Quantum simulation promises to advance materials discovery by accurately simulating complex states of matter, their microscopic excitations, and macroscopic response functions. The central challenge in resolving the underlying interacting dynamics is to combine high-fidelity evolution with the sophisticated control necessary to manipulate individual quasi-particles in quantum many-body states. Here, we report on high-precision simulation of both linear and non-linear response functions in a 2D XY spin-1/2 magnet using an analog-digital superconducting processor of up to 97 qubits. By interleaving digital gates with analog evolution precisely characterized via Hamiltonian learning, we selectively excite magnons at tunable energy densities. Measuring first the linear magnon response – a central probe in neutron-scattering experiments – we extract temperature-dependent spectra and lifetimes. Our results reveal stark variations in magnon decay rates across the Brillouin zone, with enhancement near van Hove singularities and suppression for edge-localized modes. Next, we perform a suite of nonlinear measurements, including the study of self-scattering mechanisms, as well as pump-probe spectroscopy to directly characterize the magnon interactions. While matrix-product state simulations capture the dynamics well in either small systems or at low temperatures, their predictions become inaccurate away from these limits. This work demonstrates precise simulation of the interacting dynamics in quantum magnets, and provides key insights into quasi-particles and their microscopic scattering mechanisms.
The expected emergence of cryptographically relevant quantum computers (CRQCs) will represent a singular discontinuity in the history of digital security, with wide ranging impacts. This Perspective seeks to elucidate specific implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and potential mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem over the secp256k1 curve, the core of modern blockchain cryptography. We demonstrate that Shor’s algorithm for this problem can execute with either ≤1200 logical qubits and ≤90 million Toffoli gates or ≤1450 logical qubits and ≤70 million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with 10^{−3} physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between “fast-clock” (such as superconducting and photonic) and “slow-clock” (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable “on-spend” attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, proof-of-stake consensus, and data availability sampling mechanism, as well as the enduring concern of “abandoned” assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of “digital salvage” to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to post-quantum cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the migration to PQC without delay.
This perspective outlines promising pathways and critical obstacles on the road to developing useful quantum computing applications, drawing on insights from the Google Quantum AI team. We propose a five-stage framework for this process, spanning from theoretical explorations of quantum advantage to the practicalities of compilation and resource estimation. For each stage, we discuss key trends, milestones, and inherent scientific and sociological impediments. We argue that two central stages—identifying concrete problem instances expected to exhibit quantum advantage, and connecting such problems to real-world use cases—represent essential and currently under-resourced challenges. Throughout, we touch upon related topics, including the promise of generative artificial intelligence for aspects of this research, criteria for compelling demonstrations of quantum advantage, and the future of compilation as we enter the era of early fault-tolerant quantum computing.
We describe an efficient quantum algorithm for solving the linear matrix equation AX + XB = C, where A, B and C are given complex matrices and X is unknown. This is known as the Sylvester equation, a fundamental equation with applications in control theory and physics. Assuming block-encoding access to the matrices, our approach constructs the solution matrix X/x also in a block-encoding, where x > 0 is a rescaling factor needed for normalization. This allows us to obtain certain properties of the entries of X exponentially faster than would be possible from preparing X as a quantum state. The query and gate complexities of the quantum circuit that implements this block-encoding are almost linear in a condition number that depends on A and B, and depend logarithmically in the dimension and inverse error. We show how our quantum circuits can solve BQP-complete problems efficiently, discuss potential applications and extensions of our approach, its connection to Riccati equation, and comment on open problems.
This whitepaper seeks to elucidate implications that the capabilities of developing quantum architectures have on blockchain vulnerabilities and mitigation strategies. First, we provide new resource estimates for breaking the 256-bit Elliptic Curve Discrete Logarithm Problem, the core of modern blockchain cryptography. We demonstrate that Shor's algorithm for this problem can execute with either <1200 logical qubits and <90 million Toffoli gates or <1450 logical qubits and <70 million Toffoli gates. In the interest of responsible disclosure, we use a zero-knowledge proof to validate these results without disclosing attack vectors. On superconducting architectures with 1e-3 physical error rates and planar connectivity, those circuits can execute in minutes using fewer than half a million physical qubits. We introduce a critical distinction between fast-clock (such as superconducting and photonic) and slow-clock (such as neutral atom and ion trap) architectures. Our analysis reveals that the first fast-clock CRQCs would enable on-spend attacks on public mempool transactions of some cryptocurrencies. We survey major cryptocurrency vulnerabilities through this lens, identifying systemic risks associated with advanced features in some blockchains such as smart contracts, Proof-of-Stake consensus, and Data Availability Sampling, as well as the enduring concern of abandoned assets. We argue that technical solutions would benefit from accompanying public policy and discuss various frameworks of digital salvage to regulate the recovery or destruction of dormant assets while preventing adversarial seizure. We also discuss implications for other digital assets and tokenization as well as challenges and successful examples of the ongoing transition to Post-Quantum Cryptography (PQC). Finally, we urge all vulnerable cryptocurrency communities to join the ongoing migration to PQC without delay.
We present a quantum code implementable on a regular 2D hex grid with an estimated encoding rate up to 4.5× of that of a rotated surface code patch using circuit-level noise in a one- and two-qubit 10^-3 error uniform depolarizing model. Our approach is based on yoking a dense packing of surface code twist defects, enabled by new stabilizer measurement cycles with an optimal four layers of nearest-neighbor two-qubit gates, almost no distance-reducing hook errors, and efficient decoding. We demonstrate a space-efficient architecture for computing on densely packed logical qubits, including new padding-free lattice surgery protocols in an optimal bounding box of 2d^2 data and measurement qubits per patch. Assuming a 1μs surface code cycle time and a 10μs reaction time, these developments enable chemically accurate ground state phase estimation of a broad class of `utility-scale' electronic structure simulation problems such as the 108 spin-orbital FeMoco-based nitrogen fixation catalyst in under a month with 89k noisy superconducting qubits. We elucidate a Pareto frontier of space-time trade-offs and find a minimum physical quantum volume of 1.3 mega-qubit-hours. These correspond to a 36× space and 6.6× spacetime improvement, respectively, over our previous state-of-the-art minimum-Toffoli resource estimates (Phys. Rev. X 15, 041016).
Broadly applicable quantum advantage, particularly in classical data processing and machine learning, has been a fundamental open problem. In this work, we prove that a small quantum computer of polylogarithmic size can perform large-scale classification and dimension reduction on massive classical data by processing samples on the fly, whereas any classical machine achieving the same prediction performance requires exponentially larger size. Furthermore, classical machines that are exponentially larger yet below the required size need superpolynomially more samples and time. We validate these quantum advantages in real-world applications, including single-cell RNA sequencing and movie review sentiment analysis, demonstrating four to six orders of magnitude reduction in size with fewer than 60 logical qubits. These quantum advantages are enabled by quantum oracle sketching, an algorithm for accessing the classical world in quantum superposition using only random classical data samples. Combined with classical shadows, our algorithm circumvents the data loading and readout bottleneck to construct succinct classical models from massive classical data, a task provably impossible for any classical machine that is not exponentially larger than the quantum machine. These quantum advantages persist even when classical machines are granted unlimited time or if BPP=BQP, and rely only on the correctness of quantum mechanics. Together, our results establish machine learning on classical data as a broad and natural domain of quantum advantage and a fundamental test of quantum mechanics at the complexity frontier.
Disorder in quantum many-body systems can drive transitions between ergodic and non-ergodic phases, yet the nature–and even the existence–of these transitions remains intensely debated. Using a two-dimensional array of superconducting qubits, we study an interacting spin model at finite temperature in a disordered landscape, tracking dynamics both in real space and in Hilbert space. Over a broad disorder range, we observe an intermediate non-ergodic regime with glass-like characteristics: physical observables become broadly distributed and some, but not all, degrees of freedom are effectively frozen. The Hilbert-space return probability shows slow power-law decay, consistent with finite-temperature quantum glassiness. In the same regime, we detect the onset of a finite Edwards-Anderson order parameter and the disappearance of spin diffusion. By contrast, at lower disorder, spin transport persists with a nonzero diffusion coefficient. Our results show that there is a transition out of the ergodic phase in two-dimensional systems.
Here we describe an approach for simulating electronic structure on quantum computers with significantly lower asymptotic complexity than prior work. The approach uses a real-space first-quantised representation of the molecular Hamiltonian which we propagate using high-order product formulae. Essential for this low complexity is the use of a technique similar to the fast multipole method for computing the Coulomb operator with O(η) complexity for a simulation with η particles. We show how to modify this algorithm so that it can be implemented on a quantum computer. We ultimately demonstrate an approach with t(η^4/3N^1/3 + η^1/3 N^2/3 ) (ηNt/ε)^o(1) gate complexity, where N is the number of grid points, ε is target precision, and t is the duration of time evolution. This is roughly a speedup by O(η) over most prior algorithms. We provide lower complexity than all prior work for N<η^7 (the regime of practical interest), with only first-quantised interaction-picture simulations providing better performance for N>η^7. As with the classical fast multipole method, large particle numbers η≳ 10^3 would be needed to realise this advantage.
Disorder-induced phenomena in quantum many-body systems pose significant challenges for analytical methods and numerical simulations at relevant time and system scales. To reduce the cost of disorder-sampling, we investigate quantum circuits initialized in states tunable to superpositions over all disorder configurations. In a translationally-invariant lattice gauge theory (LGT), these states can be interpreted as a superposition over gauge sectors. We observe localization in this LGT in the absence of disorder in one and two dimensions: perturbations fail to diffuse despite fully disorder-free evolution and initial states. However, Rényi entropy measurements reveal that superposition-prepared states fundamentally differ from those obtained by direct disorder sampling. Leveraging superposition, we propose an algorithm with a polynomial speedup in sampling disorder configurations, a longstanding challenge in many-body localization studies.
We present sum-of-squares spectral amplification (SOSSA), a framework for improving quantum simulation relevant to low-energy problems. We show how SOSSA can be applied to problems like energy and phase estimation and provide fast quantum algorithms for these problems that significantly improve over prior art. To illustrate the power of SOSSA in applications, we consider the Sachdev-Ye-Kitaev model, a representative strongly correlated system, and demonstrate asymptotic speedups over generic simulation methods by a factor of the square root of the system size. Our results reinforce those observed in [G. H. Low et al., arXiv:2502.15882], where SOSSA was used to achieve state-of-the-art gate costs for phase estimation of real-world quantum chemistry systems.
We demonstrate an asymptotic gate complexity improvement in first-quantized ground-state energy estimation of electronic structure Hamiltonians in a plane wave basis by employing the sum-of-squares spectral gap amplification protocol. The improvement relies on identifying a sum-of-squares representation of the Hamiltonian which provides a lower bound certificate and low cost block encoding that leads to a provably lower quantum phase estimation gate cost. This is achieved by using a sum-of-squares operator generated by the total charge density operator resulting in a block encoding normalization improvement of λ= 𝒪(ηΔ^-1.5+η^1.5Δ^-1) compared to prior work λ= 𝒪(ηΔ^-2+η^2Δ^-1) where η is the number of electrons and Δ is the simulation grid spacing. The asymptotic reduction in block encoding normalization and similar block encoding costs to prior work is demonstrated to reduce resource estimates for materials and chemical systems by a factor of 2 - 44× corresponding to the lowest cost estimates for ab initio materials simulation.
Quantum error correction (QEC) is the primary strategy for protecting a quantum computer from the environment1,2. The prerequisite of QEC is that errors must remain sufficiently rare, which requires perpetually adapting the control parameters of the computer to the drifting environmental conditions. The current solution to this problem is to terminate the entire quantum computation for recalibration, but it is incompatible with the long runtimes of future quantum algorithms3,4. Here we address this challenge by unifying calibration with computation. We grant the QEC process5-11 a dual role: its error-detection events are not only used to correct the logical quantum state but are also repurposed as a learning signal, teaching a reinforcement learning agent12-16 to continuously steer the control parameters and stabilize the quantum system during computation. We experimentally demonstrate this framework on a Willow superconducting processor, improving the logical stability of the surface code 3.5-fold against injected drift. By synthesizing our full suite of technological advances, we achieve record performance of the surface and colour codes, with average logical error per cycle of 7.72(9) × 10-4 and 8.19(14) × 10-3, respectively. Numerical simulations of large codes with tens of thousands of control parameters confirm the scalability of our RL framework, revealing an optimization speed that is independent of system size. This work thus enables a new paradigm: a quantum computer that learns from its errors and never stops computing.
Simulating quantum dynamics is one of the most important applications of quantum computers. Traditional approaches for quantum simulation involve preparing the full evolved state of the system and then measuring some physical quantity. Here, we present a different and novel approach to quantum simulation that uses a compressed quantum state that we call the "shadow state". The amplitudes of this shadow state are proportional to the time-dependent expectations of a specific set of operators of interest, and it evolves according to its own Schrödinger equation. This evolution can be simulated on a quantum computer efficiently under broad conditions. Applications of this approach to quantum simulation problems include simulating the dynamics of exponentially large systems of free fermions or free bosons, the latter example recovering a recent algorithm for simulating exponentially many classical harmonic oscillators. These simulations are hard for classical methods and also for traditional quantum approaches, as preparing the full states would require exponential resources. Shadow Hamiltonian simulation can also be extended to simulate expectations of more complex operators such as two-time correlators or Green's functions, and to study the evolution of operators themselves in the Heisenberg picture.
Understanding how interacting particles approach thermal equilibrium is a major challenge of quantum simulators1,2. Unlocking the full potential of such systems towards this goal requires flexible initial state preparation, precise time evolution and extensive probes for final state characterization. Here we present a quantum simulator comprising 69 superconducting qubits that supports both universal quantum gates and high-fidelity analogue evolution, with performance beyond the reach of classical simulation in cross-entropy benchmarking experiments. This hybrid platform features more versatile measurement capabilities compared with analogue-only simulators, which we leverage here to reveal a coarsening-induced breakdown of Kibble-Zurek scaling predictions3 in the XY model, as well as signatures of the classical Kosterlitz-Thouless phase transition4. Moreover, the digital gates enable precise energy control, allowing us to study the effects of the eigenstate thermalization hypothesis5-7 in targeted parts of the eigenspectrum. We also demonstrate digital preparation of pairwise-entangled dimer states, and image the transport of energy and vorticity during subsequent thermalization in analogue evolution. These results establish the efficacy of superconducting analogue-digital quantum processors for preparing states across many-body spectra and unveiling their thermalization dynamics.
The prevailing view is that quantum phenomena can be harnessed to tackle certain problems beyond the reach of classical approaches. Quantifying this capability as a quantum-classical separation and demonstrating it on current quantum processors has remained elusive. Using a superconducting qubit processor, we show that quantum contextuality enables certain tasks to be performed with success probabilities beyond classical limits. With a few qubits, we illustrate quantum contextuality with the magic square game, as well as quantify it through a Kochen–Specker–Bell inequality violation. To examine many-body contextuality, we implement the N-player GHZ game and separately solve a 2D hidden linear function problem, exceeding classical success rate in both. Our work proposes novel ways to benchmark quantum processors using contextuality-based algorithms.
Quantum observables in the form of few-point correlators are the key to characterizing the dynamics of quantum many-body systems. In dynamics with fast entanglement generation, quantum observables generally become insensitive to the details of the underlying dynamics at long times due to the effects of scrambling. In experimental systems, repeated time-reversal protocols have been successfully implemented to restore sensitivities of quantum observables. Using a 103-qubit superconducting quantum processor, we characterize ergodic dynamics using the second-order out-of-time-order correlators, OTOC^(2). In contrast to dynamics without time reversal, OTOC^(2) are observed to remain sensitive to the underlying dynamics at long time scales. Furthermore, by inserting Pauli operators during quantum evolution and randomizing the phases of Pauli strings in the Heisenberg picture, we observe substantial changes in OTOC^(2) values. This indicates that OTOC^(2) is dominated by constructive interference between Pauli strings that form large loops in configuration space. The observed interference mechanism endows OTOC^(2) with a high degree of classical simulation complexity, which culminates in a set of large-scale OTOC^(2) measurements exceeding the simulation capacity of known classical algorithms. Further supported by an example of Hamiltonian learning through OTOC^(2), our results indicate a viable path to practical quantum advantage.
We investigate the problem of efficiently estimating expectation values of large sets of observables from copies of an unknown many-body quantum state. This task, known as shadow tomography, is crucial for quantum simulation and quantum chemistry, where the relevant observables often include k-body fermionic or k-local Pauli operators. A key goal is to achieve sample efficiency, computational efficiency, and few-copy measurements. We introduce the notion of triply efficient shadow tomography to formalize these requirements. Prior work has shown that single-copy measurements suffice for k-local Pauli operators with constant k. However, we prove that for k-body fermionic observables and the full set of n-qubit Pauli operators, single-copy protocols fail to achieve sample-efficient tomography. We then present new protocols based on measuring two copies of the state at a time that overcome these lower bounds, providing a triply efficient protocol.
The solution of linear systems of equations is the basis of many other quantum algorithms, and recent results provided an algorithm with optimal scaling in both the condition number $\kappa$ and the allowable error $\epsilon$ [PRX Quantum \textbf{3}, 0403003 (2022)]. That work was based on the discrete adiabatic theorem, and worked out an explicit constant factor for an upper bound on the complexity. Here we show via numerical testing on random matrices that the constant factor is in practice about 1,500 times smaller than the upper bound found numerically in the previous results. That means that this approach is far more efficient than might naively be expected from the upper bound. In particular, it is over an order of magnitude more efficient than using a randomised approach from [arXiv:2305.11352] that claimed to be more efficient.
Holistic resource estimates are essential for guiding the development of fault-tolerant quantum algorithms and the computers they will run on. This is particularly true when we focus on highly-constrained early fault-tolerant devices. Many attempts to optimize algorithms for early fault-tolerance focus on simple metrics, such as the circuit depth or T-count. These metrics fail to capture critical overheads, such as the spacetime cost of Clifford operations and routing, or miss they key optimizations. We propose the FLuid Allocation of Surface code Qubits (FLASQ) cost model, tailored for architectures that use a two-dimensional lattice of qubits to implement the two-dimensional surface code. FLASQ abstracts away the complexity of routing by assuming that ancilla space and time can be fluidly rearranged, allowing for the tractable estimation of spacetime volume while still capturing important details neglected by simpler approaches. At the same time, it enforces constraints imposed by the circuit's measurement depth and the processor's reaction time. We apply FLASQ to analyze the cost of a standard two-dimensional lattice model simulation, finding that modern advances (such as magic state cultivation and the combination of quantum error correction and mitigation) reduce both the time and space required for this task by an order of magnitude compared with previous estimates. We also analyze the Hamming weight phasing approach to synthesizing parallel rotations, revealing that despite its low T-count, the overhead from imposing a 2D layout and from its use of additional ancilla qubits will make it challenging to benefit from in early fault-tolerance. We hope that the FLASQ cost model will help to better align early fault-tolerant algorithmic design with actual hardware realization costs without demanding excessive knowledge of quantum error correction from quantum algorithmists.