P Shor 1994 polynomial-time factoring + discrete-log; modern Gidney-Ekera 2021 estimates 20M qubits to break RSA-2048.