measures raw device scale and gate quality. It does not put a program on the machine.
Below-threshold error correction is an engineering prerequisite. Today’s qubits are physical qubits: individual, noisy, and prone to failure within microseconds. A logical qubit is one reliable qubit assembled from many physical ones through an error-correcting code, most often the surface code. Code distance is the size dial on that code, and a larger distance means more physical qubits spent per logical qubit and more error suppression bought in return. Below threshold, the logical error rate falls as the distance grows. Above threshold, extra qubits add noise faster than the code removes it, and the machine gets worse the bigger you build it.
The number that tracks this is the error suppression factor, written as Lambda. It states how much the logical error rate improves for each step up in code distance, and anything above 1.0 means the code is winning.
Every published route to breaking RSA or elliptic-curve cryptography runs through below-threshold operation. None of them runs through random circuit sampling. A program can lead the world on the second measure and be nowhere on the first.
The Zuchongzhi line
Pan Jianwei and Zhu Xiaobo’s group at USTC has developed the same processor family since 2021, named after the fifth-century mathematician who computed pi to seven decimal places. The lineage is the single most useful barometer of Chinese superconducting capability, because every generation has been published.
| Processor | Date | Physical qubits | Reported result |
|---|---|---|---|
| Zuchongzhi 1.0 | May 2021 | 62 | Programmable quantum walks, no advantage claim |
| Zuchongzhi 2.0 / 2.1 | Oct 2021 | 66 | Random circuit sampling advantage, distance-3 surface code error detection |
| Zuchongzhi 3.0 | Mar 2025 | 105 | 83-qubit random circuit sampling, 99.62% two-qubit gate fidelity |
| Zuchongzhi 3.2 | Dec 2025 | 107 | Below-threshold error correction at distance 7, Lambda reported at 1.40 |
Two-qubit gate fidelity is the share of two-qubit operations that come out correct. At 99.62%, roughly four operations in every thousand go wrong, and those errors compound across the depth of a circuit.
Four and a half years took this group from a quantum walk demonstration to below-threshold error correction. Google covered comparable ground from Sycamore in 2019 to Willow in December 2024. Neither program did anything the other could not follow.
What the error correction numbers say
Willow reported Lambda at 2.14 for distance 7, together with break-even: the logical qubit outlived the best physical qubit on the chip by a factor of 2.4. Zuchongzhi 3.2 reported 1.40 and made no break-even claim. On the headline metric, the Chinese result is the weaker of the two.
The architecture underneath produces a different scaling argument. Superconducting qubits do not only flip between 0 and 1. They occasionally leak into higher energy states the code cannot see, and leaked qubits corrupt error correction without registering as errors. Google’s leakage removal uses dedicated DC pulse hardware, and that means additional wiring inside the dilution refrigerator for every qubit. The USTC team reports an all-microwave scheme that suppresses leakage through pulse sequences alone, with no added hardware, and reports a 72-fold reduction in leaked population.
At 105 qubits, wiring per qubit is an inconvenience. At 100,000, it’s the whole problem. Cryogenic wiring density, heat load, and control-line count sit among the hardest constraints on scaling any superconducting machine, so a technique that trades hardware for software is worth more than one Lambda point suggests. It is also unproven at scale. So is Google’s. Nobody has built the system that settles the question.
Suppressing errors in a memory experiment is one problem. Performing operations on error-corrected qubits is a different one, and China has published almost nothing there. Quantinuum reported dozens of error-corrected logical qubits on its trapped-ion Helios system in late 2025. Harvard and QuEra have run logical circuits on neutral atoms. IBM has demonstrated real-time decoding of quantum low-density parity-check codes at sub-microsecond latency. Decoding is the classical processing step that reads the error data coming off the chip and works out which correction to apply, and it has to keep pace with the qubits, or the correction arrives too late to be worth applying. Chinese groups have published no comparable work on logical gate operations at surface-code scale, and no decoder latency benchmarks at all.
Set against what a cryptographically relevant quantum computer (CRQC) needs, both countries are a long way out. A Google estimate published in March 2026 puts breaking 256-bit elliptic-curve cryptography at roughly 1,200 logical qubits, which it maps to fewer than 500,000 noisy physical qubits. The best-characterised processors on either side are in the low hundreds of physical qubits. The interesting question is not who counts more qubits today, but who is building the error correction stack that survives four orders of magnitude of growth.
The modality spread
A focus on Zuchongzhi misses how broad the Chinese portfolio has become. Four platforms are advancing in parallel, and they’re not equally relevant to cryptography.
Photonics. The Jiuzhang series at USTC, led by Lu Chaoyang, has produced the largest photonic quantum demonstrations anywhere: 76 detected photons in 2020, 255 in 2023, and an unrefereed 2025 preprint claiming 3,050. All of them perform Gaussian boson sampling, a photon-counting task chosen because it resists classical simulation. It is not universal computation, and it does not run Shor’s algorithm. Read scale records in this line as physics, not as movement toward a CRQC.
Trapped ions. Duan Luming’s group at Tsinghua trapped 512 ions in a two-dimensional crystal with single-ion readout on 300 of them, published in Nature in 2024. It is the largest site-resolved ion system demonstrated anywhere. Four Chinese trapped-ion companies have formed since. None of them has published the two-qubit gate fidelities that determine what a machine can compute, and both Quantinuum and IonQ publish theirs.
Neutral atoms. USTC assembled a defect-free array of 2,024 rubidium atoms in 2025 using machine-learning-driven optical tweezers. A Chinese Academy of Sciences institute in Wuhan has fielded Hanyuan-1, a 100-qubit neutral-atom system that runs at room temperature in standard equipment racks with no dilution refrigerator, and has sold it commercially. Neutral atoms carry the most aggressive scaling roadmaps globally, with QuEra targeting systems of 10,000 or more physical qubits.
Silicon spin qubits. A team at the Shenzhen International Quantum Academy reported universal logical operations on a silicon processor in early 2026, encoding two logical qubits into four phosphorus nuclear spins. The system is tiny. Silicon is also the one modality that could reuse existing semiconductor fabrication lines, subject to isotopic purification and lithography requirements that are not trivial CMOS adaptation.
Qubit counts and the marketing gap
Tianyan-504, built by China Telecom Quantum Group with the Chinese Academy of Sciences and QuantumCTek, carries a 504-qubit superconducting chip and is China’s largest processor by qubit count. No independent benchmark of its gate fidelities or coherence times has been published. Qubit count without fidelity data is a marketing number. Its real significance is control electronics. A Chinese-built stack that addresses 500 qubits is a supply-chain achievement.
Origin Quantum, a USTC spinout founded by Guo Guoping and Guo Guangcan, is the only Chinese firm shipping full-stack superconducting machines. Its 72-qubit Wukong has been available on a public cloud platform since January 2024, and its published coherence figures sit well below those reported for leading Western superconducting processors. Its 2021 roadmap called for 1,024 qubits by 2025 and delivered 72. Roadmaps slip everywhere in this industry, and that gap is still wide.
Two closures changed Chinese quantum research more than any single machine did. Alibaba shut its quantum laboratory in November 2023. Baidu closed its own in January 2024 and donated the equipment to universities. The private technology giants have left the field to state-aligned institutions, which concentrates funding and narrows the base of people trying unlikely ideas.
Export controls and the self-sufficiency loop
Export controls on dilution refrigerators, cryogenic components, and quantum processors have shaped three years of Chinese hardware development. The short-term effect was disruption. The medium-term effect looks familiar.
QuantumCTek now manufactures dilution refrigerators domestically. Origin Quantum developed its own cryogenic line and has exported units. Photonic approaches attract investment partly because they sidestep the cryogenic supply chain altogether. The controls may prove counterproductive over a longer horizon, and the pattern has precedent. Restrictions on Huawei in 5G and on SMIC in semiconductors each created a guaranteed domestic market and a political mandate for import substitution. Neither industry disappeared.
Origin Quantum also distributes its Origin Pilot operating system for quantum machines free of charge, with support for superconducting, trapped-ion, and neutral-atom hardware. A university anywhere in the world can take a Chinese control stack rather than write one, and every group that does inherits Chinese design assumptions about calibration, scheduling, and hardware abstraction.
What the published record supports
Read against the capability stages that lead to a CRQC, the Chinese record splits cleanly in two.
Demonstrated and peer-reviewed: error correction on a surface code, real-time syndrome extraction, which is the business of reading out where an error occurred without disturbing the encoded data, and below-threshold operation at distance 7. Add two-dimensional qubit connectivity with tunable couplers, and a fabricated 504-qubit chip.
Not publicly demonstrated: high-fidelity logical gate operations at surface-code scale, magic state distillation, which supplies the resource an error-corrected machine needs for the gates a surface code cannot perform natively and which dominates every published CRQC cost estimate, fault-tolerant algorithm compilation, decoder latency benchmarks, and long-duration computation. No manufacturing yield data has appeared either.
That is where we’d expect a program running 12 to 24 months behind the leaders. It is also where we’d expect a program that keeps its best work classified. The published evidence supports both readings, and treating either one as settled is the error.
What this changes for a migration plan
Nothing. The inputs that set a migration date sit somewhere else entirely, and there are three of them: how long your data has to stay confidential, what your regulators have already scheduled, and how long your own cryptographic estate takes to change.
An encrypted record captured today with a 15-year confidentiality requirement already falls inside the window under every credible CRQC estimate. NIST finalised ML-KEM, ML-DSA, and SLH-DSA in August 2024, and selected Hamming Quasi-Cyclic (HQC) as a backup key-establishment algorithm in March 2025. The federal deadline structure is published. Insurers and large enterprise buyers have started to ask about it in procurement.
Hardware news changes one thing, and that is the width of the error bars. Below-threshold error correction reproduced in a second country narrows the plausible range at the low end. It does not move a date, and it does not create one. Teams that rebuild their programme around each announcement spend the decade reacting. Teams that build around data lifetime and regulatory dates spend it migrating.
Where we teach this
Reading a national hardware programme well is a specific and learnable skill. It asks what a code distance is, what a missing fidelity number rules out, which benchmarks map onto cryptographic risk, and which are physics results wearing a computing headline. We build that reading skill first with our learners, then attach it to the decisions it serves: cryptographic inventory, migration sequencing, and vendor assessment.
You can explore the certification programs at quantumacademy.com/.
For the migration methodology this work feeds into, see pqcframework.org. For the deeper technical treatment of China’s hardware record, with the full citations behind the results above, see the original analysis on PostQuantum.com.