Evidence Library · dated · sourced · citable

Questions answered with sealed evidence.

Every entry answers one question with the citable answer up top, a validity date, and sources underneath. Run entries link to sha256-sealed archives anyone can verify. We publish the negatives.

54 sealed runs49 entries3 problem classes0 quantum wins measured29/29 optimization runs: classical at proven optimumupdated 2026-07-29
Can a quantum computer break Bitcoin?
2026-09-03 · Pillar C — Claim explainers
No — as of September 3, 2026, no quantum computer has ever broken a Bitcoin key: the measured record for a public quantum attack on elliptic-curve cryptography is a disputed 15-bit demonstration, against the 256-bit keys Bitcoin actually uses. On paper the target is closer than RSA-2048 — Google's March 2026 blueprint estimates under 500,000 physical qubits and minutes per key, on a machine nobody has built — and between roughly 1.7M and 6.9M BTC already sit behind exposed public keys. Rosetta Q reads both clocks, with sources.
How many qubits does it take to break RSA-2048?
2026-09-02 · Pillar C — Claim explainers
As of September 2, 2026: nobody knows the final number, because it keeps falling. Published engineering estimates for factoring a 2048-bit RSA key have dropped from roughly a billion physical qubits (2012-era) to 20 million (2019) to under 1 million (2025) to a sub-100,000 preprint (February 2026) — a ~10,000× reduction achieved entirely on paper, on the same physics. Meanwhile the honest hardware record for Shor's algorithm is factoring 35, and zero RSA keys have ever been broken by a quantum computer. The number to watch is not any single qubit count; it is the slope of the curve — and NIST's migration deadlines (deprecate after 2030, disallow after 2035) were drafted before the last two drops.
Who is actually ahead in quantum computing in 2026?
2026-09-02 · Pillar E — Maps & data
As of September 2, 2026: no single company is ahead — each major vendor leads a different race. Google leads on error correction and a synthetic-task advantage (Willow, 0.143% error/cycle; Quantum Echoes ~13,000×). Quantinuum leads on logical-qubit execution (Helios, 98 physical → 48 error-corrected logical qubits). IBM leads on ecosystem and its 2029 roadmap (200 logical). IonQ leads on a 99.99% two-qubit fidelity claim (lab prototype). Qubit count does not rank them, and the count of useful end-to-end advantages measured on a real problem is 0 for every vendor.
Quantum annealing vs. gate-based: what can each one do?
2026-09-01 · Pillar B — Canonical dictionary
They share the word "quantum" and little else a buyer should act on. An annealer is one fixed algorithm built as a machine: it relaxes toward low-energy states of an Ising problem — 4,400+ physical qubits shipping today. A gate-based computer is a programmable machine that runs arbitrary circuits — Shor, Grover, chemistry — at 100–1,121 physical qubits. The equivalence theorem people quote covers an idealized cousin of annealing, not the hardware that ships. Neither paradigm has a measured end-to-end advantage on a useful problem as of September 2026.
Neutral atoms: is the third architecture for real?
2026-08-31 · Pillar E — Maps & data
As science, measurably yes: neutral atoms produced the largest fault-tolerant architecture demo published to date (448 atoms; Nature, Nov 2025), the best physical-to-logical encoding ratio reported on any platform (≈4.7:1), and a 50-author industry roadmap with hard numbers (Jul 2026). As computing you can buy advantage from, not yet: per-operation speed runs 100–1,000× behind superconducting machines, the flagship logical-qubit systems are sales and roadmaps rather than measurements, and measured end-to-end wins on useful problems stand at zero — same as every architecture.
What is QRAM, and why is it the silent bottleneck?
2026-08-30 · Pillar B — Canonical dictionary
QRAM (quantum random access memory) is the device that would let a quantum computer read classical data in superposition — the unstated hardware assumption behind most claimed exponential speedups on classical datasets. Without it, loading N numbers costs about N operations, which flattens those speedups before they start. Status in August 2026: the first experimental bucket-brigade QRAM was published in June 2026 — 8 memory cells at 60% fidelity — while the standard-setting survey (Quantum, Dec 2025) argues that cheap, scalable passive QRAM is unlikely with existing proposals. No QRAM at useful scale exists. Status as of: August 2026.
What is a logical qubit, and why does the physical-to-logical ratio decide the timing?
2026-08-29 · Pillar B — Canonical dictionary
A logical qubit is one dependable qubit assembled out of many unreliable physical ones through quantum error correction. The physical-to-logical ratio is the exchange rate that converts the qubit counts vendors announce into the logical qubits algorithms actually consume. Measured ratios in 2024–2025 run from 2:1 (Quantinuum Helios, at a state-prep benchmark) to 101:1 (Google Willow, one memory qubit); roadmaps assume 25:1 to 100:1 at far harder targets. A ratio quoted without its error target is a number without units. As of August 2026, no machine has run a useful end-to-end algorithm on logical qubits.
Does IBM's doped Clifford claim survive the classical counterattack?
2026-08-28 · Pillar C — Claim explainers
Neither refuted nor intact. On August 13, 2026 — day 14 of the claim — Manabe, Gu & Pan computed exact amplitudes for all 2,051 of IBM's published bitstring batches in 37.3 minutes on 256 GPUs, and instead of tearing the experiment down, independently confirmed its fidelity bound (log-XEB 0.35 vs. the certified ≥0.284). What weakened is the hardness half: the instance's quasi-1D geometry admits cheap amplitude computation, and the largest tensor came in 256× below IBM's estimate. The sampling task itself has not been reproduced classically. Status as of 2026-08-28: standing, narrower.
What is an "advantaged solve" and why does it matter?
2026-08-26 · Pillar B — Canonical dictionary
An advantaged solve is one problem instance where a quantum recipe measurably beat the strongest classical baseline its user could field — same instance, same budget, measured, dated, and re-runnable. It is a unit of evidence, not a unit of billing, and it is equally honest about counting zero. As of August 2026, zero advantaged solves are verified in Rosetta Q's ledger — including its own runs.
How can you tell if a quantum advantage claim is credible?
2026-08-25 · Pillar C — Claim explainers
You can read a "quantum advantage" headline in about ten minutes, without being an expert, by asking five questions in a fixed order: is the task useful or synthetic; did the strongest classical rival run the same instance on a matched budget; are re-runnable artifacts published; is the error bound quantitative or heuristic; and how long has the claim survived the classical counterattack. Most reversed claims of the past decade would have exited early in that tree. The three IBM claims of July 30, 2026 are currently open — and the first classical response to one of them arrived 14 days after publication. Status as of August 25, 2026.
Is quantum computing useful for materials and battery simulation today?
2026-08-24 · Pillar A — State by problem class
No — not yet, and the gap is measured in orders of magnitude. As of August 2026, every named industrial battery computation on quantum hardware is a toy demo of 4 to 12 noisy physical qubits, while published fault-tolerant costings for battery molecules ask for hundreds to roughly 100,000 logical qubits — and the best published error-correction demo produces exactly 1 logical qubit. Measured quantum advantage on any battery material: zero. The genuinely quantum bottleneck is real but narrower than the marketing: for most battery materials, classical DFT with corrections already delivers in production.
What is Grover's algorithm and how much speedup does it really give?
2026-08-23 · Pillar B — Canonical dictionary
Grover's algorithm gives a proven quadratic speedup for unstructured search — about √N oracle queries instead of N — and the ceiling is proven too: no quantum algorithm can do better. It does not speed up searching your stored data (loading N items costs about N operations), it is not a practical threat to AES (NIST expects little or no advantage), and the largest better-than-classical run to date used 5 qubits — a 32-item space. Status as of August 2026.
Which industries lead quantum adoption in 2026?
2026-08-21 · Pillar E — Maps & data
Chemicals and life sciences, travel and logistics, and financial services top the 2026 adoption surveys — but what those surveys measure is spending in anticipation, not value in production. As of August 2026: 300+ companies work with quantum vendors and a third spend over $10M a year (McKinsey QTM 2026); 13% self-report some production use, with no published criterion (IQM/TQI survey); and the top rung of the ladder — production with a measured advantage over a strong classical baseline — is empty in every industry.
How do you "cheat" on a quantum benchmark (and how do you avoid it)?
2026-08-20 · Pillar D — Methodology & runs
A quantum benchmark can mislead without anyone lying. Seven protocol-level design choices — cherry-picked instances, uneven tuning budgets, best-of-N reporting, a metric chosen after the fact, silent post-selection, a weak-class classical rival, and simulation sold as hardware — each move the verdict before a single qubit fires. Every documented benchmark reversal in the public record traces to at least one of them. The fix is protocol, not intent: pin every one of those decisions in public, before the run. Status as of: August 2026.
How much have governments committed to quantum computing?
2026-08-19 · Pillar E — Maps & data
As of August 2026, the most-cited aggregate puts public commitments to quantum at $56.7 billion (QED-C, April 2026). But "commitment" is an elastic word: that total mixes multi-year budgets, authorizations that expired without new appropriations, procurement contracts, and third-party estimates nobody can verify. In the same period those commitments grew by $12.7B, governments supplied just 3% of direct startup funding (McKinsey, April 2026). The honest number always comes with three tags: jurisdiction, date, and disbursement status.
What is a "Hamiltonian" and why does it appear in optimization?
2026-08-18 · Pillar B — Canonical dictionary
A Hamiltonian, in the optimization context, is not quantum magic: it is your cost function translated into the format quantum machines minimize — energy. The chain is mechanical: business problem → cost function → QUBO → Ising → Hamiltonian; the minimum-energy configuration spells out the best solution. Two honest footnotes: constraints get encoded as penalty terms that can distort the landscape (a miscalibrated weight makes an infeasible answer win — we show it in four lines of arithmetic), and the fact that every NP problem can be written this way (Lucas, 2014) does not mean a quantum machine solves it better. Status as of: August 2026.
What does a quantum prize challenge actually ask for?
2026-08-17 · Pillar F — Decision-maker
As of August 2026, the money asks for what the marketing skips. XPRIZE Quantum Applications ($5M, 7 finalists) cut teams that failed to demonstrate 'an advantage over strong classical baselines'; Wellcome Leap's Q4Bio paid $2M for an end-to-end run on >50 qubits of real hardware — while we found no announced winner for its $5M prize for demonstrated quantum advantage. Prize rulebooks are the industry's honest requirements document: what a paying third party demands before calling something evidence.
Why does no one maintain a neutral quantum verification ledger?
2026-08-16 · Pillar D — Methodology & runs
As of August 2026, no economically independent body runs every quantum machine under the same rule — same instances, same budgets, re-runnable artifacts, live verdicts. That ledger does not exist because every actor in the ecosystem has a rational reason not to maintain it; the closest attempts (DARPA QBI, Metriq, QOBLIB) each cover a piece of the job, and none covers all of it.
Is quantum computing useful for machine learning today?
2026-08-15 · Pillar A — State by problem class
No — not on classical data, and QML is the one class where the clock ran backwards: the flagship exponential speedups were dequantized to polynomial in 2018–2020, published benchmarks find out-of-the-box classical models ahead, and zero end-to-end QML wins against a strong classical baseline on classical data have been published as of August 2026. The one measured learning advantage uses quantum data: a 100-mode photonic experiment learned with ~11.8 orders of magnitude fewer samples (Science, Sep 2025).
What is error mitigation and why does it make quantum runs more expensive?
2026-08-14 · Pillar B — Canonical dictionary
Error mitigation is statistical post-processing that squeezes less-biased answers out of today's noisy quantum machines — no extra qubits, no logical qubit. Its price is a shot multiplier: 2.5× just to enter with debiasing on IonQ via Braket, and a sample count that is mathematically proven to blow up — superpolynomially, in the worst case — as circuits grow (Quek et al., Nature Physics 2024). It is a bridge tactic priced per shot, not a destination. Status as of: August 2026.
Superconducting vs. trapped-ion qubits: how do they differ?
2026-08-13 · Pillar E — Maps & data
The two dominant architectures trade the same physics in opposite directions. Superconducting circuits switch ~1,000× faster (two-qubit gates in ~60 ns vs ~70 µs) and cost ~190× less per shot on public clouds; trapped ions hold the production-machine fidelity record (~99.92% median two-qubit), all-to-all connectivity, and coherence measured in seconds instead of microseconds. No trade-off axis is resolved — and neither class has demonstrated end-to-end advantage on a useful problem. Status as of August 2026.
What does "radical reproducibility" mean in benchmarking?
2026-08-12 · Pillar D — Methodology & runs
Radical reproducibility means publishing the complete re-run unit — raw data, full code, random seeds, the exact problem instance and the compute budget — together, so anyone can re-execute the benchmark and get the same number without asking permission. As of August 2026 it is the standard that separates a benchmark from an anecdote: every famous reversal of a quantum computing claim was executed by someone re-running public artifacts, not by someone re-reading the paper.
What is VQE and why does it excite chemistry?
2026-08-11 · Pillar B — Canonical dictionary
VQE (Variational Quantum Eigensolver) is a hybrid quantum–classical algorithm that estimates molecular ground-state energies: a parametrized circuit prepares a trial state, the processor measures its energy, a classical optimizer closes the loop. As of August 2026 the largest chemistry VQE on hardware used 12 qubits — and computed classically trivial Hartree–Fock; no published VQE run beats strong classical methods (CCSD(T), DMRG) on the same molecule. Noise, barren plateaus and the measurement bill are the three measured brakes.
Which problems actually have proven quantum advantage?
2026-08-10 · Pillar A — State by problem class
As of August 2026 the honest list is short. Exactly one advantage theorem holds with no assumptions at all (shallow circuits — a constant-depth separation, not a runtime win). A few speedups are proven inside restricted query models, led by Grover's quadratic, which is provably optimal. The famous exponential ones — Shor above all — are conditional: the quantum runtime is proven, the classical hardness is conjecture. Of the 450+ entries in the Quantum Algorithm Zoo, most claims are asymptotic, conditional, or already dequantized. Measured end-to-end advantage on a useful problem against a strong classical baseline: still zero.
What is a qubit, and how does a quantum computer actually work?
2026-08-09 · Pillar B — Canonical dictionary
A bit is one of two definite states. A qubit is two complex amplitudes — and when you measure it, you get one ordinary bit back, probabilistically. A quantum computer does not try every answer in parallel: it choreographs amplitudes so that wrong answers cancel out (interference), which is why only some problem classes get a speedup. As of August 2026, the physical machine is a chip near 25 millikelvin or a row of trapped ions, and one 'run' means executing your circuit thousands of times and reading a histogram.
Is quantum computing useful for financial risk management today?
2026-08-07 · Pillar A — State by problem class
No — as of August 2026, no quantum computer has beaten a strong classical Monte Carlo engine on a real risk workload (VaR, CVaR, greeks) on the same instance. The quadratic speedup from quantum amplitude estimation is real mathematics, proven on paper since 2015. But published resource estimates put the crossover at ~8,000 logical qubits running at tens of MHz of logical clock — hardware that does not exist — and a quadratic speedup is exactly the kind that error-correction overhead eats first. Every hardware demo so far is component-scale: 5 qubits for VaR, 3 for option pricing, 64 for data loading.
When will my industry need quantum capacity?
2026-08-06 · Pillar F — Decision-maker
As of August 2026, no honest answer to this question is a date. Timing is set by the problem class you own, not by your industry label or any vendor's calendar. Three of the four major classes have no measured crossover; the one class with a real deadline is cryptography, where NIST has already scheduled the retirement of today's public-key algorithms — deprecated after 2030, disallowed after 2035 — regardless of when the hardware arrives. The rational posture is not a date. It is a monitoring discipline that costs almost nothing.
Quantum Volume vs. Algorithmic Qubits: what do vendor metrics actually measure?
2026-08-05 · Pillar C — Claim explainers
As of August 2026 there is no vendor-neutral single number for comparing quantum computers. Every headline metric was defined by a vendor and rewards its own architecture: Quantum Volume (defined by IBM in 2019, retired by IBM as its headline metric in 2023, record held by Quantinuum at 2^25 since September 2025), Algorithmic Qubits (defined by IonQ, at #AQ 64 since September 2025, publicly disputed by Quantinuum in March 2024), and qubit count and CLOPS (both led by IBM). Three vendors hold four different crowns under four different rulers, and no published conversion exists between them. Read every single-number claim as a choice of framing, not a ranking.
What is "dequantization" and which quantum claims did it take down?
2026-08-04 · Pillar C — Claim explainers
Dequantization is when a claimed exponential quantum speedup gets matched — up to polynomial factors — by a classical algorithm given the same data access. Since Ewin Tang's 2018 result, it has taken down the exponential claims of quantum recommendation systems, quantum PCA, nearest-centroid clustering, low-rank linear systems, and low-rank SDP/SVM solvers. Shor's factoring, sparse HHL, and Hamiltonian dynamics still stand: they are BQP-complete or unmatched after decades. Status as of: August 2026.
How do you evaluate a quantum pilot without burning the budget?
2026-08-03 · Pillar F — Decision-maker
As of August 2026 you can reach a defensible go/no-go on most quantum pilot candidates before paying for a single second of QPU time. Measure a strong classical baseline first (free), then run the quantum candidate on a noise-free simulator (≈$0 to $4.50/hour) — that run is the candidate's best case, because real hardware only adds noise. Hardware spend ($80 to $8,000+ per experiment) is the last gate of a pilot, not the first.
How much capital went to quantum hardware vs. software in 2025?
2026-08-02 · Pillar E — Maps & data
2025 was a record year under every count — $12.6B into quantum-technology startups (McKinsey, 6.3× 2024) or $4.9B of private VC (QED-C); the tallies differ because their scopes do. What no source publishes is a clean hardware/software split for 2025. The observable proxies all point one way: the year's three largest rounds — PsiQuantum $1B, Quantinuum $600M, IQM $300M+ — are hardware; the largest quantum-software round in history (Classiq, May 2025) is $110M, about a ninth of PsiQuantum's single check.
Is quantum computing useful for routing and logistics today?
2026-08-01 · Pillar A — State by problem class
No — not against a serious classical router. As of August 2026, classical solvers (OR-Tools, Hexaly, LKH) close 1,000-customer capacitated routing to under 1% of optimum in about a minute. The largest vehicle-routing instance ever run on gate-based quantum hardware is 3 nodes; a 4-node run took over 4 hours and returned an infeasible route. The smallest instance in the standard CVRPLIB benchmark needs 5,305+ logical qubits just to encode. Every published quantum-annealing 'logistics case study' that reports good routes is hybrid — a classical solver does the routing. No result beats a strong classical baseline on the same instance.
What is QAOA and what is it for (and not for)?
2026-08-01 · Pillar B — Canonical dictionary
QAOA (2014) is a hybrid quantum-classical algorithm that approximates solutions to combinatorial optimization problems with a shallow, tunable circuit. As of August 2026 it is a research instrument, not a production optimizer: no published QAOA run beats a strong classical solver on the same instance at practical scale, and the strongest evidence in its favor is a noiseless-simulation scaling study in which bare QAOA still trails the best classical heuristic (1.46^N vs 1.34^N).
Why does a weak classical baseline ruin a quantum benchmark?
2026-07-31 · Pillar D — Methodology & runs
A quantum benchmark means nothing on its own — it only means something relative to the classical method it is measured against. Put a weak, under-tuned, or wrong-class classical baseline on the other side and the quantum result 'wins' for free: the crossover point slides toward the quantum side by construction, not by physics. Every reversed 'quantum advantage' claim so far — IBM's 2023 utility run, D-Wave's 2025 spin-glass claim, a decade of quantum-ML speedups — failed the same way: a strong classical baseline showed up late. State as of July 2026.
What is the "crossover point" in quantum advantage?
2026-07-30 · Pillar B — Canonical dictionary
The crossover point is the problem size N* at which a quantum method's better asymptotic scaling finally overtakes the best classical method — despite quantum's enormous constant-factor overhead. Below N*, classical wins; above it, quantum wins. It is the single number that decides whether a speedup is real or academic, and almost no one publishes it with evidence. For a few problems it is estimated on paper (factoring RSA-2048: under a million noisy qubits, Gidney 2025; a 100-site fault-tolerant spin simulation: ~2h quantum vs ~100y classical, arXiv 2607.16116, July 2026). For the optimization problems most businesses care about, no crossover has been measured at all — including in our own 20 sealed portfolio runs.
Can quantum computing discover new drugs today?
2026-07-29 · Pillar A — State by problem class
Not the way headlines imply. As of July 2026 no quantum advantage in drug discovery has been demonstrated at useful scale. The credible near-term contribution is narrow — simulating the electronic structure of strongly-correlated molecules that classical methods approximate poorly — and even that runs inside a classical pipeline led by AlphaFold and industrial docking. Money is pouring in ($12.6B into quantum startups in 2025), demos are real (a virus genome encoded on IBM hardware; hybrid simulations of protein complexes over 12,000 atoms), but no standardized head-to-head benchmark against the strongest classical tools exists yet. We tested a nearby task ourselves — 19 sealed runs on allosteric-site ranking — and under an honest null, nothing was significant.
Is quantum computing useful for portfolio optimization today?
2026-07-28 · Pillar A — State by problem class
Not yet. As of July 2026, classical solvers like Gurobi and CP-SAT solve realistic portfolio-selection instances to a proven optimum in seconds, and no quantum method has shown a durable advantage over them at scale. A large 2025 benchmark found QAOA and quantum annealing failing to beat Gurobi — no better than random sampling on several instances — and our own 20 sealed runs put the classical solver at the proven optimum every time while QAOA sat 25–48% away. Portfolio optimization is a favorite quantum demo because it maps cleanly to a QUBO, but a clean mapping is not an advantage.
Quantum advantage vs. quantum supremacy: what's the difference?
2026-07-28 · Pillar B — Canonical dictionary
Supremacy means a quantum computer does something a classical computer practically can't — on any task, useful or not. Advantage, in its strict sense, means it beats the best classical method on a task someone actually cares about. The field swaps the words constantly, which is why every headline 'supremacy' claim so far has either been narrowed by a better classical algorithm or turned out to be a physics demo with no business use. As of July 2026, no one has shown a durable advantage on a useful, industry-relevant problem — which is exactly the gap Rosetta measures.
What does it cost to run a problem on a real quantum computer?
2026-07-27 · Pillar E — Maps & data
As of July 2026, running one job on a public QPU is cheap — a $0.30 task fee plus per-shot rates from $0.000425 (Rigetti) to $0.08 (IonQ Forte) on Amazon Braket. A real workload is not one job. A modest 100-iteration variational loop at 1,000 shots costs about $73 on the cheapest device and about $8,030 on the most expensive — the identical computation, ~110× apart. Per-shot price is not cost-per-answer: error mitigation multiplies shots, and IBM ($96/min) and Quantinuum bill by wall-clock or opaque credits, not shots.
The wrong null is inflating this whole field: allosteric sites are contiguous pockets, not independent residues
2026-07-26 · Pillar D — Methodology & runs
Allosteric-site predictions are scored by asking whether the true residues rank better than chance — and 'chance' is almost always modelled as independent residues drawn at random. But a real allosteric site is ONE contiguous pocket: its residues are spatially correlated, so the effective sample size is far smaller than the residue count, and every test assuming independence inflates significance. We built the correct null — permute contiguous distal pockets of matched size, 2,000 permutations — and applied it to our own CTQW method first. Apparent z-scores of up to |4.64| collapse to |z| < 1.2. Under the honest null nothing is significant: not our quantum walk, not diffusion, not GNM, ANM, betweenness or closeness, on any of the three targets, with every p between 0.15 and 0.85. The paired test across the full 18-config grid gives zero cells at p < 0.05 on all three targets. Sealed as EXP-0007-017. We are publishing the instrument, not a score — and the instrument's first verdict goes against us.
The harness turns to the grid: first real network-expansion runs (E.ON class)
2026-07-24 · Pillar A — State by problem class
We pointed the same Judge v1 protocol at a new problem class — distribution grid expansion, the E.ON challenge track. On a stressed IEEE case14 feeder with real congestion, a build/no-build QUBO (congestion relief measured by actual DC power flow) was fought QAOA p=2 vs OR-Tools CP-SAT. CP-SAT hit the proven optimum in ~0.3 s; QAOA landed 0.005–3.2% away across 3 seeds. Verdict: not yet. The winning plan, validated in full AC power flow, cut real line overload by 43.5%. Sealed as RQ-0033 / EXP-0033-001…003. Nothing about the protocol changed — only the problem.
Runs 009–020: n=20 joins the ladder, and the curve refuses to be a line
2026-07-24 · Pillar D — Methodology & runs
Twelve new sealed runs: 8 seeds now at n=12 and n=16, and the first four at n=20 (where gradient-based optimization hit a memory wall and the protocol switched to gradient-free COBYLA — recorded in each archive). Mean QAOA gaps: 48.2%±22.5 at n=12, 25.1%±11.1 at n=16, 41.1%±14.1 at n=20 — non-monotonic, no clean size trend. CP-SAT: proven optimum in all 20 runs to date, but its proof time grew from 0.05 s (n=12) to ~29 s (n=20). Verdict, all sizes: not yet.
V-0012: the ledger's first real verdict is a 'not yet' — on purpose
2026-07-24 · Pillar A — State by problem class
The Evidence Ledger now holds its first real, measured verdict. Recipe RQ-0012 (portfolio optimization, QAOA p=2 vs CP-SAT): NOT YET — classical reached the proven exact optimum in all 20 sealed runs at n=12/16/20; no crossover observed, no defensible size trend. Sealed as V-0012 (sha256:f510eff6…6636), backed by 20 run archives in verified triple copy. The demo entry it replaces is gone; the counter reads 1 verdict published, honestly.
How we run the same problem on both kinds of computer
2026-07-23 · Pillar D — Methodology & runs
Every Rosetta run executes one instance twice: once on a quantum algorithm, once on an industrial classical solver, under identical budgets. Today the quantum side runs on statevector simulators (CPU, cloud Linux); the classical side runs OR-Tools CP-SAT on the same machine. Real QPUs via cloud providers enter the ladder later — simulation first is a deliberate methodological choice, not a limitation we hide.
The cryptographic clock: what changes if quantum machines keep their growth rate
2026-07-23 · Pillar F — Decision-maker
The security migration is not hypothetical: NIST finalized the post-quantum standards (FIPS 203/204/205) in August 2024, NSA's CNSA 2.0 mandates PQC for new national security systems from 2027, and NIST IR 8547 deprecates RSA-2048/ECC by 2030 and removes them by 2035. Expert surveys put a cryptographically relevant quantum computer in a 2033–2037 central window. The 'harvest now, decrypt later' exposure applies to data encrypted today. Optimization advantage — what we benchmark — is a separate, harder question.
Where the money went: quantum VC, 2021–2026, with the methodology caveats attached
2026-07-23 · Pillar E — Maps & data
Private quantum investment peaked in 2021, contracted ~40% into 2023, and then broke every record: $4.9B of VC in 2025 — more than double 2024 — anchored by PsiQuantum's $1B Series E at a $7B valuation, the largest private quantum round in history. Capital remains heavily concentrated in hardware; software's share is small by every count, though sources disagree on exactly how small. That disagreement is itself a finding: the field lacks a shared measurement standard for its own money.
Run 001: what an honest quantum benchmark looks like (and why classical won)
2026-07-23 · Pillar D — Methodology & runs
We ran our first real fight: QAOA (quantum, simulated) vs OR-Tools CP-SAT (classical) on the same 12-asset portfolio instance, same time budget, fixed seed. CP-SAT reached the exact optimum in 0.113 s; QAOA landed 42.8% away in 45 s. Verdict: not yet — exactly as theory predicts at this scale. The run is sealed with a SHA-256 hash and archived in triplicate. This is entry 001 of the catalog.
Run 002: the crossover curve gets its second point (still not a trend)
2026-07-23 · Pillar D — Methodology & runs
Same fight, bigger instance: QAOA p=2 vs OR-Tools CP-SAT on a 16-asset portfolio, same Judge v1 protocol, seed 42. CP-SAT again reached the exact optimum (1.0 s); QAOA landed 20.7% away in 97.5 s. Verdict: not yet. The gap is smaller than at 12 assets (42.8%) — and we are explicitly NOT calling that a trend: one seed per size proves nothing. Sealed as EXP-0012-002.
Runs 003–008: variance dissolves the trend (and that's the system working)
2026-07-23 · Pillar D — Methodology & runs
We ran 3 new seeds per size. At n=12 the QAOA gap spans 23.4%–53.7% (mean ≈40.9%); at n=16 it spans 20.7%–42.3% (mean ≈28.8%). The ranges overlap: run 002's apparent 'gap shrinks with size' does not survive measurement. Classical CP-SAT hit the proven optimum in every one of the 8 runs to date. Verdict, all runs: not yet. Six sealed archives, EXP-0012-003 through -008.